<?xml version="1.0" encoding="UTF-8"?>
<oval_definitions xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix unix-definitions-schema.xsd http://oval.mitre.org/XMLSchema/oval-definitions-5#linux linux-definitions-schema.xsd http://oval.mitre.org/XMLSchema/oval-definitions-5#independent independent-definitions-schema.xsd http://oval.mitre.org/XMLSchema/oval-definitions-5 oval-definitions-schema.xsd http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris solaris-definitions-schema.xsd http://oval.mitre.org/XMLSchema/oval-common-5 oval-common-schema.xsd http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux hpux-definitions-schema.xsd" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:sol-def="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris" xmlns:oval-def="http://oval.mitre.org/XMLSchema/oval-definitions-5" xmlns:unix-def="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix" xmlns:ind-def="http://oval.mitre.org/XMLSchema/oval-definitions-5#independent" xmlns:hpux-def="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux" xmlns:linux-def="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5" xmlns:oval="http://oval.mitre.org/XMLSchema/oval-common-5">
  <generator>
    <oval:product_name>The MITRE Corporation</oval:product_name>
    <oval:schema_version>5.2</oval:schema_version>
    <oval:timestamp>2007-06-26T21:04:42.662-04:00</oval:timestamp>
  </generator>
  <definitions>
    <definition id="oval:org.mitre.oval:def:1341" version="0" class="vulnerability">
      <metadata>
        <title>Security Vulnerability in the Authentication Mechanism for Solaris Management Console (SMC) May Lead to Escalation of Privileges</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <platform>Sun Solaris 9</platform>
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-3094" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3094"/>
        <description>Unspecified vulnerability in the authentication mechanism in Solaris Management Console (SMC) on Sun Solaris 8 through 10 before 20070605 allows remote authenticated users to execute arbitrary code via unspecified vectors, related to the WBEM server.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-06-08T14:30:00.000-04:00">
              <contributor organization="Opsware, Inc.">Pai Peng</contributor>
            </submitted>
            <status_change date="2007-06-08T21:28:00.000-04:00">DRAFT</status_change>
            <status_change date="2007-06-26T20:49:49.371-04:00">INTERIM</status_change>
          </dates>
          <status>INTERIM</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="OR">
          <criteria operator="AND" comment="Solaris 8 (SPARC) meets Sun Alert 102902" negate="false">
            <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3437"/>
            <criterion comment="sparc architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3237"/>
            <criterion comment="Patch 111313-05 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:3715"/>
          </criteria>
          <criteria operator="AND" comment="Solaris 8 (x86) meets Sun Alert 102902" negate="false">
            <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3437"/>
            <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3912"/>
            <criterion comment="Patch 111314-05 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:3352"/>
          </criteria>
          <criteria operator="AND" comment="Solaris 9 (SPARC) meets Sun Alert 102902" negate="false">
            <criterion comment="Solaris 9 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3172"/>
            <criterion comment="sparc architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3237"/>
            <criterion comment="Patch 112945-45 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:3891"/>
          </criteria>
          <criteria operator="AND" comment="Solaris 9 (x86) meets Sun Alert 102902" negate="false">
            <criterion comment="Solaris 9 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3172"/>
            <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3912"/>
            <criterion comment="Patch 114193-35 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:3909"/>
          </criteria>
          <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 102902" negate="false">
            <criterion comment="Solaris 10 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3680"/>
            <criterion comment="sparc architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3237"/>
            <criterion comment="Patch 121308-09 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:3783"/>
          </criteria>
          <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 102902" negate="false">
            <criterion comment="Solaris 10 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3680"/>
            <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3912"/>
            <criterion comment="Patch 121309-09 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:3261"/>
          </criteria>
        </criteria>
        <criterion comment="Package SUNWwbmc installed" negate="false" test_ref="oval:org.mitre.oval:tst:3160"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1680" version="0" class="vulnerability">
      <metadata>
        <title>Security Vulnerability in the Logging Mechanism for Solaris Management Console (SMC) May Lead to Escalation of Privileges</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <platform>Sun Solaris 9</platform>
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-3093" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3093"/>
        <description>Unspecified vulnerability in the logging mechanism in Solaris Management Console (SMC) on Sun Solaris 8 through 10 before 20070605 allows remote attackers to execute arbitrary code via unspecified vectors, related to the WBEM server.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-06-08T14:30:00.000-04:00">
              <contributor organization="Opsware, Inc.">Pai Peng</contributor>
            </submitted>
            <status_change date="2007-06-08T21:28:00.000-04:00">DRAFT</status_change>
            <status_change date="2007-06-26T20:49:49.714-04:00">INTERIM</status_change>
          </dates>
          <status>INTERIM</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="OR">
          <criteria operator="AND" comment="Solaris 8 (SPARC) meets Sun Alert 102903" negate="false">
            <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3437"/>
            <criterion comment="sparc architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3237"/>
            <criterion comment="Patch 111313-06 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:3336"/>
          </criteria>
          <criteria operator="AND" comment="Solaris 8 (x86) meets Sun Alert 102903" negate="false">
            <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3437"/>
            <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3912"/>
            <criterion comment="Patch 111314-06 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:3246"/>
          </criteria>
          <criteria operator="AND" comment="Solaris 9 (SPARC) meets Sun Alert 102903" negate="false">
            <criterion comment="Solaris 9 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3172"/>
            <criterion comment="sparc architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3237"/>
            <criterion comment="Patch 112945-45 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:3891"/>
          </criteria>
          <criteria operator="AND" comment="Solaris 9 (x86) meets Sun Alert 102903" negate="false">
            <criterion comment="Solaris 9 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3172"/>
            <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3912"/>
            <criterion comment="Patch 114193-35 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:3909"/>
          </criteria>
          <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 102903" negate="false">
            <criterion comment="Solaris 10 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3680"/>
            <criterion comment="sparc architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3237"/>
            <criterion comment="Patch 121308-04 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:3382"/>
          </criteria>
          <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 102903" negate="false">
            <criterion comment="Solaris 10 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3680"/>
            <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3912"/>
            <criterion comment="Patch 121309-04 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:3316"/>
          </criteria>
        </criteria>
        <criterion comment="Package SUNWwbmc installed" negate="false" test_ref="oval:org.mitre.oval:tst:3160"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1832" version="0" class="vulnerability">
      <metadata>
        <title>A Security Vulnerability in How xscreensaver(1) Interacts With GNOME Assistive Technology May Allow Arbitrary Command Execution</title>
        <affected family="unix">
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-3069" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3069"/>
        <description>xscreensaver in Sun Solaris 10 before 20070604, when a GNOME session with Assistive Technology support is running, allows attackers with physical access to take control of the session after entering an Alt-Tab sequence.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-06-07T14:01:00.000-04:00">
              <contributor organization="Opsware, Inc.">Pai Peng</contributor>
            </submitted>
            <status_change date="2007-06-07T14:28:00.000-04:00">DRAFT</status_change>
            <status_change date="2007-06-22T08:57:41.387-04:00">INTERIM</status_change>
          </dates>
          <status>INTERIM</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="OR">
        <criteria operator="AND" comment="Solaris 10 (SPARC)" negate="false">
          <criterion comment="Solaris 10 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3680"/>
          <criterion comment="sparc architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3237"/>
          <criterion comment="Patch 120094-11 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:3833"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86)" negate="false">
          <criterion comment="Solaris 10 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3680"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3912"/>
          <criterion comment="Patch 120095-11 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:4096"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1966" version="0" class="vulnerability">
      <metadata>
        <title>A Security Vulnerability in the in.iked(1M) Service May Lead To a Denial of Service (DoS)</title>
        <affected family="unix">
          <platform>Sun Solaris 9</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-2989" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2989"/>
        <description>The libike library in Sun Solaris 9 before 20070529 contains a logic error related to a certain pointer, which allows remote attackers to cause a denial of service (in.iked daemon crash) by sending certain UDP packets with a source port different from 500. NOTE: this issue might overlap CVE-2006-2298.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-06-06T11:47:00.000-04:00">
              <contributor organization="Opsware, Inc.">Pai Peng</contributor>
            </submitted>
            <status_change date="2007-06-06T14:28:00.000-04:00">DRAFT</status_change>
            <status_change date="2007-06-22T08:57:42.447-04:00">INTERIM</status_change>
          </dates>
          <status>INTERIM</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="OR">
          <criteria operator="AND" comment="Solaris 9 (SPARC)" negate="false">
            <criterion comment="Solaris 9 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3172"/>
            <criterion comment="sparc architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3237"/>
            <criterion comment="Patch 113451-13 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:3350"/>
          </criteria>
          <criteria operator="AND" comment="Solaris 9 (x86)" negate="false">
            <criterion comment="Solaris 9 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3172"/>
            <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3912"/>
            <criterion comment="Patch 114435-12 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:3373"/>
          </criteria>
        </criteria>
        <criterion comment="/etc/inet/ike/config exists" negate="false" test_ref="oval:org.mitre.oval:tst:3233"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:2032" version="0" class="vulnerability">
      <metadata>
        <title>A Security Vulnerability in the Solaris 10 inetd(1M) Service May Lead to a Denial of Service (DoS) Condition</title>
        <affected family="unix">
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-2990" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2990"/>
        <description>Unspecified vulnerability in inetd in Sun Solaris 10 before 20070529 allows local users to cause a denial of service (daemon termination) via unspecified manipulations of the /var/run/.inetd.uds Unix domain socket file.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-06-06T11:47:00.000-04:00">
              <contributor organization="Opsware, Inc.">Pai Peng</contributor>
            </submitted>
            <status_change date="2007-06-06T14:28:00.000-04:00">DRAFT</status_change>
            <status_change date="2007-06-22T08:57:42.624-04:00">INTERIM</status_change>
          </dates>
          <status>INTERIM</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="OR">
          <criteria operator="AND" comment="Solaris 10 (SPARC)" negate="false">
            <criterion comment="Solaris 10 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3680"/>
            <criterion comment="sparc architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3237"/>
            <criterion comment="Patch 121288-03 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:3934"/>
          </criteria>
          <criteria operator="AND" comment="Solaris 10 (x86)" negate="false">
            <criterion comment="Solaris 10 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3680"/>
            <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3912"/>
            <criterion comment="Patch 121289-04 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:3679"/>
          </criteria>
        </criteria>
        <criterion comment="inetd running" negate="false" test_ref="oval:org.mitre.oval:tst:3135"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:464" version="2" class="vulnerability">
      <metadata>
        <title>Solaris 8, 9, 10 ICMP Source Quench Attack Vulnerability</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <platform>Sun Solaris 9</platform>
          <platform>Sun Solaris 10</platform>
          <product>Operating System</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0791" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0791"/>
        <description>Multiple TCP/IP and ICMP implementations allow remote attackers to cause a denial of service (network throughput reduction for TCP connections) via a blind throughput-reduction attack using spoofed Source Quench packets, aka the "ICMP Source Quench attack." NOTE: CVE-2004-0790, CVE-2004-0791, and CVE-2004-1060 have been SPLIT based on different attacks; CVE-2005-0065, CVE-2005-0066, CVE-2005-0067, and CVE-2005-0068 are related identifiers that are SPLIT based on the underlying vulnerability. While CVE normally SPLITs based on vulnerability, the attack-based identifiers exist due to the variety and number of affected implementations and solutions that address the attacks instead of the underlying vulnerabilities.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-09-22T05:52:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-09-22T20:15:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-07T09:15:47.997-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:15:55.567-04:00">ACCEPTED</status_change>
            <modified comment="Added title. Implemented by Jon Baker of The MITRE Corporation." date="2007-02-13T14:45:00.680-05:00">
              <contributor organization="Security-Database">Nabil Ouchn</contributor>
            </modified>
            <status_change date="2007-02-13T14:46:46.709-05:00">INTERIM</status_change>
            <modified comment="Standardized title." date="2007-02-23T13:00:00.812-05:00">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2007-03-21T16:17:19.479-04:00">ACCEPTED</status_change>
            <modified comment="Added missing patch checks." date="2007-06-26T10:59:00.998-04:00">
              <contributor organization="Opsware, Inc.">Pai Peng</contributor>
            </modified>
            <status_change date="2007-06-26T11:01:33.028-04:00">INTERIM</status_change>
          </dates>
          <status>INTERIM</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="OR">
        <criteria operator="AND" comment="Solaris 8 (SPARC) meets Sun Alert ID 101658 criteria." negate="false">
          <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3437"/>
          <criterion comment="sparc architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3237"/>
          <criterion comment="Patch 116965-19 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:4028"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 8 (x86) meets Sun Alert ID 101658 criteria." negate="false">
          <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3437"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3912"/>
          <criterion comment="Patch 116966-18 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:4069"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (SPARC) meets Sun Alert ID 101658 criteria." negate="false">
          <criterion comment="Solaris 9 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3172"/>
          <criterion comment="sparc architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3237"/>
          <criterion comment="Patch 118305-08 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:3204"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (x86) meets Sun Alert ID 101658 criteria." negate="false">
          <criterion comment="Solaris 9 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3172"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3912"/>
          <criterion comment="Patch 117470-07 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:4114"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert ID 101658 criteria." negate="false">
          <criterion comment="Solaris 10 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3680"/>
          <criterion comment="sparc architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3237"/>
          <criterion comment="Patch 118822-27 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:3505"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert ID 101658 criteria." negate="false">
          <criterion comment="Solaris 10 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3680"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3912"/>
          <criterion comment="Patch 118844-28 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:3302"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:622" version="2" class="vulnerability">
      <metadata>
        <title>Solaris 8, 9, 10 Blind Connection Reset Attack Vulnerability</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <platform>Sun Solaris 9</platform>
          <platform>Sun Solaris 10</platform>
          <product>Operating System</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0790" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0790"/>
        <description>Multiple TCP/IP and ICMP implementations allow remote attackers to cause a denial of service (reset TCP connections) via spoofed ICMP error messages, aka the "blind connection-reset attack." NOTE: CVE-2004-0790, CVE-2004-0791, and CVE-2004-1060 have been SPLIT based on different attacks; CVE-2005-0065, CVE-2005-0066, CVE-2005-0067, and CVE-2005-0068 are related identifiers that are SPLIT based on the underlying vulnerability. While CVE normally SPLITs based on vulnerability, the attack-based identifiers exist due to the variety and number of affected implementations and solutions that address the attacks instead of the underlying vulnerabilities.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-09-22T05:52:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-09-22T20:15:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-07T09:15:50.491-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:15:58.160-04:00">ACCEPTED</status_change>
            <modified comment="Added title. Implemented by Jon Baker of The MITRE Corporation." date="2007-02-13T14:46:00.662-05:00">
              <contributor organization="Security-Database">Nabil Ouchn</contributor>
            </modified>
            <status_change date="2007-02-13T14:47:31.744-05:00">INTERIM</status_change>
            <modified comment="Standardized title." date="2007-02-26T01:01:00.306-05:00">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2007-03-21T16:17:22.881-04:00">ACCEPTED</status_change>
            <modified comment="Added missing patch checks." date="2007-06-26T10:59:00.754-04:00">
              <contributor organization="Opsware, Inc.">Pai Peng</contributor>
            </modified>
            <status_change date="2007-06-26T11:00:29.787-04:00">INTERIM</status_change>
          </dates>
          <status>INTERIM</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="OR">
        <criteria operator="AND" comment="Solaris 8 (SPARC) meets Sun Alert ID 101658 criteria." negate="false">
          <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3437"/>
          <criterion comment="sparc architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3237"/>
          <criterion comment="Patch 116965-19 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:4028"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 8 (x86) meets Sun Alert ID 101658 criteria." negate="false">
          <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3437"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3912"/>
          <criterion comment="Patch 116966-18 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:4069"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (SPARC) meets Sun Alert ID 101658 criteria." negate="false">
          <criterion comment="Solaris 9 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3172"/>
          <criterion comment="sparc architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3237"/>
          <criterion comment="Patch 118305-08 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:3204"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (x86) meets Sun Alert ID 101658 criteria." negate="false">
          <criterion comment="Solaris 9 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3172"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3912"/>
          <criterion comment="Patch 117470-07 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:4114"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert ID 101658 criteria." negate="false">
          <criterion comment="Solaris 10 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3680"/>
          <criterion comment="sparc architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3237"/>
          <criterion comment="Patch 118822-27 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:3505"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert ID 101658 criteria." negate="false">
          <criterion comment="Solaris 10 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3680"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3912"/>
          <criterion comment="Patch 118844-28 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:3302"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:2037" version="0" class="vulnerability">
      <metadata>
        <title>GNOME XScreenSaver in Solaris 8 and 9 may Allow Physically Proximate Attackers to Access the Console</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <platform>Sun Solaris 9</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-3283" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3283"/>
        <description>GNOME XScreenSaver in Sun Solaris 8 and 9 before 20070417, when root is logged into the console, does not automatically lock the screen after a session has been inactive, which might allow physically proximate attackers to access the console.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-06-21T09:00:00.000-04:00">
              <contributor organization="Opsware, Inc.">Yuzheng Zhou</contributor>
            </submitted>
            <status_change date="2007-06-22T08:20:00.000-04:00">DRAFT</status_change>
          </dates>
          <status>DRAFT</status>
        </oval_repository>
      </metadata>
      <criteria comment="" operator="AND">
        <criteria comment="Software section" operator="OR">
          <criteria operator="AND" comment="Solaris 8 (SPARC)" negate="false">
            <extend_definition comment="Solaris 8 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1539"/>
            <criterion comment="Patch 115298-01 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:3643"/>
          </criteria>
          <criteria operator="AND" comment="Solaris 8 (x86)" negate="false">
            <extend_definition comment="Solaris 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:2059"/>
            <criterion comment="Patch 115299-01 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:3440"/>
          </criteria>
          <criteria operator="AND" comment="Solaris 9 (SPARC)" negate="false">
            <extend_definition comment="Solaris 9 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1457"/>
            <criterion comment="Patch 115158-03 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:3586"/>
          </criteria>
          <criteria operator="AND" comment="Solaris 9 (x86)" negate="false">
            <extend_definition comment="Solaris 9 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1683"/>
            <criterion comment="Patch 115159-03 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:3700"/>
          </criteria>
        </criteria>
        <criteria comment="Configuration Section" operator="AND">
          <criterion comment="Gnome (major version is equal to 2) Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3407"/>
          <criterion comment="Gnome (minor version is equal to 0) Installed" negate="false" test_ref="oval:org.mitre.oval:tst:4148"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1683" version="0" class="inventory">
      <metadata>
        <title>Solaris 9 (x86) is installed</title>
        <affected family="unix">
          <platform>Sun Solaris 9</platform>
        </affected>
        <reference source="CPE" ref_id="cpe://sun:sunos:5.9"/>
        <description>The operating system installed on the system is Sun Solaris 9 for x86.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-06-22T08:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </submitted>
            <status_change date="2007-06-22T08:20:00.000-04:00">DRAFT</status_change>
          </dates>
          <status>DRAFT</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="Solaris 9 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3172"/>
        <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3912"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1457" version="0" class="inventory">
      <metadata>
        <title>Solaris 9 (SPARC) is installed</title>
        <affected family="unix">
          <platform>Sun Solaris 9</platform>
        </affected>
        <reference source="CPE" ref_id="cpe://sun:sunos:5.9"/>
        <description>The operating system installed on the system is Sun Solaris 9 for SPARC.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-06-22T08:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </submitted>
            <status_change date="2007-06-22T08:20:00.000-04:00">DRAFT</status_change>
          </dates>
          <status>DRAFT</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="Solaris 9 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3172"/>
        <criterion comment="sparc architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3237"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1539" version="0" class="inventory">
      <metadata>
        <title>Solaris 8 (SPARC) is installed</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
        </affected>
        <reference source="CPE" ref_id="cpe://sun:sunos:5.8"/>
        <description>The operating system installed on the system is Sun Solaris 8 for SPARC.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-06-22T08:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </submitted>
            <status_change date="2007-06-22T08:20:00.000-04:00">DRAFT</status_change>
          </dates>
          <status>DRAFT</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3437"/>
        <criterion comment="sparc architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3237"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:2059" version="0" class="inventory">
      <metadata>
        <title>Solaris 8 (x86) is installed</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
        </affected>
        <reference source="CPE" ref_id="cpe://sun:sunos:5.8"/>
        <description>The operating system installed on the system is Sun Solaris 8 for x86.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-06-22T08:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </submitted>
            <status_change date="2007-06-22T08:20:00.000-04:00">DRAFT</status_change>
          </dates>
          <status>DRAFT</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3437"/>
        <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3912"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1092" version="0" class="vulnerability">
      <metadata>
        <title>Security Vulnerability in Solaris 10 NFS XDR Handling May Allow a Denial of Service to NFS Servers</title>
        <affected family="unix">
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-3223" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3223"/>
        <description>Unspecified vulnerability in the NFS server in Sun Solaris 10 before 20070613 allows remote attackers to cause a denial of service (system crash) via certain XDR data in NFS requests, probably related to processing of data by the xdr_bool and xdrmblk_getint32 functions.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-06-19T14:30:00.000-04:00">
              <contributor organization="Opsware, Inc.">Nicholas Hansen</contributor>
            </submitted>
            <status_change date="2007-06-19T14:30:00.000-04:00">DRAFT</status_change>
          </dates>
          <status>DRAFT</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="OR">
          <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 102965" negate="false">
            <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
            <criterion comment="Patch 125100-01 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:4018"/>
          </criteria>
          <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 102965" negate="false">
            <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
            <criterion comment="Patch 125101-01 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:3945"/>
          </criteria>
        </criteria>
        <criterion comment="NFS Server running (nfsd)" negate="false" test_ref="oval:org.mitre.oval:tst:3396"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1444" version="0" class="vulnerability">
      <metadata>
        <title>Security Vulnerability in IPv6 Implementation (ip6(7p)) Related to the Handling of IPsec Packets may Lead to a System Panic, Resulting in a Denial of Service (DoS)</title>
        <affected family="unix">
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-3248" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3248"/>
        <description>Unspecified vulnerability in Sun Solaris 10 before 20070614, when IPv6 interfaces are present but not configured for IPsec, allows remote attackers to cause a denial of service (system crash) via certain network traffic.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-06-19T14:30:00.000-04:00">
              <contributor organization="Opsware, Inc.">Nicholas Hansen</contributor>
            </submitted>
            <status_change date="2007-06-19T14:30:00.000-04:00">DRAFT</status_change>
          </dates>
          <status>DRAFT</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="OR">
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 102919" negate="false">
          <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
          <criterion comment="Patch 125100-09 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:4134"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 102919" negate="false">
          <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
          <criterion comment="Patch 125101-09 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:4040"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1926" version="0" class="inventory">
      <metadata>
        <title>Solaris 10 (x86) is installed</title>
        <affected family="unix">
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CPE" ref_id="cpe://sun:sunos:5.10"/>
        <description>The operating system installed on the system is Sun Solaris 10 for x86.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-06-15T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </submitted>
            <status_change date="2007-06-15T12:20:00.000-04:00">DRAFT</status_change>
          </dates>
          <status>DRAFT</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="Solaris 10 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3680"/>
        <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3912"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1440" version="0" class="inventory">
      <metadata>
        <title>Solaris 10 (SPARC) is installed</title>
        <affected family="unix">
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CPE" ref_id="cpe://sun:sunos:5.10"/>
        <description>The operating system installed on the system is Sun Solaris 10 for SPARC.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-06-15T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </submitted>
            <status_change date="2007-06-15T12:20:00.000-04:00">DRAFT</status_change>
          </dates>
          <status>DRAFT</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="Solaris 10 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3680"/>
        <criterion comment="sparc architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3237"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1085" version="0" class="vulnerability">
      <metadata>
        <title>Solaris 9 Systems With Solaris Auditing (BSM) Enabled may Panic if Certain Audit Classes are Being Audited</title>
        <affected family="unix">
          <platform>Sun Solaris 9</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-2465" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2465"/>
        <description>Unspecified vulnerability in Sun Solaris 9, when Solaris Auditing (BSM) is enabled for file read, write, attribute modify, create, or delete audit classes, allows local users to cause a denial of service (panic) via unknown vectors, possibly related to the audit_savepath function.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-06-15T09:00:00.000-04:00">
              <contributor organization="Opsware, Inc.">Pai Peng</contributor>
            </submitted>
            <status_change date="2007-06-15T11:20:00.000-04:00">DRAFT</status_change>
          </dates>
          <status>DRAFT</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Solaris 9 (SPARC) meets Sun Alert ID 102900 criteria." negate="false">
          <criterion comment="Solaris 9 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3172"/>
          <criterion comment="sparc architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3237"/>
          <criterion comment="Patch 122300-06 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:3900"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (x86) meets Sun Alert ID 102900 criteria." negate="false">
          <criterion comment="Solaris 9 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3172"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3912"/>
          <criterion comment="Patch 122301-06 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:3594"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1252" version="0" class="vulnerability">
      <metadata>
        <title>Format string vulnerability in Sun Java Web Console</title>
        <affected family="unix">
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-1681" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1681"/>
        <description>Format string vulnerability in libwebconsole_services.so in Sun Java Web Console 2.2.2 through 2.2.5 allows remote attackers to cause a denial of service (application crash), obtain sensitive information, and possibly execute arbitrary code via unspecified vectors during a failed login attempt, related to syslog.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-06-15T09:00:00.000-04:00">
              <contributor organization="Opsware, Inc.">Pai Peng</contributor>
            </submitted>
            <status_change date="2007-06-15T11:20:00.000-04:00">DRAFT</status_change>
          </dates>
          <status>DRAFT</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="OR">
        <criteria operator="AND" comment="Solaris 10 (SPARC)" negate="false">
          <criterion comment="Solaris 10 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3680"/>
          <criterion comment="sparc architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3237"/>
          <criterion comment="Patch 121211-02 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:3537"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86)" negate="false">
          <criterion comment="Solaris 10 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3680"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3912"/>
          <criterion comment="Patch 121212-02 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:3315"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1669" version="0" class="vulnerability">
      <metadata>
        <title>Security Vulnerability Relating to the acl(2) System Call May Allow Denial of Service (DoS) to the System</title>
        <affected family="unix">
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-2529" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2529"/>
        <description>Integer signedness error in the acl (facl) system call in Solaris 10 before 20070507 allows local users to cause a denial of service (kernel panic) and possibly gain privileges via a certain argument, related to ACE_SETACL.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-06-15T09:00:00.000-04:00">
              <contributor organization="Opsware, Inc.">Pai Peng</contributor>
            </submitted>
            <status_change date="2007-06-15T11:20:00.000-04:00">DRAFT</status_change>
          </dates>
          <status>DRAFT</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="OR">
        <criteria operator="AND" comment="Solaris 10 (SPARC)" negate="false">
          <criterion comment="Solaris 10 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3680"/>
          <criterion comment="sparc architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3237"/>
          <criterion comment="Patch 125100-06 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:3442"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86)" negate="false">
          <criterion comment="Solaris 10 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3680"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3912"/>
          <criterion comment="Patch 125101-06 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:3825"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1828" version="0" class="vulnerability">
      <metadata>
        <title>Buffer Overflow in "in.telnetd"or "telnetd"Process</title>
        <affected family="unix">
          <platform>Sun Solaris 7</platform>
          <platform>Sun Solaris 8</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2001-0554" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-0554"/>
        <description>Buffer overflow in BSD-based telnetd telnet daemon on various operating systems allows remote attackers to execute arbitrary commands via a set of options including AYT (Are You There), which is not properly handled by the telrcv function.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-06-15T09:00:00.000-04:00">
              <contributor organization="Opsware, Inc.">Pai Peng</contributor>
            </submitted>
            <status_change date="2007-06-15T11:20:00.000-04:00">DRAFT</status_change>
          </dates>
          <status>DRAFT</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="OR">
        <criteria operator="AND" comment="Solaris 8 (SPARC)" negate="false">
          <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3437"/>
          <criterion comment="sparc architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3237"/>
          <criteria comment="" operator="OR">
            <criteria comment="SEAM and patch 110060-10" operator="AND">
              <criteria operator="OR" comment="Solaris Enterprise Authentication Mechanism (ANY SUNWkr5sl/SUNWkr5sv/SUNWkrgdo/SUNWkrggl)">
                <criterion comment="Sun Enterprise Authentication Mechanism (SEAM, SUNWkr5sv) installed" negate="false" test_ref="oval:org.mitre.oval:tst:1161"/>
                <criterion comment=" Sun Enterprise Authentication Mechanism (SEAM, SUNWkr5sl) installed" negate="false" test_ref="oval:org.mitre.oval:tst:1160"/>
                <criterion comment=" Sun Enterprise Authentication Mechanism (SEAM, SUNWkrgdo) installed" negate="false" test_ref="oval:org.mitre.oval:tst:1159"/>
                <criterion comment=" Sun Enterprise Authentication Mechanism (SEAM, SUNWkrggl) installed" negate="false" test_ref="oval:org.mitre.oval:tst:1158"/>
              </criteria>
              <criterion comment="Patch 110060-10 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:3408"/>
            </criteria>
            <criterion comment="Patch 110668-03 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:3463"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Solaris 8 (x86)" negate="false">
          <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3437"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3912"/>
          <criteria comment="" operator="OR">
            <criteria comment="SEAM and patch 110061-10" operator="AND">
              <criteria operator="OR" comment="Solaris Enterprise Authentication Mechanism (ANY SUNWkr5sl/SUNWkr5sv/SUNWkrgdo/SUNWkrggl)">
                <criterion comment="Sun Enterprise Authentication Mechanism (SEAM, SUNWkr5sv) installed" negate="false" test_ref="oval:org.mitre.oval:tst:1161"/>
                <criterion comment=" Sun Enterprise Authentication Mechanism (SEAM, SUNWkr5sl) installed" negate="false" test_ref="oval:org.mitre.oval:tst:1160"/>
                <criterion comment=" Sun Enterprise Authentication Mechanism (SEAM, SUNWkrgdo) installed" negate="false" test_ref="oval:org.mitre.oval:tst:1159"/>
                <criterion comment=" Sun Enterprise Authentication Mechanism (SEAM, SUNWkrggl) installed" negate="false" test_ref="oval:org.mitre.oval:tst:1158"/>
              </criteria>
              <criterion comment="Patch 110061-10 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:3951"/>
            </criteria>
            <criterion comment="Patch 110669-03 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:3634"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Solaris 7 (SPARC)" negate="false">
          <criterion comment="Solaris 7 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3576"/>
          <criterion comment="sparc architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3237"/>
          <criteria comment="" operator="OR">
            <criteria comment="SEAM and patch 110057-04" operator="AND">
              <criteria operator="OR" comment="Solaris Enterprise Authentication Mechanism (ANY SUNWkr5sl/SUNWkr5sv/SUNWkrgdo/SUNWkrggl)">
                <criterion comment="Sun Enterprise Authentication Mechanism (SEAM, SUNWkr5sv) installed" negate="false" test_ref="oval:org.mitre.oval:tst:1161"/>
                <criterion comment=" Sun Enterprise Authentication Mechanism (SEAM, SUNWkr5sl) installed" negate="false" test_ref="oval:org.mitre.oval:tst:1160"/>
                <criterion comment=" Sun Enterprise Authentication Mechanism (SEAM, SUNWkrgdo) installed" negate="false" test_ref="oval:org.mitre.oval:tst:1159"/>
                <criterion comment=" Sun Enterprise Authentication Mechanism (SEAM, SUNWkrggl) installed" negate="false" test_ref="oval:org.mitre.oval:tst:1158"/>
              </criteria>
              <criterion comment="Patch 110057-04 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:3494"/>
            </criteria>
            <criterion comment="Patch 107475-04 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:4081"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Solaris 7 (x86)" negate="false">
          <criterion comment="Solaris 7 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3576"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3912"/>
          <criteria comment="" operator="OR">
            <criteria comment="SEAM and patch 110058-04" operator="AND">
              <criteria operator="OR" comment="Solaris Enterprise Authentication Mechanism (ANY SUNWkr5sl/SUNWkr5sv/SUNWkrgdo/SUNWkrggl)">
                <criterion comment="Sun Enterprise Authentication Mechanism (SEAM, SUNWkr5sv) installed" negate="false" test_ref="oval:org.mitre.oval:tst:1161"/>
                <criterion comment=" Sun Enterprise Authentication Mechanism (SEAM, SUNWkr5sl) installed" negate="false" test_ref="oval:org.mitre.oval:tst:1160"/>
                <criterion comment=" Sun Enterprise Authentication Mechanism (SEAM, SUNWkrgdo) installed" negate="false" test_ref="oval:org.mitre.oval:tst:1159"/>
                <criterion comment=" Sun Enterprise Authentication Mechanism (SEAM, SUNWkrggl) installed" negate="false" test_ref="oval:org.mitre.oval:tst:1158"/>
              </criteria>
              <criterion comment="Patch 110058-04 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:3361"/>
            </criteria>
            <criterion comment="Patch 107476-04 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:3852"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1957" version="0" class="vulnerability">
      <metadata>
        <title>Security Vulnerability in NFS Client Module May Lead to a Denial of Service Condition</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <platform>Sun Solaris 9</platform>
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-2882" ref_url="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2007-2882"/>
        <description>Unspecified vulnerability in the NFS client module in Sun Solaris 8 through 10 before 20070524, when operating as an NFS server, allows remote attackers to cause a denial of service (crash) via certain Access Control List (acl) packets.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-06-15T09:00:00.000-04:00">
              <contributor organization="Opsware, Inc.">John Wregglesworth</contributor>
            </submitted>
            <status_change date="2007-06-15T11:20:00.000-04:00">DRAFT</status_change>
          </dates>
          <status>DRAFT</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="OR">
        <criteria operator="AND" comment="Solaris 8 (SPARC)" negate="false">
          <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3437"/>
          <criterion comment="sparc architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3237"/>
          <criterion comment="Patch 116959-16 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:3570"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 8 (x86)" negate="false">
          <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3437"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3912"/>
          <criterion comment="Patch 116960-16 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:4073"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (SPARC)" negate="false">
          <criterion comment="Solaris 9 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3172"/>
          <criterion comment="sparc architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3237"/>
          <criterion comment="Patch 113318-29 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:3914"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (x86)" negate="false">
          <criterion comment="Solaris 9 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3172"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3912"/>
          <criterion comment="Patch 117468-15 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:3605"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (SPARC)" negate="false">
          <criterion comment="Solaris 10 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3680"/>
          <criterion comment="sparc architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3237"/>
          <criterion comment="Patch 124258-04 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:3213"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86)" negate="false">
          <criterion comment="Solaris 10 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3680"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3912"/>
          <criterion comment="Patch 124259-04 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:3414"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1099" version="3" class="vulnerability">
      <metadata>
        <title>Solaris 9 CDE ToolTalk Database Null Write Vulnerability</title>
        <affected family="unix">
          <platform>Sun Solaris 9</platform>
          <product>CDE</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-0677" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0677"/>
        <description>CDE ToolTalk database server (ttdbserver) allows remote attackers to overwrite arbitrary memory locations with a zero, and possibly gain privileges, via a file descriptor argument in an AUTH_UNIX procedure call, which is used as a table index by the _TT_ISCLOSE procedure.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-10-15T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Brian Soby</contributor>
            </submitted>
            <status_change date="2004-10-20T12:00:00.000-04:00">DRAFT</status_change>
            <status_change date="2004-11-03T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-12-09T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-01-11T12:00:00.000-04:00" comment="modified sat-6 - Changed test to pattern match and added check for 64bit version">
              <contributor organization="The MITRE Corporation">Brian Soby</contributor>
            </modified>
            <modified date="2005-01-14T12:00:00.000-04:00" comment="modified sat-6 - Changed regular expression test to properly check for 64bit package">
              <contributor organization="The MITRE Corporation">Brian Soby</contributor>
            </modified>
            <status_change date="2005-01-24T02:33:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-02-16T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="fixed the service_name entity used in the inetd_object" date="2007-04-10T15:17:00.627-04:00">
              <contributor organization="Opsware, Inc.">Todd Dolinsky</contributor>
            </modified>
            <status_change date="2007-04-10T15:17:29.433-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:52:14.145-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Solaris 9 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3051"/>
          <criterion comment="Toolktalk (SUNWtltk/SUNWtltkx) installed" negate="false" test_ref="oval:org.mitre.oval:tst:1169"/>
          <criterion comment="Patch 112808-02 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:1168"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="inetd.conf contains rpc.ttdbserverd" negate="false" test_ref="oval:org.mitre.oval:tst:3103"/>
          <criterion comment="inetd running" negate="false" test_ref="oval:org.mitre.oval:tst:3135"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:120" version="1" class="vulnerability">
      <metadata>
        <title>Solaris 7 KCMS Arbitrary File Access Vulnerability</title>
        <affected family="unix">
          <platform>Sun Solaris 7</platform>
          <product>kcms_server</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0027" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0027"/>
        <description>Directory traversal vulnerability in Sun Kodak Color Management System (KCMS) library service daemon (kcms_server) allows remote attackers to read arbitrary files via the KCS_OPEN_PROFILE procedure.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-01-30T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">David Proulx</contributor>
            </submitted>
            <modified comment="fixed the service_name entity used in the inetd_object" date="2007-04-10T15:15:00.237-04:00">
              <contributor organization="Opsware, Inc.">Todd Dolinsky</contributor>
            </modified>
            <status_change date="2007-04-10T15:15:57.513-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:52:14.919-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Solaris 7 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3045"/>
          <criterion comment="File kcms_server exists" negate="false" test_ref="oval:org.mitre.oval:tst:2931"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="inetd.conf contains kcms_server" negate="false" test_ref="oval:org.mitre.oval:tst:2930"/>
          <criterion comment="inetd running" negate="false" test_ref="oval:org.mitre.oval:tst:3135"/>
          <criteria operator="OR" comment="File kcms_server executable and SUID or SGID">
            <criterion comment="File kcms_server executable and SUID or SGID" negate="false" test_ref="oval:org.mitre.oval:tst:2929"/>
            <criterion comment="File kcms_server executable and SUID or SGID" negate="false" test_ref="oval:org.mitre.oval:tst:2928"/>
            <criterion comment="File kcms_server executable and SUID or SGID" negate="false" test_ref="oval:org.mitre.oval:tst:2927"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1237" version="2" class="vulnerability">
      <metadata>
        <title>Webproxy HTTP Request Smuggling (B.11.04)</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
          <product>Apache</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2088" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2088"/>
        <description>The Apache HTTP server before 1.3.34, and 2.0.x before 2.0.55, when acting as an HTTP proxy, allows remote attackers to poison the web cache, bypass web application firewall protection, and conduct XSS attacks via an HTTP request with both a "Transfer-Encoding: chunked" header and a Content-Length header, which causes Apache to incorrectly handle and forward the body of the request in a way that causes the receiving server to process it as a separate HTTP request, aka "HTTP Request Smuggling."</description>
        <oval_repository>
          <dates>
            <submitted date="2006-03-18T07:24:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-03-22T11:10:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-04-06T06:31:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-05-03T10:06:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Added CVE reference. Implemented by Jon Baker of The MITRE Corporation." date="2007-03-19T21:23:00.442-04:00">
              <contributor organization="Opsware, Inc.">Todd Dolinsky</contributor>
            </modified>
            <status_change date="2007-03-19T21:30:48.475-04:00">INTERIM</status_change>
            <status_change date="2007-04-10T13:44:19.545-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="OR">
        <criteria operator="AND" comment="VirtualvaultTS A.04.70 is installed without patch PHSS_34169 or later">
          <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.04">
            <criteria operator="AND" comment="700 Series OS Release 11.04">
              <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2515"/>
              <criterion comment="HP Release B.11.04" negate="false" test_ref="oval:org.mitre.oval:tst:1276"/>
            </criteria>
            <criteria operator="AND" comment="800 Series OS Release 11.04">
              <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2513"/>
              <criterion comment="HP Release B.11.04" negate="false" test_ref="oval:org.mitre.oval:tst:1276"/>
            </criteria>
          </criteria>
          <criterion comment="VirtualvaultTS A.04.70 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1062"/>
          <criterion comment="Patch PHSS_34169 or subsequent is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2341"/>
        </criteria>
        <criteria operator="AND" comment="VirtualvaultWS A.04.70 is installed without patch PHSS_34121 or later">
          <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.04">
            <criteria operator="AND" comment="700 Series OS Release 11.04">
              <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2515"/>
              <criterion comment="HP Release B.11.04" negate="false" test_ref="oval:org.mitre.oval:tst:1276"/>
            </criteria>
            <criteria operator="AND" comment="800 Series OS Release 11.04">
              <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2513"/>
              <criterion comment="HP Release B.11.04" negate="false" test_ref="oval:org.mitre.oval:tst:1276"/>
            </criteria>
          </criteria>
          <criterion comment="VirtualvaultWS A.04.70 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1061"/>
          <criterion comment="Patch PHSS_34121 or subsequent is installed" negate="true" test_ref="oval:org.mitre.oval:tst:1060"/>
        </criteria>
        <criteria operator="AND" comment="VirtualvaultTS A.04.60 is installed without patch PHSS_34170 or later">
          <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.04">
            <criteria operator="AND" comment="700 Series OS Release 11.04">
              <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2515"/>
              <criterion comment="HP Release B.11.04" negate="false" test_ref="oval:org.mitre.oval:tst:1276"/>
            </criteria>
            <criteria operator="AND" comment="800 Series OS Release 11.04">
              <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2513"/>
              <criterion comment="HP Release B.11.04" negate="false" test_ref="oval:org.mitre.oval:tst:1276"/>
            </criteria>
          </criteria>
          <criterion comment="VirtualvaultTS A.04.60 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1059"/>
          <criterion comment="Patch PHSS_34170 or subsequent is installed" negate="true" test_ref="oval:org.mitre.oval:tst:1058"/>
        </criteria>
        <criteria operator="AND" comment="VirtualvaultWS A.04.60 is installed without patch PHSS_34120 or later">
          <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.04">
            <criteria operator="AND" comment="700 Series OS Release 11.04">
              <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2515"/>
              <criterion comment="HP Release B.11.04" negate="false" test_ref="oval:org.mitre.oval:tst:1276"/>
            </criteria>
            <criteria operator="AND" comment="800 Series OS Release 11.04">
              <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2513"/>
              <criterion comment="HP Release B.11.04" negate="false" test_ref="oval:org.mitre.oval:tst:1276"/>
            </criteria>
          </criteria>
          <criterion comment="VirtualvaultWS A.04.60 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1057"/>
          <criterion comment="Patch PHSS_34120 or subsequent is installed" negate="true" test_ref="oval:org.mitre.oval:tst:1056"/>
        </criteria>
        <criteria operator="AND" comment="VirtualvaultTS A.04.50 is installed without patch PHSS_34171 or later">
          <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.04">
            <criteria operator="AND" comment="700 Series OS Release 11.04">
              <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2515"/>
              <criterion comment="HP Release B.11.04" negate="false" test_ref="oval:org.mitre.oval:tst:1276"/>
            </criteria>
            <criteria operator="AND" comment="800 Series OS Release 11.04">
              <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2513"/>
              <criterion comment="HP Release B.11.04" negate="false" test_ref="oval:org.mitre.oval:tst:1276"/>
            </criteria>
          </criteria>
          <criterion comment="VirtualvaultTS A.04.50 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1055"/>
          <criterion comment="Patch PHSS_34171 or subsequent is installed" negate="true" test_ref="oval:org.mitre.oval:tst:1054"/>
        </criteria>
        <criteria operator="AND" comment="VirtualvaultWS A.04.50 is installed without patch PHSS_34119 or later">
          <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.04">
            <criteria operator="AND" comment="700 Series OS Release 11.04">
              <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2515"/>
              <criterion comment="HP Release B.11.04" negate="false" test_ref="oval:org.mitre.oval:tst:1276"/>
            </criteria>
            <criteria operator="AND" comment="800 Series OS Release 11.04">
              <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2513"/>
              <criterion comment="HP Release B.11.04" negate="false" test_ref="oval:org.mitre.oval:tst:1276"/>
            </criteria>
          </criteria>
          <criterion comment="VirtualvaultWS A.04.50 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1053"/>
          <criterion comment="Patch PHSS_34119 or subsequent is installed" negate="true" test_ref="oval:org.mitre.oval:tst:1052"/>
        </criteria>
        <criteria operator="AND" comment="HP_Webproxy.HPWEB-PX-CORE A.02.10 is installed without patch PHSS_34203 or later">
          <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.04">
            <criteria operator="AND" comment="700 Series OS Release 11.04">
              <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2515"/>
              <criterion comment="HP Release B.11.04" negate="false" test_ref="oval:org.mitre.oval:tst:1276"/>
            </criteria>
            <criteria operator="AND" comment="800 Series OS Release 11.04">
              <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2513"/>
              <criterion comment="HP Release B.11.04" negate="false" test_ref="oval:org.mitre.oval:tst:1276"/>
            </criteria>
          </criteria>
          <criterion comment="HP_Webproxy.HPWEB-PX-CORE A.02.10 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1051"/>
          <criterion comment="Patch PHSS_34203 or subsequent is installed" negate="true" test_ref="oval:org.mitre.oval:tst:1050"/>
        </criteria>
        <criteria operator="AND" comment="HP_Webproxy.HPWEB-PX-CORE A.02.00 is installed without patch PHSS_34204 or later">
          <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.04">
            <criteria operator="AND" comment="700 Series OS Release 11.04">
              <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2515"/>
              <criterion comment="HP Release B.11.04" negate="false" test_ref="oval:org.mitre.oval:tst:1276"/>
            </criteria>
            <criteria operator="AND" comment="800 Series OS Release 11.04">
              <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2513"/>
              <criterion comment="HP Release B.11.04" negate="false" test_ref="oval:org.mitre.oval:tst:1276"/>
            </criteria>
          </criteria>
          <criterion comment="HP_Webproxy.HPWEB-PX-CORE A.02.00 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1049"/>
          <criterion comment="Patch PHSS_34204 or subsequent is installed" negate="true" test_ref="oval:org.mitre.oval:tst:1048"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:124" version="2" class="vulnerability">
      <metadata>
        <title>Solaris 7 cachefsd Heap Overflow Vulnerability</title>
        <affected family="unix">
          <platform>Sun Solaris 7</platform>
          <product>cachefsd</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-0033" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0033"/>
        <description>Heap-based buffer overflow in cfsd_calloc function of Solaris cachefsd allows remote attackers to execute arbitrary code via a request with a long directory and cache name.</description>
        <oval_repository>
          <dates>
            <submitted date="2002-10-17T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">David Proulx</contributor>
            </submitted>
            <modified date="2005-01-28T12:00:00.000-04:00" comment="Added patch test">
              <contributor organization="The MITRE Corporation">Brian Soby</contributor>
            </modified>
            <status_change date="2005-02-01T08:29:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-02-16T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="fixed the service_name entity used in the inetd_object" date="2007-04-10T15:17:00.350-04:00">
              <contributor organization="Opsware, Inc.">Todd Dolinsky</contributor>
            </modified>
            <status_change date="2007-04-10T15:17:46.093-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:52:15.088-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Solaris 7 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3045"/>
          <criterion comment="File cachefsd exists" negate="false" test_ref="oval:org.mitre.oval:tst:3053"/>
          <criterion comment="Patch 108800-02 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:3024"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="inetd.conf contains cachefsd" negate="false" test_ref="oval:org.mitre.oval:tst:3049"/>
          <criterion comment="inetd running" negate="false" test_ref="oval:org.mitre.oval:tst:3135"/>
          <criteria operator="OR" comment="File cachefsd executable">
            <criterion comment="File cachefsd executable" negate="false" test_ref="oval:org.mitre.oval:tst:3048"/>
            <criterion comment="File cachefsd executable" negate="false" test_ref="oval:org.mitre.oval:tst:3047"/>
            <criterion comment="File cachefsd executable" negate="false" test_ref="oval:org.mitre.oval:tst:3046"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1273" version="3" class="vulnerability">
      <metadata>
        <title>Solaris SAdmin Client Credentials Remote Administrative Access Vulnerability</title>
        <affected family="unix">
          <platform>Sun Solaris 7</platform>
          <platform>Sun Solaris 8</platform>
          <platform>Sun Solaris 9</platform>
          <product>Sadmin</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0722" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0722"/>
        <description>The default installation of sadmind on Solaris uses weak authentication (AUTH_SYS), which allows local and remote attackers to spoof Solstice AdminSuite clients and gain root privileges via a certain sequence of RPC packets.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-10-15T02:06:00.000-04:00">
              <contributor organization="The MITRE Corporation">Brian Soby</contributor>
            </submitted>
            <modified date="2004-10-15T02:21:00.000-04:00" comment="Added check for sadmind called with strong authentication">
              <contributor organization="The MITRE Corporation">Brian Soby</contributor>
            </modified>
            <status_change date="2004-10-20T02:35:00.000-04:00">DRAFT</status_change>
            <status_change date="2004-11-03T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-12-09T08:46:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected datatype on version element of patch state. Datatype must be int." date="2007-01-04T08:56:00.454-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-01-04T08:58:16.556-05:00">INTERIM</status_change>
            <status_change date="2007-02-20T13:39:38.256-05:00">ACCEPTED</status_change>
            <modified comment="fixed the service_name entity used in the inetd_object" date="2007-04-10T15:09:00.555-04:00">
              <contributor organization="Opsware, Inc.">Todd Dolinsky</contributor>
            </modified>
            <status_change date="2007-04-10T15:13:41.722-04:00">INTERIM</status_change>
            <modified comment="fixed the service_name entity used in the inetd_object" date="2007-04-10T15:13:00.562-04:00">
              <contributor organization="Opsware, Inc.">Todd Dolinsky</contributor>
            </modified>
            <status_change date="2007-04-25T19:52:15.291-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criteria operator="OR" comment="Solaris 7,8,or 9 installed">
            <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3145"/>
            <criterion comment="Solaris 7 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3045"/>
            <criterion comment="Solaris 9 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3051"/>
          </criteria>
          <criterion comment="System and Network Administration Framework Installed" negate="false" test_ref="oval:org.mitre.oval:tst:1024"/>
          <criterion comment="Patch 116457-02 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:1022"/>
          <criterion comment="Patch 116442-01 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:1021"/>
          <criterion comment="Patch 116454-01 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:1020"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="inetd running" negate="false" test_ref="oval:org.mitre.oval:tst:3135"/>
          <criterion comment="inetd.conf contains sadmind" negate="false" test_ref="oval:org.mitre.oval:tst:1023"/>
          <criterion comment="Sadmin called using strong authentication" negate="true" test_ref="oval:org.mitre.oval:tst:1019"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:149" version="1" class="vulnerability">
      <metadata>
        <title>Solaris 8 X Font Server Remote Buffer Overrun</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <product>fs.auto, xfs</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-1317" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-1317"/>
        <description>Buffer overflow in Dispatch() routine for XFS font server (fs.auto) on Solaris 2.5.1 through 9 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a certain XFS query.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-09-08T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">David Proulx</contributor>
            </submitted>
            <modified comment="fixed the service_name entity used in the inetd_object" date="2007-04-10T15:16:00.255-04:00">
              <contributor organization="Opsware, Inc.">Todd Dolinsky</contributor>
            </modified>
            <status_change date="2007-04-10T15:16:47.778-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:52:16.773-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3145"/>
          <criterion comment="File fs.auto exists" negate="false" test_ref="oval:org.mitre.oval:tst:2873"/>
          <criterion comment="File xfs exists" negate="false" test_ref="oval:org.mitre.oval:tst:2872"/>
          <criterion comment="Patch 109862-03 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:2871"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="inetd.conf contains fs.auto" negate="false" test_ref="oval:org.mitre.oval:tst:2870"/>
          <criterion comment="inetd running" negate="false" test_ref="oval:org.mitre.oval:tst:3135"/>
          <criteria operator="OR" comment="File xfs executable">
            <criterion comment="File xfs executable" negate="false" test_ref="oval:org.mitre.oval:tst:2869"/>
            <criterion comment="File xfs executable" negate="false" test_ref="oval:org.mitre.oval:tst:2868"/>
            <criterion comment="File xfs executable" negate="false" test_ref="oval:org.mitre.oval:tst:2867"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:15" version="1" class="vulnerability">
      <metadata>
        <title>Solaris 8 CDE ToolTalk Database Null Write Vulnerability</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <product>CDE</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-0677" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0677"/>
        <description>CDE ToolTalk database server (ttdbserver) allows remote attackers to overwrite arbitrary memory locations with a zero, and possibly gain privileges, via a file descriptor argument in an AUTH_UNIX procedure call, which is used as a table index by the _TT_ISCLOSE procedure.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-01-31T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">David Proulx</contributor>
            </submitted>
            <modified comment="fixed the service_name entity used in the inetd_object" date="2007-04-10T15:17:00.627-04:00">
              <contributor organization="Opsware, Inc.">Todd Dolinsky</contributor>
            </modified>
            <status_change date="2007-04-10T15:17:28.303-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:52:16.975-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3145"/>
          <criterion comment="File rpc.ttdbserverd exists" negate="false" test_ref="oval:org.mitre.oval:tst:3105"/>
          <criterion comment="Patch 110286-09 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:3104"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="inetd.conf contains rpc.ttdbserverd" negate="false" test_ref="oval:org.mitre.oval:tst:3103"/>
          <criterion comment="inetd running" negate="false" test_ref="oval:org.mitre.oval:tst:3135"/>
          <criteria operator="OR" comment="File rpc.ttdbserverd executable">
            <criterion comment="File rpc.ttdbserverd executable" negate="false" test_ref="oval:org.mitre.oval:tst:3102"/>
            <criterion comment="File rpc.ttdbserverd executable" negate="false" test_ref="oval:org.mitre.oval:tst:3101"/>
            <criterion comment="File rpc.ttdbserverd executable" negate="false" test_ref="oval:org.mitre.oval:tst:3100"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:152" version="1" class="vulnerability">
      <metadata>
        <title>Solaris 7 X Font Server Remote Buffer Overrun</title>
        <affected family="unix">
          <platform>Sun Solaris 7</platform>
          <product>fs.auto, xfs</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-1317" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-1317"/>
        <description>Buffer overflow in Dispatch() routine for XFS font server (fs.auto) on Solaris 2.5.1 through 9 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a certain XFS query.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-09-08T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">David Proulx</contributor>
            </submitted>
            <modified comment="fixed the service_name entity used in the inetd_object" date="2007-04-10T15:16:00.255-04:00">
              <contributor organization="Opsware, Inc.">Todd Dolinsky</contributor>
            </modified>
            <status_change date="2007-04-10T15:16:47.568-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:52:17.491-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Solaris 7 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3045"/>
          <criterion comment="File fs.auto exists" negate="false" test_ref="oval:org.mitre.oval:tst:2873"/>
          <criterion comment="File xfs exists" negate="false" test_ref="oval:org.mitre.oval:tst:2872"/>
          <criterion comment="Patch 108117-06 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:2864"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="inetd.conf contains fs.auto" negate="false" test_ref="oval:org.mitre.oval:tst:2870"/>
          <criterion comment="inetd running" negate="false" test_ref="oval:org.mitre.oval:tst:3135"/>
          <criteria operator="OR" comment="File xfs executable">
            <criterion comment="File xfs executable" negate="false" test_ref="oval:org.mitre.oval:tst:2869"/>
            <criterion comment="File xfs executable" negate="false" test_ref="oval:org.mitre.oval:tst:2868"/>
            <criterion comment="File xfs executable" negate="false" test_ref="oval:org.mitre.oval:tst:2867"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:175" version="1" class="vulnerability">
      <metadata>
        <title>Solaris 8 CDE ToolTalk Database Server Symbolic Link Vulnerability</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <product>CDE</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-0678" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0678"/>
        <description>CDE ToolTalk database server (ttdbserver) allows local users to overwrite arbitrary files via a symlink attack on the transaction log file used by the _TT_TRANSACTION RPC procedure.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-01-29T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">David Proulx</contributor>
            </submitted>
            <modified comment="fixed the service_name entity used in the inetd_object" date="2007-04-10T15:17:00.627-04:00">
              <contributor organization="Opsware, Inc.">Todd Dolinsky</contributor>
            </modified>
            <status_change date="2007-04-10T15:17:27.752-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:52:18.807-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3145"/>
          <criterion comment="File rpc.ttdbserverd exists" negate="false" test_ref="oval:org.mitre.oval:tst:3105"/>
          <criterion comment="Patch 110286-09 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:3104"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="inetd.conf contains rpc.ttdbserverd" negate="false" test_ref="oval:org.mitre.oval:tst:3103"/>
          <criterion comment="inetd running" negate="false" test_ref="oval:org.mitre.oval:tst:3135"/>
          <criteria operator="OR" comment="File rpc.ttdbserverd executable">
            <criterion comment="File rpc.ttdbserverd executable" negate="false" test_ref="oval:org.mitre.oval:tst:3102"/>
            <criterion comment="File rpc.ttdbserverd executable" negate="false" test_ref="oval:org.mitre.oval:tst:3101"/>
            <criterion comment="File rpc.ttdbserverd executable" negate="false" test_ref="oval:org.mitre.oval:tst:3100"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1754" version="2" class="vulnerability">
      <metadata>
        <title>HP Security Update Fixes VirtualVault Apache HTTP Request Smuggling Vulnerability</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
          <product>LDAP</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-1689" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1689"/>
        <description>Unspecified vulnerability in su in HP HP-UX B.11.11, when using the LDAP netgroup feature, allows local users to gain unspecified access.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-04-06T06:39:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-04-12T05:16:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-05-03T10:06:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-05-31T09:45:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Added CVE reference. Implemented by Jon Baker of The MITRE Corporation." date="2007-03-19T21:15:00.392-04:00">
              <contributor organization="Opsware, Inc.">Todd Dolinsky</contributor>
            </modified>
            <status_change date="2007-03-19T21:23:35.434-04:00">INTERIM</status_change>
            <status_change date="2007-04-10T13:44:22.733-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.11">
          <criteria operator="AND" comment="700 Series OS Release 11.11">
            <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2515"/>
            <criterion comment="HP Release B.11.11" negate="false" test_ref="oval:org.mitre.oval:tst:2514"/>
          </criteria>
          <criteria operator="AND" comment="800 Series OS Release 11.11">
            <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2513"/>
            <criterion comment="HP Release B.11.11" negate="false" test_ref="oval:org.mitre.oval:tst:2514"/>
          </criteria>
        </criteria>
        <criterion comment="Patch PHCO_34545 or subsequent is installed" negate="true" test_ref="oval:org.mitre.oval:tst:737"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:177" version="1" class="vulnerability">
      <metadata>
        <title>Solaris 7 CDE ToolTalk Database Heap Corruption Vulnerability</title>
        <affected family="unix">
          <platform>Sun Solaris 7</platform>
          <product>CDE</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-0679" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0679"/>
        <description>Buffer overflow in Common Desktop Environment (CDE) ToolTalk RPC database server (rpc.ttdbserverd) allows remote attackers to execute arbitrary code via an argument to the _TT_CREATE_FILE procedure.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-01-29T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">David Proulx</contributor>
            </submitted>
            <modified comment="fixed the service_name entity used in the inetd_object" date="2007-04-10T15:17:00.627-04:00">
              <contributor organization="Opsware, Inc.">Todd Dolinsky</contributor>
            </modified>
            <status_change date="2007-04-10T15:17:28.951-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:52:19.005-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Solaris 7 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3045"/>
          <criterion comment="File rpc.ttdbserverd exists" negate="false" test_ref="oval:org.mitre.oval:tst:3105"/>
          <criterion comment="Patch 107893-20 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:2850"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="inetd.conf contains rpc.ttdbserverd" negate="false" test_ref="oval:org.mitre.oval:tst:3103"/>
          <criterion comment="inetd running" negate="false" test_ref="oval:org.mitre.oval:tst:3135"/>
          <criteria operator="OR" comment="File rpc.ttdbserverd executable">
            <criterion comment="File rpc.ttdbserverd executable" negate="false" test_ref="oval:org.mitre.oval:tst:3102"/>
            <criterion comment="File rpc.ttdbserverd executable" negate="false" test_ref="oval:org.mitre.oval:tst:3101"/>
            <criterion comment="File rpc.ttdbserverd executable" negate="false" test_ref="oval:org.mitre.oval:tst:3100"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:192" version="1" class="vulnerability">
      <metadata>
        <title>Solaris 8 CDE ToolTalk Database Heap Corruption Vulnerability</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <product>CDE</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-0679" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0679"/>
        <description>Buffer overflow in Common Desktop Environment (CDE) ToolTalk RPC database server (rpc.ttdbserverd) allows remote attackers to execute arbitrary code via an argument to the _TT_CREATE_FILE procedure.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-01-29T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">David Proulx</contributor>
            </submitted>
            <modified comment="fixed the service_name entity used in the inetd_object" date="2007-04-10T15:17:00.627-04:00">
              <contributor organization="Opsware, Inc.">Todd Dolinsky</contributor>
            </modified>
            <status_change date="2007-04-10T15:17:28.508-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:52:20.651-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3145"/>
          <criterion comment="File rpc.ttdbserverd exists" negate="false" test_ref="oval:org.mitre.oval:tst:3105"/>
          <criterion comment="Patch 110286-10 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:2827"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="inetd.conf contains rpc.ttdbserverd" negate="false" test_ref="oval:org.mitre.oval:tst:3103"/>
          <criterion comment="inetd running" negate="false" test_ref="oval:org.mitre.oval:tst:3135"/>
          <criteria operator="OR" comment="File rpc.ttdbserverd executable">
            <criterion comment="File rpc.ttdbserverd executable" negate="false" test_ref="oval:org.mitre.oval:tst:3102"/>
            <criterion comment="File rpc.ttdbserverd executable" negate="false" test_ref="oval:org.mitre.oval:tst:3101"/>
            <criterion comment="File rpc.ttdbserverd executable" negate="false" test_ref="oval:org.mitre.oval:tst:3100"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:195" version="1" class="vulnerability">
      <metadata>
        <title>Solaris 8 KCMS Arbitrary File Access Vulnerability</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <product>kcms_server</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0027" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0027"/>
        <description>Directory traversal vulnerability in Sun Kodak Color Management System (KCMS) library service daemon (kcms_server) allows remote attackers to read arbitrary files via the KCS_OPEN_PROFILE procedure.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-01-24T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">David Proulx</contributor>
            </submitted>
            <modified comment="fixed the service_name entity used in the inetd_object" date="2007-04-10T15:15:00.237-04:00">
              <contributor organization="Opsware, Inc.">Todd Dolinsky</contributor>
            </modified>
            <status_change date="2007-04-10T15:15:57.654-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:52:21.718-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3145"/>
          <criterion comment="File kcms_server exists" negate="false" test_ref="oval:org.mitre.oval:tst:2931"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="inetd.conf contains kcms_server" negate="false" test_ref="oval:org.mitre.oval:tst:2930"/>
          <criterion comment="inetd running" negate="false" test_ref="oval:org.mitre.oval:tst:3135"/>
          <criteria operator="OR" comment="File kcms_server executable and SUID or SGID">
            <criterion comment="File kcms_server executable and SUID or SGID" negate="false" test_ref="oval:org.mitre.oval:tst:2929"/>
            <criterion comment="File kcms_server executable and SUID or SGID" negate="false" test_ref="oval:org.mitre.oval:tst:2928"/>
            <criterion comment="File kcms_server executable and SUID or SGID" negate="false" test_ref="oval:org.mitre.oval:tst:2927"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1970" version="2" class="vulnerability">
      <metadata>
        <title>Off-by-one Error in fb_realpath()</title>
        <affected family="unix">
          <platform>Sun Solaris 9</platform>
          <product>Solaris Management Console (SMC)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0466" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0466"/>
        <description>Off-by-one error in the fb_realpath() function, as derived from the realpath function in BSD, may allow attackers to execute arbitrary code, as demonstrated in wu-ftpd 2.5.0 through 2.6.2 via commands that cause pathnames of length MAXPATHLEN+1 to trigger a buffer overflow, including (1) STOR, (2) RETR, (3) APPE, (4) DELE, (5) MKD, (6) RMD, (7) STOU, or (8) RNTO.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-04-13T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Brian Soby</contributor>
            </submitted>
            <status_change date="2005-04-20T12:13:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-05-11T05:41:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-06-01T03:30:00.000-04:00">ACCEPTED</status_change>
            <modified comment="fixed the service_name entity used in the inetd_object" date="2007-04-10T15:14:00.011-04:00">
              <contributor organization="Opsware, Inc.">Todd Dolinsky</contributor>
            </modified>
            <status_change date="2007-04-10T15:15:14.122-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:52:21.868-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Solaris 9 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3051"/>
          <criterion comment="FTP Server - Usr (SUNWftpu) installed" negate="false" test_ref="oval:org.mitre.oval:tst:661"/>
          <criterion comment="Patch 114564-02 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:660"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="inetd.conf contains in.ftpd" negate="false" test_ref="oval:org.mitre.oval:tst:659"/>
          <criterion comment="inetd running" negate="false" test_ref="oval:org.mitre.oval:tst:3135"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:2592" version="2" class="vulnerability">
      <metadata>
        <title>KCMS KCS_OPEN_PROFILE File Disclosure Vulnerability</title>
        <affected family="unix">
          <platform>Sun Solaris 7</platform>
          <product>kcms_server</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0027" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0027"/>
        <description>Directory traversal vulnerability in Sun Kodak Color Management System (KCMS) library service daemon (kcms_server) allows remote attackers to read arbitrary files via the KCS_OPEN_PROFILE procedure.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-01-19T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Brian Soby</contributor>
            </submitted>
            <status_change date="2005-01-24T03:40:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-02-16T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-03-09T07:56:00.000-04:00">ACCEPTED</status_change>
            <modified comment="fixed the service_name entity used in the inetd_object" date="2007-04-10T15:15:00.237-04:00">
              <contributor organization="Opsware, Inc.">Todd Dolinsky</contributor>
            </modified>
            <status_change date="2007-04-10T15:15:57.329-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:52:24.241-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criteria operator="OR" comment="Solaris 7,8,or 9 installed">
            <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3145"/>
            <criterion comment="Solaris 7 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3045"/>
            <criterion comment="Solaris 9 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3051"/>
          </criteria>
          <criterion comment="Kodak Color Managment Server (KCMS) Runtime Environment (SUNWkcsrt/SUNWkcsrx) installed" negate="false" test_ref="oval:org.mitre.oval:tst:505"/>
          <criterion comment="Patch 114636-01 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:504"/>
          <criterion comment="Patch 107337-03 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:503"/>
          <criterion comment="Patch 111400-02 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:502"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="inetd.conf contains kcms_server" negate="false" test_ref="oval:org.mitre.oval:tst:2930"/>
          <criterion comment="inetd running" negate="false" test_ref="oval:org.mitre.oval:tst:3135"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:2770" version="3" class="vulnerability">
      <metadata>
        <title>Solaris 9 CDE ToolTalk Database Server Symbolic Link Vulnerability</title>
        <affected family="unix">
          <platform>Sun Solaris 9</platform>
          <product>CDE</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-0678" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0678"/>
        <description>CDE ToolTalk database server (ttdbserver) allows local users to overwrite arbitrary files via a symlink attack on the transaction log file used by the _TT_TRANSACTION RPC procedure.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-10-15T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Brian Soby</contributor>
            </submitted>
            <status_change date="2004-10-20T12:00:00.000-04:00">DRAFT</status_change>
            <status_change date="2004-11-03T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-12-09T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-01-11T12:00:00.000-04:00" comment="modified sat-6 - Changed test to pattern match and added check for 64bit version">
              <contributor organization="The MITRE Corporation">Brian Soby</contributor>
            </modified>
            <modified date="2005-01-14T12:00:00.000-04:00" comment="modified sat-6 - Changed regular expression test to properly check for 64bit package">
              <contributor organization="The MITRE Corporation">Brian Soby</contributor>
            </modified>
            <status_change date="2005-01-24T02:39:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-02-16T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="fixed the service_name entity used in the inetd_object" date="2007-04-10T15:17:00.627-04:00">
              <contributor organization="Opsware, Inc.">Todd Dolinsky</contributor>
            </modified>
            <status_change date="2007-04-10T15:17:29.208-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:52:24.787-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Solaris 9 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3051"/>
          <criterion comment="Toolktalk (SUNWtltk/SUNWtltkx) installed" negate="false" test_ref="oval:org.mitre.oval:tst:1169"/>
          <criterion comment="Patch 112808-02 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:1168"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="inetd running" negate="false" test_ref="oval:org.mitre.oval:tst:3135"/>
          <criterion comment="inetd.conf contains rpc.ttdbserverd" negate="false" test_ref="oval:org.mitre.oval:tst:3103"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:2816" version="2" class="vulnerability">
      <metadata>
        <title>XFS Dispatch() Buffer Overflow</title>
        <affected family="unix">
          <platform>Sun Solaris 9</platform>
          <product>fs.auto, xfs</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-1317" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-1317"/>
        <description>Buffer overflow in Dispatch() routine for XFS font server (fs.auto) on Solaris 2.5.1 through 9 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a certain XFS query.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-01-19T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Brian Soby</contributor>
            </submitted>
            <status_change date="2005-01-24T03:40:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-02-16T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-03-09T07:56:00.000-04:00">ACCEPTED</status_change>
            <modified comment="fixed the service_name entity used in the inetd_object" date="2007-04-10T15:16:00.255-04:00">
              <contributor organization="Opsware, Inc.">Todd Dolinsky</contributor>
            </modified>
            <status_change date="2007-04-10T15:16:47.366-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:52:25.482-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Solaris 9 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3051"/>
          <criterion comment="X Window System Font Server (SUNWxwfs) installed" negate="false" test_ref="oval:org.mitre.oval:tst:478"/>
          <criterion comment="Patch 113923-02 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:477"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="inetd.conf contains fs.auto" negate="false" test_ref="oval:org.mitre.oval:tst:2870"/>
          <criterion comment="inetd running" negate="false" test_ref="oval:org.mitre.oval:tst:3135"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:31" version="2" class="vulnerability">
      <metadata>
        <title>Solaris 8/9 cachefsd Heap Overflow Vulnerability</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <product>cachefsd</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-0033" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0033"/>
        <description>Heap-based buffer overflow in cfsd_calloc function of Solaris cachefsd allows remote attackers to execute arbitrary code via a request with a long directory and cache name.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-01-31T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">David Proulx</contributor>
            </submitted>
            <modified date="2005-01-28T12:00:00.000-04:00" comment="Updated to include Solaris 9 and Solaris 9 patch info">
              <contributor organization="The MITRE Corporation">Brian Soby</contributor>
            </modified>
            <status_change date="2005-02-01T08:24:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-02-16T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="fixed the service_name entity used in the inetd_object" date="2007-04-10T15:17:00.350-04:00">
              <contributor organization="Opsware, Inc.">Todd Dolinsky</contributor>
            </modified>
            <status_change date="2007-04-10T15:17:46.309-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:52:26.771-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="File cachefsd exists" negate="false" test_ref="oval:org.mitre.oval:tst:3053"/>
          <criterion comment="Patch 110896-02 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:3052"/>
          <criteria operator="OR" comment="Solaris 8 or 9 installed">
            <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3145"/>
            <criterion comment="Solaris 9 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3051"/>
          </criteria>
          <criterion comment="Patch 114008-01 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:3050"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="inetd.conf contains cachefsd" negate="false" test_ref="oval:org.mitre.oval:tst:3049"/>
          <criterion comment="inetd running" negate="false" test_ref="oval:org.mitre.oval:tst:3135"/>
          <criteria operator="OR" comment="File cachefsd executable">
            <criterion comment="File cachefsd executable" negate="false" test_ref="oval:org.mitre.oval:tst:3048"/>
            <criterion comment="File cachefsd executable" negate="false" test_ref="oval:org.mitre.oval:tst:3047"/>
            <criterion comment="File cachefsd executable" negate="false" test_ref="oval:org.mitre.oval:tst:3046"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:41" version="1" class="vulnerability">
      <metadata>
        <title>Solaris 7 RWall Daemon Syslog Format String Vulnerability</title>
        <affected family="unix">
          <platform>Sun Solaris 7</platform>
          <product>rpc.rwalld</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-0573" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0573"/>
        <description>Format string vulnerability in RPC wall daemon (rpc.rwalld) for Solaris 2.5.1 through 8 allows remote attackers to execute arbitrary code via format strings in a message that is not properly provided to the syslog function when the wall command cannot be executed.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-01-30T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">David Proulx</contributor>
            </submitted>
            <modified comment="fixed the service_name entity used in the inetd_object" date="2007-04-10T15:16:00.472-04:00">
              <contributor organization="Opsware, Inc.">Todd Dolinsky</contributor>
            </modified>
            <status_change date="2007-04-10T15:17:04.573-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:52:29.060-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Solaris 7 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3045"/>
          <criterion comment="File rpc.rwalld exists" negate="false" test_ref="oval:org.mitre.oval:tst:3032"/>
          <criterion comment="Patch 112899-01 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:3031"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="inetd.conf contains rpc.rwalld" negate="false" test_ref="oval:org.mitre.oval:tst:3030"/>
          <criterion comment="inetd running" negate="false" test_ref="oval:org.mitre.oval:tst:3135"/>
          <criteria operator="OR" comment="File rpc.rwalld executable">
            <criterion comment="File rpc.rwalld executable" negate="false" test_ref="oval:org.mitre.oval:tst:3029"/>
            <criterion comment="File rpc.rwalld executable" negate="false" test_ref="oval:org.mitre.oval:tst:3028"/>
            <criterion comment="File rpc.rwalld executable" negate="false" test_ref="oval:org.mitre.oval:tst:3027"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:42" version="2" class="vulnerability">
      <metadata>
        <title>Solaris 7 RPC xdr_array Buffer Overflow</title>
        <affected family="unix">
          <platform>Sun Solaris 7</platform>
          <product>libnsl</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-0391" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0391"/>
        <description>Integer overflow in xdr_array function in RPC servers for operating systems that use libc, glibc, or other code based on SunRPC including dietlibc, allows remote attackers to execute arbitrary code by passing a large number of arguments to xdr_array through RPC services such as rpc.cmsd and dmispd.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-01-02T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">David Proulx</contributor>
            </submitted>
            <modified date="2006-07-03T12:56:00.000-04:00" comment="Added negate=true attribute to criteria sub-block to fix conversion error from OVAL 4.2 to OVAL 5.0">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2006-07-03T12:56:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-09-27T12:29:24.285-04:00">ACCEPTED</status_change>
            <modified comment="fixed the service_name entity used in the inetd_object" date="2007-04-10T15:14:00.967-04:00">
              <contributor organization="Opsware, Inc.">Todd Dolinsky</contributor>
            </modified>
            <status_change date="2007-04-10T15:14:45.338-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:52:29.513-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Solaris 7 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3045"/>
          <criteria operator="OR" comment="rpc.cmsd or dmispd exist">
            <criterion comment="File rpc.cmsd exists" negate="false" test_ref="oval:org.mitre.oval:tst:3140"/>
            <criterion comment="File dmispd exists" negate="false" test_ref="oval:org.mitre.oval:tst:3139"/>
          </criteria>
          <criteria operator="AND" comment="Patches 106942-22 and 108451-06" negate="true">
            <criterion comment="Patch 106942-22 or later installed" negate="false" test_ref="oval:org.mitre.oval:tst:3026"/>
            <criterion comment="Patch 108541-06 or later installed" negate="false" test_ref="oval:org.mitre.oval:tst:3025"/>
          </criteria>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="rpc.cmsd enabled OR dmispd running">
            <criteria operator="AND" comment="rpc.cmsd enabled">
              <criterion comment="inetd.conf contains rpc.cmsd" negate="false" test_ref="oval:org.mitre.oval:tst:3136"/>
              <criterion comment="inetd running" negate="false" test_ref="oval:org.mitre.oval:tst:3135"/>
              <criteria operator="OR" comment="File rpc.cmsd executable">
                <criterion comment="File rpc.cmsd executable" negate="false" test_ref="oval:org.mitre.oval:tst:3134"/>
                <criterion comment="File rpc.cmsd executable" negate="false" test_ref="oval:org.mitre.oval:tst:3133"/>
                <criterion comment="File rpc.cmsd executable" negate="false" test_ref="oval:org.mitre.oval:tst:3132"/>
              </criteria>
            </criteria>
            <criterion comment="dmispd running" negate="false" test_ref="oval:org.mitre.oval:tst:3131"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:43" version="2" class="vulnerability">
      <metadata>
        <title>Solaris 7 cachefsd Buffer Overrun Vulnerability</title>
        <affected family="unix">
          <platform>Sun Solaris 7</platform>
          <product>cachefsd</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-0084" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0084"/>
        <description>Buffer overflow in the fscache_setup function of cachefsd in Solaris 2.6, 7, and 8 allows local users to gain root privileges via a long mount argument.</description>
        <oval_repository>
          <dates>
            <submitted date="2002-10-17T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">David Proulx</contributor>
            </submitted>
            <modified date="2005-01-28T12:00:00.000-04:00" comment="Updated to add patch test">
              <contributor organization="The MITRE Corporation">Brian Soby</contributor>
            </modified>
            <status_change date="2005-02-01T08:25:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-02-16T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="fixed the service_name entity used in the inetd_object" date="2007-04-10T15:17:00.350-04:00">
              <contributor organization="Opsware, Inc.">Todd Dolinsky</contributor>
            </modified>
            <status_change date="2007-04-10T15:17:45.882-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:52:30.070-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Solaris 7 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3045"/>
          <criterion comment="File cachefsd exists" negate="false" test_ref="oval:org.mitre.oval:tst:3053"/>
          <criterion comment="Patch 108800-02 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:3024"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="inetd.conf contains cachefsd" negate="false" test_ref="oval:org.mitre.oval:tst:3049"/>
          <criterion comment="inetd running" negate="false" test_ref="oval:org.mitre.oval:tst:3135"/>
          <criteria operator="OR" comment="File cachefsd executable">
            <criterion comment="File cachefsd executable" negate="false" test_ref="oval:org.mitre.oval:tst:3048"/>
            <criterion comment="File cachefsd executable" negate="false" test_ref="oval:org.mitre.oval:tst:3047"/>
            <criterion comment="File cachefsd executable" negate="false" test_ref="oval:org.mitre.oval:tst:3046"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:4329" version="2" class="vulnerability">
      <metadata>
        <title>cachefsd DoS via Invalid RPC Request</title>
        <affected family="unix">
          <platform>Sun Solaris 7</platform>
          <platform>Sun Solaris 8</platform>
          <platform>Sun Solaris 9</platform>
          <product>cachefsd</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-0085" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0085"/>
        <description>cachefsd in Solaris 2.6, 7, and 8 allows remote attackers to cause a denial of service (crash) via an invalid procedure call in an RPC request.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-02-01T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Brian Soby</contributor>
       