<?xml version="1.0" encoding="UTF-8"?>
<oval xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval#unix unix-schema.xsd http://oval.mitre.org/XMLSchema/oval#independent independent-schema.xsd http://oval.mitre.org/XMLSchema/oval#solaris solaris-schema.xsd http://oval.mitre.org/XMLSchema/oval oval-schema.xsd" xmlns:oval="http://oval.mitre.org/XMLSchema/oval" xmlns="http://oval.mitre.org/XMLSchema/oval" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:solaris="http://oval.mitre.org/XMLSchema/oval#solaris">
  <generator>
    <schema_version>4.1</schema_version>
    <timestamp>20051116211256</timestamp>
  </generator>
  <definitions>
    <definition id="OVAL7" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 8</solaris:platform>
        <product>kcms_configure</product>
      </affected>
      <dates>
        <submitted date="2002-09-17-12:00">
          <contributor organization="The MITRE Corporation">David Proulx</contributor>
        </submitted>
      </dates>
      <description>kcms_configure as included with Solaris 7 and 8 allows a local attacker to gain additional privileges via a buffer overflow in a command line argument.</description>
      <reference source="CVE">CVE-2001-0594</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="uut-4" comment="Solaris 8 Installed" negate="false"/>
          <criterion test_ref="uft-5" comment="File kcms_configure exists" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-202" comment="File kcms_configure executable and SUID or SGID" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL9" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 8</solaris:platform>
        <product>libnsl</product>
      </affected>
      <dates>
        <submitted date="2003-01-28-12:00">
          <contributor organization="The MITRE Corporation">David Proulx</contributor>
        </submitted>
      </dates>
      <description>Integer overflow in xdr_array function in RPC servers for operating systems that use libc, glibc, or other code based on SunRPC including dietlibc, allows remote attackers to execute arbitrary code by passing a large number of arguments to xdr_array through RPC services such as rpc.cmsd and dmispd.</description>
      <reference source="CVE">CVE-2002-0391</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="uut-4" comment="Solaris 8 Installed" negate="false"/>
          <criterion test_ref="cmp-204" comment="rpc.cmsd or dmispd exist" negate="false"/>
          <criterion test_ref="cmp-205" comment="Patches 108827-30 and 108901-06" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-206" comment="rpc.cmsd enabled OR dmispd running" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL10" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 8</solaris:platform>
        <product>xlock</product>
      </affected>
      <dates>
        <submitted date="2002-09-17-12:00">
          <contributor organization="The MITRE Corporation">David Proulx</contributor>
        </submitted>
      </dates>
      <description>Heap overflow in xlock in Solaris 2.6 through 8 allows local users to gain root privileges via a long (1) XFILESEARCHPATH or (2) XUSERFILESEARCHPATH environmental variable.</description>
      <reference source="CVE">CVE-2001-0652</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="uut-4" comment="Solaris 8 Installed" negate="false"/>
          <criterion test_ref="uft-8" comment="File xlock exists" negate="false"/>
          <criterion test_ref="spt-203" comment="Patch 108652-38 or later installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-209" comment="File xlock SUID and executable" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL11" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 8</solaris:platform>
        <product>snmpdx</product>
      </affected>
      <dates>
        <submitted date="2002-09-25-12:00">
          <contributor organization="The MITRE Corporation">David Proulx</contributor>
        </submitted>
      </dates>
      <description>Format string vulnerability in the logging component of snmpdx for Solaris 5.6 through 8 allows remote attackers to gain root privileges.</description>
      <reference source="CVE">CVE-2002-0796</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="uut-4" comment="Solaris 8 Installed" negate="false"/>
          <criterion test_ref="uft-9" comment="File snmpdx exists" negate="false"/>
          <criterion test_ref="spt-204" comment="Patch 108869-16 or later installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="uct-6" comment="snmpdx running" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL14" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 8</solaris:platform>
        <product>Xsun</product>
      </affected>
      <dates>
        <submitted date="2002-08-23-12:00">
          <contributor organization="The MITRE Corporation">David Proulx</contributor>
        </submitted>
      </dates>
      <description>Buffer overflow in Xsun on Solaris 2.6 through 8 allows local users to gain root privileges via a long -co (color database) command line argument.</description>
      <reference source="CVE">CVE-2002-0158</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="uut-4" comment="Solaris 8 Installed" negate="false"/>
          <criterion test_ref="uft-10" comment="File Xsun exists" negate="false"/>
          <criterion test_ref="spt-205" comment="Patch 108652-52 or later installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-210" comment="File Xsun SGID and executable" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL15" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 8</solaris:platform>
        <product>CDE</product>
      </affected>
      <dates>
        <submitted date="2003-01-31-12:00">
          <contributor organization="The MITRE Corporation">David Proulx</contributor>
        </submitted>
      </dates>
      <description>CDE ToolTalk database server (ttdbserver) allows remote attackers to overwrite arbitrary memory locations with a zero, and possibly gain privileges, via a file descriptor argument in an AUTH_UNIX procedure call, which is used as a table index by the _TT_ISCLOSE procedure.</description>
      <reference source="CVE">CVE-2002-0677</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="uut-4" comment="Solaris 8 Installed" negate="false"/>
          <criterion test_ref="uft-11" comment="File rpc.ttdbserverd exists" negate="false"/>
          <criterion test_ref="spt-206" comment="Patch 110286-09 or later installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="sit-202" comment="inetd.conf contains rpc.ttdbserverd" negate="false"/>
          <criterion test_ref="uct-4" comment="inetd running" negate="false"/>
          <criterion test_ref="cmp-211" comment="File rpc.ttdbserverd executable" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL31" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 8</solaris:platform>
        <product>cachefsd</product>
      </affected>
      <dates>
        <submitted date="2003-01-31-12:00">
          <contributor organization="The MITRE Corporation">David Proulx</contributor>
        </submitted>
        <modified date="2005-01-28-12:00" comment="Updated to include Solaris 9 and Solaris 9 patch info">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </modified>
        <status_change date="2005-02-01-08:24">INTERIM</status_change>
        <status_change date="2005-02-16-12:00">ACCEPTED</status_change>
      </dates>
      <description>Heap-based buffer overflow in cfsd_calloc function of Solaris cachefsd allows remote attackers to execute arbitrary code via a request with a long directory and cache name.</description>
      <reference source="CVE">CVE-2002-0033</reference>
      <status>ACCEPTED</status>
      <version>3</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="uft-12" comment="File cachefsd exists" negate="false"/>
          <criterion test_ref="spt-207" comment="Patch 110896-02 or later installed" negate="true"/>
          <criterion test_ref="cmp-1081" comment="Solaris 8 or 9 installed" negate="false"/>
          <criterion test_ref="spt-111" comment="Patch 114008-01 or later installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="sit-203" comment="inetd.conf contains cachefsd" negate="false"/>
          <criterion test_ref="uct-4" comment="inetd running" negate="false"/>
          <criterion test_ref="cmp-217" comment="File cachefsd executable" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL33" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 7</solaris:platform>
        <product>Xsun</product>
      </affected>
      <dates>
        <submitted date="2002-10-17-12:00">
          <contributor organization="The MITRE Corporation">David Proulx</contributor>
        </submitted>
      </dates>
      <description>Buffer overflow in Xsun on Solaris 2.6 through 8 allows local users to gain root privileges via a long -co (color database) command line argument.</description>
      <reference source="CVE">CVE-2002-0158</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="uut-5" comment="Solaris 7 Installed" negate="false"/>
          <criterion test_ref="uft-10" comment="File Xsun exists" negate="false"/>
          <criterion test_ref="spt-208" comment="Patch 108376-38 or later installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-210" comment="File Xsun SGID and executable" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL34" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 7</solaris:platform>
        <product>whodo</product>
      </affected>
      <dates>
        <submitted date="2002-10-17-12:00">
          <contributor organization="The MITRE Corporation">David Proulx</contributor>
        </submitted>
      </dates>
      <description>Buffer overflow in whodo in Solaris SunOS 5.5.1 through 5.8 allows local users to execute arbitrary code via a long (1) SOR or (2) CFIME environment variable.</description>
      <reference source="CVE">CVE-2001-1076</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="uut-5" comment="Solaris 7 Installed" negate="false"/>
          <criterion test_ref="uft-13" comment="File whodo exists" negate="false"/>
          <criterion test_ref="spt-209" comment="Patch 111600-01 or later installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-219" comment="File whodo SUID and executable" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL41" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 7</solaris:platform>
        <product>rpc.rwalld</product>
      </affected>
      <dates>
        <submitted date="2003-01-30-12:00">
          <contributor organization="The MITRE Corporation">David Proulx</contributor>
        </submitted>
      </dates>
      <description>Format string vulnerability in RPC wall daemon (rpc.rwalld) for Solaris 2.5.1 through 8 allows remote attackers to execute arbitrary code via format strings in a message that is not properly provided to the syslog function when the wall command cannot be executed.</description>
      <reference source="CVE">CVE-2002-0573</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="uut-5" comment="Solaris 7 Installed" negate="false"/>
          <criterion test_ref="uft-14" comment="File rpc.rwalld exists" negate="false"/>
          <criterion test_ref="spt-210" comment="Patch 112899-01 or later installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="sit-204" comment="inetd.conf contains rpc.rwalld" negate="false"/>
          <criterion test_ref="uct-4" comment="inetd running" negate="false"/>
          <criterion test_ref="cmp-221" comment="File rpc.rwalld executable" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL42" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 7</solaris:platform>
        <product>libnsl</product>
      </affected>
      <dates>
        <submitted date="2003-01-02-12:00">
          <contributor organization="The MITRE Corporation">David Proulx</contributor>
        </submitted>
      </dates>
      <description>Integer overflow in xdr_array function in RPC servers for operating systems that use libc, glibc, or other code based on SunRPC including dietlibc, allows remote attackers to execute arbitrary code by passing a large number of arguments to xdr_array through RPC services such as rpc.cmsd and dmispd.</description>
      <reference source="CVE">CVE-2002-0391</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="uut-5" comment="Solaris 7 Installed" negate="false"/>
          <criterion test_ref="cmp-204" comment="rpc.cmsd or dmispd exist" negate="false"/>
          <criterion test_ref="cmp-223" comment="Patches 106942-22 and 108451-06" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-206" comment="rpc.cmsd enabled OR dmispd running" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL43" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 7</solaris:platform>
        <product>cachefsd</product>
      </affected>
      <dates>
        <submitted date="2002-10-17-12:00">
          <contributor organization="The MITRE Corporation">David Proulx</contributor>
        </submitted>
        <modified date="2005-01-28-12:00" comment="Updated to add patch test">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </modified>
        <status_change date="2005-02-01-08:25">INTERIM</status_change>
        <status_change date="2005-02-16-12:00">ACCEPTED</status_change>
      </dates>
      <description>Buffer overflow in the fscache_setup function of cachefsd in Solaris 2.6, 7, and 8 allows local users to gain root privileges via a long mount argument.</description>
      <reference source="CVE">CVE-2002-0084</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="uut-5" comment="Solaris 7 Installed" negate="false"/>
          <criterion test_ref="uft-12" comment="File cachefsd exists" negate="false"/>
          <criterion test_ref="spt-109" comment="Patch 108800-02 or later installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="sit-203" comment="inetd.conf contains cachefsd" negate="false"/>
          <criterion test_ref="uct-4" comment="inetd running" negate="false"/>
          <criterion test_ref="cmp-217" comment="File cachefsd executable" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL47" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 8</solaris:platform>
        <product>whodo</product>
      </affected>
      <dates>
        <submitted date="2002-09-17-12:00">
          <contributor organization="The MITRE Corporation">David Proulx</contributor>
        </submitted>
      </dates>
      <description>Buffer overflow in whodo in Solaris SunOS 5.5.1 through 5.8 allows local users to execute arbitrary code via a long (1) SOR or (2) CFIME environment variable.</description>
      <reference source="CVE">CVE-2001-1076</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="uut-4" comment="Solaris 8 Installed" negate="false"/>
          <criterion test_ref="uft-13" comment="File whodo exists" negate="false"/>
          <criterion test_ref="spt-213" comment="Patch 111826-01 or later installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-219" comment="File whodo SUID and executable" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL48" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 7</solaris:platform>
        <product>admintool</product>
      </affected>
      <dates>
        <submitted date="2002-10-17-12:00">
          <contributor organization="The MITRE Corporation">David Proulx</contributor>
        </submitted>
      </dates>
      <description>Buffer overflow in admintool in Solaris 2.6, 7, and 8 allows local users to gain root privileges via a long media installation path.</description>
      <reference source="CVE">CVE-2002-0088</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="uut-5" comment="Solaris 7 Installed" negate="false"/>
          <criterion test_ref="uft-15" comment="File admintool exists" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-229" comment="File admintool SUID and executable" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL56" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 8</solaris:platform>
        <product>rpc.yppasswdd</product>
      </affected>
      <dates>
        <submitted date="2002-08-30-12:00">
          <contributor organization="The MITRE Corporation">David Proulx</contributor>
        </submitted>
      </dates>
      <description>Buffer overflow in rpc.yppasswdd (yppasswd server) in Solaris 2.6, 7 and 8 allows remote attackers to gain root access via a long username.</description>
      <reference source="CVE">CVE-2001-0779</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="uut-4" comment="Solaris 8 Installed" negate="false"/>
          <criterion test_ref="uft-16" comment="File rpc.yppasswdd exists" negate="false"/>
          <criterion test_ref="spt-214" comment="Patch 111596-02 or later installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="uct-7" comment="rpc.yppasswdd running" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL60" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 8</solaris:platform>
        <product>admintool</product>
      </affected>
      <dates>
        <submitted date="2002-09-17-12:00">
          <contributor organization="The MITRE Corporation">David Proulx</contributor>
        </submitted>
      </dates>
      <description>Buffer overflow in admintool in Solaris 2.6, 7, and 8 allows local users to gain root privileges via a long media installation path.</description>
      <reference source="CVE">CVE-2002-0088</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="uut-4" comment="Solaris 8 Installed" negate="false"/>
          <criterion test_ref="uft-15" comment="File admintool exists" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-229" comment="File admintool SUID and executable" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL62" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 7</solaris:platform>
        <product>mibiisa</product>
      </affected>
      <dates>
        <submitted date="2002-10-17-12:00">
          <contributor organization="The MITRE Corporation">David Proulx</contributor>
        </submitted>
      </dates>
      <description>Buffer overflow in the MIB parsing component of mibiisa for Solaris 5.6 through 8 allows remote attackers to gain root privileges.</description>
      <reference source="CVE">CVE-2002-0797</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="uut-5" comment="Solaris 7 Installed" negate="false"/>
          <criterion test_ref="uft-17" comment="File mibiisa exists" negate="false"/>
          <criterion test_ref="spt-215" comment="Patch 107709-19 or later installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="uct-8" comment="mibiisa running" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL65" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 7</solaris:platform>
        <product>kcms_configure</product>
      </affected>
      <dates>
        <submitted date="2002-09-17-12:00">
          <contributor organization="The MITRE Corporation">David Proulx</contributor>
        </submitted>
      </dates>
      <description>kcms_configure as included with Solaris 7 and 8 allows a local attacker to gain additional privileges via a buffer overflow in a command line argument.</description>
      <reference source="CVE">CVE-2001-0594</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="uut-5" comment="Solaris 7 Installed" negate="false"/>
          <criterion test_ref="uft-5" comment="File kcms_configure exists" negate="false"/>
          <criterion test_ref="spt-216" comment="Patch 107337-02 or later installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-202" comment="File kcms_configure executable and SUID or SGID" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL67" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 8</solaris:platform>
        <product>admintool</product>
      </affected>
      <dates>
        <submitted date="2002-09-17-12:00">
          <contributor organization="The MITRE Corporation">David Proulx</contributor>
        </submitted>
      </dates>
      <description>Buffer overflow in admintool in Solaris 2.5 through 8 allows local users to gain root privileges via long arguments to (1) the -d command line option, or (2) the PRODVERS argument in the .cdtoc file.</description>
      <reference source="CVE">CVE-2002-0089</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="uut-4" comment="Solaris 8 Installed" negate="false"/>
          <criterion test_ref="uft-15" comment="File admintool exists" negate="false"/>
          <criterion test_ref="spt-217" comment="Patch 110453-01 or later installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-229" comment="File admintool SUID and executable" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL68" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 7</solaris:platform>
        <product>admintool</product>
      </affected>
      <dates>
        <submitted date="2002-10-17-12:00">
          <contributor organization="The MITRE Corporation">David Proulx</contributor>
        </submitted>
      </dates>
      <description>Buffer overflow in admintool in Solaris 2.5 through 8 allows local users to gain root privileges via long arguments to (1) the -d command line option, or (2) the PRODVERS argument in the .cdtoc file.</description>
      <reference source="CVE">CVE-2002-0089</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="uut-5" comment="Solaris 7 Installed" negate="false"/>
          <criterion test_ref="uft-15" comment="File admintool exists" negate="false"/>
          <criterion test_ref="spt-218" comment="Patch 108721-02 or later installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-229" comment="File admintool SUID and executable" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL70" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 8</solaris:platform>
        <product>dtspcd</product>
      </affected>
      <dates>
        <submitted date="2002-08-23-12:00">
          <contributor organization="The MITRE Corporation">David Proulx</contributor>
        </submitted>
      </dates>
      <description>Buffer overflow in the client connection routine of libDtSvc.so.1 in CDE Subprocess Control Service (dtspcd) allows remote attackers to execute arbitrary commands</description>
      <reference source="CVE">CVE-2001-0803</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="uut-4" comment="Solaris 8 Installed" negate="false"/>
          <criterion test_ref="uft-18" comment="File dtspcd exists" negate="false"/>
          <criterion test_ref="spt-219" comment="Patch 108949-07 or later installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="sit-205" comment="inetd.conf contains dtspcd" negate="false"/>
          <criterion test_ref="uct-4" comment="inetd running" negate="false"/>
          <criterion test_ref="cmp-239" comment="File dtspcd executable" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL74" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 7</solaris:platform>
        <product>dtspcd</product>
      </affected>
      <dates>
        <submitted date="2002-10-17-12:00">
          <contributor organization="The MITRE Corporation">David Proulx</contributor>
        </submitted>
      </dates>
      <description>Buffer overflow in the client connection routine of libDtSvc.so.1 in CDE Subprocess Control Service (dtspcd) allows remote attackers to execute arbitrary commands</description>
      <reference source="CVE">CVE-2001-0803</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="uut-5" comment="Solaris 7 Installed" negate="false"/>
          <criterion test_ref="uft-18" comment="File dtspcd exists" negate="false"/>
          <criterion test_ref="spt-220" comment="Patch 106934-04 or later installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="sit-205" comment="inetd.conf contains dtspcd" negate="false"/>
          <criterion test_ref="uct-4" comment="inetd running" negate="false"/>
          <criterion test_ref="cmp-239" comment="File dtspcd executable" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL79" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 8</solaris:platform>
        <product>rpc.rwalld</product>
      </affected>
      <dates>
        <submitted date="2003-01-30-12:00">
          <contributor organization="The MITRE Corporation">David Proulx</contributor>
        </submitted>
      </dates>
      <description>Format string vulnerability in RPC wall daemon (rpc.rwalld) for Solaris 2.5.1 through 8 allows remote attackers to execute arbitrary code via format strings in a message that is not properly provided to the syslog function when the wall command cannot be executed.</description>
      <reference source="CVE">CVE-2002-0573</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="uut-4" comment="Solaris 8 Installed" negate="false"/>
          <criterion test_ref="uft-14" comment="File rpc.rwalld exists" negate="false"/>
          <criterion test_ref="spt-221" comment="Patch 112846-01 or later installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="sit-204" comment="inetd.conf contains rpc.rwalld" negate="false"/>
          <criterion test_ref="uct-4" comment="inetd running" negate="false"/>
          <criterion test_ref="cmp-221" comment="File rpc.rwalld executable" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL80" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 7</solaris:platform>
        <product>CDE</product>
      </affected>
      <dates>
        <submitted date="2003-01-29-12:00">
          <contributor organization="The MITRE Corporation">David Proulx</contributor>
        </submitted>
      </dates>
      <description>CDE ToolTalk database server (ttdbserver) allows local users to overwrite arbitrary files via a symlink attack on the transaction log file used by the _TT_TRANSACTION RPC procedure.</description>
      <reference source="CVE">CVE-2002-0678</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="uut-5" comment="Solaris 7 Installed" negate="false"/>
          <criterion test_ref="uft-11" comment="File rpc.ttdbserverd exists" negate="false"/>
          <criterion test_ref="spt-222" comment="Patch 107893-19 or later installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="sit-202" comment="inetd.conf contains rpc.ttdbserverd" negate="false"/>
          <criterion test_ref="uct-4" comment="inetd running" negate="false"/>
          <criterion test_ref="cmp-211" comment="File rpc.ttdbserverd executable" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL86" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 8</solaris:platform>
        <product>lbxproxy</product>
      </affected>
      <dates>
        <submitted date="2002-08-30-12:00">
          <contributor organization="The MITRE Corporation">David Proulx</contributor>
        </submitted>
      </dates>
      <description>Buffer overflow in Low BandWidth X proxy (lbxproxy) in Solaris 8 allows local users to execute arbitrary code via a long display command line option.</description>
      <reference source="CVE">CVE-2002-0090</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="uut-4" comment="Solaris 8 Installed" negate="false"/>
          <criterion test_ref="uft-19" comment="File lbxproxy exists" negate="false"/>
          <criterion test_ref="spt-223" comment="Patch 108652-51 or later installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-247" comment="File lbxproxy SGID and executable" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL91" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 7</solaris:platform>
        <product>CDE</product>
      </affected>
      <dates>
        <submitted date="2003-01-31-12:00">
          <contributor organization="The MITRE Corporation">David Proulx</contributor>
        </submitted>
      </dates>
      <description>CDE ToolTalk database server (ttdbserver) allows remote attackers to overwrite arbitrary memory locations with a zero, and possibly gain privileges, via a file descriptor argument in an AUTH_UNIX procedure call, which is used as a table index by the _TT_ISCLOSE procedure.</description>
      <reference source="CVE">CVE-2002-0677</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="uut-5" comment="Solaris 7 Installed" negate="false"/>
          <criterion test_ref="uft-11" comment="File rpc.ttdbserverd exists" negate="false"/>
          <criterion test_ref="spt-222" comment="Patch 107893-19 or later installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="sit-202" comment="inetd.conf contains rpc.ttdbserverd" negate="false"/>
          <criterion test_ref="uct-4" comment="inetd running" negate="false"/>
          <criterion test_ref="cmp-211" comment="File rpc.ttdbserverd executable" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL94" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 8</solaris:platform>
        <product>mibiisa</product>
      </affected>
      <dates>
        <submitted date="2002-09-25-12:00">
          <contributor organization="The MITRE Corporation">David Proulx</contributor>
        </submitted>
      </dates>
      <description>Buffer overflow in the MIB parsing component of mibiisa for Solaris 5.6 through 8 allows remote attackers to gain root privileges.</description>
      <reference source="CVE">CVE-2002-0797</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="uut-4" comment="Solaris 8 Installed" negate="false"/>
          <criterion test_ref="uft-17" comment="File mibiisa exists" negate="false"/>
          <criterion test_ref="spt-204" comment="Patch 108869-16 or later installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="uct-8" comment="mibiisa running" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL97" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 8</solaris:platform>
        <product>cachefsd</product>
      </affected>
      <dates>
        <submitted date="2002-09-17-12:00">
          <contributor organization="The MITRE Corporation">David Proulx</contributor>
        </submitted>
        <modified date="2005-01-27-12:00" comment="Updated to add patch test">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </modified>
        <modified date="2005-01-28-12:00" comment="Added Solaris 9 and Solaris 9 patch test to the definition">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </modified>
        <status_change date="2005-02-01-08:28">INTERIM</status_change>
        <status_change date="2005-02-16-12:00">ACCEPTED</status_change>
      </dates>
      <description>Buffer overflow in the fscache_setup function of cachefsd in Solaris 2.6, 7, and 8 allows local users to gain root privileges via a long mount argument.</description>
      <reference source="CVE">CVE-2002-0084</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="uft-12" comment="File cachefsd exists" negate="false"/>
          <criterion test_ref="cmp-1081" comment="Solaris 8 or 9 installed" negate="false"/>
          <criterion test_ref="spt-110" comment="Patch 110896-02 or later installed" negate="true"/>
          <criterion test_ref="spt-111" comment="Patch 114008-01 or later installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="sit-203" comment="inetd.conf contains cachefsd" negate="false"/>
          <criterion test_ref="uct-4" comment="inetd running" negate="false"/>
          <criterion test_ref="cmp-217" comment="File cachefsd executable" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL102" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 7</solaris:platform>
        <product>rpc.yppasswdd</product>
      </affected>
      <dates>
        <submitted date="2002-10-17-12:00">
          <contributor organization="The MITRE Corporation">David Proulx</contributor>
        </submitted>
      </dates>
      <description>Buffer overflow in rpc.yppasswdd (yppasswd server) in Solaris 2.6, 7 and 8 allows remote attackers to gain root access via a long username.</description>
      <reference source="CVE">CVE-2001-0779</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="uut-5" comment="Solaris 7 Installed" negate="false"/>
          <criterion test_ref="uft-16" comment="File rpc.yppasswdd exists" negate="false"/>
          <criterion test_ref="spt-224" comment="Patch 111590-02 or later installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="uct-7" comment="rpc.yppasswdd running" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL114" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 7</solaris:platform>
        <product>snmpdx</product>
      </affected>
      <dates>
        <submitted date="2002-10-17-12:00">
          <contributor organization="The MITRE Corporation">David Proulx</contributor>
        </submitted>
      </dates>
      <description>Format string vulnerability in the logging component of snmpdx for Solaris 5.6 through 8 allows remote attackers to gain root privileges.</description>
      <reference source="CVE">CVE-2002-0796</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="uut-5" comment="Solaris 7 Installed" negate="false"/>
          <criterion test_ref="uft-9" comment="File snmpdx exists" negate="false"/>
          <criterion test_ref="spt-215" comment="Patch 107709-19 or later installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="uct-6" comment="snmpdx running" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL120" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 7</solaris:platform>
        <product>kcms_server</product>
      </affected>
      <dates>
        <submitted date="2003-01-30-12:00">
          <contributor organization="The MITRE Corporation">David Proulx</contributor>
        </submitted>
      </dates>
      <description>Directory traversal vulnerability in Sun Kodak Color Management System (KCMS) library service daemon (kcms_server) allows remote attackers to read arbitrary files via the KCS_OPEN_PROFILE procedure.</description>
      <reference source="CVE">CVE-2003-0027</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="uut-5" comment="Solaris 7 Installed" negate="false"/>
          <criterion test_ref="uft-20" comment="File kcms_server exists" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="sit-206" comment="inetd.conf contains kcms_server" negate="false"/>
          <criterion test_ref="uct-4" comment="inetd running" negate="false"/>
          <criterion test_ref="cmp-255" comment="File kcms_server executable and SUID or SGID" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL124" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 7</solaris:platform>
        <product>cachefsd</product>
      </affected>
      <dates>
        <submitted date="2002-10-17-12:00">
          <contributor organization="The MITRE Corporation">David Proulx</contributor>
        </submitted>
        <modified date="2005-01-28-12:00" comment="Added patch test">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </modified>
        <status_change date="2005-02-01-08:29">INTERIM</status_change>
        <status_change date="2005-02-16-12:00">ACCEPTED</status_change>
      </dates>
      <description>Heap-based buffer overflow in cfsd_calloc function of Solaris cachefsd allows remote attackers to execute arbitrary code via a request with a long directory and cache name.</description>
      <reference source="CVE">CVE-2002-0033</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="uut-5" comment="Solaris 7 Installed" negate="false"/>
          <criterion test_ref="uft-12" comment="File cachefsd exists" negate="false"/>
          <criterion test_ref="spt-109" comment="Patch 108800-02 or later installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="sit-203" comment="inetd.conf contains cachefsd" negate="false"/>
          <criterion test_ref="uct-4" comment="inetd running" negate="false"/>
          <criterion test_ref="cmp-217" comment="File cachefsd executable" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL131" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 7</solaris:platform>
        <product>xlock</product>
      </affected>
      <dates>
        <submitted date="2002-10-17-12:00">
          <contributor organization="The MITRE Corporation">David Proulx</contributor>
        </submitted>
      </dates>
      <description>Heap overflow in xlock in Solaris 2.6 through 8 allows local users to gain root privileges via a long (1) XFILESEARCHPATH or (2) XUSERFILESEARCHPATH environmental variable.</description>
      <reference source="CVE">CVE-2001-0652</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="uut-5" comment="Solaris 7 Installed" negate="false"/>
          <criterion test_ref="uft-8" comment="File xlock exists" negate="false"/>
          <criterion test_ref="spt-225" comment="Patch 108376-30 or later installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-209" comment="File xlock SUID and executable" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL149" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 8</solaris:platform>
        <product>fs.auto, xfs</product>
      </affected>
      <dates>
        <submitted date="2003-09-08-12:00">
          <contributor organization="The MITRE Corporation">David Proulx</contributor>
        </submitted>
      </dates>
      <description>Buffer overflow in Dispatch() routine for XFS font server (fs.auto) on Solaris 2.5.1 through 9 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a certain XFS query.</description>
      <reference source="CVE">CVE-2002-1317</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="uut-4" comment="Solaris 8 Installed" negate="false"/>
          <criterion test_ref="uft-21" comment="File fs.auto exists" negate="false"/>
          <criterion test_ref="uft-22" comment="File xfs exists" negate="false"/>
          <criterion test_ref="spt-226" comment="Patch 109862-03 or later installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="sit-207" comment="inetd.conf contains fs.auto" negate="false"/>
          <criterion test_ref="uct-4" comment="inetd running" negate="false"/>
          <criterion test_ref="cmp-267" comment="File xfs executable" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL152" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 7</solaris:platform>
        <product>fs.auto, xfs</product>
      </affected>
      <dates>
        <submitted date="2003-09-08-12:00">
          <contributor organization="The MITRE Corporation">David Proulx</contributor>
        </submitted>
      </dates>
      <description>Buffer overflow in Dispatch() routine for XFS font server (fs.auto) on Solaris 2.5.1 through 9 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a certain XFS query.</description>
      <reference source="CVE">CVE-2002-1317</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="uut-5" comment="Solaris 7 Installed" negate="false"/>
          <criterion test_ref="uft-21" comment="File fs.auto exists" negate="false"/>
          <criterion test_ref="uft-22" comment="File xfs exists" negate="false"/>
          <criterion test_ref="spt-227" comment="Patch 108117-06 or later installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="sit-207" comment="inetd.conf contains fs.auto" negate="false"/>
          <criterion test_ref="uct-4" comment="inetd running" negate="false"/>
          <criterion test_ref="cmp-267" comment="File xfs executable" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL175" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 8</solaris:platform>
        <product>CDE</product>
      </affected>
      <dates>
        <submitted date="2003-01-29-12:00">
          <contributor organization="The MITRE Corporation">David Proulx</contributor>
        </submitted>
      </dates>
      <description>CDE ToolTalk database server (ttdbserver) allows local users to overwrite arbitrary files via a symlink attack on the transaction log file used by the _TT_TRANSACTION RPC procedure.</description>
      <reference source="CVE">CVE-2002-0678</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="uut-4" comment="Solaris 8 Installed" negate="false"/>
          <criterion test_ref="uft-11" comment="File rpc.ttdbserverd exists" negate="false"/>
          <criterion test_ref="spt-206" comment="Patch 110286-09 or later installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="sit-202" comment="inetd.conf contains rpc.ttdbserverd" negate="false"/>
          <criterion test_ref="uct-4" comment="inetd running" negate="false"/>
          <criterion test_ref="cmp-211" comment="File rpc.ttdbserverd executable" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL177" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 7</solaris:platform>
        <product>CDE</product>
      </affected>
      <dates>
        <submitted date="2003-01-29-12:00">
          <contributor organization="The MITRE Corporation">David Proulx</contributor>
        </submitted>
      </dates>
      <description>Buffer overflow in Common Desktop Environment (CDE) ToolTalk RPC database server (rpc.ttdbserverd) allows remote attackers to execute arbitrary code via an argument to the _TT_CREATE_FILE procedure.</description>
      <reference source="CVE">CVE-2002-0679</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="uut-5" comment="Solaris 7 Installed" negate="false"/>
          <criterion test_ref="uft-11" comment="File rpc.ttdbserverd exists" negate="false"/>
          <criterion test_ref="spt-228" comment="Patch 107893-20 or later installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="sit-202" comment="inetd.conf contains rpc.ttdbserverd" negate="false"/>
          <criterion test_ref="uct-4" comment="inetd running" negate="false"/>
          <criterion test_ref="cmp-211" comment="File rpc.ttdbserverd executable" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL179" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 7</solaris:platform>
        <product>lbxproxy</product>
      </affected>
      <dates>
        <submitted date="2002-10-17-12:00">
          <contributor organization="The MITRE Corporation">David Proulx</contributor>
        </submitted>
      </dates>
      <description>Buffer overflow in Low BandWidth X proxy (lbxproxy) in Solaris 8 allows local users to execute arbitrary code via a long display command line option.</description>
      <reference source="CVE">CVE-2002-0090</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="uut-5" comment="Solaris 7 Installed" negate="false"/>
          <criterion test_ref="uft-19" comment="File lbxproxy exists" negate="false"/>
          <criterion test_ref="spt-229" comment="Patch 107654-10 or later installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-247" comment="File lbxproxy SGID and executable" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL192" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 8</solaris:platform>
        <product>CDE</product>
      </affected>
      <dates>
        <submitted date="2003-01-29-12:00">
          <contributor organization="The MITRE Corporation">David Proulx</contributor>
        </submitted>
      </dates>
      <description>Buffer overflow in Common Desktop Environment (CDE) ToolTalk RPC database server (rpc.ttdbserverd) allows remote attackers to execute arbitrary code via an argument to the _TT_CREATE_FILE procedure.</description>
      <reference source="CVE">CVE-2002-0679</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="uut-4" comment="Solaris 8 Installed" negate="false"/>
          <criterion test_ref="uft-11" comment="File rpc.ttdbserverd exists" negate="false"/>
          <criterion test_ref="spt-230" comment="Patch 110286-10 or later installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="sit-202" comment="inetd.conf contains rpc.ttdbserverd" negate="false"/>
          <criterion test_ref="uct-4" comment="inetd running" negate="false"/>
          <criterion test_ref="cmp-211" comment="File rpc.ttdbserverd executable" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL195" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 8</solaris:platform>
        <product>kcms_server</product>
      </affected>
      <dates>
        <submitted date="2003-01-24-12:00">
          <contributor organization="The MITRE Corporation">David Proulx</contributor>
        </submitted>
      </dates>
      <description>Directory traversal vulnerability in Sun Kodak Color Management System (KCMS) library service daemon (kcms_server) allows remote attackers to read arbitrary files via the KCS_OPEN_PROFILE procedure.</description>
      <reference source="CVE">CVE-2003-0027</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="uut-4" comment="Solaris 8 Installed" negate="false"/>
          <criterion test_ref="uft-20" comment="File kcms_server exists" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="sit-206" comment="inetd.conf contains kcms_server" negate="false"/>
          <criterion test_ref="uct-4" comment="inetd running" negate="false"/>
          <criterion test_ref="cmp-255" comment="File kcms_server executable and SUID or SGID" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL449" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 9</solaris:platform>
        <product>Bind</product>
      </affected>
      <dates>
        <submitted date="2005-01-19-12:00">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </submitted>
        <status_change date="2005-01-24-03:40">DRAFT</status_change>
        <status_change date="2005-02-16-12:00">INTERIM</status_change>
        <status_change date="2005-03-09-07:56">ACCEPTED</status_change>
      </dates>
      <description>BIND 8.3.x through 8.3.3 allows remote attackers to cause a denial of service (termination due to assertion failure) via a request for a subdomain that does not exist, with an OPT resource record with a large UDP payload size.</description>
      <reference source="CVE">CVE-2002-1220</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="uut-6" comment="Solaris 9 Installed" negate="false"/>
          <criterion test_ref="sat-19" comment="Internet Domain Name Server (BIND, SUNWinamd) installed" negate="false"/>
          <criterion test_ref="spt-26" comment="Patch 112970-03 or later installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="uct-14" comment="in.named running" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL555" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 7</solaris:platform>
        <product>Xsun</product>
      </affected>
      <dates>
        <submitted date="2004-12-28-12:00">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </submitted>
        <status_change date="2005-01-12-12:41">DRAFT</status_change>
        <status_change date="2005-02-02-12:00">INTERIM</status_change>
        <status_change date="2005-02-23-09:25">ACCEPTED</status_change>
      </dates>
      <description>Buffer overflow in Xsun in Solaris 8 and earlier allows local users to execute arbitrary commands via a long HOME environmental variable.</description>
      <reference source="CVE">CVE-2001-0422</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-43" comment="Solaris 7 or 8 installed" negate="false"/>
          <criterion test_ref="spt-4" comment="Patch 108376-25 or later installed" negate="true"/>
          <criterion test_ref="spt-5" comment="Patch 108652-30 or later installed" negate="true"/>
          <criterion test_ref="sat-12" comment="X Window System platform software (SUNWxwplt) installed" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL592" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 7</solaris:platform>
        <solaris:platform>Sun Solaris 8</solaris:platform>
        <solaris:platform>Sun Solaris 9</solaris:platform>
        <product>Licence Logging Service</product>
      </affected>
      <dates>
        <submitted date="2005-04-13-12:00">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </submitted>
        <status_change date="2005-04-20-12:13">DRAFT</status_change>
        <status_change date="2005-05-11-05:41">INTERIM</status_change>
        <status_change date="2005-06-01-03:30">ACCEPTED</status_change>
      </dates>
      <description>Unknown vulnerability in the rwho daemon (in.rwhod) for Solaris 7 through 9 allows remote attackers to execute arbitrary code.</description>
      <reference source="CVE">CVE-2004-1351</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-87" comment="Solaris 7 or 8 OR Solaris 9 and Remote Network Server Commands (SUNWrcmds) installed" negate="false"/>
          <criterion test_ref="spt-68" comment="Patch 118239-01 or later installed" negate="true"/>
          <criterion test_ref="spt-69" comment="Patch 116984-01 or later installed" negate="true"/>
          <criterion test_ref="spt-70" comment="Patch 117455-01 or later installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="uct-19" comment="in.rwhod is running" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL1048" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 7</solaris:platform>
        <solaris:platform>Sun Solaris 8</solaris:platform>
        <product>snmpdx</product>
      </affected>
      <dates>
        <submitted date="2005-02-01-12:00">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </submitted>
        <status_change date="2005-02-01-08:41">DRAFT</status_change>
        <status_change date="2005-02-16-12:00">INTERIM</status_change>
        <status_change date="2005-03-09-07:56">ACCEPTED</status_change>
      </dates>
      <description>Vulnerabilities in a large number of SNMP implementations allow remote attackers to cause a denial of service or gain privileges via SNMPv1 trap handling, as demonstrated by the PROTOS c06-SNMPv1 test suite.  NOTE: It is highly likely that this candidate will be SPLIT into multiple candidates, one or more for each vendor.  This and other SNMP-related candidates will be updated when more accurate information is available.</description>
      <reference source="CVE">CVE-2002-0012</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-43" comment="Solaris 7 or 8 installed" negate="false"/>
          <criterion test_ref="sat-48" comment="Solstice Enterprise Agents SNMP (SUNWsasnm) installed" negate="false"/>
          <criterion test_ref="spt-104" comment="Patch 107709-18 or later installed" negate="true"/>
          <criterion test_ref="spt-105" comment="Patch 108869-15 or later installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="uct-6" comment="snmpdx running" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL1099" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 9</solaris:platform>
        <product>CDE</product>
      </affected>
      <dates>
        <submitted date="2004-10-15-12:00">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </submitted>
        <status_change date="2004-10-20-12:00">DRAFT</status_change>
        <status_change date="2004-11-03-12:00">INTERIM</status_change>
        <status_change date="2004-12-09-12:00">ACCEPTED</status_change>
        <modified date="2005-01-11-12:00" comment="modified sat-6 - Changed test to pattern match and added check for 64bit version">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </modified>
        <modified date="2005-01-14-12:00" comment="modified sat-6 - Changed regular expression test to properly check for 64bit package">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </modified>
        <status_change date="2005-01-24-02:33">INTERIM</status_change>
        <status_change date="2005-02-16-12:00">ACCEPTED</status_change>
      </dates>
      <description>CDE ToolTalk database server (ttdbserver) allows remote attackers to overwrite arbitrary memory locations with a zero, and possibly gain privileges, via a file descriptor argument in an AUTH_UNIX procedure call, which is used as a table index by the _TT_ISCLOSE procedure.</description>
      <reference source="CVE">CVE-2002-0677</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="uut-6" comment="Solaris 9 Installed" negate="false"/>
          <criterion test_ref="sat-6" comment="Toolktalk (SUNWtltk/SUNWtltkx) installed" negate="false"/>
          <criterion test_ref="spt-255" comment="Patch 112808-02 or later installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="sit-202" comment="inetd.conf contains rpc.ttdbserverd" negate="false"/>
          <criterion test_ref="uct-4" comment="inetd running" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL1110" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 7</solaris:platform>
        <solaris:platform>Sun Solaris 8</solaris:platform>
        <solaris:platform>Sun Solaris 9</solaris:platform>
        <product>Solaris Enterprise Authentication Mechanism (SEAM)</product>
      </affected>
      <dates>
        <submitted date="2005-02-01-12:00">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </submitted>
        <status_change date="2005-02-01-08:41">DRAFT</status_change>
        <status_change date="2005-02-16-12:00">INTERIM</status_change>
        <status_change date="2005-03-09-07:56">ACCEPTED</status_change>
      </dates>
      <description>MIT Kerberos V5 Key Distribution Center (KDC) before 1.2.5 allows remote authenticated attackers to cause a denial of service (crash) on KDCs within the same realm via a certain protocol request that causes a null dereference.</description>
      <reference source="CVE">CVE-2003-0058</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-157" comment="Solaris 7 and Solaris Enterprise Authentication Mechanism OR Solaris 8 or 9 installed" negate="false"/>
          <criterion test_ref="spt-96" comment="Patch 112536-02 or later installed" negate="true"/>
          <criterion test_ref="spt-99" comment="Patch 112908-04 or later installed" negate="true"/>
          <criterion test_ref="spt-97" comment="Patch 112237-07 or later installed" negate="true"/>
          <criterion test_ref="spt-98" comment="Patch 112390-07 or later installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="tft-5" comment="/etc/krb5/krb5.conf is configured with a kerberos domain" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL1127" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 7</solaris:platform>
        <solaris:platform>Sun Solaris 8</solaris:platform>
        <solaris:platform>Sun Solaris 9</solaris:platform>
        <product>uucp</product>
      </affected>
      <dates>
        <submitted date="2005-04-13-04:00">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </submitted>
        <status_change date="2005-04-20-04:00">DRAFT</status_change>
        <status_change date="2005-05-11-04:00">INTERIM</status_change>
        <status_change date="2005-06-01-04:00">ACCEPTED</status_change>
        <modified date="2005-08-22-04:00" comment="Product set to uucp; was mistakenly .NET framework">
          <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
        </modified>
        <status_change date="2005-08-25-10:03">INTERIM</status_change>
        <status_change date="2005-09-21-01:33">INTERIM</status_change>
        <status_change date="2005-10-12-05:49">ACCEPTED</status_change>
      </dates>
      <description>Multiple buffer overflows in uucp for Sun Solaris 2.6, 7, 8, and 9 allow local users to execute arbitrary code as the uucp user.</description>
      <reference source="CVE">CVE-2004-1359</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-1080" comment="Solaris 7,8,or 9 installed" negate="false"/>
          <criterion test_ref="sat-42" comment="Networking UUCP Utilities - Usr (SUNWbnuu) installed" negate="false"/>
          <criterion test_ref="spt-86" comment="Patch 106952-04 or later installed" negate="true"/>
          <criterion test_ref="spt-87" comment="Patch 111570-03 or later installed" negate="true"/>
          <criterion test_ref="spt-88" comment="Patch 113322-02 or later installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1227" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 8</solaris:platform>
        <product>mozilla</product>
      </affected>
      <dates>
        <submitted date="2005-01-19-12:00">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </submitted>
        <status_change date="2005-01-24-03:40">DRAFT</status_change>
        <status_change date="2005-02-16-12:00">INTERIM</status_change>
        <status_change date="2005-03-09-07:56">ACCEPTED</status_change>
      </dates>
      <description>Mozilla allows remote attackers to cause Mozilla to open a URI as a different MIME type than expected via a null character (%00) in an FTP URI.</description>
      <reference source="CVE">CVE-2004-0760</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-1081" comment="Solaris 8 or 9 installed" negate="false"/>
          <criterion test_ref="cmp-72" comment="Mozilla components (any SUNWmoznav/SUNWmozmail) installed" negate="false"/>
          <criterion test_ref="spt-46" comment="Patch 117765-02 or later installed" negate="true"/>
          <criterion test_ref="spt-47" comment="Patch 117767-02 or later installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1273" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 7</solaris:platform>
        <solaris:platform>Sun Solaris 8</solaris:platform>
        <solaris:platform>Sun Solaris 9</solaris:platform>
        <product>Sadmin</product>
      </affected>
      <dates>
        <submitted date="2004-10-15-02:06">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </submitted>
        <modified date="2004-10-15-02:21" comment="Added check for sadmind called with strong authentication">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </modified>
        <status_change date="2004-10-20-02:35">DRAFT</status_change>
        <status_change date="2004-11-03-12:00">INTERIM</status_change>
        <status_change date="2004-12-09-08:46">ACCEPTED</status_change>
      </dates>
      <description>The default installation of sadmind on Solaris uses weak authentication (AUTH_SYS), which allows local and remote attackers to spoof Solstice AdminSuite clients and gain root privileges via a certain sequence of RPC packets.</description>
      <reference source="CVE">CVE-2003-0722</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-1080" comment="Solaris 7,8,or 9 installed" negate="false"/>
          <criterion test_ref="sat-7" comment="System and Network Administration Framework Installed" negate="false"/>
          <criterion test_ref="spt-259" comment="Patch 116457-02 or later installed" negate="true"/>
          <criterion test_ref="spt-260" comment="Patch 116442-01 or later installed" negate="true"/>
          <criterion test_ref="spt-261" comment="Patch 116454-01 or later installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="uct-4" comment="inetd running" negate="false"/>
          <criterion test_ref="sit-209" comment="inetd.conf contains sadmind" negate="false"/>
          <criterion test_ref="sit-210" comment="Sadmin called using strong authentication" negate="true"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL1436" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 7</solaris:platform>
        <product>CDE</product>
      </affected>
      <dates>
        <submitted date="2004-10-12-12:37">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </submitted>
        <modified date="2004-10-12-12:47" comment="Added patch 107180-31 test for Solaris 7.  Changed vulnerable software test logic a little">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </modified>
        <status_change date="2004-10-13-01:15">DRAFT</status_change>
        <status_change date="2004-10-27-12:00">INTERIM</status_change>
        <status_change date="2004-11-17-10:00">ACCEPTED</status_change>
      </dates>
      <description>Double-free vulnerability in dtlogin in CDE on Solaris, HP-UX, and other operating systems allows remote attackers to execute arbitrary code via a crafted XDMCP packet.</description>
      <reference source="CVE">CVE-2004-0368</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="uft-23" comment="File /usr/dt/bin/dtlogin exists" negate="false"/>
          <criterion test_ref="cmp-1080" comment="Solaris 7,8,or 9 installed" negate="false"/>
          <criterion test_ref="spt-231" comment="Patch 108919-21 or later installed" negate="false"/>
          <criterion test_ref="spt-232" comment="Patch 112807-09 or later installed" negate="false"/>
          <criterion test_ref="spt-249" comment="Patch 107180-31 or later installed" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="uct-9" comment="dtlogin running" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL1467" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 9</solaris:platform>
        <product>Samba</product>
      </affected>
      <dates>
        <submitted date="2005-01-19-12:00">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </submitted>
        <status_change date="2005-01-24-03:40">DRAFT</status_change>
        <status_change date="2005-02-16-12:00">INTERIM</status_change>
        <status_change date="2005-03-09-07:56">ACCEPTED</status_change>
      </dates>
      <description>Buffer overflow in samba 2.2.2 through 2.2.6 allows remote attackers to cause a denial of service and possibly execute arbitrary code via an encrypted password that causes the overflow during decryption in which a DOS codepage string is converted to a little-endian UCS2 unicode string.</description>
      <reference source="CVE">CVE-2002-1318</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="uut-6" comment="Solaris 9 Installed" negate="false"/>
          <criterion test_ref="sat-28" comment="Samba - Usr (SUNWsmbau) installed" negate="false"/>
          <criterion test_ref="spt-48" comment="Patch 114684-01 or later installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="uct-15" comment="smbd running" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL1479" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 7</solaris:platform>
        <product>libpng</product>
      </affected>
      <dates>
        <submitted date="2004-12-12-12:00">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </submitted>
        <status_change date="2005-01-24-12:04">DRAFT</status_change>
        <status_change date="2005-02-16-12:00">INTERIM</status_change>
        <status_change date="2005-03-09-07:56">ACCEPTED</status_change>
      </dates>
      <description>Multiple integer overflows in the (1) png_read_png in pngread.c or (2) png_handle_sPLT functions in pngrutil.c or (3) progressive display image reading capability in libpng 1.2.5 and earlier allow remote attackers to cause a denial of service (application crash) via a malformed PNG image.</description>
      <reference source="CVE">CVE-2004-0599</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-1080" comment="Solaris 7,8,or 9 installed" negate="false"/>
          <criterion test_ref="sat-11" comment="Netscape installed" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1482" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 8</solaris:platform>
        <solaris:platform>Sun Solaris 9</solaris:platform>
        <product>Solaris Management Console (SMC)</product>
      </affected>
      <dates>
        <submitted date="2005-04-13-04:00">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </submitted>
        <status_change date="2005-04-20-04:00">DRAFT</status_change>
        <status_change date="2005-05-11-04:00">INTERIM</status_change>
        <status_change date="2005-06-01-04:00">ACCEPTED</status_change>
        <modified date="2005-08-22-04:00" comment="Affected product changed to Sun Management Console (SMC); mistakenly was .NET framework">
          <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
        </modified>
        <status_change date="2005-08-25-10:03">INTERIM</status_change>
        <status_change date="2005-09-21-01:33">INTERIM</status_change>
        <status_change date="2005-10-12-05:49">ACCEPTED</status_change>
      </dates>
      <description>The Solaris Management Console (SMC) in Sun Solaris 8 and 9 generates different 404 error messages when a file does not exist versus when a file exists but is otherwise inacessible, which could allow remote attackers to obtain sensitive information in conjunction with a directory traversal (..) attack.</description>
      <reference source="CVE">CVE-2004-1354</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-1081" comment="Solaris 8 or 9 installed" negate="false"/>
          <criterion test_ref="sat-40" comment="Solaris Management Console Web Components (SUNWwbmc) installed" negate="false"/>
          <criterion test_ref="spt-76" comment="Patch 111313-02 or later installed" negate="true"/>
          <criterion test_ref="spt-77" comment="Patch 116807-01 or later installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="uct-20" comment="smcboot running" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL1528" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 8</solaris:platform>
        <product>tcsh</product>
      </affected>
      <dates>
        <submitted date="2005-04-13-04:00">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </submitted>
        <status_change date="2005-04-20-04:00">DRAFT</status_change>
        <status_change date="2005-05-11-04:00">INTERIM</status_change>
        <status_change date="2005-06-01-04:00">ACCEPTED</status_change>
        <modified date="2005-08-22-04:00" comment="Affected product changed to tcsh; mistakenly was .NET framework">
          <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
        </modified>
        <status_change date="2005-08-25-10:03">INTERIM</status_change>
        <status_change date="2005-08-25-10:05">DRAFT</status_change>
        <status_change date="2005-09-21-01:33">INTERIM</status_change>
        <status_change date="2005-10-12-05:49">ACCEPTED</status_change>
      </dates>
      <description>Unknown vulnerability in the ls-F builtin function in tcsh on Solaris 8 allows local users to create or delete files as other users, and gain privileges.</description>
      <reference source="CVE">CVE-2003-1024</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="uut-4" comment="Solaris 8 Installed" negate="false"/>
          <criterion test_ref="spt-95" comment="Patch 110943-02 or later installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1654" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 8</solaris:platform>
        <product>Licence Logging Service</product>
      </affected>
      <dates>
        <submitted date="2005-04-13-12:00">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </submitted>
        <status_change date="2005-04-20-12:13">DRAFT</status_change>
        <status_change date="2005-05-11-05:41">INTERIM</status_change>
        <status_change date="2005-06-01-03:30">ACCEPTED</status_change>
      </dates>
      <description>gzip before 1.3 in Solaris 8, when called with the -f or -force flags, will change the permissions of files that are hard linked to the target files, which allows local users to view or modify these files.</description>
      <reference source="CVE">CVE-2004-1349</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="uut-4" comment="Solaris 8 Installed" negate="false"/>
          <criterion test_ref="sat-36" comment="GNU Zip (gzip, SUNWgzip) installed" negate="false"/>
          <criterion test_ref="spt-67" comment="Patch 112668-02 or later installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1684" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 8</solaris:platform>
        <solaris:platform>Sun Solaris 9</solaris:platform>
        <product>sendfilev()</product>
      </affected>
      <dates>
        <submitted date="2005-04-13-04:00">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </submitted>
        <status_change date="2005-04-20-04:00">DRAFT</status_change>
        <status_change date="2005-05-11-04:00">INTERIM</status_change>
        <status_change date="2005-06-01-04:00">ACCEPTED</status_change>
        <status_change date="2005-08-25-10:03">INTERIM</status_change>
        <status_change date="2005-08-25-10:05">DRAFT</status_change>
        <status_change date="2005-09-21-01:33">INTERIM</status_change>
        <status_change date="2005-10-12-05:49">ACCEPTED</status_change>
      </dates>
      <description>Unknown vulnerability in the sendfilev function in Sun Solaris 8 and 9 allows local users to cause a denial of service (system panic) via unknown vectors.</description>
      <reference source="CVE">CVE-2004-1356</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-1081" comment="Solaris 8 or 9 installed" negate="false"/>
          <criterion test_ref="spt-81" comment="Patch 108528-27 or later installed" negate="true"/>
          <criterion test_ref="spt-80" comment="Patch 112233-12 or later installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1707" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 8</solaris:platform>
        <product>Sun Enterprise Storage Manager (ESM)</product>
      </affected>
      <dates>
        <submitted date="2005-01-19-12:00">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </submitted>
        <status_change date="2005-01-24-03:40">DRAFT</status_change>
        <status_change date="2005-02-16-12:00">INTERIM</status_change>
        <status_change date="2005-03-09-07:56">ACCEPTED</status_change>
      </dates>
      <description/>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-1081" comment="Solaris 8 or 9 installed" negate="false"/>
          <criterion test_ref="sat-1" comment="Sun Enterprise Storage Manager installed" negate="false"/>
          <criterion test_ref="spt-242" comment="Patch 117367-01 or later installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1732" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 7</solaris:platform>
        <solaris:platform>Sun Solaris 8</solaris:platform>
        <solaris:platform>Sun Solaris 9</solaris:platform>
        <product>/usr/lib/print/conv_fix</product>
      </affected>
      <dates>
        <submitted date="2005-04-13-04:00">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </submitted>
        <status_change date="2005-04-20-04:00">DRAFT</status_change>
        <status_change date="2005-05-11-04:00">INTERIM</status_change>
        <status_change date="2005-06-01-04:00">ACCEPTED</status_change>
        <status_change date="2005-08-25-10:03">INTERIM</status_change>
        <status_change date="2005-08-25-10:05">DRAFT</status_change>
        <status_change date="2005-09-21-01:33">INTERIM</status_change>
        <status_change date="2005-10-12-05:49">ACCEPTED</status_change>
      </dates>
      <description>Unknown vulnerability in conv_fix in Sun Solaris 7 through 9, when invoked by conv_lpd, allows local users to overwrite arbitrary files.</description>
      <reference source="CVE">CVE-2004-1360</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-1080" comment="Solaris 7,8,or 9 installed" negate="false"/>
          <criterion test_ref="sat-43" comment="SunSoft Print - Client - Usr (SUNWpcu) installed" negate="false"/>
          <criterion test_ref="spt-89" comment="Patch 107115-14 or later installed" negate="true"/>
          <criterion test_ref="spt-90" comment="Patch 109320-09 or later installed" negate="true"/>
          <criterion test_ref="spt-91" comment="Patch 113329-05 or later installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1844" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 7</solaris:platform>
        <product>NIS</product>
      </affected>
      <dates>
        <submitted date="2004-12-29-12:00">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </submitted>
        <status_change date="2005-01-12-12:41">DRAFT</status_change>
        <status_change date="2005-02-02-12:00">INTERIM</status_change>
        <status_change date="2005-02-23-09:25">ACCEPTED</status_change>
      </dates>
      <description>Buffer overflow in ypbind daemon in Solaris 5.4 through 8 allows remote attackers to execute arbitrary code.</description>
      <reference source="CVE">CVE-2001-1328</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-43" comment="Solaris 7 or 8 installed" negate="false"/>
          <criterion test_ref="sat-13" comment="NIS/NIS+ Utilities installed (SUNWnisu)" negate="false"/>
          <criterion test_ref="spt-8" comment="Patch 108750-02 or later installed" negate="true"/>
          <criterion test_ref="spt-9" comment="Patch 110322-01 or later installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="uct-3" comment="ypbind running" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL1880" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 7</solaris:platform>
        <product>dtspcd</product>
      </affected>
      <dates>
        <submitted date="2005-02-01-12:00">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </submitted>
        <status_change date="2005-02-01-08:41">DRAFT</status_change>
        <status_change date="2005-02-16-12:00">INTERIM</status_change>
        <status_change date="2005-03-09-07:56">ACCEPTED</status_change>
      </dates>
      <description>The CDE dtspcd daemon allows local users to execute arbitrary commands via a symlink attack.</description>
      <reference source="CVE">CVE-1999-0689</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="uut-5" comment="Solaris 7 Installed" negate="false"/>
          <criterion test_ref="sat-49" comment="CDE Daemons (SUNWdtdmn) installed" negate="false"/>
          <criterion test_ref="spt-107" comment="Patch 108221-01 or later installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1905" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 7</solaris:platform>
        <solaris:platform>Sun Solaris 8</solaris:platform>
        <solaris:platform>Sun Solaris 9</solaris:platform>
        <product>CDE</product>
      </affected>
      <dates>
        <submitted date="2005-02-01-12:00">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </submitted>
        <status_change date="2005-02-01-08:41">DRAFT</status_change>
        <status_change date="2005-02-16-12:00">INTERIM</status_change>
        <status_change date="2005-03-09-07:56">ACCEPTED</status_change>
      </dates>
      <description>Heap-based buffer overflow in dtsession for Solaris 2.5.1 through Solaris 9 allows local users to gain root privileges via a long HOME environment variable.</description>
      <reference source="CVE">CVE-2003-0092</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-1080" comment="Solaris 7,8,or 9 installed" negate="false"/>
          <criterion test_ref="sat-47" comment="CDE Desktop Window Manager (SUNWdtwm) installed" negate="false"/>
          <criterion test_ref="spt-100" comment="Patch 107702-12 or later installed" negate="true"/>
          <criterion test_ref="spt-101" comment="Patch 109354-19 or later installed" negate="true"/>
          <criterion test_ref="spt-102" comment="Patch 114497-01 or later installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1970" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 9</solaris:platform>
        <product>Solaris Management Console (SMC)</product>
      </affected>
      <dates>
        <submitted date="2005-04-13-12:00">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </submitted>
        <status_change date="2005-04-20-12:13">DRAFT</status_change>
        <status_change date="2005-05-11-05:41">INTERIM</status_change>
        <status_change date="2005-06-01-03:30">ACCEPTED</status_change>
      </dates>
      <description>Off-by-one error in the fb_realpath() function, as derived from the realpath function in BSD, may allow attackers to execute arbitrary code, as demonstrated in wu-ftpd 2.5.0 through 2.6.2 via commands that cause pathnames of length MAXPATHLEN+1 to trigger a buffer overflow, including (1) STOR, (2) RETR, (3) APPE, (4) DELE, (5) MKD, (6) RMD, (7) STOU, or (8) RNTO.</description>
      <reference source="CVE">CVE-2003-0466</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="uut-6" comment="Solaris 9 Installed" negate="false"/>
          <criterion test_ref="sat-34" comment="FTP Server - Usr (SUNWftpu) installed" negate="false"/>
          <criterion test_ref="spt-60" comment="Patch 114564-02 or later installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="sit-3" comment="inetd.conf contains in.ftpd" negate="false"/>
          <criterion test_ref="uct-4" comment="inetd running" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL1982" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 8</solaris:platform>
        <solaris:platform>Sun Solaris 9</solaris:platform>
        <product>Apache</product>
      </affected>
      <dates>
        <submitted date="2004-10-14-01:13">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </submitted>
        <modified date="2004-10-18-03:12" comment="Changed apache test to file test">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </modified>
        <modified date="2004-10-19-11:17" comment="Changed apache test to package test">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </modified>
        <status_change date="2004-10-20-02:35">DRAFT</status_change>
        <status_change date="2004-11-03-12:00">INTERIM</status_change>
        <status_change date="2004-12-09-08:46">ACCEPTED</status_change>
      </dates>
      <description>Apache 1.4.x before 1.3.30, and 2.0.x before 2.0.49, when using multiple listening sockets on certain platforms, allows remote attackers to cause a denial of service (blocked new connections) via a "short-lived connection on a rarely-accessed listening socket."</description>
      <reference source="CVE">CVE-2004-0174</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-1081" comment="Solaris 8 or 9 installed" negate="false"/>
          <criterion test_ref="spt-253" comment="Patch 116973-01 or later installed" negate="true"/>
          <criterion test_ref="spt-254" comment="Patch 113146-05 or later installed" negate="true"/>
          <criterion test_ref="sat-5" comment="Apache (SUNWapchu) installed" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="uct-10" comment="Apache running (httpd)" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL2002" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 7</solaris:platform>
        <product>Solaris Enterprise Authentication Mechanism (SEAM)</product>
      </affected>
      <dates>
        <submitted date="2004-10-11-12:00">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </submitted>
        <status_change date="2004-10-13-12:00">DRAFT</status_change>
        <modified date="2005-01-14-12:00" comment="Changed two unknown tests for kerberos configuration to Solaris text file contents tests ">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </modified>
        <status_change date="2005-02-02-12:00">INTERIM</status_change>
        <status_change date="2005-02-23-09:25">ACCEPTED</status_change>
      </dates>
      <description>Multiple buffer overflows in krb5_aname_to_localname for MIT Kerberos 5 (krb5) 1.3.3 and earlier allow remote attackers to execute arbitrary code as root.</description>
      <reference source="CVE">CVE-2004-0523</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="uft-25" comment="Kerberos 5 installed" negate="false"/>
          <criterion test_ref="cmp-1080" comment="Solaris 7,8,or 9 installed" negate="false"/>
          <criterion test_ref="spt-246" comment="Patch 112908-16 or later installed" negate="true"/>
          <criterion test_ref="spt-247" comment="Patch 112536-05 or later installed" negate="true"/>
          <criterion test_ref="cmp-1104" comment="Patches 112237-11 and 112390-09 or greater installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="tft-5" comment="/etc/krb5/krb5.conf is configured with a kerberos domain" negate="false"/>
          <criterion test_ref="tft-6" comment="/etc/krb5/krb5.conf is configured with explicit or rules-based mapping" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL2011" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 7</solaris:platform>
        <product>Bind</product>
      </affected>
      <dates>
        <submitted date="2004-10-19-12:00">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </submitted>
        <status_change date="2004-10-20-12:00">DRAFT</status_change>
        <status_change date="2004-11-03-12:00">INTERIM</status_change>
        <status_change date="2004-12-09-12:00">ACCEPTED</status_change>
        <modified date="2005-01-11-12:00" comment="modified sat-10 - Changed test to pattern match to check for 64bit version of Core Solaris">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </modified>
        <modified date="2005-01-14-12:00" comment="modified sat-10 - Changed regular expression to properly check for 64bit package">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </modified>
        <status_change date="2005-01-24-02:36">INTERIM</status_change>
        <status_change date="2005-02-16-12:00">ACCEPTED</status_change>
      </dates>
      <description>ISC BIND 8.3.x before 8.3.7, and 8.4.x before 8.4.3, allows remote attackers to poison the cache via a malicious name server that returns negative responses with a large TTL (time-to-live) value.</description>
      <reference source="CVE">CVE-2003-0914</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-1080" comment="Solaris 7,8,or 9 installed" negate="false"/>
          <criterion test_ref="spt-270" comment="Patch 106938-08 or later installed" negate="true"/>
          <criterion test_ref="spt-271" comment="Patch 109326-13 or later installed" negate="true"/>
          <criterion test_ref="spt-272" comment="Patch 112970-06 or later installed" negate="true"/>
          <criterion test_ref="sat-10" comment="Core Solaris (SUNWcsu/SUNWcsxu) installed" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="uct-14" comment="in.named running" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL2025" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 7</solaris:platform>
        <product>login</product>
      </affected>
      <dates>
        <submitted date="2004-12-29-12:00">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </submitted>
        <status_change date="2005-01-12-12:41">DRAFT</status_change>
        <status_change date="2005-02-02-12:00">INTERIM</status_change>
        <status_change date="2005-02-23-09:25">ACCEPTED</status_change>
      </dates>
      <description>Buffer overflow in login in various System V based operating systems allows remote attackers to execute arbitrary commands via a large number of arguments through services such as telnet and rlogin.</description>
      <reference source="CVE">CVE-2001-0797</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-43" comment="Solaris 7 or 8 installed" negate="false"/>
          <criterion test_ref="spt-6" comment="Patch 112300-01 or later installed" negate="true"/>
          <criterion test_ref="spt-7" comment="Patch 111085-02 or later installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL2065" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 9</solaris:platform>
        <product>pam_krb5</product>
      </affected>
      <dates>
        <submitted date="2004-10-12-12:00">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </submitted>
        <status_change date="2004-10-13-12:00">DRAFT</status_change>
        <modified date="2005-01-14-12:00" comment="Changed all unknown tests to solaris file contents tests">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </modified>
        <status_change date="2005-02-02-12:00">INTERIM</status_change>
        <status_change date="2005-02-23-09:25">ACCEPTED</status_change>
      </dates>
      <description>Solaris 9, when configured as a Kerberos client with patch 112908-12 or 115168-03 and using pam_krb5 as an "auth" module with the debug feature enabled, records passwords in plaintext, which could allow local users to gain other user's passwords by reading log files.</description>
      <reference source="CVE">CVE-2004-0653</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="uut-6" comment="Solaris 9 Installed" negate="false"/>
          <criterion test_ref="uft-25" comment="Kerberos 5 installed" negate="false"/>
          <criterion test_ref="spt-248" comment="Patch 112908-13 or later installed" negate="true"/>
          <criterion test_ref="spt-236" comment="Patch 112908-12 installed" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="tft-7" comment="/etc/pam.conf is configured to use pam_krb5 as an 'auth' module and the debug feature of pam_krb5 is enabled" negate="false"/>
          <criterion test_ref="tft-5" comment="/etc/krb5/krb5.conf is configured with a kerberos domain" negate="false"/>
          <criterion test_ref="tft-8" comment="/etc/syslog.conf is configured to log &quot;debug&quot; level messages for at least daemon" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL2094" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 7</solaris:platform>
        <product>Bind</product>
      </affected>
      <dates>
        <submitted date="2005-01-19-12:00">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </submitted>
        <status_change date="2005-01-24-03:40">DRAFT</status_change>
        <status_change date="2005-02-16-12:00">INTERIM</status_change>
        <status_change date="2005-03-09-07:56">ACCEPTED</status_change>
      </dates>
      <description>BIND 8.x through 8.3.3 allows remote attackers to cause a denial of service (crash) via SIG RR elements with invalid expiry times, which are removed from the internal BIND database and later cause a null dereference.</description>
      <reference source="CVE">CVE-2002-1221</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-1080" comment="Solaris 7,8,or 9 installed" negate="false"/>
          <criterion test_ref="sat-19" comment="Internet Domain Name Server (BIND, SUNWinamd) installed" negate="false"/>
          <criterion test_ref="spt-24" comment="Patch 106938-07 or later installed" negate="true"/>
          <criterion test_ref="spt-25" comment="Patch 109326-10 or later installed" negate="true"/>
          <criterion test_ref="spt-26" comment="Patch 112970-03 or later installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="uct-14" comment="in.named running" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL2139" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 9</solaris:platform>
        <product>Kerberos5</product>
      </affected>
      <dates>
        <submitted date="2004-10-12-12:00">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </submitted>
        <status_change date="2004-10-13-12:00">DRAFT</status_change>
        <modified date="2005-01-14-12:00" comment="Changed kerberos unknown test to solaris file contents test">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </modified>
        <status_change date="2005-02-02-12:00">INTERIM</status_change>
        <status_change date="2005-02-23-09:25">ACCEPTED</status_change>
      </dates>
      <description>The asn1buf_skiptail function in the ASN.1 decoder library for MIT Kerberos 5 (krb5) 1.2.2 through 1.3.4 allows remote attackers to cause a denial of service (infinite loop) via a certain BER encoding.</description>
      <reference source="CVE">CVE-2004-0644</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="uut-6" comment="Solaris 9 Installed" negate="false"/>
          <criterion test_ref="uft-25" comment="Kerberos 5 installed" negate="false"/>
          <criterion test_ref="spt-250" comment="Patch 112908-15 or later installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="tft-5" comment="/etc/krb5/krb5.conf is configured with a kerberos domain" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL2163" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 9</solaris:platform>
        <product>Samba</product>
      </affected>
      <dates>
        <submitted date="2004-12-30-12:00">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </submitted>
        <status_change date="2005-01-12-12:41">DRAFT</status_change>
        <status_change date="2005-02-02-12:00">INTERIM</status_change>
        <status_change date="2005-02-23-09:25">ACCEPTED</status_change>
      </dates>
      <description>Buffer overflow in the call_trans2open function in trans2.c for Samba 2.2.x before 2.2.8a, 2.0.10 and earlier 2.0.x versions, and Samba-TNG before 0.3.2, allows remote attackers to execute arbitrary code.</description>
      <reference source="CVE">CVE-2003-0201</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="uut-6" comment="Solaris 9 Installed" negate="false"/>
          <criterion test_ref="sat-15" comment="Samba (SUNWsmbar) installed" negate="false"/>
          <criterion test_ref="spt-15" comment="Patch 114684-02 or later installed" negate="true"/>
        </software>
        <configuration operation="OR">
          <criterion test_ref="cmp-56" comment="Inetd running and inetd.conf contains smbd" negate="false"/>
          <criterion test_ref="uct-15" comment="smbd running" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL2183" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 9</solaris:platform>
        <product>Sendmail</product>
      </affected>
      <dates>
        <submitted date="2004-12-22-12:00">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </submitted>
        <status_change date="2005-01-12-12:00">DRAFT</status_change>
        <modified date="2005-01-27-12:00" comment="Removed &quot;Sendmail running&quot; configuration test.  Sendmail installs as SUID root">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </modified>
        <status_change date="2005-04-20-12:13">INTERIM</status_change>
        <status_change date="2005-05-11-05:41">ACCEPTED</status_change>
      </dates>
      <description>Buffer overflow in Sendmail before 8.12.5, when configured to use a custom DNS map to query TXT records, allows remote attackers to cause a denial of service and possibly execute arbitrary code via a malicious DNS server.</description>
      <reference source="CVE">CVE-2002-0906</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="uut-6" comment="Solaris 9 Installed" negate="false"/>
          <criterion test_ref="sat-3" comment="Sendmail - root (SUNWsndmr) installed" negate="false"/>
          <criterion test_ref="spt-2" comment="Patch 113575-01 or later installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL2222" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 7</solaris:platform>
        <solaris:platform>Sun Solaris 8</solaris:platform>
        <solaris:platform>Sun Solaris 9</solaris:platform>
        <product>Sendmail</product>
      </affected>
      <dates>
        <submitted date="2005-04-13-12:00">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </submitted>
        <status_change date="2005-04-20-12:13">DRAFT</status_change>
        <status_change date="2005-05-11-05:41">INTERIM</status_change>
        <status_change date="2005-06-01-03:30">ACCEPTED</status_change>
      </dates>
      <description>Buffer overflow in Sendmail 5.79 to 8.12.7 allows remote attackers to execute arbitrary code via certain formatted address fields, related to sender and recipient header comments as processed by the crackaddr function of headers.c.</description>
      <reference source="CVE">CVE-2002-1337</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-1080" comment="Solaris 7,8,or 9 installed" negate="false"/>
          <criterion test_ref="sat-14" comment="Sendmail - user (SUNWsndmu) installed" negate="false"/>
          <criterion test_ref="spt-63" comment="Patch 107684-08 or later installed" negate="true"/>
          <criterion test_ref="spt-64" comment="Patch 110615-08 or later installed" negate="true"/>
          <criterion test_ref="spt-65" comment="Patch 113575-03 or later installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="uct-11" comment="Sendmail running" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL2248" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 7</solaris:platform>
        <product>libc</product>
      </affected>
      <dates>
        <submitted date="2005-04-13-12:00">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </submitted>
        <status_change date="2005-04-20-12:13">DRAFT</status_change>
        <status_change date="2005-05-11-05:41">INTERIM</status_change>
        <status_change date="2005-06-01-03:30">ACCEPTED</status_change>
      </dates>
      <description>The Sun RPC functionality in multiple libc implementations does not provide a time-out mechanism when reading data from TCP connections, which allows remote attackers to cause a denial of service (hang).</description>
      <reference source="CVE">CVE-2002-1265</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="uut-5" comment="Solaris 7 Installed" negate="false"/>
          <criterion test_ref="cmp-287" comment="All RPC w/TCP patches installed - CVE-2002-1265" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="uct-21" comment="rpcbind running" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL2378" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 7</solaris:platform>
        <product>libpng</product>
      </affected>
      <dates>
        <submitted date="2004-12-12-12:00">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </submitted>
        <status_change date="2005-01-24-12:04">DRAFT</status_change>
        <status_change date="2005-02-16-12:00">INTERIM</status_change>
        <status_change date="2005-03-09-07:56">ACCEPTED</status_change>
      </dates>
      <description>Multiple buffer overflows in libpng 1.2.5 and earlier, as used in multiple products, allow remote attackers to execute arbitrary code via malformed PNG images in which (1) the png_handle_tRNS function does not properly validate the length of transparency chunk (tRNS) data, or the (2) png_handle_sBIT or (3) png_handle_hIST functions do not perform sufficient bounds checking.</description>
      <reference source="CVE">CVE-2004-0597</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-1080" comment="Solaris 7,8,or 9 installed" negate="false"/>
          <criterion test_ref="sat-11" comment="Netscape installed" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL2418" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 8</solaris:platform>
        <product>mozilla</product>
      </affected>
      <dates>
        <submitted date="2005-01-19-12:00">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </submitted>
        <status_change date="2005-01-24-03:40">DRAFT</status_change>
        <status_change date="2005-02-16-12:00">INTERIM</status_change>
        <status_change date="2005-03-09-07:56">ACCEPTED</status_change>
      </dates>
      <description>Mozilla before 1.7, Firefox before 0.9, and Thunderbird before 0.7, allow remote web sites to hijack the user interface via the "chrome" flag and XML User Interface Language (XUL) files.</description>
      <reference source="CVE">CVE-2004-0764</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-1081" comment="Solaris 8 or 9 installed" negate="false"/>
          <criterion test_ref="cmp-72" comment="Mozilla components (any SUNWmoznav/SUNWmozmail) installed" negate="false"/>
          <criterion test_ref="spt-46" comment="Patch 117765-02 or later installed" negate="true"/>
          <criterion test_ref="spt-47" comment="Patch 117767-02 or later installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL2423" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 7</solaris:platform>
        <product>NIS</product>
      </affected>
      <dates>
        <submitted date="2005-01-19-12:00">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </submitted>
        <status_change date="2005-01-24-03:40">DRAFT</status_change>
        <status_change date="2005-02-16-12:00">INTERIM</status_change>
        <status_change date="2005-03-09-07:56">ACCEPTED</status_change>
      </dates>
      <description>The getdbm procedure in ypxfrd allows local users to read arbitrary files, and remote attackers to read databases outside /var/yp, via a directory traversal and symlink attack on the domain and map arguments.</description>
      <reference source="CVE">CVE-2002-1199</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-1080" comment="Solaris 7,8,or 9 installed" negate="false"/>
          <criterion test_ref="sat-20" comment="NIS Server - User (SUNWypu) installed" negate="false"/>
          <criterion test_ref="spt-33" comment="Patch 106541-24 or later installed" negate="true"/>
          <criterion test_ref="spt-34" comment="Patch 109328-03 or later installed" negate="true"/>
          <criterion test_ref="spt-35" comment="Patch 113579-01 or later installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="uct-17" comment="ypxfrd running" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL2426" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 7</solaris:platform>
        <solaris:platform>Sun Solaris 8</solaris:platform>
        <solaris:platform>Sun Solaris 9</solaris:platform>
        <product>Basic Security Module</product>
      </affected>
      <dates>
        <submitted date="2004-10-12-09:40">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </submitted>
        <status_change date="2004-10-13-01:15">DRAFT</status_change>
      </dates>
      <description>Unknown vulnerability in the Basic Security Module (BSM), when configured to audit either the Administrative (ad) or the System-Wide Administration (as) audit class in Solaris 7, 8, and 9, allows local users to cause a denial of service (kernel panic).</description>
      <reference source="CVE">CVE-2004-0654</reference>
      <status>DRAFT</status>
      <version>0</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="spt-233" comment="Patch 106541-33 or later installed" negate="true"/>
          <criterion test_ref="spt-234" comment="Patch 109007-18 or later installed" negate="true"/>
          <criterion test_ref="spt-235" comment="Patch 114332-12 or later installed" negate="true"/>
          <criterion test_ref="cmp-1080" comment="Solaris 7,8,or 9 installed" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="ukn-26" comment="Basic Security Module enabled" negate="false"/>
          <criterion test_ref="ukn-27" comment="Auditing Administrative or System-Wide Administrative audit classes" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL2536" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 8</solaris:platform>
        <product>Kerberos5</product>
      </affected>
      <dates>
        <submitted date="2005-01-19-12:00">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </submitted>
        <status_change date="2005-01-24-03:40">DRAFT</status_change>
        <status_change date="2005-02-16-12:00">INTERIM</status_change>
        <status_change date="2005-03-09-07:56">ACCEPTED</status_change>
      </dates>
      <description>The Key Distribution Center (KDC) in Kerberos 5 (krb5) 1.2.7 and earlier allows remote, authenticated attackers to cause a denial of service (crash) on KDCs within the same realm using a certain protocol request that causes the KDC to corrupt its heap (aka "buffer underrun").</description>
      <reference source="CVE">CVE-2003-0082</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <notes>
        <note>Vulnerability exists in standard Solaris kerberos and SEAM.  This definition only covers Solaris kerberos</note>
      </notes>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-1081" comment="Solaris 8 or 9 installed" negate="false"/>
          <criterion test_ref="cmp-74" comment="Kerberos v5 (any SUNWkrbr/SUNWkrbu/SUNWkrbux) installed" negate="false"/>
          <criterion test_ref="cmp-79" comment="Patches 112237-09 and 112390-08 or later installed" negate="true"/>
          <criterion test_ref="cmp-81" comment="Patches 112925-03,112923-03,112921-02, and 112908-10 or later installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="tft-5" comment="/etc/krb5/krb5.conf is configured with a kerberos domain" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL2539" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 7</solaris:platform>
        <product>Bind</product>
      </affected>
      <dates>
        <submitted date="2005-01-19-12:00">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </submitted>
        <status_change date="2005-01-24-03:40">DRAFT</status_change>
        <status_change date="2005-02-16-12:00">INTERIM</status_change>
        <status_change date="2005-03-09-07:56">ACCEPTED</status_change>
      </dates>
      <description>Buffer overflow in named in BIND 4 versions 4.9.10 and earlier, and 8 versions 8.3.3 and earlier, allows remote attackers to execute arbitrary code via a certain DNS server response containing SIG resource records (RR).</description>
      <reference source="CVE">CVE-2002-1219</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-1080" comment="Solaris 7,8,or 9 installed" negate="false"/>
          <criterion test_ref="sat-19" comment="Internet Domain Name Server (BIND, SUNWinamd) installed" negate="false"/>
          <criterion test_ref="spt-24" comment="Patch 106938-07 or later installed" negate="true"/>
          <criterion test_ref="spt-25" comment="Patch 109326-10 or later installed" negate="true"/>
          <criterion test_ref="spt-26" comment="Patch 112970-03 or later installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="uct-14" comment="in.named running" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL2572" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 7</solaris:platform>
        <product>libpng</product>
      </affected>
      <dates>
        <submitted date="2004-12-12-12:00">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </submitted>
        <status_change date="2005-01-24-12:04">DRAFT</status_change>
        <status_change date="2005-02-16-12:00">INTERIM</status_change>
        <status_change date="2005-03-09-07:56">ACCEPTED</status_change>
      </dates>
      <description>The png_handle_iCCP function in libpng 1.2.5 and earlier allows remote attackers to cause a denial of service (application crash) via a certain PNG image that triggers a null dereference.</description>
      <reference source="CVE">CVE-2004-0598</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-1080" comment="Solaris 7,8,or 9 installed" negate="false"/>
          <criterion test_ref="sat-11" comment="Netscape installed" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL2590" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 8</solaris:platform>
        <solaris:platform>Sun Solaris 9</solaris:platform>
        <product>Sun Cluster</product>
      </affected>
      <dates>
        <submitted date="2004-10-19-03:11">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </submitted>
        <status_change date="2004-10-20-02:35">DRAFT</status_change>
        <status_change date="2004-11-03-12:00">INTERIM</status_change>
        <status_change date="2004-12-09-08:46">ACCEPTED</status_change>
      </dates>
      <description>Double-free vulnerability in OpenSSL 0.9.7 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via an SSL client certificate with a certain invalid ASN.1 encoding.</description>
      <reference source="CVE">CVE-2003-0545</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-1081" comment="Solaris 8 or 9 installed" negate="false"/>
          <criterion test_ref="spt-266" comment="Patch 113505-02 or later installed" negate="true"/>
          <criterion test_ref="spt-267" comment="Patch 113508-02 or later installed" negate="true"/>
          <criterion test_ref="spt-268" comment="Patch 115054-01 or later installed" negate="true"/>
          <criterion test_ref="spt-269" comment="Patch 115055-01 or later installed" negate="true"/>
          <criterion test_ref="sat-8" comment="SunCluster Component SUNWscvw installed" negate="false"/>
          <criterion test_ref="sat-5" comment="Apache (SUNWapchu) installed" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="uct-13" comment="Apache running with SunPlex Manager config" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL2592" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 7</solaris:platform>
        <product>kcms_server</product>
      </affected>
      <dates>
        <submitted date="2005-01-19-12:00">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </submitted>
        <status_change date="2005-01-24-03:40">DRAFT</status_change>
        <status_change date="2005-02-16-12:00">INTERIM</status_change>
        <status_change date="2005-03-09-07:56">ACCEPTED</status_change>
      </dates>
      <description>Directory traversal vulnerability in Sun Kodak Color Management System (KCMS) library service daemon (kcms_server) allows remote attackers to read arbitrary files via the KCS_OPEN_PROFILE procedure.</description>
      <reference source="CVE">CVE-2003-0027</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-1080" comment="Solaris 7,8,or 9 installed" negate="false"/>
          <criterion test_ref="sat-18" comment="Kodak Color Managment Server (KCMS) Runtime Environment (SUNWkcsrt/SUNWkcsrx) installed" negate="false"/>
          <criterion test_ref="spt-20" comment="Patch 114636-01 or later installed" negate="true"/>
          <criterion test_ref="spt-21" comment="Patch 107337-03 or later installed" negate="true"/>
          <criterion test_ref="spt-22" comment="Patch 111400-02 or later installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="sit-206" comment="inetd.conf contains kcms_server" negate="false"/>
          <criterion test_ref="uct-4" comment="inetd running" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL2621" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 8</solaris:platform>
        <product>Sun Crypto Accelerator 4000</product>
      </affected>
      <dates>
        <submitted date="2004-10-12-09:44">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </submitted>
        <status_change date="2004-10-13-01:15">DRAFT</status_change>
        <status_change date="2004-10-27-12:00">INTERIM</status_change>
        <status_change date="2004-11-17-10:00">ACCEPTED</status_change>
      </dates>
      <description>The do_change_cipher_spec function in OpenSSL 0.9.6c to 0.9.6k, and 0.9.7a to 0.9.7c, allows remote attackers to cause a denial of service (crash) via a crafted SSL/TLS handshake that triggers a null dereference.</description>
      <reference source="CVE">CVE-2004-0079</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-1081" comment="Solaris 8 or 9 installed" negate="false"/>
          <criterion test_ref="spt-243" comment="Patch 114796-04 or later installed" negate="true"/>
          <criterion test_ref="sat-2" comment="Sun Crypto Accelerator 4000 software installed" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="uct-10" comment="Apache running (httpd)" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL2665" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 7</solaris:platform>
        <product>Sun Am7990 Ethernet Driver</product>
      </affected>
      <dates>
        <submitted date="2004-12-30-12:00">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </submitted>
        <status_change date="2005-01-12-12:41">DRAFT</status_change>
      </dates>
      <description>Multiple ethernet Network Interface Card (NIC) device drivers do not pad frames with null bytes, which allows remote attackers to obtain information from previous packets or kernel memory by using malformed packets, as demonstrated by Etherleak.</description>
      <reference source="CVE">CVE-2003-0001</reference>
      <status>DRAFT</status>
      <version>0</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-1080" comment="Solaris 7,8,or 9 installed" negate="false"/>
          <criterion test_ref="spt-16" comment="Patch 112604-02 or later installed" negate="true"/>
          <criterion test_ref="spt-17" comment="Patch 112609-02 or later installed" negate="true"/>
          <criterion test_ref="spt-18" comment="Patch 115172-01 or later installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="uft-30" comment="Lance Ethernet (le) interface configured to start" negate="false"/>
          <criterion test_ref="ukn-2" comment="Lance Ethernet interface in use" negate="false"/>
        </configuration>
      </criteria>
    </