<?xml version="1.0" encoding="UTF-8"?>
<oval xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval#unix unix-schema.xsd http://oval.mitre.org/XMLSchema/oval#independent independent-schema.xsd http://oval.mitre.org/XMLSchema/oval#solaris solaris-schema.xsd http://oval.mitre.org/XMLSchema/oval oval-schema.xsd" xmlns:oval="http://oval.mitre.org/XMLSchema/oval" xmlns="http://oval.mitre.org/XMLSchema/oval" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:solaris="http://oval.mitre.org/XMLSchema/oval#solaris">
  <generator>
    <schema_version>4.2</schema_version>
    <timestamp>20060614215733</timestamp>
  </generator>
  <definitions>
    <definition id="OVAL7" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 8</solaris:platform>
        <product>kcms_configure</product>
      </affected>
      <dates>
        <submitted date="2002-09-17-12:00">
          <contributor organization="The MITRE Corporation">David Proulx</contributor>
        </submitted>
      </dates>
      <description>kcms_configure as included with Solaris 7 and 8 allows a local attacker to gain additional privileges via a buffer overflow in a command line argument.</description>
      <reference source="CVE">CVE-2001-0594</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="uut-4" comment="Solaris 8 Installed" negate="false"/>
          <criterion test_ref="uft-5" comment="File kcms_configure exists" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-202" comment="File kcms_configure executable and SUID or SGID" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL9" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 8</solaris:platform>
        <product>libnsl</product>
      </affected>
      <dates>
        <submitted date="2003-01-28-12:00">
          <contributor organization="The MITRE Corporation">David Proulx</contributor>
        </submitted>
      </dates>
      <description>Integer overflow in xdr_array function in RPC servers for operating systems that use libc, glibc, or other code based on SunRPC including dietlibc, allows remote attackers to execute arbitrary code by passing a large number of arguments to xdr_array through RPC services such as rpc.cmsd and dmispd.</description>
      <reference source="CVE">CVE-2002-0391</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="uut-4" comment="Solaris 8 Installed" negate="false"/>
          <criterion test_ref="cmp-204" comment="rpc.cmsd or dmispd exist" negate="false"/>
          <criterion test_ref="cmp-205" comment="Patches 108827-30 and 108901-06" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-206" comment="rpc.cmsd enabled OR dmispd running" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL10" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 8</solaris:platform>
        <product>xlock</product>
      </affected>
      <dates>
        <submitted date="2002-09-17-12:00">
          <contributor organization="The MITRE Corporation">David Proulx</contributor>
        </submitted>
      </dates>
      <description>Heap overflow in xlock in Solaris 2.6 through 8 allows local users to gain root privileges via a long (1) XFILESEARCHPATH or (2) XUSERFILESEARCHPATH environmental variable.</description>
      <reference source="CVE">CVE-2001-0652</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="uut-4" comment="Solaris 8 Installed" negate="false"/>
          <criterion test_ref="uft-8" comment="File xlock exists" negate="false"/>
          <criterion test_ref="spt-203" comment="Patch 108652-38 or later installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-209" comment="File xlock SUID and executable" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL11" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 8</solaris:platform>
        <product>snmpdx</product>
      </affected>
      <dates>
        <submitted date="2002-09-25-12:00">
          <contributor organization="The MITRE Corporation">David Proulx</contributor>
        </submitted>
      </dates>
      <description>Format string vulnerability in the logging component of snmpdx for Solaris 5.6 through 8 allows remote attackers to gain root privileges.</description>
      <reference source="CVE">CVE-2002-0796</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="uut-4" comment="Solaris 8 Installed" negate="false"/>
          <criterion test_ref="uft-9" comment="File snmpdx exists" negate="false"/>
          <criterion test_ref="spt-204" comment="Patch 108869-16 or later installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="uct-6" comment="snmpdx running" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL14" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 8</solaris:platform>
        <product>Xsun</product>
      </affected>
      <dates>
        <submitted date="2002-08-23-12:00">
          <contributor organization="The MITRE Corporation">David Proulx</contributor>
        </submitted>
      </dates>
      <description>Buffer overflow in Xsun on Solaris 2.6 through 8 allows local users to gain root privileges via a long -co (color database) command line argument.</description>
      <reference source="CVE">CVE-2002-0158</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="uut-4" comment="Solaris 8 Installed" negate="false"/>
          <criterion test_ref="uft-10" comment="File Xsun exists" negate="false"/>
          <criterion test_ref="spt-205" comment="Patch 108652-52 or later installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-210" comment="File Xsun SGID and executable" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL15" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 8</solaris:platform>
        <product>CDE</product>
      </affected>
      <dates>
        <submitted date="2003-01-31-12:00">
          <contributor organization="The MITRE Corporation">David Proulx</contributor>
        </submitted>
      </dates>
      <description>CDE ToolTalk database server (ttdbserver) allows remote attackers to overwrite arbitrary memory locations with a zero, and possibly gain privileges, via a file descriptor argument in an AUTH_UNIX procedure call, which is used as a table index by the _TT_ISCLOSE procedure.</description>
      <reference source="CVE">CVE-2002-0677</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="uut-4" comment="Solaris 8 Installed" negate="false"/>
          <criterion test_ref="uft-11" comment="File rpc.ttdbserverd exists" negate="false"/>
          <criterion test_ref="spt-206" comment="Patch 110286-09 or later installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="sit-202" comment="inetd.conf contains rpc.ttdbserverd" negate="false"/>
          <criterion test_ref="uct-4" comment="inetd running" negate="false"/>
          <criterion test_ref="cmp-211" comment="File rpc.ttdbserverd executable" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL31" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 8</solaris:platform>
        <product>cachefsd</product>
      </affected>
      <dates>
        <submitted date="2003-01-31-12:00">
          <contributor organization="The MITRE Corporation">David Proulx</contributor>
        </submitted>
        <modified date="2005-01-28-12:00" comment="Updated to include Solaris 9 and Solaris 9 patch info">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </modified>
        <status_change date="2005-02-01-08:24">INTERIM</status_change>
        <status_change date="2005-02-16-12:00">ACCEPTED</status_change>
      </dates>
      <description>Heap-based buffer overflow in cfsd_calloc function of Solaris cachefsd allows remote attackers to execute arbitrary code via a request with a long directory and cache name.</description>
      <reference source="CVE">CVE-2002-0033</reference>
      <status>ACCEPTED</status>
      <version>3</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="uft-12" comment="File cachefsd exists" negate="false"/>
          <criterion test_ref="spt-207" comment="Patch 110896-02 or later installed" negate="true"/>
          <criterion test_ref="cmp-1081" comment="Solaris 8 or 9 installed" negate="false"/>
          <criterion test_ref="spt-111" comment="Patch 114008-01 or later installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="sit-203" comment="inetd.conf contains cachefsd" negate="false"/>
          <criterion test_ref="uct-4" comment="inetd running" negate="false"/>
          <criterion test_ref="cmp-217" comment="File cachefsd executable" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL33" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 7</solaris:platform>
        <product>Xsun</product>
      </affected>
      <dates>
        <submitted date="2002-10-17-12:00">
          <contributor organization="The MITRE Corporation">David Proulx</contributor>
        </submitted>
      </dates>
      <description>Buffer overflow in Xsun on Solaris 2.6 through 8 allows local users to gain root privileges via a long -co (color database) command line argument.</description>
      <reference source="CVE">CVE-2002-0158</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="uut-5" comment="Solaris 7 Installed" negate="false"/>
          <criterion test_ref="uft-10" comment="File Xsun exists" negate="false"/>
          <criterion test_ref="spt-208" comment="Patch 108376-38 or later installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-210" comment="File Xsun SGID and executable" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL34" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 7</solaris:platform>
        <product>whodo</product>
      </affected>
      <dates>
        <submitted date="2002-10-17-12:00">
          <contributor organization="The MITRE Corporation">David Proulx</contributor>
        </submitted>
      </dates>
      <description>Buffer overflow in whodo in Solaris SunOS 5.5.1 through 5.8 allows local users to execute arbitrary code via a long (1) SOR or (2) CFIME environment variable.</description>
      <reference source="CVE">CVE-2001-1076</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="uut-5" comment="Solaris 7 Installed" negate="false"/>
          <criterion test_ref="uft-13" comment="File whodo exists" negate="false"/>
          <criterion test_ref="spt-209" comment="Patch 111600-01 or later installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-219" comment="File whodo SUID and executable" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL41" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 7</solaris:platform>
        <product>rpc.rwalld</product>
      </affected>
      <dates>
        <submitted date="2003-01-30-12:00">
          <contributor organization="The MITRE Corporation">David Proulx</contributor>
        </submitted>
      </dates>
      <description>Format string vulnerability in RPC wall daemon (rpc.rwalld) for Solaris 2.5.1 through 8 allows remote attackers to execute arbitrary code via format strings in a message that is not properly provided to the syslog function when the wall command cannot be executed.</description>
      <reference source="CVE">CVE-2002-0573</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="uut-5" comment="Solaris 7 Installed" negate="false"/>
          <criterion test_ref="uft-14" comment="File rpc.rwalld exists" negate="false"/>
          <criterion test_ref="spt-210" comment="Patch 112899-01 or later installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="sit-204" comment="inetd.conf contains rpc.rwalld" negate="false"/>
          <criterion test_ref="uct-4" comment="inetd running" negate="false"/>
          <criterion test_ref="cmp-221" comment="File rpc.rwalld executable" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL42" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 7</solaris:platform>
        <product>libnsl</product>
      </affected>
      <dates>
        <submitted date="2003-01-02-12:00">
          <contributor organization="The MITRE Corporation">David Proulx</contributor>
        </submitted>
      </dates>
      <description>Integer overflow in xdr_array function in RPC servers for operating systems that use libc, glibc, or other code based on SunRPC including dietlibc, allows remote attackers to execute arbitrary code by passing a large number of arguments to xdr_array through RPC services such as rpc.cmsd and dmispd.</description>
      <reference source="CVE">CVE-2002-0391</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="uut-5" comment="Solaris 7 Installed" negate="false"/>
          <criterion test_ref="cmp-204" comment="rpc.cmsd or dmispd exist" negate="false"/>
          <criterion test_ref="cmp-223" comment="Patches 106942-22 and 108451-06" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-206" comment="rpc.cmsd enabled OR dmispd running" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL43" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 7</solaris:platform>
        <product>cachefsd</product>
      </affected>
      <dates>
        <submitted date="2002-10-17-12:00">
          <contributor organization="The MITRE Corporation">David Proulx</contributor>
        </submitted>
        <modified date="2005-01-28-12:00" comment="Updated to add patch test">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </modified>
        <status_change date="2005-02-01-08:25">INTERIM</status_change>
        <status_change date="2005-02-16-12:00">ACCEPTED</status_change>
      </dates>
      <description>Buffer overflow in the fscache_setup function of cachefsd in Solaris 2.6, 7, and 8 allows local users to gain root privileges via a long mount argument.</description>
      <reference source="CVE">CVE-2002-0084</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="uut-5" comment="Solaris 7 Installed" negate="false"/>
          <criterion test_ref="uft-12" comment="File cachefsd exists" negate="false"/>
          <criterion test_ref="spt-109" comment="Patch 108800-02 or later installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="sit-203" comment="inetd.conf contains cachefsd" negate="false"/>
          <criterion test_ref="uct-4" comment="inetd running" negate="false"/>
          <criterion test_ref="cmp-217" comment="File cachefsd executable" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL47" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 8</solaris:platform>
        <product>whodo</product>
      </affected>
      <dates>
        <submitted date="2002-09-17-12:00">
          <contributor organization="The MITRE Corporation">David Proulx</contributor>
        </submitted>
      </dates>
      <description>Buffer overflow in whodo in Solaris SunOS 5.5.1 through 5.8 allows local users to execute arbitrary code via a long (1) SOR or (2) CFIME environment variable.</description>
      <reference source="CVE">CVE-2001-1076</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="uut-4" comment="Solaris 8 Installed" negate="false"/>
          <criterion test_ref="uft-13" comment="File whodo exists" negate="false"/>
          <criterion test_ref="spt-213" comment="Patch 111826-01 or later installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-219" comment="File whodo SUID and executable" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL48" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 7</solaris:platform>
        <product>Admintool</product>
      </affected>
      <dates>
        <submitted date="2002-10-17-12:00">
          <contributor organization="The MITRE Corporation">David Proulx</contributor>
        </submitted>
        <modified date="2006-06-13-02:02" comment="modified uft-15 - admintool is either /bin/admintool or /usr/bin/admintool (or both).  Regular expression had been ^.*/bin/admintool$, which could cause arbitrary-depth search.  Changed to ^(/usr)?/bin/admintool$, which bounds the search properly.">
          <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
        </modified>
        <modified date="2006-06-13-02:20" comment="modified upt-845 - admintool is either /bin/admintool or /usr/bin/admintool (or both). Regular expression had been ^.*/bin/admintool$, which could cause arbitrary-depth search. Changed to ^(/usr)?/bin/admintool$, which bounds the search properly.  Also modified to test for both SUID and OEXEC bits, so a second test is not needed.">
          <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
        </modified>
        <modified date="2006-06-13-02:22" comment="Removed compound test for &quot;admintool SUID and executable&quot; because new version of upt-845 does both.">
          <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
        </modified>
        <status_change date="2006-06-14-07:41">INTERIM</status_change>
      </dates>
      <description>Buffer overflow in admintool in Solaris 2.6, 7, and 8 allows local users to gain root privileges via a long media installation path.</description>
      <reference source="CVE">CVE-2002-0088</reference>
      <status>INTERIM</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="uut-5" comment="Solaris 7 Installed" negate="false"/>
          <criterion test_ref="uft-15" comment="File admintool exists" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="upt-845" comment="File admintool SUID and executable" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL56" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 8</solaris:platform>
        <product>rpc.yppasswdd</product>
      </affected>
      <dates>
        <submitted date="2002-08-30-12:00">
          <contributor organization="The MITRE Corporation">David Proulx</contributor>
        </submitted>
      </dates>
      <description>Buffer overflow in rpc.yppasswdd (yppasswd server) in Solaris 2.6, 7 and 8 allows remote attackers to gain root access via a long username.</description>
      <reference source="CVE">CVE-2001-0779</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="uut-4" comment="Solaris 8 Installed" negate="false"/>
          <criterion test_ref="uft-16" comment="File rpc.yppasswdd exists" negate="false"/>
          <criterion test_ref="spt-214" comment="Patch 111596-02 or later installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="uct-7" comment="rpc.yppasswdd running" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL60" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 8</solaris:platform>
        <product>Admintool</product>
      </affected>
      <dates>
        <submitted date="2002-09-17-12:00">
          <contributor organization="The MITRE Corporation">David Proulx</contributor>
        </submitted>
        <modified date="2006-06-13-02:02" comment="modified uft-15 - admintool is either /bin/admintool or /usr/bin/admintool (or both).  Regular expression had been ^.*/bin/admintool$, which could cause arbitrary-depth search.  Changed to ^(/usr)?/bin/admintool$, which bounds the search properly.">
          <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
        </modified>
        <modified date="2006-06-13-02:20" comment="modified upt-845 - admintool is either /bin/admintool or /usr/bin/admintool (or both). Regular expression had been ^.*/bin/admintool$, which could cause arbitrary-depth search. Changed to ^(/usr)?/bin/admintool$, which bounds the search properly.  Also modified to test for both SUID and OEXEC bits, so a second test is not needed.">
          <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
        </modified>
        <modified date="2006-06-13-02:23" comment="Removed compound test for &quot;admintool SUID and executable&quot; because new version of upt-845 does both.">
          <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
        </modified>
        <status_change date="2006-06-14-07:41">INTERIM</status_change>
      </dates>
      <description>Buffer overflow in admintool in Solaris 2.6, 7, and 8 allows local users to gain root privileges via a long media installation path.</description>
      <reference source="CVE">CVE-2002-0088</reference>
      <status>INTERIM</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="uut-4" comment="Solaris 8 Installed" negate="false"/>
          <criterion test_ref="uft-15" comment="File admintool exists" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="upt-845" comment="File admintool SUID and executable" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL62" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 7</solaris:platform>
        <product>mibiisa</product>
      </affected>
      <dates>
        <submitted date="2002-10-17-12:00">
          <contributor organization="The MITRE Corporation">David Proulx</contributor>
        </submitted>
      </dates>
      <description>Buffer overflow in the MIB parsing component of mibiisa for Solaris 5.6 through 8 allows remote attackers to gain root privileges.</description>
      <reference source="CVE">CVE-2002-0797</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="uut-5" comment="Solaris 7 Installed" negate="false"/>
          <criterion test_ref="uft-17" comment="File mibiisa exists" negate="false"/>
          <criterion test_ref="spt-215" comment="Patch 107709-19 or later installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="uct-8" comment="mibiisa running" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL65" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 7</solaris:platform>
        <product>kcms_configure</product>
      </affected>
      <dates>
        <submitted date="2002-09-17-12:00">
          <contributor organization="The MITRE Corporation">David Proulx</contributor>
        </submitted>
      </dates>
      <description>kcms_configure as included with Solaris 7 and 8 allows a local attacker to gain additional privileges via a buffer overflow in a command line argument.</description>
      <reference source="CVE">CVE-2001-0594</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="uut-5" comment="Solaris 7 Installed" negate="false"/>
          <criterion test_ref="uft-5" comment="File kcms_configure exists" negate="false"/>
          <criterion test_ref="spt-216" comment="Patch 107337-02 or later installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-202" comment="File kcms_configure executable and SUID or SGID" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL67" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 8</solaris:platform>
        <product>Admintool</product>
      </affected>
      <dates>
        <submitted date="2002-09-17-12:00">
          <contributor organization="The MITRE Corporation">David Proulx</contributor>
        </submitted>
        <modified date="2006-06-13-02:02" comment="modified uft-15 - admintool is either /bin/admintool or /usr/bin/admintool (or both).  Regular expression had been ^.*/bin/admintool$, which could cause arbitrary-depth search.  Changed to ^(/usr)?/bin/admintool$, which bounds the search properly.">
          <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
        </modified>
        <modified date="2006-06-13-02:20" comment="modified upt-845 - admintool is either /bin/admintool or /usr/bin/admintool (or both). Regular expression had been ^.*/bin/admintool$, which could cause arbitrary-depth search. Changed to ^(/usr)?/bin/admintool$, which bounds the search properly.  Also modified to test for both SUID and OEXEC bits, so a second test is not needed.">
          <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
        </modified>
        <modified date="2006-06-13-02:24" comment="Removed compound test for &quot;admintool SUID and executable&quot; because new version of upt-845 does both.">
          <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
        </modified>
        <status_change date="2006-06-14-07:41">INTERIM</status_change>
      </dates>
      <description>Buffer overflow in admintool in Solaris 2.5 through 8 allows local users to gain root privileges via long arguments to (1) the -d command line option, or (2) the PRODVERS argument in the .cdtoc file.</description>
      <reference source="CVE">CVE-2002-0089</reference>
      <status>INTERIM</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="uut-4" comment="Solaris 8 Installed" negate="false"/>
          <criterion test_ref="uft-15" comment="File admintool exists" negate="false"/>
          <criterion test_ref="spt-217" comment="Patch 110453-01 or later installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="upt-845" comment="File admintool SUID and executable" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL68" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 7</solaris:platform>
        <product>Admintool</product>
      </affected>
      <dates>
        <submitted date="2002-10-17-12:00">
          <contributor organization="The MITRE Corporation">David Proulx</contributor>
        </submitted>
        <modified date="2006-06-13-02:02" comment="modified uft-15 - admintool is either /bin/admintool or /usr/bin/admintool (or both).  Regular expression had been ^.*/bin/admintool$, which could cause arbitrary-depth search.  Changed to ^(/usr)?/bin/admintool$, which bounds the search properly.">
          <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
        </modified>
        <modified date="2006-06-13-02:20" comment="modified upt-845 - admintool is either /bin/admintool or /usr/bin/admintool (or both). Regular expression had been ^.*/bin/admintool$, which could cause arbitrary-depth search. Changed to ^(/usr)?/bin/admintool$, which bounds the search properly.  Also modified to test for both SUID and OEXEC bits, so a second test is not needed.">
          <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
        </modified>
        <modified date="2006-06-13-02:25" comment="Removed compound test for &quot;admintool SUID and executable&quot; because new version of upt-845 does both.">
          <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
        </modified>
        <status_change date="2006-06-14-07:41">INTERIM</status_change>
      </dates>
      <description>Buffer overflow in admintool in Solaris 2.5 through 8 allows local users to gain root privileges via long arguments to (1) the -d command line option, or (2) the PRODVERS argument in the .cdtoc file.</description>
      <reference source="CVE">CVE-2002-0089</reference>
      <status>INTERIM</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="uut-5" comment="Solaris 7 Installed" negate="false"/>
          <criterion test_ref="uft-15" comment="File admintool exists" negate="false"/>
          <criterion test_ref="spt-218" comment="Patch 108721-02 or later installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="upt-845" comment="File admintool SUID and executable" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL70" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 8</solaris:platform>
        <product>dtspcd</product>
      </affected>
      <dates>
        <submitted date="2002-08-23-12:00">
          <contributor organization="The MITRE Corporation">David Proulx</contributor>
        </submitted>
      </dates>
      <description>Buffer overflow in the client connection routine of libDtSvc.so.1 in CDE Subprocess Control Service (dtspcd) allows remote attackers to execute arbitrary commands</description>
      <reference source="CVE">CVE-2001-0803</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="uut-4" comment="Solaris 8 Installed" negate="false"/>
          <criterion test_ref="uft-18" comment="File dtspcd exists" negate="false"/>
          <criterion test_ref="spt-219" comment="Patch 108949-07 or later installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="sit-205" comment="inetd.conf contains dtspcd" negate="false"/>
          <criterion test_ref="uct-4" comment="inetd running" negate="false"/>
          <criterion test_ref="cmp-239" comment="File dtspcd executable" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL74" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 7</solaris:platform>
        <product>dtspcd</product>
      </affected>
      <dates>
        <submitted date="2002-10-17-12:00">
          <contributor organization="The MITRE Corporation">David Proulx</contributor>
        </submitted>
      </dates>
      <description>Buffer overflow in the client connection routine of libDtSvc.so.1 in CDE Subprocess Control Service (dtspcd) allows remote attackers to execute arbitrary commands</description>
      <reference source="CVE">CVE-2001-0803</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="uut-5" comment="Solaris 7 Installed" negate="false"/>
          <criterion test_ref="uft-18" comment="File dtspcd exists" negate="false"/>
          <criterion test_ref="spt-220" comment="Patch 106934-04 or later installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="sit-205" comment="inetd.conf contains dtspcd" negate="false"/>
          <criterion test_ref="uct-4" comment="inetd running" negate="false"/>
          <criterion test_ref="cmp-239" comment="File dtspcd executable" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL79" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 8</solaris:platform>
        <product>rpc.rwalld</product>
      </affected>
      <dates>
        <submitted date="2003-01-30-12:00">
          <contributor organization="The MITRE Corporation">David Proulx</contributor>
        </submitted>
      </dates>
      <description>Format string vulnerability in RPC wall daemon (rpc.rwalld) for Solaris 2.5.1 through 8 allows remote attackers to execute arbitrary code via format strings in a message that is not properly provided to the syslog function when the wall command cannot be executed.</description>
      <reference source="CVE">CVE-2002-0573</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="uut-4" comment="Solaris 8 Installed" negate="false"/>
          <criterion test_ref="uft-14" comment="File rpc.rwalld exists" negate="false"/>
          <criterion test_ref="spt-221" comment="Patch 112846-01 or later installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="sit-204" comment="inetd.conf contains rpc.rwalld" negate="false"/>
          <criterion test_ref="uct-4" comment="inetd running" negate="false"/>
          <criterion test_ref="cmp-221" comment="File rpc.rwalld executable" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL80" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 7</solaris:platform>
        <product>CDE</product>
      </affected>
      <dates>
        <submitted date="2003-01-29-12:00">
          <contributor organization="The MITRE Corporation">David Proulx</contributor>
        </submitted>
      </dates>
      <description>CDE ToolTalk database server (ttdbserver) allows local users to overwrite arbitrary files via a symlink attack on the transaction log file used by the _TT_TRANSACTION RPC procedure.</description>
      <reference source="CVE">CVE-2002-0678</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="uut-5" comment="Solaris 7 Installed" negate="false"/>
          <criterion test_ref="uft-11" comment="File rpc.ttdbserverd exists" negate="false"/>
          <criterion test_ref="spt-222" comment="Patch 107893-19 or later installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="sit-202" comment="inetd.conf contains rpc.ttdbserverd" negate="false"/>
          <criterion test_ref="uct-4" comment="inetd running" negate="false"/>
          <criterion test_ref="cmp-211" comment="File rpc.ttdbserverd executable" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL86" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 8</solaris:platform>
        <product>lbxproxy</product>
      </affected>
      <dates>
        <submitted date="2002-08-30-12:00">
          <contributor organization="The MITRE Corporation">David Proulx</contributor>
        </submitted>
      </dates>
      <description>Buffer overflow in Low BandWidth X proxy (lbxproxy) in Solaris 8 allows local users to execute arbitrary code via a long display command line option.</description>
      <reference source="CVE">CVE-2002-0090</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="uut-4" comment="Solaris 8 Installed" negate="false"/>
          <criterion test_ref="uft-19" comment="File lbxproxy exists" negate="false"/>
          <criterion test_ref="spt-223" comment="Patch 108652-51 or later installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-247" comment="File lbxproxy SGID and executable" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL91" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 7</solaris:platform>
        <product>CDE</product>
      </affected>
      <dates>
        <submitted date="2003-01-31-12:00">
          <contributor organization="The MITRE Corporation">David Proulx</contributor>
        </submitted>
      </dates>
      <description>CDE ToolTalk database server (ttdbserver) allows remote attackers to overwrite arbitrary memory locations with a zero, and possibly gain privileges, via a file descriptor argument in an AUTH_UNIX procedure call, which is used as a table index by the _TT_ISCLOSE procedure.</description>
      <reference source="CVE">CVE-2002-0677</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="uut-5" comment="Solaris 7 Installed" negate="false"/>
          <criterion test_ref="uft-11" comment="File rpc.ttdbserverd exists" negate="false"/>
          <criterion test_ref="spt-222" comment="Patch 107893-19 or later installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="sit-202" comment="inetd.conf contains rpc.ttdbserverd" negate="false"/>
          <criterion test_ref="uct-4" comment="inetd running" negate="false"/>
          <criterion test_ref="cmp-211" comment="File rpc.ttdbserverd executable" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL94" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 8</solaris:platform>
        <product>mibiisa</product>
      </affected>
      <dates>
        <submitted date="2002-09-25-12:00">
          <contributor organization="The MITRE Corporation">David Proulx</contributor>
        </submitted>
      </dates>
      <description>Buffer overflow in the MIB parsing component of mibiisa for Solaris 5.6 through 8 allows remote attackers to gain root privileges.</description>
      <reference source="CVE">CVE-2002-0797</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="uut-4" comment="Solaris 8 Installed" negate="false"/>
          <criterion test_ref="uft-17" comment="File mibiisa exists" negate="false"/>
          <criterion test_ref="spt-204" comment="Patch 108869-16 or later installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="uct-8" comment="mibiisa running" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL97" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 8</solaris:platform>
        <product>cachefsd</product>
      </affected>
      <dates>
        <submitted date="2002-09-17-12:00">
          <contributor organization="The MITRE Corporation">David Proulx</contributor>
        </submitted>
        <modified date="2005-01-27-12:00" comment="Updated to add patch test">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </modified>
        <modified date="2005-01-28-12:00" comment="Added Solaris 9 and Solaris 9 patch test to the definition">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </modified>
        <status_change date="2005-02-01-08:28">INTERIM</status_change>
        <status_change date="2005-02-16-12:00">ACCEPTED</status_change>
      </dates>
      <description>Buffer overflow in the fscache_setup function of cachefsd in Solaris 2.6, 7, and 8 allows local users to gain root privileges via a long mount argument.</description>
      <reference source="CVE">CVE-2002-0084</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="uft-12" comment="File cachefsd exists" negate="false"/>
          <criterion test_ref="cmp-1081" comment="Solaris 8 or 9 installed" negate="false"/>
          <criterion test_ref="spt-110" comment="Patch 110896-02 or later installed" negate="true"/>
          <criterion test_ref="spt-111" comment="Patch 114008-01 or later installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="sit-203" comment="inetd.conf contains cachefsd" negate="false"/>
          <criterion test_ref="uct-4" comment="inetd running" negate="false"/>
          <criterion test_ref="cmp-217" comment="File cachefsd executable" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL102" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 7</solaris:platform>
        <product>rpc.yppasswdd</product>
      </affected>
      <dates>
        <submitted date="2002-10-17-12:00">
          <contributor organization="The MITRE Corporation">David Proulx</contributor>
        </submitted>
      </dates>
      <description>Buffer overflow in rpc.yppasswdd (yppasswd server) in Solaris 2.6, 7 and 8 allows remote attackers to gain root access via a long username.</description>
      <reference source="CVE">CVE-2001-0779</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="uut-5" comment="Solaris 7 Installed" negate="false"/>
          <criterion test_ref="uft-16" comment="File rpc.yppasswdd exists" negate="false"/>
          <criterion test_ref="spt-224" comment="Patch 111590-02 or later installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="uct-7" comment="rpc.yppasswdd running" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL114" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 7</solaris:platform>
        <product>snmpdx</product>
      </affected>
      <dates>
        <submitted date="2002-10-17-12:00">
          <contributor organization="The MITRE Corporation">David Proulx</contributor>
        </submitted>
      </dates>
      <description>Format string vulnerability in the logging component of snmpdx for Solaris 5.6 through 8 allows remote attackers to gain root privileges.</description>
      <reference source="CVE">CVE-2002-0796</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="uut-5" comment="Solaris 7 Installed" negate="false"/>
          <criterion test_ref="uft-9" comment="File snmpdx exists" negate="false"/>
          <criterion test_ref="spt-215" comment="Patch 107709-19 or later installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="uct-6" comment="snmpdx running" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL120" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 7</solaris:platform>
        <product>kcms_server</product>
      </affected>
      <dates>
        <submitted date="2003-01-30-12:00">
          <contributor organization="The MITRE Corporation">David Proulx</contributor>
        </submitted>
      </dates>
      <description>Directory traversal vulnerability in Sun Kodak Color Management System (KCMS) library service daemon (kcms_server) allows remote attackers to read arbitrary files via the KCS_OPEN_PROFILE procedure.</description>
      <reference source="CVE">CVE-2003-0027</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="uut-5" comment="Solaris 7 Installed" negate="false"/>
          <criterion test_ref="uft-20" comment="File kcms_server exists" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="sit-206" comment="inetd.conf contains kcms_server" negate="false"/>
          <criterion test_ref="uct-4" comment="inetd running" negate="false"/>
          <criterion test_ref="cmp-255" comment="File kcms_server executable and SUID or SGID" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL124" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 7</solaris:platform>
        <product>cachefsd</product>
      </affected>
      <dates>
        <submitted date="2002-10-17-12:00">
          <contributor organization="The MITRE Corporation">David Proulx</contributor>
        </submitted>
        <modified date="2005-01-28-12:00" comment="Added patch test">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </modified>
        <status_change date="2005-02-01-08:29">INTERIM</status_change>
        <status_change date="2005-02-16-12:00">ACCEPTED</status_change>
      </dates>
      <description>Heap-based buffer overflow in cfsd_calloc function of Solaris cachefsd allows remote attackers to execute arbitrary code via a request with a long directory and cache name.</description>
      <reference source="CVE">CVE-2002-0033</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="uut-5" comment="Solaris 7 Installed" negate="false"/>
          <criterion test_ref="uft-12" comment="File cachefsd exists" negate="false"/>
          <criterion test_ref="spt-109" comment="Patch 108800-02 or later installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="sit-203" comment="inetd.conf contains cachefsd" negate="false"/>
          <criterion test_ref="uct-4" comment="inetd running" negate="false"/>
          <criterion test_ref="cmp-217" comment="File cachefsd executable" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL131" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 7</solaris:platform>
        <product>xlock</product>
      </affected>
      <dates>
        <submitted date="2002-10-17-12:00">
          <contributor organization="The MITRE Corporation">David Proulx</contributor>
        </submitted>
      </dates>
      <description>Heap overflow in xlock in Solaris 2.6 through 8 allows local users to gain root privileges via a long (1) XFILESEARCHPATH or (2) XUSERFILESEARCHPATH environmental variable.</description>
      <reference source="CVE">CVE-2001-0652</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="uut-5" comment="Solaris 7 Installed" negate="false"/>
          <criterion test_ref="uft-8" comment="File xlock exists" negate="false"/>
          <criterion test_ref="spt-225" comment="Patch 108376-30 or later installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-209" comment="File xlock SUID and executable" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL149" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 8</solaris:platform>
        <product>fs.auto, xfs</product>
      </affected>
      <dates>
        <submitted date="2003-09-08-12:00">
          <contributor organization="The MITRE Corporation">David Proulx</contributor>
        </submitted>
      </dates>
      <description>Buffer overflow in Dispatch() routine for XFS font server (fs.auto) on Solaris 2.5.1 through 9 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a certain XFS query.</description>
      <reference source="CVE">CVE-2002-1317</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="uut-4" comment="Solaris 8 Installed" negate="false"/>
          <criterion test_ref="uft-21" comment="File fs.auto exists" negate="false"/>
          <criterion test_ref="uft-22" comment="File xfs exists" negate="false"/>
          <criterion test_ref="spt-226" comment="Patch 109862-03 or later installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="sit-207" comment="inetd.conf contains fs.auto" negate="false"/>
          <criterion test_ref="uct-4" comment="inetd running" negate="false"/>
          <criterion test_ref="cmp-267" comment="File xfs executable" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL152" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 7</solaris:platform>
        <product>fs.auto, xfs</product>
      </affected>
      <dates>
        <submitted date="2003-09-08-12:00">
          <contributor organization="The MITRE Corporation">David Proulx</contributor>
        </submitted>
      </dates>
      <description>Buffer overflow in Dispatch() routine for XFS font server (fs.auto) on Solaris 2.5.1 through 9 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a certain XFS query.</description>
      <reference source="CVE">CVE-2002-1317</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="uut-5" comment="Solaris 7 Installed" negate="false"/>
          <criterion test_ref="uft-21" comment="File fs.auto exists" negate="false"/>
          <criterion test_ref="uft-22" comment="File xfs exists" negate="false"/>
          <criterion test_ref="spt-227" comment="Patch 108117-06 or later installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="sit-207" comment="inetd.conf contains fs.auto" negate="false"/>
          <criterion test_ref="uct-4" comment="inetd running" negate="false"/>
          <criterion test_ref="cmp-267" comment="File xfs executable" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL175" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 8</solaris:platform>
        <product>CDE</product>
      </affected>
      <dates>
        <submitted date="2003-01-29-12:00">
          <contributor organization="The MITRE Corporation">David Proulx</contributor>
        </submitted>
      </dates>
      <description>CDE ToolTalk database server (ttdbserver) allows local users to overwrite arbitrary files via a symlink attack on the transaction log file used by the _TT_TRANSACTION RPC procedure.</description>
      <reference source="CVE">CVE-2002-0678</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="uut-4" comment="Solaris 8 Installed" negate="false"/>
          <criterion test_ref="uft-11" comment="File rpc.ttdbserverd exists" negate="false"/>
          <criterion test_ref="spt-206" comment="Patch 110286-09 or later installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="sit-202" comment="inetd.conf contains rpc.ttdbserverd" negate="false"/>
          <criterion test_ref="uct-4" comment="inetd running" negate="false"/>
          <criterion test_ref="cmp-211" comment="File rpc.ttdbserverd executable" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL177" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 7</solaris:platform>
        <product>CDE</product>
      </affected>
      <dates>
        <submitted date="2003-01-29-12:00">
          <contributor organization="The MITRE Corporation">David Proulx</contributor>
        </submitted>
      </dates>
      <description>Buffer overflow in Common Desktop Environment (CDE) ToolTalk RPC database server (rpc.ttdbserverd) allows remote attackers to execute arbitrary code via an argument to the _TT_CREATE_FILE procedure.</description>
      <reference source="CVE">CVE-2002-0679</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="uut-5" comment="Solaris 7 Installed" negate="false"/>
          <criterion test_ref="uft-11" comment="File rpc.ttdbserverd exists" negate="false"/>
          <criterion test_ref="spt-228" comment="Patch 107893-20 or later installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="sit-202" comment="inetd.conf contains rpc.ttdbserverd" negate="false"/>
          <criterion test_ref="uct-4" comment="inetd running" negate="false"/>
          <criterion test_ref="cmp-211" comment="File rpc.ttdbserverd executable" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL179" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 7</solaris:platform>
        <product>lbxproxy</product>
      </affected>
      <dates>
        <submitted date="2002-10-17-12:00">
          <contributor organization="The MITRE Corporation">David Proulx</contributor>
        </submitted>
      </dates>
      <description>Buffer overflow in Low BandWidth X proxy (lbxproxy) in Solaris 8 allows local users to execute arbitrary code via a long display command line option.</description>
      <reference source="CVE">CVE-2002-0090</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="uut-5" comment="Solaris 7 Installed" negate="false"/>
          <criterion test_ref="uft-19" comment="File lbxproxy exists" negate="false"/>
          <criterion test_ref="spt-229" comment="Patch 107654-10 or later installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="cmp-247" comment="File lbxproxy SGID and executable" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL192" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 8</solaris:platform>
        <product>CDE</product>
      </affected>
      <dates>
        <submitted date="2003-01-29-12:00">
          <contributor organization="The MITRE Corporation">David Proulx</contributor>
        </submitted>
      </dates>
      <description>Buffer overflow in Common Desktop Environment (CDE) ToolTalk RPC database server (rpc.ttdbserverd) allows remote attackers to execute arbitrary code via an argument to the _TT_CREATE_FILE procedure.</description>
      <reference source="CVE">CVE-2002-0679</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="uut-4" comment="Solaris 8 Installed" negate="false"/>
          <criterion test_ref="uft-11" comment="File rpc.ttdbserverd exists" negate="false"/>
          <criterion test_ref="spt-230" comment="Patch 110286-10 or later installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="sit-202" comment="inetd.conf contains rpc.ttdbserverd" negate="false"/>
          <criterion test_ref="uct-4" comment="inetd running" negate="false"/>
          <criterion test_ref="cmp-211" comment="File rpc.ttdbserverd executable" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL195" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 8</solaris:platform>
        <product>kcms_server</product>
      </affected>
      <dates>
        <submitted date="2003-01-24-12:00">
          <contributor organization="The MITRE Corporation">David Proulx</contributor>
        </submitted>
      </dates>
      <description>Directory traversal vulnerability in Sun Kodak Color Management System (KCMS) library service daemon (kcms_server) allows remote attackers to read arbitrary files via the KCS_OPEN_PROFILE procedure.</description>
      <reference source="CVE">CVE-2003-0027</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="uut-4" comment="Solaris 8 Installed" negate="false"/>
          <criterion test_ref="uft-20" comment="File kcms_server exists" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="sit-206" comment="inetd.conf contains kcms_server" negate="false"/>
          <criterion test_ref="uct-4" comment="inetd running" negate="false"/>
          <criterion test_ref="cmp-255" comment="File kcms_server executable and SUID or SGID" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL449" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 9</solaris:platform>
        <product>Bind</product>
      </affected>
      <dates>
        <submitted date="2005-01-19-12:00">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </submitted>
        <status_change date="2005-01-24-03:40">DRAFT</status_change>
        <status_change date="2005-02-16-12:00">INTERIM</status_change>
        <status_change date="2005-03-09-07:56">ACCEPTED</status_change>
      </dates>
      <description>BIND 8.3.x through 8.3.3 allows remote attackers to cause a denial of service (termination due to assertion failure) via a request for a subdomain that does not exist, with an OPT resource record with a large UDP payload size.</description>
      <reference source="CVE">CVE-2002-1220</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="uut-6" comment="Solaris 9 Installed" negate="false"/>
          <criterion test_ref="sat-19" comment="Internet Domain Name Server (BIND, SUNWinamd) installed" negate="false"/>
          <criterion test_ref="spt-26" comment="Patch 112970-03 or later installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="uct-14" comment="in.named running" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL555" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 7</solaris:platform>
        <product>Xsun</product>
      </affected>
      <dates>
        <submitted date="2004-12-28-12:00">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </submitted>
        <status_change date="2005-01-12-12:41">DRAFT</status_change>
        <status_change date="2005-02-02-12:00">INTERIM</status_change>
        <status_change date="2005-02-23-09:25">ACCEPTED</status_change>
      </dates>
      <description>Buffer overflow in Xsun in Solaris 8 and earlier allows local users to execute arbitrary commands via a long HOME environmental variable.</description>
      <reference source="CVE">CVE-2001-0422</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-43" comment="Solaris 7 or 8 installed" negate="false"/>
          <criterion test_ref="spt-4" comment="Patch 108376-25 or later installed" negate="true"/>
          <criterion test_ref="spt-5" comment="Patch 108652-30 or later installed" negate="true"/>
          <criterion test_ref="sat-12" comment="X Window System platform software (SUNWxwplt) installed" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL592" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 7</solaris:platform>
        <solaris:platform>Sun Solaris 8</solaris:platform>
        <solaris:platform>Sun Solaris 9</solaris:platform>
        <product>Licence Logging Service</product>
      </affected>
      <dates>
        <submitted date="2005-04-13-12:00">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </submitted>
        <status_change date="2005-04-20-12:13">DRAFT</status_change>
        <status_change date="2005-05-11-05:41">INTERIM</status_change>
        <status_change date="2005-06-01-03:30">ACCEPTED</status_change>
      </dates>
      <description>Unknown vulnerability in the rwho daemon (in.rwhod) for Solaris 7 through 9 allows remote attackers to execute arbitrary code.</description>
      <reference source="CVE">CVE-2004-1351</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-87" comment="Solaris 7 or 8 OR Solaris 9 and Remote Network Server Commands (SUNWrcmds) installed" negate="false"/>
          <criterion test_ref="spt-68" comment="Patch 118239-01 or later installed" negate="true"/>
          <criterion test_ref="spt-69" comment="Patch 116984-01 or later installed" negate="true"/>
          <criterion test_ref="spt-70" comment="Patch 117455-01 or later installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="uct-19" comment="in.rwhod is running" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL662" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 8</solaris:platform>
        <solaris:platform>Sun Solaris 9</solaris:platform>
        <solaris:platform>Sun Solaris 10</solaris:platform>
        <product>Operating System</product>
      </affected>
      <dates>
        <submitted date="2006-01-16-12:05">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2006-01-25-07:30">DRAFT</status_change>
        <status_change date="2006-02-22-08:27">INTERIM</status_change>
        <status_change date="2006-03-09-12:19">ACCEPTED</status_change>
      </dates>
      <description>Multiple unspecified vulnerabilities in lpsched in Sun Solaris 8, 9, and 10 allow local users to delete arbitrary files or disable the LP print service via unknown attack vectors.</description>
      <reference source="CVE">CVE-2006-0227</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="OR">
          <criterion test_ref="cmp-719" comment="Solaris 8 (SPARC) meets Sun Alert ID 102033 criteria." negate="false"/>
          <criterion test_ref="cmp-720" comment="Solaris 8 (x86) meets Sun Alert ID 102033 criteria." negate="false"/>
          <criterion test_ref="cmp-721" comment="Solaris 9 (SPARC) meets Sun Alert ID 102033 criteria." negate="false"/>
          <criterion test_ref="cmp-722" comment="Solaris 9 (x86) meets Sun Alert ID 102033 criteria." negate="false"/>
          <criterion test_ref="cmp-723" comment="Solaris 10 (sparc) meets Sun Alert ID 102033 criteria." negate="false"/>
          <criterion test_ref="cmp-724" comment="Solaris 10 (x86) meets Sun Alert ID 102033 criteria." negate="false"/>
          <criterion test_ref="uft-32" comment="Target is configured as a print server" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL702" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 9</solaris:platform>
        <solaris:platform>Sun Solaris 10</solaris:platform>
        <product>Operating System</product>
      </affected>
      <dates>
        <submitted date="2006-01-12-11:25">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2006-01-25-07:30">DRAFT</status_change>
        <status_change date="2006-02-22-08:27">INTERIM</status_change>
        <status_change date="2006-03-09-12:19">ACCEPTED</status_change>
      </dates>
      <description>Unspecified vulnerability in Sun Solaris 9 and 10 for the x86 platform allows local users to gain privileges or cause a denial of service (panic) via unspecified vectors, possibly involving functions from the mm driver.</description>
      <reference source="CVE">CVE-2006-0190</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="OR">
          <criterion test_ref="cmp-713" comment="Solaris 9 (x86) meets Sun Alert ID 102066 criteria." negate="false"/>
          <criterion test_ref="cmp-714" comment="Solaris 10 (x86) meets Sun Alert ID 102066 and 102108 criteria." negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL881" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 8</solaris:platform>
        <solaris:platform>Sun Solaris 9</solaris:platform>
        <solaris:platform>Sun Solaris 10</solaris:platform>
        <product>Operating System</product>
      </affected>
      <dates>
        <submitted date="2006-04-14-06:41">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2006-04-19-10:08">DRAFT</status_change>
        <status_change date="2006-05-10-08:33">INTERIM</status_change>
        <status_change date="2006-05-31-09:45">ACCEPTED</status_change>
      </dates>
      <description>The Bourne shell (sh) in Solaris 8, 9, and 10 allows local users to cause a denial of service (sh crash) via an unspecified attack vector that causes sh processes to crash during creation of temporary files.</description>
      <reference source="CVE">CVE-2006-1780</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="OR">
          <criterion test_ref="cmp-845" comment="Solaris 8 (SPARC) meets Sun Alert ID 102282 criteria." negate="false"/>
          <criterion test_ref="cmp-846" comment="Solaris 9 (SPARC) meets Sun Alert ID 102282 criteria." negate="false"/>
          <criterion test_ref="cmp-847" comment="Solaris 10 (SPARC) meets Sun Alert ID 102282 criteria." negate="false"/>
          <criterion test_ref="cmp-853" comment="Solaris 8 (x86) meets Sun Alert ID 102282 criteria." negate="false"/>
          <criterion test_ref="cmp-854" comment="Solaris 9 (x86) meets Sun Alert ID 102282 criteria." negate="false"/>
          <criterion test_ref="cmp-855" comment="Solaris 10 (x86) meets Sun Alert ID 102282 criteria." negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL998" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 9</solaris:platform>
        <solaris:platform>Sun Solaris 10</solaris:platform>
        <product>X</product>
      </affected>
      <dates>
        <submitted date="2006-02-12-01:16">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2006-03-09-12:19">DRAFT</status_change>
        <status_change date="2006-04-06-06:30">INTERIM</status_change>
        <status_change date="2006-05-03-10:06">ACCEPTED</status_change>
      </dates>
      <description>Multiple integer overflows in XFree86 before 4.3.0 allow user-complicit attackers to execute arbitrary code via a crafted pixmap image.</description>
      <reference source="CVE">CVE-2005-2495</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="OR">
          <criterion test_ref="cmp-755" comment="Solaris 9 (x86,Xorg) meets Sun Alert ID 101926 criteria." negate="false"/>
          <criterion test_ref="cmp-757" comment="Solaris 10 (x86,Xorg) meets Sun Alert ID 101926 criteria." negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="uct-23" comment="The Xorg X server is running" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL1044" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 8</solaris:platform>
        <solaris:platform>Sun Solaris 9</solaris:platform>
        <solaris:platform>Sun Solaris 10</solaris:platform>
        <product>X</product>
      </affected>
      <dates>
        <submitted date="2006-02-12-01:16">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2006-03-09-12:19">DRAFT</status_change>
        <status_change date="2006-04-06-06:30">INTERIM</status_change>
        <status_change date="2006-05-03-10:06">ACCEPTED</status_change>
      </dates>
      <description>Multiple integer overflows in XFree86 before 4.3.0 allow user-complicit attackers to execute arbitrary code via a crafted pixmap image.</description>
      <reference source="CVE">CVE-2005-2495</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="OR">
          <criterion test_ref="cmp-750" comment="Solaris 8 (SPARC,Xsun) meets Sun Alert ID 101926 criteria." negate="false"/>
          <criterion test_ref="cmp-751" comment="Solaris 9 (SPARC,Xsun) meets Sun Alert ID 101926 criteria." negate="false"/>
          <criterion test_ref="cmp-752" comment="Solaris 10 (SPARC,Xsun) meets Sun Alert ID 101926 criteria." negate="false"/>
          <criterion test_ref="cmp-753" comment="Solaris 8 (x86,Xsun) meets Sun Alert ID 101926 criteria." negate="false"/>
          <criterion test_ref="cmp-754" comment="Solaris 9 (x86,Xsun) meets Sun Alert ID 101926 criteria." negate="false"/>
          <criterion test_ref="cmp-756" comment="Solaris 10 (x86,Xsun) meets Sun Alert ID 101926 criteria." negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="uct-22" comment="The Xsun X server is running" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL1048" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 7</solaris:platform>
        <solaris:platform>Sun Solaris 8</solaris:platform>
        <product>snmpdx</product>
      </affected>
      <dates>
        <submitted date="2005-02-01-12:00">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </submitted>
        <status_change date="2005-02-01-08:41">DRAFT</status_change>
        <status_change date="2005-02-16-12:00">INTERIM</status_change>
        <status_change date="2005-03-09-07:56">ACCEPTED</status_change>
      </dates>
      <description>Vulnerabilities in a large number of SNMP implementations allow remote attackers to cause a denial of service or gain privileges via SNMPv1 trap handling, as demonstrated by the PROTOS c06-SNMPv1 test suite.  NOTE: It is highly likely that this candidate will be SPLIT into multiple candidates, one or more for each vendor.  This and other SNMP-related candidates will be updated when more accurate information is available.</description>
      <reference source="CVE">CVE-2002-0012</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-43" comment="Solaris 7 or 8 installed" negate="false"/>
          <criterion test_ref="sat-48" comment="Solstice Enterprise Agents SNMP (SUNWsasnm) installed" negate="false"/>
          <criterion test_ref="spt-104" comment="Patch 107709-18 or later installed" negate="true"/>
          <criterion test_ref="spt-105" comment="Patch 108869-15 or later installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="uct-6" comment="snmpdx running" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL1074" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 10</solaris:platform>
        <product>Perl</product>
      </affected>
      <dates>
        <submitted date="2006-03-02-02:05">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2006-03-09-12:19">DRAFT</status_change>
        <status_change date="2006-04-06-06:30">INTERIM</status_change>
        <status_change date="2006-05-03-10:06">ACCEPTED</status_change>
      </dates>
      <description>Integer overflow in the format string functionality (Perl_sv_vcatpvfn) in Perl 5.9.2 and 5.8.6 Perl allows attackers to overwrite arbitrary memory and possibly execute arbitrary code via format string specifiers with large values, which causes an integer wrap and leads to a buffer overflow, as demonstrated using format string vulnerabilities in Perl applications.</description>
      <reference source="CVE">CVE-2005-3962</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="OR">
          <criterion test_ref="cmp-769" comment="Solaris 10 (SPARC) meets Sun Alert ID 102192 criteria." negate="false"/>
          <criterion test_ref="cmp-770" comment="Solaris 10 (x86) meets Sun Alert ID 102192 criteria." negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1099" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 9</solaris:platform>
        <product>CDE</product>
      </affected>
      <dates>
        <submitted date="2004-10-15-12:00">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </submitted>
        <status_change date="2004-10-20-12:00">DRAFT</status_change>
        <status_change date="2004-11-03-12:00">INTERIM</status_change>
        <status_change date="2004-12-09-12:00">ACCEPTED</status_change>
        <modified date="2005-01-11-12:00" comment="modified sat-6 - Changed test to pattern match and added check for 64bit version">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </modified>
        <modified date="2005-01-14-12:00" comment="modified sat-6 - Changed regular expression test to properly check for 64bit package">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </modified>
        <status_change date="2005-01-24-02:33">INTERIM</status_change>
        <status_change date="2005-02-16-12:00">ACCEPTED</status_change>
      </dates>
      <description>CDE ToolTalk database server (ttdbserver) allows remote attackers to overwrite arbitrary memory locations with a zero, and possibly gain privileges, via a file descriptor argument in an AUTH_UNIX procedure call, which is used as a table index by the _TT_ISCLOSE procedure.</description>
      <reference source="CVE">CVE-2002-0677</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="uut-6" comment="Solaris 9 Installed" negate="false"/>
          <criterion test_ref="sat-6" comment="Toolktalk (SUNWtltk/SUNWtltkx) installed" negate="false"/>
          <criterion test_ref="spt-255" comment="Patch 112808-02 or later installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="sit-202" comment="inetd.conf contains rpc.ttdbserverd" negate="false"/>
          <criterion test_ref="uct-4" comment="inetd running" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL1110" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 7</solaris:platform>
        <solaris:platform>Sun Solaris 8</solaris:platform>
        <solaris:platform>Sun Solaris 9</solaris:platform>
        <product>Solaris Enterprise Authentication Mechanism (SEAM)</product>
      </affected>
      <dates>
        <submitted date="2005-02-01-12:00">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </submitted>
        <status_change date="2005-02-01-08:41">DRAFT</status_change>
        <status_change date="2005-02-16-12:00">INTERIM</status_change>
        <status_change date="2005-03-09-07:56">ACCEPTED</status_change>
      </dates>
      <description>MIT Kerberos V5 Key Distribution Center (KDC) before 1.2.5 allows remote authenticated attackers to cause a denial of service (crash) on KDCs within the same realm via a certain protocol request that causes a null dereference.</description>
      <reference source="CVE">CVE-2003-0058</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-157" comment="Solaris 7 and Solaris Enterprise Authentication Mechanism OR Solaris 8 or 9 installed" negate="false"/>
          <criterion test_ref="spt-96" comment="Patch 112536-02 or later installed" negate="true"/>
          <criterion test_ref="spt-99" comment="Patch 112908-04 or later installed" negate="true"/>
          <criterion test_ref="spt-97" comment="Patch 112237-07 or later installed" negate="true"/>
          <criterion test_ref="spt-98" comment="Patch 112390-07 or later installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="tft-5" comment="/etc/krb5/krb5.conf is configured with a kerberos domain" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL1127" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 7</solaris:platform>
        <solaris:platform>Sun Solaris 8</solaris:platform>
        <solaris:platform>Sun Solaris 9</solaris:platform>
        <product>uucp</product>
      </affected>
      <dates>
        <submitted date="2005-04-13-04:00">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </submitted>
        <status_change date="2005-04-20-04:00">DRAFT</status_change>
        <status_change date="2005-05-11-04:00">INTERIM</status_change>
        <status_change date="2005-06-01-04:00">ACCEPTED</status_change>
        <modified date="2005-08-22-04:00" comment="Product set to uucp; was mistakenly .NET framework">
          <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
        </modified>
        <status_change date="2005-08-25-10:03">INTERIM</status_change>
        <status_change date="2005-09-21-01:33">INTERIM</status_change>
        <status_change date="2005-10-12-05:49">ACCEPTED</status_change>
      </dates>
      <description>Multiple buffer overflows in uucp for Sun Solaris 2.6, 7, 8, and 9 allow local users to execute arbitrary code as the uucp user.</description>
      <reference source="CVE">CVE-2004-1359</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-1080" comment="Solaris 7,8,or 9 installed" negate="false"/>
          <criterion test_ref="sat-42" comment="Networking UUCP Utilities - Usr (SUNWbnuu) installed" negate="false"/>
          <criterion test_ref="spt-86" comment="Patch 106952-04 or later installed" negate="true"/>
          <criterion test_ref="spt-87" comment="Patch 111570-03 or later installed" negate="true"/>
          <criterion test_ref="spt-88" comment="Patch 113322-02 or later installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1227" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 8</solaris:platform>
        <product>mozilla</product>
      </affected>
      <dates>
        <submitted date="2005-01-19-12:00">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </submitted>
        <status_change date="2005-01-24-03:40">DRAFT</status_change>
        <status_change date="2005-02-16-12:00">INTERIM</status_change>
        <status_change date="2005-03-09-07:56">ACCEPTED</status_change>
      </dates>
      <description>Mozilla allows remote attackers to cause Mozilla to open a URI as a different MIME type than expected via a null character (%00) in an FTP URI.</description>
      <reference source="CVE">CVE-2004-0760</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-1081" comment="Solaris 8 or 9 installed" negate="false"/>
          <criterion test_ref="cmp-72" comment="Mozilla components (any SUNWmoznav/SUNWmozmail) installed" negate="false"/>
          <criterion test_ref="spt-46" comment="Patch 117765-02 or later installed" negate="true"/>
          <criterion test_ref="spt-47" comment="Patch 117767-02 or later installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1273" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 7</solaris:platform>
        <solaris:platform>Sun Solaris 8</solaris:platform>
        <solaris:platform>Sun Solaris 9</solaris:platform>
        <product>Sadmin</product>
      </affected>
      <dates>
        <submitted date="2004-10-15-02:06">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </submitted>
        <modified date="2004-10-15-02:21" comment="Added check for sadmind called with strong authentication">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </modified>
        <status_change date="2004-10-20-02:35">DRAFT</status_change>
        <status_change date="2004-11-03-12:00">INTERIM</status_change>
        <status_change date="2004-12-09-08:46">ACCEPTED</status_change>
      </dates>
      <description>The default installation of sadmind on Solaris uses weak authentication (AUTH_SYS), which allows local and remote attackers to spoof Solstice AdminSuite clients and gain root privileges via a certain sequence of RPC packets.</description>
      <reference source="CVE">CVE-2003-0722</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-1080" comment="Solaris 7,8,or 9 installed" negate="false"/>
          <criterion test_ref="sat-7" comment="System and Network Administration Framework Installed" negate="false"/>
          <criterion test_ref="spt-259" comment="Patch 116457-02 or later installed" negate="true"/>
          <criterion test_ref="spt-260" comment="Patch 116442-01 or later installed" negate="true"/>
          <criterion test_ref="spt-261" comment="Patch 116454-01 or later installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="uct-4" comment="inetd running" negate="false"/>
          <criterion test_ref="sit-209" comment="inetd.conf contains sadmind" negate="false"/>
          <criterion test_ref="sit-210" comment="Sadmin called using strong authentication" negate="true"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL1409" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 7</solaris:platform>
        <solaris:platform>Sun Solaris 8</solaris:platform>
        <solaris:platform>Sun Solaris 9</solaris:platform>
        <product>Solaris Management Console</product>
      </affected>
      <dates>
        <submitted date="2006-01-11-12:56">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2006-01-12-09:18">DRAFT</status_change>
        <status_change date="2006-02-01-09:08">INTERIM</status_change>
        <status_change date="2006-02-22-08:27">ACCEPTED</status_change>
      </dates>
      <description>The (1) slsmgr and (2) slsadmin programs in Sun Solaris PC NetLink 2.0 create temporary files insecurely, which allows local users to gain privileges.</description>
      <reference source="CVE">CVE-2005-4552</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-1080" comment="Solaris 7,8,or 9 installed" negate="false"/>
          <criterion test_ref="uut-10003" comment="sparc architecture" negate="false"/>
          <criterion test_ref="sat-51" comment="the SUNWlzas package (for slsadmin) is installed" negate="false"/>
          <criterion test_ref="spt-154" comment="Patch 121332-01 or later installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1436" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 7</solaris:platform>
        <product>CDE</product>
      </affected>
      <dates>
        <submitted date="2004-10-12-12:37">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </submitted>
        <modified date="2004-10-12-12:47" comment="Added patch 107180-31 test for Solaris 7.  Changed vulnerable software test logic a little">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </modified>
        <status_change date="2004-10-13-01:15">DRAFT</status_change>
        <status_change date="2004-10-27-12:00">INTERIM</status_change>
        <status_change date="2004-11-17-10:00">ACCEPTED</status_change>
      </dates>
      <description>Double-free vulnerability in dtlogin in CDE on Solaris, HP-UX, and other operating systems allows remote attackers to execute arbitrary code via a crafted XDMCP packet.</description>
      <reference source="CVE">CVE-2004-0368</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="uft-23" comment="File /usr/dt/bin/dtlogin exists" negate="false"/>
          <criterion test_ref="cmp-1080" comment="Solaris 7,8,or 9 installed" negate="false"/>
          <criterion test_ref="spt-231" comment="Patch 108919-21 or later installed" negate="false"/>
          <criterion test_ref="spt-232" comment="Patch 112807-09 or later installed" negate="false"/>
          <criterion test_ref="spt-249" comment="Patch 107180-31 or later installed" negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="uct-9" comment="dtlogin running" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL1445" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 8</solaris:platform>
        <solaris:platform>Sun Solaris 9</solaris:platform>
        <solaris:platform>Sun Solaris 10</solaris:platform>
        <product>Solaris Management Console</product>
      </affected>
      <dates>
        <submitted date="2006-01-11-12:56">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2006-01-12-09:18">DRAFT</status_change>
        <status_change date="2006-02-01-09:08">INTERIM</status_change>
        <status_change date="2006-02-22-08:27">ACCEPTED</status_change>
      </dates>
      <description>The default configuration of the web server for the Solaris Management Console (SMC) in Solaris 8, 9, and 10 enables the HTTP TRACE method, which could allow remote attackers to obtain sensitive information such as cookies and authentication data from HTTP headers.</description>
      <reference source="CVE">CVE-2005-3398</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="OR">
          <criterion test_ref="cmp-695" comment="Solaris 8 (SPARC) meets Sun Alert ID 102016 criteria." negate="false"/>
          <criterion test_ref="cmp-696" comment="Solaris 8 (x86) meets Sun Alert ID 102016 criteria." negate="false"/>
          <criterion test_ref="cmp-697" comment="Solaris 9 (SPARC) meets Sun Alert ID 102016 criteria." negate="false"/>
          <criterion test_ref="cmp-698" comment="Solaris 9 (x86) meets Sun Alert ID 102016 criteria." negate="false"/>
          <criterion test_ref="cmp-699" comment="Solaris 10 (SPARC) meets Sun Alert ID 102016 criteria." negate="false"/>
          <criterion test_ref="cmp-700" comment="Solaris 10 (x86) meets Sun Alert ID 102016 criteria." negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1467" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 9</solaris:platform>
        <product>Samba</product>
      </affected>
      <dates>
        <submitted date="2005-01-19-12:00">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </submitted>
        <status_change date="2005-01-24-03:40">DRAFT</status_change>
        <status_change date="2005-02-16-12:00">INTERIM</status_change>
        <status_change date="2005-03-09-07:56">ACCEPTED</status_change>
      </dates>
      <description>Buffer overflow in samba 2.2.2 through 2.2.6 allows remote attackers to cause a denial of service and possibly execute arbitrary code via an encrypted password that causes the overflow during decryption in which a DOS codepage string is converted to a little-endian UCS2 unicode string.</description>
      <reference source="CVE">CVE-2002-1318</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="uut-6" comment="Solaris 9 Installed" negate="false"/>
          <criterion test_ref="sat-28" comment="Samba - Usr (SUNWsmbau) installed" negate="false"/>
          <criterion test_ref="spt-48" comment="Patch 114684-01 or later installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="uct-15" comment="smbd running" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL1470" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 8</solaris:platform>
        <solaris:platform>Sun Solaris 9</solaris:platform>
        <product>Operating System</product>
      </affected>
      <dates>
        <submitted date="2006-03-28-09:02">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2006-04-06-06:30">DRAFT</status_change>
        <status_change date="2006-05-03-10:06">INTERIM</status_change>
        <status_change date="2006-05-31-09:45">ACCEPTED</status_change>
      </dates>
      <description>'An unspecified vulnerability in the \"/usr/ucb/ps\" command could allow unprivileged local users to see environment settings for processes of other users.  When the \'e\' flag is used, a low-privileged user can see environment variables and values for processes that belong to root and any other system users. NOTE: \"/usr/bin/ps\" is the default \'ps\' command for most users per the command search path and is not affected by this vulnerability'</description>
      <reference source="MISC">http://sunsolve9.sun.com/search/document.do?assetkey=1-26-102215-1&amp;amp;searchclause=</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="OR">
          <criterion test_ref="cmp-812" comment="Solaris 8 (SPARC) meets Sun Alert ID 102215 criteria." negate="false"/>
          <criterion test_ref="cmp-813" comment="Solaris 9 (SPARC) meets Sun Alert ID 102215 criteria." negate="false"/>
          <criterion test_ref="cmp-814" comment="Solaris 8 (x86) meets Sun Alert ID 102215 criteria." negate="false"/>
          <criterion test_ref="cmp-817" comment="Solaris 9 (x86) meets Sun Alert ID 102215 criteria." negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1479" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 7</solaris:platform>
        <product>libpng</product>
      </affected>
      <dates>
        <submitted date="2004-12-12-12:00">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </submitted>
        <status_change date="2005-01-24-12:04">DRAFT</status_change>
        <status_change date="2005-02-16-12:00">INTERIM</status_change>
        <status_change date="2005-03-09-07:56">ACCEPTED</status_change>
      </dates>
      <description>Multiple integer overflows in the (1) png_read_png in pngread.c or (2) png_handle_sPLT functions in pngrutil.c or (3) progressive display image reading capability in libpng 1.2.5 and earlier allow remote attackers to cause a denial of service (application crash) via a malformed PNG image.</description>
      <reference source="CVE">CVE-2004-0599</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-1080" comment="Solaris 7,8,or 9 installed" negate="false"/>
          <criterion test_ref="sat-11" comment="Netscape installed" negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1482" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 8</solaris:platform>
        <solaris:platform>Sun Solaris 9</solaris:platform>
        <product>Solaris Management Console (SMC)</product>
      </affected>
      <dates>
        <submitted date="2005-04-13-04:00">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </submitted>
        <status_change date="2005-04-20-04:00">DRAFT</status_change>
        <status_change date="2005-05-11-04:00">INTERIM</status_change>
        <status_change date="2005-06-01-04:00">ACCEPTED</status_change>
        <modified date="2005-08-22-04:00" comment="Affected product changed to Sun Management Console (SMC); mistakenly was .NET framework">
          <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
        </modified>
        <status_change date="2005-08-25-10:03">INTERIM</status_change>
        <status_change date="2005-09-21-01:33">INTERIM</status_change>
        <status_change date="2005-10-12-05:49">ACCEPTED</status_change>
      </dates>
      <description>The Solaris Management Console (SMC) in Sun Solaris 8 and 9 generates different 404 error messages when a file does not exist versus when a file exists but is otherwise inacessible, which could allow remote attackers to obtain sensitive information in conjunction with a directory traversal (..) attack.</description>
      <reference source="CVE">CVE-2004-1354</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-1081" comment="Solaris 8 or 9 installed" negate="false"/>
          <criterion test_ref="sat-40" comment="Solaris Management Console Web Components (SUNWwbmc) installed" negate="false"/>
          <criterion test_ref="spt-76" comment="Patch 111313-02 or later installed" negate="true"/>
          <criterion test_ref="spt-77" comment="Patch 116807-01 or later installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="uct-20" comment="smcboot running" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL1528" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 8</solaris:platform>
        <product>TENEX C Shell (tcsh)</product>
      </affected>
      <dates>
        <submitted date="2005-04-13-04:00">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </submitted>
        <status_change date="2005-04-20-04:00">DRAFT</status_change>
        <status_change date="2005-05-11-04:00">INTERIM</status_change>
        <status_change date="2005-06-01-04:00">ACCEPTED</status_change>
        <modified date="2005-08-22-04:00" comment="Affected product changed to tcsh; mistakenly was .NET framework">
          <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
        </modified>
        <status_change date="2005-08-25-10:03">INTERIM</status_change>
        <status_change date="2005-08-25-10:05">DRAFT</status_change>
        <status_change date="2005-09-21-01:33">INTERIM</status_change>
        <status_change date="2005-10-12-05:49">ACCEPTED</status_change>
      </dates>
      <description>Unknown vulnerability in the ls-F builtin function in tcsh on Solaris 8 allows local users to create or delete files as other users, and gain privileges.</description>
      <reference source="CVE">CVE-2003-1024</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="uut-4" comment="Solaris 8 Installed" negate="false"/>
          <criterion test_ref="spt-95" comment="Patch 110943-02 or later installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1534" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 8</solaris:platform>
        <solaris:platform>Sun Solaris 9</solaris:platform>
        <product>Operating System</product>
      </affected>
      <dates>
        <submitted date="2006-01-11-12:56">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2006-01-12-09:18">DRAFT</status_change>
        <modified date="2006-01-17-01:07" comment="Updated reference to CVE-2006-0161, per Rob Hollis.">
          <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
        </modified>
        <status_change date="2006-02-01-09:08">INTERIM</status_change>
        <status_change date="2006-02-22-08:27">ACCEPTED</status_change>
      </dates>
      <description>Unspecified vulnerability in uucp in Sun Solaris 8 and 9 has unknown impact and attack vectors.  NOTE: due to the vagueness of the vendor advisory, it is not clear whether this is related to CVE-2004-0780.</description>
      <reference source="CVE">CVE-2006-0161</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="OR">
          <criterion test_ref="cmp-703" comment="Solaris 8 (SPARC) meets Sun Alert ID 101933 criteria." negate="false"/>
          <criterion test_ref="cmp-704" comment="Solaris 8 (x86) meets Sun Alert ID 101933 criteria." negate="false"/>
          <criterion test_ref="cmp-705" comment="Solaris 9 (SPARC) meets Sun Alert ID 101933 criteria." negate="false"/>
          <criterion test_ref="cmp-612" comment="Solaris 9 (x86) meets Sun Alert ID 101933 criteria." negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1580" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 10</solaris:platform>
        <product>X</product>
      </affected>
      <dates>
        <submitted date="2006-02-19-05:38">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2006-02-22-08:27">DRAFT</status_change>
        <status_change date="2006-03-09-12:19">INTERIM</status_change>
        <status_change date="2006-04-06-06:30">ACCEPTED</status_change>
      </dates>
      <description>Unspecified vulnerability in in.rexecd in Solaris 10 allows local users to gain privileges on Kerberos systems via unknown attack vectors.</description>
      <reference source="CVE">CVE-2006-0769</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="OR">
          <criterion test_ref="cmp-758" comment="Solaris 10 (SPARC) meets Sun Alert ID 102186 criteria." negate="false"/>
          <criterion test_ref="cmp-759" comment="Solaris 10 (x86) meets Sun Alert ID 102186 criteria." negate="false"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="tft-15" comment="Target is configured to reference pam_krb5" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL1608" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 10</solaris:platform>
        <product>Operating System</product>
      </affected>
      <dates>
        <submitted date="2006-01-12-11:25">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2006-01-25-07:30">DRAFT</status_change>
        <status_change date="2006-02-22-08:27">INTERIM</status_change>
        <status_change date="2006-03-09-12:19">ACCEPTED</status_change>
      </dates>
      <description>Unspecified vulnerability in Sun Solaris 10 allows local users to cause a denial of service (null dereference) via unspecified vectors involving the use of the find command on the "/proc" filesystem. NOTE: due to the vagueness of the vendor advisory, it is not clear whether this is related to CVE-2005-3250.</description>
      <reference source="CVE">CVE-2006-0191</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="OR">
          <criterion test_ref="cmp-715" comment="Solaris 10 (sparc) meets Sun Alert ID 102108 criteria." negate="false"/>
          <criterion test_ref="cmp-714" comment="Solaris 10 (x86) meets Sun Alert ID 102066 and 102108 criteria." negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1617" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 8</solaris:platform>
        <solaris:platform>Sun Solaris 9</solaris:platform>
        <product>Operating System</product>
      </affected>
      <dates>
        <submitted date="2006-03-21-04:03">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2006-03-22-11:10">DRAFT</status_change>
        <status_change date="2006-04-06-06:31">INTERIM</status_change>
        <status_change date="2006-05-03-10:06">ACCEPTED</status_change>
      </dates>
      <description>Integer overflow in pixbuf_create_from_xpm (io-xpm.c) in the XPM image decoder for gtk+ 2.4.4 (gtk2) and earlier, and gdk-pixbuf before 0.22, allows remote attackers to execute arbitrary code via certain n_col and cpp values that enable a heap-based buffer overflow.  NOTE: this identifier is ONLY for gtk+.  It was incorrectly referenced in an advisory for a different issue (CVE-2004-0687).</description>
      <reference source="CVE">CVE-2004-0782</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="OR">
          <criterion test_ref="cmp-792" comment="GNOME 2.0 Solaris 8 (SPARC) meets Sun Alert ID 101776 criteria." negate="false"/>
          <criterion test_ref="cmp-793" comment="GNOME 2.0 Solaris 8 (x86) meets Sun Alert ID 101776 criteria." negate="false"/>
          <criterion test_ref="cmp-794" comment="GNOME 2.0 Solaris 9 (SPARC) meets Sun Alert ID 101776 criteria." negate="false"/>
          <criterion test_ref="cmp-795" comment="GNOME 2.0.2 Solaris 9 (SPARC) meets Sun Alert ID 101776 criteria." negate="false"/>
          <criterion test_ref="cmp-796" comment="GNOME 2.0 Solaris 9 (x86) meets Sun Alert ID 101776 criteria." negate="false"/>
          <criterion test_ref="cmp-797" comment="GNOME 2.0.2 Solaris 9 (x86) meets Sun Alert ID 101776 criteria." negate="false"/>
          <criterion test_ref="cmp-798" comment="Solaris 9 (x86) with JDS release 2 meets Sun Alert ID 101776 criteria." negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1618" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 8</solaris:platform>
        <solaris:platform>Sun Solaris 9</solaris:platform>
        <solaris:platform>Sun Solaris 10</solaris:platform>
        <product>Operating System</product>
      </affected>
      <dates>
        <submitted date="2006-03-04-10:16">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2006-03-09-12:19">DRAFT</status_change>
        <status_change date="2006-04-06-06:30">INTERIM</status_change>
        <status_change date="2006-05-03-10:06">ACCEPTED</status_change>
      </dates>
      <description>'An undisclosed vulnerability in the pagedata subsystem in /proc may allow a local unprivileged user to cause significant performance degradation and even panic the system.'</description>
      <reference source="MISC">http://sunsolve9.sun.com/search/document.do?assetkey=1-26-102159-1&amp;amp;searchclause=</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="OR">
          <criterion test_ref="cmp-771" comment="Solaris 8 (SPARC) meets Sun Alert ID 102159 criteria." negate="false"/>
          <criterion test_ref="cmp-772" comment="Solaris 9 (SPARC) meets Sun Alert ID 102159 criteria." negate="false"/>
          <criterion test_ref="cmp-773" comment="Solaris 10 (SPARC) meets Sun Alert ID 102159 criteria." negate="false"/>
          <criterion test_ref="cmp-774" comment="Solaris 8 (x86) meets Sun Alert ID 102159 criteria." negate="false"/>
          <criterion test_ref="cmp-775" comment="Solaris 9 (x86) meets Sun Alert ID 102159 criteria." negate="false"/>
          <criterion test_ref="cmp-776" comment="Solaris 10 (x86) meets Sun Alert ID 102159 criteria." negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1628" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 8</solaris:platform>
        <solaris:platform>Sun Solaris 9</solaris:platform>
        <solaris:platform>Sun Solaris 10</solaris:platform>
        <product>Operating System</product>
      </affected>
      <dates>
        <submitted date="2006-02-26-12:31">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2006-03-09-12:19">DRAFT</status_change>
        <status_change date="2006-04-06-06:30">INTERIM</status_change>
        <status_change date="2006-05-03-10:06">ACCEPTED</status_change>
      </dates>
      <description>Unspecified vulnerability in the hsfs filesystem in Solaris 8, 9, and 10 allows unspecified attackers to cause a denial of service (panic) or execute arbitrary code.</description>
      <reference source="CVE">CVE-2006-0901</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="OR">
          <criterion test_ref="cmp-763" comment="Solaris 8 (SPARC) meets Sun Alert ID 102161 criteria." negate="false"/>
          <criterion test_ref="cmp-764" comment="Solaris 9 (SPARC) meets Sun Alert ID 102161 criteria." negate="false"/>
          <criterion test_ref="cmp-765" comment="Solaris 10 (SPARC) meets Sun Alert ID 102161 criteria." negate="false"/>
          <criterion test_ref="cmp-766" comment="Solaris 8 (x86) meets Sun Alert ID 102161 criteria." negate="false"/>
          <criterion test_ref="cmp-767" comment="Solaris 9 (x86) meets Sun Alert ID 102161 criteria." negate="false"/>
          <criterion test_ref="cmp-768" comment="Solaris 10 (x86) meets Sun Alert ID 102161 criteria." negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1654" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 8</solaris:platform>
        <product>Licence Logging Service</product>
      </affected>
      <dates>
        <submitted date="2005-04-13-12:00">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </submitted>
        <status_change date="2005-04-20-12:13">DRAFT</status_change>
        <status_change date="2005-05-11-05:41">INTERIM</status_change>
        <status_change date="2005-06-01-03:30">ACCEPTED</status_change>
      </dates>
      <description>gzip before 1.3 in Solaris 8, when called with the -f or -force flags, will change the permissions of files that are hard linked to the target files, which allows local users to view or modify these files.</description>
      <reference source="CVE">CVE-2004-1349</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="uut-4" comment="Solaris 8 Installed" negate="false"/>
          <criterion test_ref="sat-36" comment="GNU Zip (gzip, SUNWgzip) installed" negate="false"/>
          <criterion test_ref="spt-67" comment="Patch 112668-02 or later installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1684" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 8</solaris:platform>
        <solaris:platform>Sun Solaris 9</solaris:platform>
        <product>sendfilev()</product>
      </affected>
      <dates>
        <submitted date="2005-04-13-04:00">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </submitted>
        <status_change date="2005-04-20-04:00">DRAFT</status_change>
        <status_change date="2005-05-11-04:00">INTERIM</status_change>
        <status_change date="2005-06-01-04:00">ACCEPTED</status_change>
        <status_change date="2005-08-25-10:03">INTERIM</status_change>
        <status_change date="2005-08-25-10:05">DRAFT</status_change>
        <status_change date="2005-09-21-01:33">INTERIM</status_change>
        <status_change date="2005-10-12-05:49">ACCEPTED</status_change>
      </dates>
      <description>Unknown vulnerability in the sendfilev function in Sun Solaris 8 and 9 allows local users to cause a denial of service (system panic) via unknown vectors.</description>
      <reference source="CVE">CVE-2004-1356</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-1081" comment="Solaris 8 or 9 installed" negate="false"/>
          <criterion test_ref="spt-81" comment="Patch 108528-27 or later installed" negate="true"/>
          <criterion test_ref="spt-80" comment="Patch 112233-12 or later installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1697" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 10</solaris:platform>
        <product>Operating System</product>
      </affected>
      <dates>
        <submitted date="2006-03-21-04:03">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2006-03-22-11:10">DRAFT</status_change>
        <status_change date="2006-04-06-06:31">INTERIM</status_change>
        <status_change date="2006-05-03-10:06">ACCEPTED</status_change>
      </dates>
      <description>X.Org server (xorg-server) 1.0.0 and later, X11R6.9.0, and X11R7.0 inadvertently treats the address of the geteuid function as if it is the return value of a call to geteuid, which allows local users to bypass intended restrictions and (1) execute arbitrary code via the -modulepath command line option or (2) overwrite arbitrary files via -logfile.</description>
      <reference source="CVE">CVE-2006-0745</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="uut-10001" comment="Solaris 10 Installed" negate="false"/>
          <criterion test_ref="uut-10002" comment="ix86 architecture" negate="false"/>
          <criterion test_ref="cmp-791" comment="Patch 118966-14 through 118966-16 is installed." negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1707" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 8</solaris:platform>
        <product>Sun Enterprise Storage Manager (ESM)</product>
      </affected>
      <dates>
        <submitted date="2005-01-19-12:00">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </submitted>
        <status_change date="2005-01-24-03:40">DRAFT</status_change>
        <status_change date="2005-02-16-12:00">INTERIM</status_change>
        <status_change date="2005-03-09-07:56">ACCEPTED</status_change>
      </dates>
      <description/>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-1081" comment="Solaris 8 or 9 installed" negate="false"/>
          <criterion test_ref="sat-1" comment="Sun Enterprise Storage Manager installed" negate="false"/>
          <criterion test_ref="spt-242" comment="Patch 117367-01 or later installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1732" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 7</solaris:platform>
        <solaris:platform>Sun Solaris 8</solaris:platform>
        <solaris:platform>Sun Solaris 9</solaris:platform>
      </affected>
      <dates>
        <submitted date="2005-04-13-04:00">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </submitted>
        <status_change date="2005-04-20-04:00">DRAFT</status_change>
        <status_change date="2005-05-11-04:00">INTERIM</status_change>
        <status_change date="2005-06-01-04:00">ACCEPTED</status_change>
        <status_change date="2005-08-25-10:03">INTERIM</status_change>
        <status_change date="2005-08-25-10:05">DRAFT</status_change>
        <status_change date="2005-09-21-01:33">INTERIM</status_change>
        <status_change date="2005-10-12-05:49">ACCEPTED</status_change>
      </dates>
      <description>Unknown vulnerability in conv_fix in Sun Solaris 7 through 9, when invoked by conv_lpd, allows local users to overwrite arbitrary files.</description>
      <reference source="CVE">CVE-2004-1360</reference>
      <status>ACCEPTED</status>
      <version>2</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-1080" comment="Solaris 7,8,or 9 installed" negate="false"/>
          <criterion test_ref="sat-43" comment="SunSoft Print - Client - Usr (SUNWpcu) installed" negate="false"/>
          <criterion test_ref="spt-89" comment="Patch 107115-14 or later installed" negate="true"/>
          <criterion test_ref="spt-90" comment="Patch 109320-09 or later installed" negate="true"/>
          <criterion test_ref="spt-91" comment="Patch 113329-05 or later installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1786" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 8</solaris:platform>
        <solaris:platform>Sun Solaris 9</solaris:platform>
        <product>Operating System</product>
      </affected>
      <dates>
        <submitted date="2006-03-21-04:03">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2006-03-22-11:10">DRAFT</status_change>
        <status_change date="2006-04-06-06:31">INTERIM</status_change>
        <status_change date="2006-05-03-10:06">ACCEPTED</status_change>
      </dates>
      <description>Stack-based buffer overflow in xpm_extract_color (io-xpm.c) in the XPM image decoder for gtk+ 2.4.4 (gtk2) and earlier, and gdk-pixbuf before 0.22, may allow remote attackers to execute arbitrary code via a certain color string.  NOTE: this identifier is ONLY for gtk+.  It was incorrectly referenced in an advisory for a different issue (CVE-2004-0688).</description>
      <reference source="CVE">CVE-2004-0783</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="OR">
          <criterion test_ref="cmp-792" comment="GNOME 2.0 Solaris 8 (SPARC) meets Sun Alert ID 101776 criteria." negate="false"/>
          <criterion test_ref="cmp-793" comment="GNOME 2.0 Solaris 8 (x86) meets Sun Alert ID 101776 criteria." negate="false"/>
          <criterion test_ref="cmp-794" comment="GNOME 2.0 Solaris 9 (SPARC) meets Sun Alert ID 101776 criteria." negate="false"/>
          <criterion test_ref="cmp-795" comment="GNOME 2.0.2 Solaris 9 (SPARC) meets Sun Alert ID 101776 criteria." negate="false"/>
          <criterion test_ref="cmp-796" comment="GNOME 2.0 Solaris 9 (x86) meets Sun Alert ID 101776 criteria." negate="false"/>
          <criterion test_ref="cmp-797" comment="GNOME 2.0.2 Solaris 9 (x86) meets Sun Alert ID 101776 criteria." negate="false"/>
          <criterion test_ref="cmp-798" comment="Solaris 9 (x86) with JDS release 2 meets Sun Alert ID 101776 criteria." negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1840" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 8</solaris:platform>
        <solaris:platform>Sun Solaris 9</solaris:platform>
        <product>LDAP</product>
      </affected>
      <dates>
        <submitted date="2006-04-14-06:41">
          <contributor organization="ThreatGuard">Robert L. Hollis</contributor>
        </submitted>
        <status_change date="2006-04-19-10:08">DRAFT</status_change>
        <status_change date="2006-05-10-08:33">INTERIM</status_change>
        <status_change date="2006-05-31-09:45">ACCEPTED</status_change>
      </dates>
      <description>Unspecified vulnerability in Solaris 8 and 9 allows local users to obtain the LDAP Directory Server root Distinguished Name (rootDN) password when a privileged user (1) runs idsconfig; or "insecurely" runs LDAP2 commands with the -w option, including (2) ldapadd, (3) ldapdelete, (4) ldapmodify, (5) ldapmodrdn, and (6) ldapsearch.</description>
      <reference source="CVE">CVE-2006-1782</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="OR">
          <criterion test_ref="cmp-856" comment="Solaris 8 (SPARC) meets Sun Alert ID 102113 criteria." negate="false"/>
          <criterion test_ref="cmp-857" comment="Solaris 9 (SPARC) meets Sun Alert ID 102113 criteria." negate="false"/>
          <criterion test_ref="cmp-858" comment="Solaris 8 (x86) meets Sun Alert ID 102113 criteria." negate="false"/>
          <criterion test_ref="cmp-859" comment="Solaris 9 (x86) meets Sun Alert ID 102113 criteria." negate="false"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1844" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 7</solaris:platform>
        <product>NIS</product>
      </affected>
      <dates>
        <submitted date="2004-12-29-12:00">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </submitted>
        <status_change date="2005-01-12-12:41">DRAFT</status_change>
        <status_change date="2005-02-02-12:00">INTERIM</status_change>
        <status_change date="2005-02-23-09:25">ACCEPTED</status_change>
      </dates>
      <description>Buffer overflow in ypbind daemon in Solaris 5.4 through 8 allows remote attackers to execute arbitrary code.</description>
      <reference source="CVE">CVE-2001-1328</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-43" comment="Solaris 7 or 8 installed" negate="false"/>
          <criterion test_ref="sat-13" comment="NIS/NIS+ Utilities installed (SUNWnisu)" negate="false"/>
          <criterion test_ref="spt-8" comment="Patch 108750-02 or later installed" negate="true"/>
          <criterion test_ref="spt-9" comment="Patch 110322-01 or later installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="uct-3" comment="ypbind running" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL1880" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 7</solaris:platform>
        <product>dtspcd</product>
      </affected>
      <dates>
        <submitted date="2005-02-01-12:00">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </submitted>
        <status_change date="2005-02-01-08:41">DRAFT</status_change>
        <status_change date="2005-02-16-12:00">INTERIM</status_change>
        <status_change date="2005-03-09-07:56">ACCEPTED</status_change>
      </dates>
      <description>The CDE dtspcd daemon allows local users to execute arbitrary commands via a symlink attack.</description>
      <reference source="CVE">CVE-1999-0689</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="uut-5" comment="Solaris 7 Installed" negate="false"/>
          <criterion test_ref="sat-49" comment="CDE Daemons (SUNWdtdmn) installed" negate="false"/>
          <criterion test_ref="spt-107" comment="Patch 108221-01 or later installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1905" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 7</solaris:platform>
        <solaris:platform>Sun Solaris 8</solaris:platform>
        <solaris:platform>Sun Solaris 9</solaris:platform>
        <product>CDE</product>
      </affected>
      <dates>
        <submitted date="2005-02-01-12:00">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </submitted>
        <status_change date="2005-02-01-08:41">DRAFT</status_change>
        <status_change date="2005-02-16-12:00">INTERIM</status_change>
        <status_change date="2005-03-09-07:56">ACCEPTED</status_change>
      </dates>
      <description>Heap-based buffer overflow in dtsession for Solaris 2.5.1 through Solaris 9 allows local users to gain root privileges via a long HOME environment variable.</description>
      <reference source="CVE">CVE-2003-0092</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-1080" comment="Solaris 7,8,or 9 installed" negate="false"/>
          <criterion test_ref="sat-47" comment="CDE Desktop Window Manager (SUNWdtwm) installed" negate="false"/>
          <criterion test_ref="spt-100" comment="Patch 107702-12 or later installed" negate="true"/>
          <criterion test_ref="spt-101" comment="Patch 109354-19 or later installed" negate="true"/>
          <criterion test_ref="spt-102" comment="Patch 114497-01 or later installed" negate="true"/>
        </software>
      </criteria>
    </definition>
    <definition id="OVAL1970" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 9</solaris:platform>
        <product>Solaris Management Console (SMC)</product>
      </affected>
      <dates>
        <submitted date="2005-04-13-12:00">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </submitted>
        <status_change date="2005-04-20-12:13">DRAFT</status_change>
        <status_change date="2005-05-11-05:41">INTERIM</status_change>
        <status_change date="2005-06-01-03:30">ACCEPTED</status_change>
      </dates>
      <description>Off-by-one error in the fb_realpath() function, as derived from the realpath function in BSD, may allow attackers to execute arbitrary code, as demonstrated in wu-ftpd 2.5.0 through 2.6.2 via commands that cause pathnames of length MAXPATHLEN+1 to trigger a buffer overflow, including (1) STOR, (2) RETR, (3) APPE, (4) DELE, (5) MKD, (6) RMD, (7) STOU, or (8) RNTO.</description>
      <reference source="CVE">CVE-2003-0466</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="uut-6" comment="Solaris 9 Installed" negate="false"/>
          <criterion test_ref="sat-34" comment="FTP Server - Usr (SUNWftpu) installed" negate="false"/>
          <criterion test_ref="spt-60" comment="Patch 114564-02 or later installed" negate="true"/>
        </software>
        <configuration operation="AND">
          <criterion test_ref="sit-3" comment="inetd.conf contains in.ftpd" negate="false"/>
          <criterion test_ref="uct-4" comment="inetd running" negate="false"/>
        </configuration>
      </criteria>
    </definition>
    <definition id="OVAL1982" class="vulnerability">
      <affected family="solaris">
        <solaris:platform>Sun Solaris 8</solaris:platform>
        <solaris:platform>Sun Solaris 9</solaris:platform>
        <product>Apache</product>
      </affected>
      <dates>
        <submitted date="2004-10-14-01:13">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </submitted>
        <modified date="2004-10-18-03:12" comment="Changed apache test to file test">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </modified>
        <modified date="2004-10-19-11:17" comment="Changed apache test to package test">
          <contributor organization="The MITRE Corporation">Brian Soby</contributor>
        </modified>
        <status_change date="2004-10-20-02:35">DRAFT</status_change>
        <status_change date="2004-11-03-12:00">INTERIM</status_change>
        <status_change date="2004-12-09-08:46">ACCEPTED</status_change>
      </dates>
      <description>Apache 1.4.x before 1.3.30, and 2.0.x before 2.0.49, when using multiple listening sockets on certain platforms, allows remote attackers to cause a denial of service (blocked new connections) via a "short-lived connection on a rarely-accessed listening socket."</description>
      <reference source="CVE">CVE-2004-0174</reference>
      <status>ACCEPTED</status>
      <version>1</version>
      <criteria>
        <software operation="AND">
          <criterion test_ref="cmp-1081" comment="Solaris 8 or 9 installed" negate="false"/>
          <criterion test_ref="spt-253" com