<?xml version="1.0" encoding="UTF-8"?>
<oval_definitions xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-definitions-5 oval-definitions-schema.xsd http://oval.mitre.org/XMLSchema/oval-definitions-5#linux linux-definitions-schema.xsd http://oval.mitre.org/XMLSchema/oval-definitions-5#windows windows-definitions-schema.xsd http://oval.mitre.org/XMLSchema/oval-definitions-5#independent independent-definitions-schema.xsd http://oval.mitre.org/XMLSchema/oval-common-5 oval-common-schema.xsd http://oval.mitre.org/XMLSchema/oval-definitions-5#unix unix-definitions-schema.xsd" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:oval="http://oval.mitre.org/XMLSchema/oval-common-5" xmlns:oval-def="http://oval.mitre.org/XMLSchema/oval-definitions-5">
  <generator>
    <oval:product_name>The OVAL Repository</oval:product_name>
    <oval:schema_version>5.9</oval:schema_version>
    <oval:timestamp>2012-01-27T05:03:23.535-05:00</oval:timestamp>
  </generator>
  <definitions>
    <definition version="1" id="oval:org.mitre.oval:def:8413" class="patch">
      <metadata>
        <title>DSA-1802 squirrelmail -- several vulnerabilities</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <platform>Debian GNU/Linux 4.0</platform>
          <product>squirrelmail</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2009/dsa-1802" ref_id="DSA-1802"/>
        <description>Several remote vulnerabilities have been discovered in SquirrelMail, a webmail application. The Common Vulnerabilities and Exposures project identifies the following problems: Cross site scripting was possible through a number of pages which allowed an attacker to steal sensitive session data. Code injection was possible when SquirrelMail was configured to use the map_yp_alias function to authenticate users. This is not the default. It was possible to hijack an active user session by planting a specially crafted cookie into the user's browser. Specially crafted HTML emails could use the CSS positioning feature to place email content over the SquirrelMail user interface, allowing for phishing.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:13-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T08:00:44.925-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:05:33.775-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:04:16.520-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Platform section" operator="OR">
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Architecture independent section" operator="AND">
              <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criterion comment="squirrelmail is earlier than 1.4.15-4+lenny2" test_ref="oval:org.mitre.oval:tst:20530"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 4.0 is installed" definition_ref="oval:org.mitre.oval:def:6461"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Architecture independent section" operator="AND">
              <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criterion comment="squirrelmail is earlier than 1.4.9a-5" test_ref="oval:org.mitre.oval:tst:20305"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:8408" class="patch">
      <metadata>
        <title>DSA-1762 icu -- insufficient input sanitising</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <platform>Debian GNU/Linux 4.0</platform>
          <product>icu</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2009/dsa-1762" ref_id="DSA-1762"/>
        <description>It was discovered that icu, the internal components for Unicode, did not properly sanitise invalid encoded data, which could lead to crosssite scripting attacks.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:13-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T08:00:38.275-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:05:33.307-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:04:16.001-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Platform section" operator="OR">
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Architecture independent section" operator="AND">
              <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criterion comment="icu-doc is earlier than 3.8.1-3+lenny1" test_ref="oval:org.mitre.oval:tst:20386"/>
            </criteria>
            <criteria comment="Architecture dependent section" operator="AND">
              <criteria comment="Supported architectures section" operator="OR">
                <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
                <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
                <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
                <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
                <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
                <criterion comment="Installed architecture is armel" test_ref="oval:org.mitre.oval:tst:11101"/>
                <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
                <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
                <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
                <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
                <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
                <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
              </criteria>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="libicu38 DPKG is earlier than 3.8.1-3+lenny1" test_ref="oval:org.mitre.oval:tst:19463"/>
                <criterion comment="libicu38-dbg DPKG is earlier than 3.8.1-3+lenny1" test_ref="oval:org.mitre.oval:tst:20268"/>
                <criterion comment="libicu-dev DPKG is earlier than 3.8.1-3+lenny1" test_ref="oval:org.mitre.oval:tst:20455"/>
              </criteria>
            </criteria>
            <criteria comment="Architecture dependent section" operator="AND">
              <criteria comment="Supported architectures section" operator="OR">
                <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
              </criteria>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="lib32icu38 DPKG is earlier than 3.8.1-3+lenny1" test_ref="oval:org.mitre.oval:tst:20426"/>
                <criterion comment="lib32icu-dev DPKG is earlier than 3.8.1-3+lenny1" test_ref="oval:org.mitre.oval:tst:20422"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 4.0 is installed" definition_ref="oval:org.mitre.oval:def:6461"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Architecture independent section" operator="AND">
              <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criterion comment="icu-doc is earlier than 3.6-2etch2" test_ref="oval:org.mitre.oval:tst:20067"/>
            </criteria>
            <criteria comment="Architecture dependent section" operator="AND">
              <criteria comment="Supported architectures section" operator="OR">
                <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
                <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
                <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
                <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
                <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
                <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
                <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
                <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
                <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
                <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
              </criteria>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="libicu36-dev DPKG is earlier than 3.6-2etch2" test_ref="oval:org.mitre.oval:tst:20050"/>
                <criterion comment="libicu36 DPKG is earlier than 3.6-2etch2" test_ref="oval:org.mitre.oval:tst:19727"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:8391" class="patch">
      <metadata>
        <title>DSA-1748 libsoup -- integer overflow</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 4.0</platform>
          <product>libsoup</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2009/dsa-1748" ref_id="DSA-1748"/>
        <description>It was discovered that libsoup, an HTTP library implementation in C, handles large strings insecurely via its Base64 encoding functions. This could possibly lead to the execution of arbitrary code.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:12-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T07:59:48.446-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:05:32.919-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:04:15.631-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Release section" operator="AND">
        <extend_definition comment="Debian 4.0 is installed" definition_ref="oval:org.mitre.oval:def:6461"/>
        <criteria comment="Architecture section" operator="OR">
          <criteria comment="Architecture independent section" operator="AND">
            <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
            <criterion comment="libsoup2.2-doc is earlier than 2.2.98-2+etch1" test_ref="oval:org.mitre.oval:tst:19748"/>
          </criteria>
          <criteria comment="Architecture dependent section" operator="AND">
            <criteria comment="Supported architectures section" operator="OR">
              <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
              <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
              <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
              <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
              <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
              <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
              <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
              <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
              <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
              <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
            </criteria>
            <criteria comment="Packages section" operator="OR">
              <criterion comment="libsoup2.2-8 DPKG is earlier than 2.2.98-2+etch1" test_ref="oval:org.mitre.oval:tst:19770"/>
              <criterion comment="libsoup2.2-dev DPKG is earlier than 2.2.98-2+etch1" test_ref="oval:org.mitre.oval:tst:19668"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:8390" class="patch">
      <metadata>
        <title>DSA-1892 dovecot -- buffer overflow</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <platform>Debian GNU/Linux 4.0</platform>
          <product>dovecot</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2009/dsa-1892" ref_id="DSA-1892"/>
        <description>It was discovered that the SIEVE component of dovecot, a mail server that supports mbox and maildir mailboxes, is vulnerable to a buffer overflow when processing SIEVE scripts. This can be used to elevate privileges to the dovecot system user. An attacker who is able to install SIEVE scripts executed by the server is therefore able to read and modify arbitrary email messages on the system.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:12-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T08:00:21.275-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:05:32.484-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:04:15.188-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Platform section" operator="OR">
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Architecture dependent section" operator="AND">
              <criteria comment="Supported architectures section" operator="OR">
                <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
                <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
                <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
                <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
                <criterion comment="Installed architecture is armel" test_ref="oval:org.mitre.oval:tst:11101"/>
                <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
                <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
                <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
                <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
                <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
                <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
              </criteria>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="dovecot-pop3d DPKG is earlier than 1.0.15-2.3+lenny1" test_ref="oval:org.mitre.oval:tst:20162"/>
                <criterion comment="dovecot-common DPKG is earlier than 1.0.15-2.3+lenny1" test_ref="oval:org.mitre.oval:tst:19778"/>
                <criterion comment="dovecot-imapd DPKG is earlier than 1.0.15-2.3+lenny1" test_ref="oval:org.mitre.oval:tst:20133"/>
                <criterion comment="dovecot-dev DPKG is earlier than 1.0.15-2.3+lenny1" test_ref="oval:org.mitre.oval:tst:20214"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 4.0 is installed" definition_ref="oval:org.mitre.oval:def:6461"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Architecture dependent section" operator="AND">
              <criteria comment="Supported architectures section" operator="OR">
                <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
                <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
                <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
                <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
                <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
                <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
                <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
                <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
                <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
              </criteria>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="dovecot-pop3d DPKG is earlier than 1.0.rc15-2etch5" test_ref="oval:org.mitre.oval:tst:20136"/>
                <criterion comment="dovecot-common DPKG is earlier than 1.0.rc15-2etch5" test_ref="oval:org.mitre.oval:tst:19805"/>
                <criterion comment="dovecot-imapd DPKG is earlier than 1.0.rc15-2etch5" test_ref="oval:org.mitre.oval:tst:20210"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:8385" class="patch">
      <metadata>
        <title>DSA-1734 opensc -- programming error</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <product>opensc</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2009/dsa-1734" ref_id="DSA-1734"/>
        <description>b.badrignans discovered that OpenSC, a set of smart card utilities, could store private data on a smart card without proper access restrictions. Only blank cards initialised with OpenSC are affected by this problem. This update only improves creating new private data objects, but cards already initialised with such private data objects need to be modified to repair the access control conditions on such cards. Instructions for a variety of situations can be found at the OpenSC web site: http://www.opensc-project.org/security.html  The oldstable distribution (etch) is not affected by this problem.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:11-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T07:59:32.813-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:05:32.248-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:04:14.910-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Release section" operator="AND">
        <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
        <criteria comment="Architecture section" operator="OR">
          <criteria comment="Packages section" operator="OR">
            <criterion comment="libopensc2 DPKG is earlier than 0.11.4-5+lenny1" test_ref="oval:org.mitre.oval:tst:19122"/>
            <criterion comment="libopensc2-dev DPKG is earlier than 0.11.4-5+lenny1" test_ref="oval:org.mitre.oval:tst:19505"/>
            <criterion comment="opensc DPKG is earlier than 0.11.4-5+lenny1" test_ref="oval:org.mitre.oval:tst:19501"/>
            <criterion comment="mozilla-opensc DPKG is earlier than 0.11.4-5+lenny1" test_ref="oval:org.mitre.oval:tst:18934"/>
            <criterion comment="libopensc2-dbg DPKG is earlier than 0.11.4-5+lenny1" test_ref="oval:org.mitre.oval:tst:19635"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:8381" class="patch">
      <metadata>
        <title>DSA-1749 linux-2.6 -- denial of service/privilege escalation/sensitive memory leak</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <product>linux-2.6</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2009/dsa-1749" ref_id="DSA-1749"/>
        <description>Several vulnerabilities have been discovered in the Linux kernel that may lead to a denial of service or privilege escalation. The Common Vulnerabilities and Exposures project identifies the following problems: Christian Borntraeger discovered an issue effecting the alpha, mips, powerpc, s390 and sparc64 architectures that allows local users to cause a denial of service or potentially gain elevated privileges. Vegard Nossum discovered a memory leak in the keyctl subsystem that allows local users to cause a denial of service by consuming all of kernel memory. Wei Yongjun discovered a memory overflow in the SCTP implementation that can be triggered by remote users. Duane Griffin provided a fix for an issue in the eCryptfs subsystem which allows local users to cause a denial of service (fault or memory corruption). Pavel Roskin provided a fix for an issue in the dell_rbu driver that allows a local user to cause a denial of service (oops) by reading 0 bytes from a sysfs entry. Clement LECIGNE discovered a bug in the sock_getsockopt function that may result in leaking sensitive kernel memory. Roel Kluin discovered inverted logic in the skfddi driver that permits local, unprivileged users to reset the driver statistics. Peter Kerwien discovered an issue in the ext4 filesystem that allows local users to cause a denial of service (kernel oops) during a resize operation. Sami Liedes reported an issue in the ext4 filesystem that allows local users to cause a denial of service (kernel oops) when accessing a specially crafted corrupt filesystem. David Maciejak reported an issue in the ext4 filesystem that allows local users to cause a denial of service (kernel oops) when mounting a specially crafted corrupt filesystem. David Maciejak reported an additional issue in the ext4 filesystem that allows local users to cause a denial of service (kernel oops) when mounting a specially crafted corrupt filesystem.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:12-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T07:59:53.235-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:05:31.395-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:04:14.106-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Release section" operator="AND">
        <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
        <criteria comment="Architecture section" operator="OR">
          <criteria comment="Architecture independent section" operator="AND">
            <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
            <criteria comment="Packages section" operator="OR">
              <criterion comment="linux-patch-debian-2.6.26 is earlier than 2.6.26-13lenny2" test_ref="oval:org.mitre.oval:tst:19025"/>
              <criterion comment="linux-support-2.6.26-1 is earlier than 2.6.26-13lenny2" test_ref="oval:org.mitre.oval:tst:19910"/>
              <criterion comment="linux-doc-2.6.26 is earlier than 2.6.26-13lenny2" test_ref="oval:org.mitre.oval:tst:19400"/>
              <criterion comment="linux-tree-2.6.26 is earlier than 2.6.26-13lenny2" test_ref="oval:org.mitre.oval:tst:19875"/>
              <criterion comment="linux-source-2.6.26 is earlier than 2.6.26-13lenny2" test_ref="oval:org.mitre.oval:tst:19907"/>
              <criterion comment="linux-manual-2.6.26 is earlier than 2.6.26-13lenny2" test_ref="oval:org.mitre.oval:tst:19029"/>
            </criteria>
          </criteria>
          <criteria comment="Architecture dependent section" operator="AND">
            <criteria comment="Supported architectures section" operator="OR">
              <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
            </criteria>
            <criteria comment="Packages section" operator="OR">
              <criterion comment="linux-headers-2.6.26-1-all DPKG is earlier than 2.6.26-13lenny2" test_ref="oval:org.mitre.oval:tst:19865"/>
              <criterion comment="linux-image-2.6.26-1-vserver-s390x DPKG is earlier than 2.6.26-13lenny2" test_ref="oval:org.mitre.oval:tst:19422"/>
              <criterion comment="linux-headers-2.6.26-1-common DPKG is earlier than 2.6.26-13lenny2" test_ref="oval:org.mitre.oval:tst:19663"/>
              <criterion comment="linux-image-2.6.26-1-s390 DPKG is earlier than 2.6.26-13lenny2" test_ref="oval:org.mitre.oval:tst:19858"/>
              <criterion comment="linux-headers-2.6.26-1-all-s390 DPKG is earlier than 2.6.26-13lenny2" test_ref="oval:org.mitre.oval:tst:19704"/>
              <criterion comment="linux-headers-2.6.26-1-common-vserver DPKG is earlier than 2.6.26-13lenny2" test_ref="oval:org.mitre.oval:tst:19149"/>
              <criterion comment="linux-headers-2.6.26-1-vserver-s390x DPKG is earlier than 2.6.26-13lenny2" test_ref="oval:org.mitre.oval:tst:19872"/>
              <criterion comment="linux-headers-2.6.26-1-s390x DPKG is earlier than 2.6.26-13lenny2" test_ref="oval:org.mitre.oval:tst:19894"/>
              <criterion comment="linux-libc-dev DPKG is earlier than 2.6.26-13lenny2" test_ref="oval:org.mitre.oval:tst:19667"/>
              <criterion comment="linux-headers-2.6.26-1-s390 DPKG is earlier than 2.6.26-13lenny2" test_ref="oval:org.mitre.oval:tst:19827"/>
              <criterion comment="linux-image-2.6.26-1-s390-tape DPKG is earlier than 2.6.26-13lenny2" test_ref="oval:org.mitre.oval:tst:19688"/>
              <criterion comment="linux-image-2.6.26-1-s390x DPKG is earlier than 2.6.26-13lenny2" test_ref="oval:org.mitre.oval:tst:19851"/>
            </criteria>
          </criteria>
          <criteria comment="Architecture dependent section" operator="AND">
            <criteria comment="Supported architectures section" operator="OR">
              <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
            </criteria>
            <criteria comment="Packages section" operator="OR">
              <criterion comment="linux-headers-2.6.26-1-vserver-amd64 DPKG is earlier than 2.6.26-13lenny2" test_ref="oval:org.mitre.oval:tst:19916"/>
              <criterion comment="linux-headers-2.6.26-1-all DPKG is earlier than 2.6.26-13lenny2" test_ref="oval:org.mitre.oval:tst:19734"/>
              <criterion comment="linux-headers-2.6.26-1-all-amd64 DPKG is earlier than 2.6.26-13lenny2" test_ref="oval:org.mitre.oval:tst:19763"/>
              <criterion comment="linux-image-2.6.26-1-vserver-amd64 DPKG is earlier than 2.6.26-13lenny2" test_ref="oval:org.mitre.oval:tst:19861"/>
              <criterion comment="linux-headers-2.6.26-1-common DPKG is earlier than 2.6.26-13lenny2" test_ref="oval:org.mitre.oval:tst:18980"/>
              <criterion comment="linux-image-2.6.26-1-openvz-amd64 DPKG is earlier than 2.6.26-13lenny2" test_ref="oval:org.mitre.oval:tst:19936"/>
              <criterion comment="linux-headers-2.6.26-1-amd64 DPKG is earlier than 2.6.26-13lenny2" test_ref="oval:org.mitre.oval:tst:19911"/>
              <criterion comment="linux-headers-2.6.26-1-openvz-amd64 DPKG is earlier than 2.6.26-13lenny2" test_ref="oval:org.mitre.oval:tst:19745"/>
              <criterion comment="linux-modules-2.6.26-1-xen-amd64 DPKG is earlier than 2.6.26-13lenny2" test_ref="oval:org.mitre.oval:tst:19389"/>
              <criterion comment="linux-headers-2.6.26-1-common-vserver DPKG is earlier than 2.6.26-13lenny2" test_ref="oval:org.mitre.oval:tst:19442"/>
              <criterion comment="linux-headers-2.6.26-1-xen-amd64 DPKG is earlier than 2.6.26-13lenny2" test_ref="oval:org.mitre.oval:tst:19585"/>
              <criterion comment="linux-image-2.6.26-1-amd64 DPKG is earlier than 2.6.26-13lenny2" test_ref="oval:org.mitre.oval:tst:19809"/>
              <criterion comment="linux-headers-2.6.26-1-common-openvz DPKG is earlier than 2.6.26-13lenny2" test_ref="oval:org.mitre.oval:tst:19807"/>
              <criterion comment="linux-libc-dev DPKG is earlier than 2.6.26-13lenny2" test_ref="oval:org.mitre.oval:tst:19515"/>
              <criterion comment="linux-image-2.6.26-1-xen-amd64 DPKG is earlier than 2.6.26-13lenny2" test_ref="oval:org.mitre.oval:tst:19794"/>
              <criterion comment="linux-headers-2.6.26-1-common-xen DPKG is earlier than 2.6.26-13lenny2" test_ref="oval:org.mitre.oval:tst:19157"/>
              <criterion comment="xen-linux-system-2.6.26-1-xen-amd64 DPKG is earlier than 2.6.26-13lenny2" test_ref="oval:org.mitre.oval:tst:19882"/>
            </criteria>
          </criteria>
          <criteria comment="Architecture depended section" operator="AND">
            <criteria comment="Supported platform section" operator="AND">
              <criterion comment="hppa architecture" test_ref="oval:org.mitre.oval:tst:11164"/>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="linux-headers-2.6.26-1-parisc64 DPKG is earlier than 2.6.26-13lenny2" test_ref="oval:org.mitre.oval:tst:19857"/>
                <criterion comment="linux-headers-2.6.26-1-all-hppa DPKG is earlier than 2.6.26-13lenny2" test_ref="oval:org.mitre.oval:tst:19978"/>
                <criterion comment="linux-headers-2.6.26-1-common DPKG is earlier than 2.6.26-13lenny2" test_ref="oval:org.mitre.oval:tst:20086"/>
                <criterion comment="linux-image-2.6.26-1-parisc DPKG is earlier than 2.6.26-13lenny2" test_ref="oval:org.mitre.oval:tst:19707"/>
                <criterion comment="linux-headers-2.6.26-1-all DPKG is earlier than 2.6.26-13lenny2" test_ref="oval:org.mitre.oval:tst:19849"/>
                <criterion comment="linux-image-2.6.26-1-parisc64-smp DPKG is earlier than 2.6.26-13lenny2" test_ref="oval:org.mitre.oval:tst:19888"/>
                <criterion comment="linux-image-2.6.26-1-parisc64 DPKG is earlier than 2.6.26-13lenny2" test_ref="oval:org.mitre.oval:tst:19969"/>
                <criterion comment="linux-image-2.6.26-1-parisc-smp DPKG is earlier than 2.6.26-13lenny2" test_ref="oval:org.mitre.oval:tst:19931"/>
                <criterion comment="linux-libc-dev DPKG is earlier than 2.6.26-13lenny2" test_ref="oval:org.mitre.oval:tst:19886"/>
                <criterion comment="linux-headers-2.6.26-1-parisc DPKG is earlier than 2.6.26-13lenny2" test_ref="oval:org.mitre.oval:tst:20081"/>
                <criterion comment="linux-headers-2.6.26-1-parisc64-smp DPKG is earlier than 2.6.26-13lenny2" test_ref="oval:org.mitre.oval:tst:19964"/>
                <criterion comment="linux-headers-2.6.26-1-parisc-smp DPKG is earlier than 2.6.26-13lenny2" test_ref="oval:org.mitre.oval:tst:19760"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:8375" class="patch">
      <metadata>
        <title>DSA-1736 mahara -- insufficient input sanitising</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <product>mahara</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2009/dsa-1736" ref_id="DSA-1736"/>
        <description>It was discovered that mahara, an electronic portfolio, weblog, and resume builder, is prone to cross-site scripting attacks, which allows the injection of arbitrary Java or HTML code. The oldstable distribution (etch) does not contain mahara.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:11-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T07:59:37.394-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:05:31.178-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:04:13.210-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Release section" operator="AND">
        <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
        <criteria comment="Architecture section" operator="OR">
          <criteria comment="Architecture independent section" operator="AND">
            <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
            <criteria comment="Packages section" operator="OR">
              <criterion comment="mahara-apache2 is earlier than 1.0.4-4+lenny1" test_ref="oval:org.mitre.oval:tst:18975"/>
              <criterion comment="mahara is earlier than 1.0.4-4+lenny1" test_ref="oval:org.mitre.oval:tst:19440"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:8370" class="patch">
      <metadata>
        <title>DSA-1737 wesnoth -- several vulnerabilities</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <platform>Debian GNU/Linux 4.0</platform>
          <product>wesnoth</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2009/dsa-1737" ref_id="DSA-1737"/>
        <description>Several security issues have been discovered in wesnoth, a fantasy turn-based strategy game. The Common Vulnerabilities and Exposures project identifies the following problems: Daniel Franke discovered that the wesnoth server is prone to a denial of service attack when receiving special crafted compressed data. Daniel Franke discovered that the sandbox implementation for the python AIs can be used to execute arbitrary python code on wesnoth clients. In order to prevent this issue, the python support has been disabled. A compatibility patch was included, so that the affected campagne is still working properly.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:11-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T07:59:36.478-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:05:30.268-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:04:12.386-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Platform section" operator="OR">
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Architecture independent section" operator="AND">
              <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="wesnoth-sotbe is earlier than 1.4.4-2+lenny1" test_ref="oval:org.mitre.oval:tst:19644"/>
                <criterion comment="wesnoth-aoi is earlier than 1.4.4-2+lenny1" test_ref="oval:org.mitre.oval:tst:19599"/>
                <criterion comment="wesnoth-tsg is earlier than 1.4.4-2+lenny1" test_ref="oval:org.mitre.oval:tst:19642"/>
                <criterion comment="wesnoth-nr is earlier than 1.4.4-2+lenny1" test_ref="oval:org.mitre.oval:tst:19252"/>
                <criterion comment="wesnoth-l is earlier than 1.4.4-2+lenny1" test_ref="oval:org.mitre.oval:tst:19621"/>
                <criterion comment="wesnoth-music is earlier than 1.4.4-2+lenny1" test_ref="oval:org.mitre.oval:tst:19102"/>
                <criterion comment="wesnoth-thot is earlier than 1.4.4-2+lenny1" test_ref="oval:org.mitre.oval:tst:18684"/>
                <criterion comment="wesnoth-httt is earlier than 1.4.4-2+lenny1" test_ref="oval:org.mitre.oval:tst:19623"/>
                <criterion comment="wesnoth-tools is earlier than 1.4.4-2+lenny1" test_ref="oval:org.mitre.oval:tst:19254"/>
                <criterion comment="wesnoth-sof is earlier than 1.4.4-2+lenny1" test_ref="oval:org.mitre.oval:tst:19647"/>
                <criterion comment="wesnoth-data is earlier than 1.4.4-2+lenny1" test_ref="oval:org.mitre.oval:tst:19180"/>
                <criterion comment="wesnoth-ttb is earlier than 1.4.4-2+lenny1" test_ref="oval:org.mitre.oval:tst:18852"/>
                <criterion comment="wesnoth-trow is earlier than 1.4.4-2+lenny1" test_ref="oval:org.mitre.oval:tst:19580"/>
                <criterion comment="wesnoth-did is earlier than 1.4.4-2+lenny1" test_ref="oval:org.mitre.oval:tst:19593"/>
                <criterion comment="wesnoth-ei is earlier than 1.4.4-2+lenny1" test_ref="oval:org.mitre.oval:tst:18711"/>
                <criterion comment="wesnoth-utbs is earlier than 1.4.4-2+lenny1" test_ref="oval:org.mitre.oval:tst:19691"/>
                <criterion comment="wesnoth-all is earlier than 1.4.4-2+lenny1" test_ref="oval:org.mitre.oval:tst:19658"/>
              </criteria>
            </criteria>
            <criteria comment="Architecture dependent section" operator="AND">
              <criteria comment="Supported architectures section" operator="OR">
                <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
                <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
                <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
                <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
                <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
                <criterion comment="Installed architecture is armel" test_ref="oval:org.mitre.oval:tst:11101"/>
                <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
                <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
                <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
                <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
                <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
                <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
              </criteria>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="wesnoth-server DPKG is earlier than 1.4.4-2+lenny1" test_ref="oval:org.mitre.oval:tst:19684"/>
                <criterion comment="wesnoth DPKG is earlier than 1.4.4-2+lenny1" test_ref="oval:org.mitre.oval:tst:19693"/>
                <criterion comment="wesnoth-editor DPKG is earlier than 1.4.4-2+lenny1" test_ref="oval:org.mitre.oval:tst:19589"/>
                <criterion comment="wesnoth-dbg DPKG is earlier than 1.4.4-2+lenny1" test_ref="oval:org.mitre.oval:tst:19609"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 4.0 is installed" definition_ref="oval:org.mitre.oval:def:6461"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Architecture independent section" operator="AND">
              <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="wesnoth-data is earlier than 1.2-5" test_ref="oval:org.mitre.oval:tst:19639"/>
                <criterion comment="wesnoth-tsg is earlier than 1.2-5" test_ref="oval:org.mitre.oval:tst:18938"/>
                <criterion comment="wesnoth-music is earlier than 1.2-5" test_ref="oval:org.mitre.oval:tst:19552"/>
                <criterion comment="wesnoth-httt is earlier than 1.2-5" test_ref="oval:org.mitre.oval:tst:19496"/>
                <criterion comment="wesnoth-ttb is earlier than 1.2-5" test_ref="oval:org.mitre.oval:tst:18990"/>
                <criterion comment="wesnoth-trow is earlier than 1.2-5" test_ref="oval:org.mitre.oval:tst:19610"/>
                <criterion comment="wesnoth-ei is earlier than 1.2-5" test_ref="oval:org.mitre.oval:tst:19105"/>
                <criterion comment="wesnoth-utbs is earlier than 1.2-5" test_ref="oval:org.mitre.oval:tst:19280"/>
              </criteria>
            </criteria>
            <criteria comment="Architecture dependent section" operator="AND">
              <criteria comment="Supported architectures section" operator="OR">
                <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
                <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
                <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
                <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
                <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
                <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
                <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
                <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
                <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
                <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
              </criteria>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="wesnoth-server DPKG is earlier than 1.2-5" test_ref="oval:org.mitre.oval:tst:19262"/>
                <criterion comment="wesnoth DPKG is earlier than 1.2-5" test_ref="oval:org.mitre.oval:tst:19011"/>
                <criterion comment="wesnoth-editor DPKG is earlier than 1.2-5" test_ref="oval:org.mitre.oval:tst:19710"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:8369" class="patch">
      <metadata>
        <title>DSA-1898 openswan -- denial of service</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <platform>Debian GNU/Linux 4.0</platform>
          <product>openswan</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2009/dsa-1898" ref_id="DSA-1898"/>
        <description>It was discovered that the pluto daemon in openswan, an implementation of IPSEC and IKE, could crash when processing a crafted X.509 certificate.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:12-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T08:00:02.425-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:05:29.775-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:04:11.891-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Platform section" operator="OR">
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Architecture independent section" operator="AND">
              <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="linux-patch-openswan is earlier than 2.4.12+dfsg-1.3+lenny2" test_ref="oval:org.mitre.oval:tst:19959"/>
                <criterion comment="openswan-modules-source is earlier than 2.4.12+dfsg-1.3+lenny2" test_ref="oval:org.mitre.oval:tst:19789"/>
              </criteria>
            </criteria>
            <criteria comment="Architecture dependent section" operator="AND">
              <criteria comment="Supported architectures section" operator="OR">
                <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
                <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
                <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
                <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
                <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
                <criterion comment="Installed architecture is armel" test_ref="oval:org.mitre.oval:tst:11101"/>
                <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
                <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
                <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
                <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
                <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
                <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
              </criteria>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="openswan DPKG is earlier than 2.4.12+dfsg-1.3+lenny2" test_ref="oval:org.mitre.oval:tst:19979"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 4.0 is installed" definition_ref="oval:org.mitre.oval:def:6461"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Architecture independent section" operator="AND">
              <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="linux-patch-openswan is earlier than 2.4.6+dfsg.2-1.1+etch2" test_ref="oval:org.mitre.oval:tst:19963"/>
                <criterion comment="openswan-modules-source is earlier than 2.4.6+dfsg.2-1.1+etch2" test_ref="oval:org.mitre.oval:tst:19531"/>
              </criteria>
            </criteria>
            <criteria comment="Packages section" operator="OR">
              <criterion comment="openswan DPKG is earlier than 2.4.6+dfsg.2-1.1+etch2" test_ref="oval:org.mitre.oval:tst:19100"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:8365" class="patch">
      <metadata>
        <title>DSA-1895 xmltooling -- several vulnerabilities</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <product>xmltooling</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2009/dsa-1895" ref_id="DSA-1895"/>
        <description>Several vulnerabilities have been discovered in the xmltooling packages, as used by Shibboleth: Chris Ries discovered that decoding a crafted URL leads to a crash (and potentially, arbitrary code execution). Ian Young discovered that embedded NUL characters in certificate names were not correctly handled, exposing configurations using PKIX trust validation to impersonation attacks. Incorrect processing of SAML metadata ignores key usage constraints. This minor issue also needs a correction in the opensaml2 packages, which will be provided in an upcoming stable point release (and, before that, via stable-proposed-updates).</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:12-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T08:00:05.686-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:05:29.390-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:04:11.499-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Release section" operator="AND">
        <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
        <criteria comment="Architecture section" operator="OR">
          <criteria comment="Architecture independent section" operator="AND">
            <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
            <criteria comment="Packages section" operator="OR">
              <criterion comment="xmltooling-schemas is earlier than 1.0-2+lenny1" test_ref="oval:org.mitre.oval:tst:19568"/>
              <criterion comment="libxmltooling-doc is earlier than 1.0-2+lenny1" test_ref="oval:org.mitre.oval:tst:20173"/>
            </criteria>
          </criteria>
          <criteria comment="Architecture dependent section" operator="AND">
            <criteria comment="Supported architectures section" operator="OR">
              <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
              <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
              <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
              <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
              <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
              <criterion comment="Installed architecture is armel" test_ref="oval:org.mitre.oval:tst:11101"/>
              <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
              <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
              <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
              <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
              <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
              <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
            </criteria>
            <criteria comment="Packages section" operator="OR">
              <criterion comment="libxmltooling-dev DPKG is earlier than 1.0-2+lenny1" test_ref="oval:org.mitre.oval:tst:20154"/>
              <criterion comment="libxmltooling1 DPKG is earlier than 1.0-2+lenny1" test_ref="oval:org.mitre.oval:tst:19846"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:8363" class="patch">
      <metadata>
        <title>DSA-1598 libtk-img -- buffer overflow</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 4.0</platform>
          <product>libtk-img</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2008/dsa-1598" ref_id="DSA-1598"/>
        <description>It was discovered that a buffer overflow in the GIF image parsing code of Tk, a cross-platform graphical toolkit, could lead to denial of service and potentially the execution of arbitrary code.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:12-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T07:59:47.801-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:05:29.071-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:04:11.172-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Release section" operator="AND">
        <extend_definition comment="Debian 4.0 is installed" definition_ref="oval:org.mitre.oval:def:6461"/>
        <criteria comment="Architecture section" operator="OR">
          <criteria comment="Architecture dependent section" operator="AND">
            <criteria comment="Supported architectures section" operator="OR">
              <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
              <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
              <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
              <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
              <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
              <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
              <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
              <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
              <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
              <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
            </criteria>
            <criteria comment="Packages section" operator="OR">
              <criterion comment="libtk-img DPKG is earlier than 1.3-15etch2" test_ref="oval:org.mitre.oval:tst:18917"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:8362" class="patch">
      <metadata>
        <title>DSA-1743 libtk-img -- buffer overflows</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <platform>Debian GNU/Linux 4.0</platform>
          <product>libtk-img</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2009/dsa-1743" ref_id="DSA-1743"/>
        <description>Two buffer overflows have been found in the GIF image parsing code of Tk, a cross-platform graphical toolkit, which could lead to the execution of arbitrary code. The Common Vulnerabilities and Exposures project identifies the following problems: It was discovered that libtk-img is prone to a buffer overflow via specially crafted multi-frame interlaced GIF files. It was discovered that libtk-img is prone to a buffer overflow via specially crafted GIF files with certain subimage sizes.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:12-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T08:00:01.602-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:05:28.646-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:04:10.743-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Platform section" operator="OR">
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Architecture independent section" operator="AND">
              <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criterion comment="libtk-img-doc is earlier than 1.3-release-7+lenny1" test_ref="oval:org.mitre.oval:tst:19876"/>
            </criteria>
            <criteria comment="Packages section" operator="OR">
              <criterion comment="libtk-img DPKG is earlier than 1.3-release-7+lenny1" test_ref="oval:org.mitre.oval:tst:20000"/>
              <criterion comment="libtk-img-dev DPKG is earlier than 1.3-release-7+lenny1" test_ref="oval:org.mitre.oval:tst:19985"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 4.0 is installed" definition_ref="oval:org.mitre.oval:def:6461"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Architecture dependent section" operator="AND">
              <criteria comment="Supported architectures section" operator="OR">
                <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
                <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
                <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
                <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
                <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
                <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
                <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
                <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
                <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
                <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
              </criteria>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="libtk-img DPKG is earlier than 1.3-15etch3" test_ref="oval:org.mitre.oval:tst:19877"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:8361" class="patch">
      <metadata>
        <title>DSA-1593 tomcat5.5 -- missing input sanitising</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 4.0</platform>
          <product>tomcat5.5</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2008/dsa-1593" ref_id="DSA-1593"/>
        <description>It was discovered that the Host Manager web application performed insufficient input sanitising, which could lead to cross-site scripting.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:11-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T07:59:41.736-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:05:28.410-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:04:10.496-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Release section" operator="AND">
        <extend_definition comment="Debian 4.0 is installed" definition_ref="oval:org.mitre.oval:def:6461"/>
        <criteria comment="Architecture section" operator="OR">
          <criteria comment="Architecture independent section" operator="AND">
            <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
            <criteria comment="Packages section" operator="OR">
              <criterion comment="libtomcat5.5-java is earlier than 5.5.20-2etch3" test_ref="oval:org.mitre.oval:tst:19123"/>
              <criterion comment="tomcat5.5-admin is earlier than 5.5.20-2etch3" test_ref="oval:org.mitre.oval:tst:19679"/>
              <criterion comment="tomcat5.5-webapps is earlier than 5.5.20-2etch3" test_ref="oval:org.mitre.oval:tst:19358"/>
              <criterion comment="tomcat5.5 is earlier than 5.5.20-2etch3" test_ref="oval:org.mitre.oval:tst:19573"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:8347" class="patch">
      <metadata>
        <title>DSA-1688 courier-authlib -- SQL injection</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 4.0</platform>
          <product>courier-authlib</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2008/dsa-1688" ref_id="DSA-1688"/>
        <description>Two SQL injection vulnerabilities have been found in courier-authlib, the courier authentification library. The MySQL database interface used insufficient escaping mechanisms when constructing SQL statements, leading to SQL injection vulnerabilities if certain charsets are used (CVE-2008-2380). A similar issue affects the PostgreSQL database interface (CVE-2008-2667).</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:13-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T08:00:39.503-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:05:28.133-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:04:10.214-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Release section" operator="AND">
        <extend_definition comment="Debian 4.0 is installed" definition_ref="oval:org.mitre.oval:def:6461"/>
        <criteria comment="Architecture section" operator="OR">
          <criteria comment="Packages section" operator="OR">
            <criterion comment="courier-authlib-userdb DPKG is earlier than 0.58-4+etch2" test_ref="oval:org.mitre.oval:tst:20396"/>
            <criterion comment="courier-authdaemon DPKG is earlier than 0.58-4+etch2" test_ref="oval:org.mitre.oval:tst:20457"/>
            <criterion comment="courier-authlib-mysql DPKG is earlier than 0.58-4+etch2" test_ref="oval:org.mitre.oval:tst:19925"/>
            <criterion comment="courier-authlib-pipe DPKG is earlier than 0.58-4+etch2" test_ref="oval:org.mitre.oval:tst:20083"/>
            <criterion comment="courier-authlib-postgresql DPKG is earlier than 0.58-4+etch2" test_ref="oval:org.mitre.oval:tst:20297"/>
            <criterion comment="courier-authlib-ldap DPKG is earlier than 0.58-4+etch2" test_ref="oval:org.mitre.oval:tst:19675"/>
            <criterion comment="courier-authlib DPKG is earlier than 0.58-4+etch2" test_ref="oval:org.mitre.oval:tst:19476"/>
            <criterion comment="courier-authlib-dev DPKG is earlier than 0.58-4+etch2" test_ref="oval:org.mitre.oval:tst:20328"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:8336" class="patch">
      <metadata>
        <title>DSA-1445 maradns -- programming error</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 4.0</platform>
          <platform>Debian GNU/Linux 3.1</platform>
          <product>maradns</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2008/dsa-1445" ref_id="DSA-1445"/>
        <description>Michael Krieger and Sam Trenholme discovered a programming error in MaraDNS, a simple security-aware Domain Name Service server, which might lead to denial of service through malformed DNS packets. For the old stable distribution (sarge), this problem has been fixed in version 1.0.27-2. For the stable distribution (etch), this problem has been fixed in version 1.2.12.04-1etch2. For the unstable distribution (sid), this problem has been fixed in version 1.2.12.08-1. We recommend that you upgrade your maradns package.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:12-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T08:00:27.335-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:05:27.862-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:04:09.931-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Platform section" operator="OR">
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 4.0 is installed" definition_ref="oval:org.mitre.oval:def:6461"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Packages section" operator="OR">
              <criterion comment="maradns DPKG is earlier than 1.2.12.04-1etch2" test_ref="oval:org.mitre.oval:tst:19587"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 3.1 is installed" definition_ref="oval:org.mitre.oval:def:7692"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Packages section" operator="OR">
              <criterion comment="maradns DPKG is earlier than 1.0.27-2" test_ref="oval:org.mitre.oval:tst:20010"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:8333" class="patch">
      <metadata>
        <title>DSA-1807 cyrus-sasl2, cyrus-sasl2-heimdal -- buffer overflow</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <product>cyrus-sasl2</product>
          <product>cyrus-sasl2-heimdal</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2009/dsa-1807" ref_id="DSA-1807"/>
        <description>James Ralston discovered that the sasl_encode64() function of cyrus-sasl2, a free library implementing the Simple Authentication and Security Layer, suffers from a missing null termination in certain situations. This causes several buffer overflows in situations where cyrus-sasl2 itself requires the string to be null terminated which can lead to denial of service or arbitrary code execution. Important notice (Quoting from US-CERT): While this patch will fix currently vulnerable code, it can cause non-vulnerable existing code to break. Here's a function prototype from include/saslutil.h to clarify my explanation: Assume a scenario where calling code has been written in such a way that it calculates the exact size required for base64 encoding in advance, then allocates a buffer of that exact size, passing a pointer to the buffer into sasl_encode64() as *out. As long as this code does not anticipate that the buffer is NUL-terminated (does not call any string-handling functions like strlen(), for example) the code will work and it will not be vulnerable. Once this patch is applied, that same code will break because sasl_encode64() will begin to return SASL_BUFOVER.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:13-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T08:00:40.952-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:05:27.372-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:04:09.429-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Release section" operator="AND">
        <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
        <criteria comment="Architecture section" operator="OR">
          <criteria comment="Architecture independent section" operator="AND">
            <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
            <criterion comment="cyrus-sasl2-doc is earlier than 2.1.22.dfsg1-23+lenny1" test_ref="oval:org.mitre.oval:tst:20447"/>
          </criteria>
          <criteria comment="Architecture dependent section" operator="AND">
            <criteria comment="Supported architectures section" operator="OR">
              <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
              <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
              <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
              <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
              <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
              <criterion comment="Installed architecture is armel" test_ref="oval:org.mitre.oval:tst:11101"/>
              <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
              <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
              <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
              <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
              <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
              <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
            </criteria>
            <criteria comment="Packages section" operator="OR">
              <criterion comment="libsasl2-2 DPKG is earlier than 2.1.22.dfsg1-23+lenny1" test_ref="oval:org.mitre.oval:tst:20234"/>
              <criterion comment="libsasl2-modules-gssapi-heimdal DPKG is earlier than 2.1.22.dfsg1-23+lenny1" test_ref="oval:org.mitre.oval:tst:20148"/>
              <criterion comment="cyrus-sasl2-heimdal-dbg DPKG is earlier than 2.1.22.dfsg1-23+lenny1" test_ref="oval:org.mitre.oval:tst:20365"/>
              <criterion comment="sasl2-bin DPKG is earlier than 2.1.22.dfsg1-23+lenny1" test_ref="oval:org.mitre.oval:tst:20378"/>
              <criterion comment="cyrus-sasl2-dbg DPKG is earlier than 2.1.22.dfsg1-23+lenny1" test_ref="oval:org.mitre.oval:tst:19990"/>
              <criterion comment="libsasl2-modules-gssapi-mit DPKG is earlier than 2.1.22.dfsg1-23+lenny1" test_ref="oval:org.mitre.oval:tst:20409"/>
              <criterion comment="libsasl2-dev DPKG is earlier than 2.1.22.dfsg1-23+lenny1" test_ref="oval:org.mitre.oval:tst:20331"/>
              <criterion comment="libsasl2-modules-sql DPKG is earlier than 2.1.22.dfsg1-23+lenny1" test_ref="oval:org.mitre.oval:tst:19896"/>
              <criterion comment="libsasl2-modules DPKG is earlier than 2.1.22.dfsg1-23+lenny1" test_ref="oval:org.mitre.oval:tst:20458"/>
              <criterion comment="libsasl2-modules-ldap DPKG is earlier than 2.1.22.dfsg1-23+lenny1" test_ref="oval:org.mitre.oval:tst:20215"/>
              <criterion comment="libsasl2-modules-otp DPKG is earlier than 2.1.22.dfsg1-23+lenny1" test_ref="oval:org.mitre.oval:tst:20402"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:8331" class="patch">
      <metadata>
        <title>DSA-1590 samba -- buffer overflow</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 4.0</platform>
          <product>samba</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2008/dsa-1590" ref_id="DSA-1590"/>
        <description>Alin Rad Pop discovered that Samba contained a buffer overflow condition when processing certain responses received while acting as a client, leading to arbitrary code execution (CVE-2008-1105).</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:11-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T07:59:41.119-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:05:26.981-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:04:09.013-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Release section" operator="AND">
        <extend_definition comment="Debian 4.0 is installed" definition_ref="oval:org.mitre.oval:def:6461"/>
        <criteria comment="Architecture section" operator="OR">
          <criteria comment="Architecture independent section" operator="AND">
            <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
            <criteria comment="Packages section" operator="OR">
              <criterion comment="samba-doc is earlier than 3.0.24-6etch10" test_ref="oval:org.mitre.oval:tst:19516"/>
              <criterion comment="samba-doc-pdf is earlier than 3.0.24-6etch10" test_ref="oval:org.mitre.oval:tst:19650"/>
            </criteria>
          </criteria>
          <criteria comment="Packages section" operator="OR">
            <criterion comment="smbfs DPKG is earlier than 3.0.24-6etch10" test_ref="oval:org.mitre.oval:tst:19141"/>
            <criterion comment="samba DPKG is earlier than 3.0.24-6etch10" test_ref="oval:org.mitre.oval:tst:18768"/>
            <criterion comment="libsmbclient DPKG is earlier than 3.0.24-6etch10" test_ref="oval:org.mitre.oval:tst:19724"/>
            <criterion comment="smbclient DPKG is earlier than 3.0.24-6etch10" test_ref="oval:org.mitre.oval:tst:19744"/>
            <criterion comment="winbind DPKG is earlier than 3.0.24-6etch10" test_ref="oval:org.mitre.oval:tst:19411"/>
            <criterion comment="swat DPKG is earlier than 3.0.24-6etch10" test_ref="oval:org.mitre.oval:tst:19562"/>
            <criterion comment="libpam-smbpass DPKG is earlier than 3.0.24-6etch10" test_ref="oval:org.mitre.oval:tst:19399"/>
            <criterion comment="libsmbclient-dev DPKG is earlier than 3.0.24-6etch10" test_ref="oval:org.mitre.oval:tst:19712"/>
            <criterion comment="python-samba DPKG is earlier than 3.0.24-6etch10" test_ref="oval:org.mitre.oval:tst:19168"/>
            <criterion comment="samba-common DPKG is earlier than 3.0.24-6etch10" test_ref="oval:org.mitre.oval:tst:19388"/>
            <criterion comment="samba-dbg DPKG is earlier than 3.0.24-6etch10" test_ref="oval:org.mitre.oval:tst:19395"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:8328" class="patch">
      <metadata>
        <title>DSA-1805 pidgin -- several vulnerabilities</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <product>pidgin</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2009/dsa-1805" ref_id="DSA-1805"/>
        <description>Several vulnerabilities have been discovered in Pidgin, a graphical multi-protocol instant messaging client. The Common Vulnerabilities and Exposures project identifies the following problems: A buffer overflow in the Jabber file transfer code may lead to denial of service or the execution of arbitrary code. Memory corruption in an internal library may lead to denial of service. The patch provided for the security issue tracked as CVE-2008-2927 - integer overflows in the MSN protocol handler - was found to be incomplete. The old stable distribution (etch) is affected under the source package name gaim. However, due to build problems the updated packages couldn't be released along with the stable version. It will be released once the build problem is resolved.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:13-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T08:00:42.555-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:05:26.542-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:04:08.553-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Release section" operator="AND">
        <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
        <criteria comment="Architecture section" operator="OR">
          <criteria comment="Architecture independent section" operator="AND">
            <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
            <criteria comment="Packages section" operator="OR">
              <criterion comment="libpurple-dev is earlier than 2.4.3-4lenny2" test_ref="oval:org.mitre.oval:tst:20333"/>
              <criterion comment="finch-dev is earlier than 2.4.3-4lenny2" test_ref="oval:org.mitre.oval:tst:20175"/>
              <criterion comment="pidgin-dev is earlier than 2.4.3-4lenny2" test_ref="oval:org.mitre.oval:tst:20002"/>
              <criterion comment="libpurple-bin is earlier than 2.4.3-4lenny2" test_ref="oval:org.mitre.oval:tst:20245"/>
              <criterion comment="pidgin-data is earlier than 2.4.3-4lenny2" test_ref="oval:org.mitre.oval:tst:20394"/>
            </criteria>
          </criteria>
          <criteria comment="Architecture dependent section" operator="AND">
            <criteria comment="Supported architectures section" operator="OR">
              <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
              <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
              <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
              <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
              <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
              <criterion comment="Installed architecture is armel" test_ref="oval:org.mitre.oval:tst:11101"/>
              <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
              <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
              <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
              <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
              <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
              <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
            </criteria>
            <criteria comment="Packages section" operator="OR">
              <criterion comment="finch DPKG is earlier than 2.4.3-4lenny2" test_ref="oval:org.mitre.oval:tst:19558"/>
              <criterion comment="pidgin-dbg DPKG is earlier than 2.4.3-4lenny2" test_ref="oval:org.mitre.oval:tst:20510"/>
              <criterion comment="pidgin DPKG is earlier than 2.4.3-4lenny2" test_ref="oval:org.mitre.oval:tst:19582"/>
              <criterion comment="libpurple0 DPKG is earlier than 2.4.3-4lenny2" test_ref="oval:org.mitre.oval:tst:19613"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:8321" class="patch">
      <metadata>
        <title>DSA-1731 ndiswrapper -- buffer overflow</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 4.0</platform>
          <product>ndiswrapper</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2009/dsa-1731" ref_id="DSA-1731"/>
        <description>Anders Kaseorg discovered that ndiswrapper suffers from buffer overflows via specially crafted wireless network traffic, due to incorrectly handling long ESSIDs. This could lead to the execution of arbitrary code.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:11-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T07:59:28.447-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:05:26.294-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:04:08.265-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Release section" operator="AND">
        <extend_definition comment="Debian 4.0 is installed" definition_ref="oval:org.mitre.oval:def:6461"/>
        <criteria comment="Architecture section" operator="OR">
          <criteria comment="Architecture independent section" operator="AND">
            <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
            <criteria comment="Packages section" operator="OR">
              <criterion comment="ndiswrapper-source is earlier than 1.28-1+etch1" test_ref="oval:org.mitre.oval:tst:19350"/>
              <criterion comment="ndiswrapper-common is earlier than 1.28-1+etch1" test_ref="oval:org.mitre.oval:tst:19601"/>
            </criteria>
          </criteria>
          <criteria comment="Architecture dependent section" operator="AND">
            <criteria comment="Supported architectures section" operator="OR">
              <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
              <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
            </criteria>
            <criteria comment="Packages section" operator="OR">
              <criterion comment="ndiswrapper-utils-1.9 DPKG is earlier than 1.28-1+etch1" test_ref="oval:org.mitre.oval:tst:19457"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:8316" class="patch">
      <metadata>
        <title>DSA-1676 flamethrower (0.1.8-1+etch1) -- insecure temp file generation</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 4.0</platform>
          <product>flamethrower (0.1.8-1+etch1)</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2008/dsa-1676" ref_id="DSA-1676"/>
        <description>Dmitry E. Oboukhov discovered that flamethrower creates predictable temporary filenames, which may lead to a local denial of service through a symlink attack.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:10-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T07:58:31.775-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:05:26.096-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:04:07.901-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Release section" operator="AND">
        <extend_definition comment="Debian 4.0 is installed" definition_ref="oval:org.mitre.oval:def:6461"/>
        <criteria comment="Architecture section" operator="OR">
          <criteria comment="Architecture independent section" operator="AND">
            <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
            <criterion comment="flamethrower is earlier than 0.1.8-1+etch1" test_ref="oval:org.mitre.oval:tst:18406"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:8315" class="patch">
      <metadata>
        <title>DSA-1735 znc -- missing input sanitization</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 4.0</platform>
          <product>znc</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2009/dsa-1735" ref_id="DSA-1735"/>
        <description>It was discovered that znc, an IRC proxy/bouncer, does not properly sanitize input contained in configuration change requests to the webadmin interface. This allows authenticated users to elevate their privileges and indirectly execute arbitrary commands (CVE-2009-0759).</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:11-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T07:59:32.248-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:05:25.843-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:04:07.706-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Release section" operator="AND">
        <extend_definition comment="Debian 4.0 is installed" definition_ref="oval:org.mitre.oval:def:6461"/>
        <criteria comment="Architecture section" operator="OR">
          <criteria comment="Packages section" operator="OR">
            <criterion comment="znc DPKG is earlier than 0.058-2+lenny1" test_ref="oval:org.mitre.oval:tst:19268"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:8313" class="patch">
      <metadata>
        <title>DSA-1595 xorg-server -- several vulnerabilities</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 4.0</platform>
          <product>xorg-server</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2008/dsa-1595" ref_id="DSA-1595"/>
        <description>Several local vulnerabilities have been discovered in the X Window system. The Common Vulnerabilities and Exposures project identifies the following problems: Lack of validation of the parameters of the SProcSecurityGenerateAuthorization and SProcRecordCreateContext functions makes it possible for a specially crafted request to trigger the swapping of bytes outside the parameter of these requests, causing memory corruption. An integer overflow in the validation of the parameters of the ShmPutImage() request makes it possible to trigger the copy of arbitrary server memory to a pixmap that can subsequently be read by the client, to read arbitrary parts of the X server memory space. An integer overflow may occur in the computation of the size of the glyph to be allocated by the AllocateGlyph() function which will cause less memory to be allocated than expected, leading to later heap overflow. An integer overflow may occur in the computation of the size of the glyph to be allocated by the ProcRenderCreateCursor() function which will cause less memory to be allocated than expected, leading later to dereferencing un-mapped memory, causing a crash of the X server. Integer overflows can also occur in the code validating the parameters for the SProcRenderCreateLinearGradient, SProcRenderCreateRadialGradient and SProcRenderCreateConicalGradient functions, leading to memory corruption by swapping bytes outside of the intended request parameters.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:11-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T07:59:38.175-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:05:25.586-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:04:07.430-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Release section" operator="AND">
        <extend_definition comment="Debian 4.0 is installed" definition_ref="oval:org.mitre.oval:def:6461"/>
        <criteria comment="Architecture section" operator="OR">
          <criteria comment="Packages section" operator="OR">
            <criterion comment="xserver-xorg-core DPKG is earlier than 1.1.1-21etch5" test_ref="oval:org.mitre.oval:tst:19560"/>
            <criterion comment="xdmx DPKG is earlier than 1.1.1-21etch5" test_ref="oval:org.mitre.oval:tst:19394"/>
            <criterion comment="xserver-xorg-dev DPKG is earlier than 1.1.1-21etch5" test_ref="oval:org.mitre.oval:tst:19641"/>
            <criterion comment="xvfb DPKG is earlier than 1.1.1-21etch5" test_ref="oval:org.mitre.oval:tst:19616"/>
            <criterion comment="xnest DPKG is earlier than 1.1.1-21etch5" test_ref="oval:org.mitre.oval:tst:19536"/>
            <criterion comment="xserver-xephyr DPKG is earlier than 1.1.1-21etch5" test_ref="oval:org.mitre.oval:tst:19660"/>
            <criterion comment="xdmx-tools DPKG is earlier than 1.1.1-21etch5" test_ref="oval:org.mitre.oval:tst:19578"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:8312" class="patch">
      <metadata>
        <title>DSA-1568 b2evolution -- insufficient input sanitising</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 4.0</platform>
          <product>b2evolution</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2008/dsa-1568" ref_id="DSA-1568"/>
        <description>"unsticky" discovered that b2evolution, a blog engine, performs insufficient input sanitising, allowing for cross site scripting.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:12-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T08:00:25.708-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:05:25.381-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:04:07.221-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Release section" operator="AND">
        <extend_definition comment="Debian 4.0 is installed" definition_ref="oval:org.mitre.oval:def:6461"/>
        <criteria comment="Architecture section" operator="OR">
          <criteria comment="Architecture independent section" operator="AND">
            <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
            <criterion comment="b2evolution is earlier than 0.9.2-3+etch1" test_ref="oval:org.mitre.oval:tst:20107"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:8309" class="patch">
      <metadata>
        <title>DSA-1672 imlib2 -- buffer overflow</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 4.0</platform>
          <product>imlib2</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2008/dsa-1672" ref_id="DSA-1672"/>
        <description>Julien Danjou and Peter De Wachter discovered that a buffer overflow in the XPM loader of Imlib2, a powerful image loading and rendering library, might lead to arbitrary code execution.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:10-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T07:58:34.821-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:05:25.050-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:04:06.608-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Release section" operator="AND">
        <extend_definition comment="Debian 4.0 is installed" definition_ref="oval:org.mitre.oval:def:6461"/>
        <criteria comment="Architecture section" operator="OR">
          <criteria comment="Architecture dependent section" operator="AND">
            <criteria comment="Supported architectures section" operator="OR">
              <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
              <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
              <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
              <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
              <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
              <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
              <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
              <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
              <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
              <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
            </criteria>
            <criteria comment="Packages section" operator="OR">
              <criterion comment="libimlib2-dev DPKG is earlier than 1.3.0.0debian1-4+etch2" test_ref="oval:org.mitre.oval:tst:18947"/>
              <criterion comment="libimlib2 DPKG is earlier than 1.3.0.0debian1-4+etch2" test_ref="oval:org.mitre.oval:tst:18328"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:8307" class="patch">
      <metadata>
        <title>DSA-1446 wireshark -- several vulnerabilities</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 4.0</platform>
          <platform>Debian GNU/Linux 3.1</platform>
          <product>wireshark</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2008/dsa-1446" ref_id="DSA-1446"/>
        <description>Several remote vulnerabilities have been discovered in the Wireshark network traffic analyzer, which may lead to denial of service. The Common Vulnerabilities and Exposures project identifies the following problems: The RPL dissector could be tricked into an infinite loop. The CIP dissector could be tricked into excessive memory allocation. For the old stable distribution (sarge), these problems have been fixed in version 0.10.10-2sarge11. (In Sarge Wireshark used to be called Ethereal). For the stable distribution (etch), these problems have been fixed in version 0.99.4-5.etch.2. For the unstable distribution (sid), these problems have been fixed in version 0.99.7-1. We recommend that you upgrade your wireshark packages.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:12-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T08:00:26.802-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:05:24.635-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:04:06.240-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Platform section" operator="OR">
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 4.0 is installed" definition_ref="oval:org.mitre.oval:def:6461"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Packages section" operator="OR">
              <criterion comment="wireshark-dev DPKG is earlier than 0.99.4-5.etch.2" test_ref="oval:org.mitre.oval:tst:20207"/>
              <criterion comment="tshark DPKG is earlier than 0.99.4-5.etch.2" test_ref="oval:org.mitre.oval:tst:20121"/>
              <criterion comment="ethereal-dev DPKG is earlier than 0.99.4-5.etch.2" test_ref="oval:org.mitre.oval:tst:19937"/>
              <criterion comment="tethereal DPKG is earlier than 0.99.4-5.etch.2" test_ref="oval:org.mitre.oval:tst:20018"/>
              <criterion comment="wireshark-common DPKG is earlier than 0.99.4-5.etch.2" test_ref="oval:org.mitre.oval:tst:19920"/>
              <criterion comment="ethereal DPKG is earlier than 0.99.4-5.etch.2" test_ref="oval:org.mitre.oval:tst:19791"/>
              <criterion comment="ethereal-common DPKG is earlier than 0.99.4-5.etch.2" test_ref="oval:org.mitre.oval:tst:20003"/>
              <criterion comment="wireshark DPKG is earlier than 0.99.4-5.etch.2" test_ref="oval:org.mitre.oval:tst:20271"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 3.1 is installed" definition_ref="oval:org.mitre.oval:def:7692"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Packages section" operator="OR">
              <criterion comment="ethereal-dev DPKG is earlier than 0.10.10-2sarge11" test_ref="oval:org.mitre.oval:tst:19590"/>
              <criterion comment="ethereal-common DPKG is earlier than 0.10.10-2sarge11" test_ref="oval:org.mitre.oval:tst:20190"/>
              <criterion comment="tethereal DPKG is earlier than 0.10.10-2sarge11" test_ref="oval:org.mitre.oval:tst:20147"/>
              <criterion comment="ethereal DPKG is earlier than 0.10.10-2sarge11" test_ref="oval:org.mitre.oval:tst:20130"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:8306" class="patch">
      <metadata>
        <title>DSA-1850 libmodplug -- several vulnerabilities</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <platform>Debian GNU/Linux 4.0</platform>
          <product>libmodplug</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2009/dsa-1850" ref_id="DSA-1850"/>
        <description>Several vulnerabilities have been discovered in libmodplug, the shared libraries for mod music based on ModPlug. The Common Vulnerabilities and Exposures project identifies the following problems: It was discovered that libmodplug is prone to an integer overflow when processing a MED file with a crafted song comment or song name. It was discovered that libmodplug is prone to a buffer overflow in the PATinst function, when processing a long instrument name.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:10-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T07:58:48.501-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:05:24.245-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:04:05.717-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Platform section" operator="OR">
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Architecture independent section" operator="AND">
              <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criterion comment="libmodplug-dev is earlier than 0.8.4-1+lenny1" test_ref="oval:org.mitre.oval:tst:18977"/>
            </criteria>
            <criteria comment="Architecture dependent section" operator="AND">
              <criteria comment="Supported architectures section" operator="OR">
                <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
                <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
                <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
                <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
                <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
                <criterion comment="Installed architecture is armel" test_ref="oval:org.mitre.oval:tst:11101"/>
                <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
                <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
                <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
                <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
                <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
              </criteria>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="libmodplug0c2 DPKG is earlier than 0.8.4-1+lenny1" test_ref="oval:org.mitre.oval:tst:19028"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 4.0 is installed" definition_ref="oval:org.mitre.oval:def:6461"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Architecture independent section" operator="AND">
              <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criterion comment="libmodplug-dev is earlier than 0.7-5.2+etch1" test_ref="oval:org.mitre.oval:tst:19258"/>
            </criteria>
            <criteria comment="Packages section" operator="OR">
              <criterion comment="libmodplug0c2 DPKG is earlier than 0.7-5.2+etch1" test_ref="oval:org.mitre.oval:tst:18805"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:8300" class="patch">
      <metadata>
        <title>DSA-1800 linux-2.6 -- denial of service/privilege escalation/sensitive memory leak</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <product>linux-2.6</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2009/dsa-1800" ref_id="DSA-1800"/>
        <description>Several vulnerabilities have been discovered in the Linux kernel that may lead to a denial of service, privilege escalation or a sensitive memory leak. The Common Vulnerabilities and Exposures project identifies the following problems: Chris Evans discovered a situation in which a child process can send an arbitrary signal to its parent. Roland McGrath discovered an issue on amd64 kernels that allows local users to circumvent system call audit configurations which filter based on the syscall numbers or argument details. Roland McGrath discovered an issue on amd64 kernels with CONFIG_SECCOMP enabled. By making a specially crafted syscall, local users can bypass access restrictions. Jiri Olsa discovered that a local user can cause a denial of service (system hang) using a SHM_INFO shmctl call on kernels compiled with CONFIG_SHMEM disabled. This issue does not affect prebuilt Debian kernels. Mikulas Patocka reported an issue in the console subsystem that allows a local user to cause memory corruption by selecting a small number of 3-byte UTF-8 characters. Igor Zhbanov reported that nfsd was not properly dropping CAP_MKNOD, allowing users to create device nodes on file systems exported with root_squash. Dan Carpenter reported a coding issue in the selinux subsystem that allows local users to bypass certain networking checks when running with compat_net=1. Shaohua Li reported an issue in the AGP subsystem they may allow local users to read sensitive kernel memory due to a leak of uninitialized memory. Benjamin Gilbert reported a local denial of service vulnerability in the KVM VMX implementation that allows local users to trigger an oops. Thomas Pollet reported an overflow in the af_rose implementation that allows remote attackers to retrieve uninitialized kernel memory that may contain sensitive data. Oleg Nesterov discovered an issue in the exit_notify function that allows local users to send an arbitrary signal to a process by running a program that modifies the exit_signal field and then uses an exec system call to launch a setuid application. Daniel Hokka Zakrisson discovered that a kill(-1) is permitted to reach processes outside of the current process namespace. Pavan Naregundi reported an issue in the CIFS filesystem code that allows remote users to overwrite memory via a long nativeFileSystem field in a Tree Connect response during mount.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:13-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T08:00:50.655-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:05:23.360-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:04:04.847-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Release section" operator="AND">
        <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
        <criteria comment="Architecture section" operator="OR">
          <criteria comment="Architecture independent section" operator="AND">
            <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
            <criteria comment="Packages section" operator="OR">
              <criterion comment="linux-patch-debian-2.6.26 is earlier than 2.6.26-15lenny2" test_ref="oval:org.mitre.oval:tst:20152"/>
              <criterion comment="linux-support-2.6.26-2 is earlier than 2.6.26-15lenny2" test_ref="oval:org.mitre.oval:tst:20463"/>
              <criterion comment="linux-doc-2.6.26 is earlier than 2.6.26-15lenny2" test_ref="oval:org.mitre.oval:tst:20581"/>
              <criterion comment="linux-tree-2.6.26 is earlier than 2.6.26-15lenny2" test_ref="oval:org.mitre.oval:tst:20515"/>
              <criterion comment="linux-source-2.6.26 is earlier than 2.6.26-15lenny2" test_ref="oval:org.mitre.oval:tst:20509"/>
              <criterion comment="linux-manual-2.6.26 is earlier than 2.6.26-15lenny2" test_ref="oval:org.mitre.oval:tst:20586"/>
            </criteria>
          </criteria>
          <criteria comment="Architecture dependent section" operator="AND">
            <criteria comment="Supported architectures section" operator="OR">
              <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
            </criteria>
            <criteria comment="Packages section" operator="OR">
              <criterion comment="linux-headers-2.6.26-2-all DPKG is earlier than 2.6.26-15lenny2" test_ref="oval:org.mitre.oval:tst:20602"/>
              <criterion comment="linux-image-2.6.26-2-vserver-s390x DPKG is earlier than 2.6.26-15lenny2" test_ref="oval:org.mitre.oval:tst:20358"/>
              <criterion comment="linux-image-2.6.26-2-s390 DPKG is earlier than 2.6.26-15lenny2" test_ref="oval:org.mitre.oval:tst:20499"/>
              <criterion comment="linux-headers-2.6.26-2-s390 DPKG is earlier than 2.6.26-15lenny2" test_ref="oval:org.mitre.oval:tst:20375"/>
              <criterion comment="linux-image-2.6.26-2-s390-tape DPKG is earlier than 2.6.26-15lenny2" test_ref="oval:org.mitre.oval:tst:20404"/>
              <criterion comment="linux-headers-2.6.26-2-all-s390 DPKG is earlier than 2.6.26-15lenny2" test_ref="oval:org.mitre.oval:tst:20335"/>
              <criterion comment="linux-headers-2.6.26-2-vserver-s390x DPKG is earlier than 2.6.26-15lenny2" test_ref="oval:org.mitre.oval:tst:20539"/>
              <criterion comment="linux-headers-2.6.26-2-common-vserver DPKG is earlier than 2.6.26-15lenny2" test_ref="oval:org.mitre.oval:tst:20373"/>
              <criterion comment="linux-libc-dev DPKG is earlier than 2.6.26-15lenny2" test_ref="oval:org.mitre.oval:tst:20461"/>
              <criterion comment="linux-image-2.6.26-2-s390x DPKG is earlier than 2.6.26-15lenny2" test_ref="oval:org.mitre.oval:tst:20117"/>
              <criterion comment="linux-headers-2.6.26-2-common DPKG is earlier than 2.6.26-15lenny2" test_ref="oval:org.mitre.oval:tst:19880"/>
              <criterion comment="linux-headers-2.6.26-2-s390x DPKG is earlier than 2.6.26-15lenny2" test_ref="oval:org.mitre.oval:tst:20354"/>
            </criteria>
          </criteria>
          <criteria comment="Architecture dependent section" operator="AND">
            <criteria comment="Supported architectures section" operator="OR">
              <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
            </criteria>
            <criteria comment="Packages section" operator="OR">
              <criterion comment="xen-linux-system-2.6.26-2-xen-amd64 DPKG is earlier than 2.6.26-15lenny2" test_ref="oval:org.mitre.oval:tst:20537"/>
              <criterion comment="linux-headers-2.6.26-2-all DPKG is earlier than 2.6.26-15lenny2" test_ref="oval:org.mitre.oval:tst:20576"/>
              <criterion comment="linux-modules-2.6.26-2-xen-amd64 DPKG is earlier than 2.6.26-15lenny2" test_ref="oval:org.mitre.oval:tst:20523"/>
              <criterion comment="linux-headers-2.6.26-2-openvz-amd64 DPKG is earlier than 2.6.26-15lenny2" test_ref="oval:org.mitre.oval:tst:20434"/>
              <criterion comment="linux-headers-2.6.26-2-common-vserver DPKG is earlier than 2.6.26-15lenny2" test_ref="oval:org.mitre.oval:tst:20555"/>
              <criterion comment="linux-image-2.6.26-2-openvz-amd64 DPKG is earlier than 2.6.26-15lenny2" test_ref="oval:org.mitre.oval:tst:20549"/>
              <criterion comment="linux-image-2.6.26-2-amd64 DPKG is earlier than 2.6.26-15lenny2" test_ref="oval:org.mitre.oval:tst:20460"/>
              <criterion comment="user-mode-linux DPKG is earlier than 2.6.26-1um-2+15lenny2" test_ref="oval:org.mitre.oval:tst:20584"/>
              <criterion comment="linux-headers-2.6.26-2-common-openvz DPKG is earlier than 2.6.26-15lenny2" test_ref="oval:org.mitre.oval:tst:20446"/>
              <criterion comment="linux-image-2.6.26-2-vserver-amd64 DPKG is earlier than 2.6.26-15lenny2" test_ref="oval:org.mitre.oval:tst:20437"/>
              <criterion comment="linux-headers-2.6.26-2-all-amd64 DPKG is earlier than 2.6.26-15lenny2" test_ref="oval:org.mitre.oval:tst:20527"/>
              <criterion comment="linux-image-2.6.26-2-xen-amd64 DPKG is earlier than 2.6.26-15lenny2" test_ref="oval:org.mitre.oval:tst:20167"/>
              <criterion comment="linux-headers-2.6.26-2-common-xen DPKG is earlier than 2.6.26-15lenny2" test_ref="oval:org.mitre.oval:tst:19738"/>
              <criterion comment="linux-libc-dev DPKG is earlier than 2.6.26-15lenny2" test_ref="oval:org.mitre.oval:tst:20546"/>
              <criterion comment="linux-headers-2.6.26-2-xen-amd64 DPKG is earlier than 2.6.26-15lenny2" test_ref="oval:org.mitre.oval:tst:20494"/>
              <criterion comment="linux-headers-2.6.26-2-amd64 DPKG is earlier than 2.6.26-15lenny2" test_ref="oval:org.mitre.oval:tst:20540"/>
              <criterion comment="linux-headers-2.6.26-2-common DPKG is earlier than 2.6.26-15lenny2" test_ref="oval:org.mitre.oval:tst:19838"/>
              <criterion comment="linux-headers-2.6.26-2-vserver-amd64 DPKG is earlier than 2.6.26-15lenny2" test_ref="oval:org.mitre.oval:tst:20414"/>
            </criteria>
          </criteria>
          <criteria comment="Architecture depended section" operator="AND">
            <criteria comment="Supported platform section" operator="AND">
              <criterion comment="hppa architecture" test_ref="oval:org.mitre.oval:tst:11164"/>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="linux-headers-2.6.26-2-all DPKG is earlier than 2.6.26-15lenny2" test_ref="oval:org.mitre.oval:tst:20741"/>
                <criterion comment="linux-headers-2.6.26-2-parisc DPKG is earlier than 2.6.26-15lenny2" test_ref="oval:org.mitre.oval:tst:20442"/>
                <criterion comment="linux-image-2.6.26-2-parisc64 DPKG is earlier than 2.6.26-15lenny2" test_ref="oval:org.mitre.oval:tst:20610"/>
                <criterion comment="linux-image-2.6.26-2-parisc DPKG is earlier than 2.6.26-15lenny2" test_ref="oval:org.mitre.oval:tst:19821"/>
                <criterion comment="linux-headers-2.6.26-2-parisc-smp DPKG is earlier than 2.6.26-15lenny2" test_ref="oval:org.mitre.oval:tst:20553"/>
                <criterion comment="linux-headers-2.6.26-2-all-hppa DPKG is earlier than 2.6.26-15lenny2" test_ref="oval:org.mitre.oval:tst:20652"/>
                <criterion comment="linux-headers-2.6.26-2-parisc64 DPKG is earlier than 2.6.26-15lenny2" test_ref="oval:org.mitre.oval:tst:20604"/>
                <criterion comment="linux-headers-2.6.26-2-parisc64-smp DPKG is earlier than 2.6.26-15lenny2" test_ref="oval:org.mitre.oval:tst:20740"/>
                <criterion comment="linux-libc-dev DPKG is earlier than 2.6.26-15lenny2" test_ref="oval:org.mitre.oval:tst:20501"/>
                <criterion comment="linux-image-2.6.26-2-parisc64-smp DPKG is earlier than 2.6.26-15lenny2" test_ref="oval:org.mitre.oval:tst:20179"/>
                <criterion comment="linux-headers-2.6.26-2-common DPKG is earlier than 2.6.26-15lenny2" test_ref="oval:org.mitre.oval:tst:20281"/>
                <criterion comment="linux-image-2.6.26-2-parisc-smp DPKG is earlier than 2.6.26-15lenny2" test_ref="oval:org.mitre.oval:tst:20082"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:8299" class="patch">
      <metadata>
        <title>DSA-1852 fetchmail -- insufficient input validation</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <platform>Debian GNU/Linux 4.0</platform>
          <product>fetchmail</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2009/dsa-1852" ref_id="DSA-1852"/>
        <description>It was discovered that fetchmail, a full-featured remote mail retrieval and forwarding utility, is vulnerable to the "Null Prefix Attacks Against SSL/TLS Certificates" recently published at the Blackhat conference. This allows an attacker to perform undetected man-in-the-middle attacks via a crafted ITU-T X.509 certificate with an injected null byte in the subjectAltName or Common Name fields. Note, as a fetchmail user you should always use strict certificate validation through either these option combinations: sslcertck ssl sslproto ssl3 (for service on SSL-wrapped ports) or sslcertck sslproto tls1 (for STARTTLS-based services)</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:11-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T07:58:50.207-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:05:22.899-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:04:04.408-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Platform section" operator="OR">
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Architecture independent section" operator="AND">
              <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criterion comment="fetchmailconf is earlier than 6.3.9~rc2-4+lenny1" test_ref="oval:org.mitre.oval:tst:18983"/>
            </criteria>
            <criteria comment="Architecture dependent section" operator="AND">
              <criteria comment="Supported architectures section" operator="OR">
                <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
                <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
                <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
                <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
                <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
                <criterion comment="Installed architecture is armel" test_ref="oval:org.mitre.oval:tst:11101"/>
                <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
                <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
                <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
                <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
                <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
                <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
              </criteria>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="fetchmail DPKG is earlier than 6.3.9~rc2-4+lenny1" test_ref="oval:org.mitre.oval:tst:19217"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 4.0 is installed" definition_ref="oval:org.mitre.oval:def:6461"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Architecture independent section" operator="AND">
              <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criterion comment="fetchmailconf is earlier than 6.3.6-1etch2" test_ref="oval:org.mitre.oval:tst:18503"/>
            </criteria>
            <criteria comment="Architecture dependent section" operator="AND">
              <criteria comment="Supported architectures section" operator="OR">
                <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
                <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
                <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
                <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
                <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
                <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
                <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
                <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
                <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
              </criteria>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="fetchmail DPKG is earlier than 6.3.6-1etch2" test_ref="oval:org.mitre.oval:tst:19174"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:8294" class="patch">
      <metadata>
        <title>DSA-1803 nsd, nsd3 -- buffer overflow</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <platform>Debian GNU/Linux 4.0</platform>
          <product>nsd</product>
          <product>nsd3</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2009/dsa-1803" ref_id="DSA-1803"/>
        <description>Ilja van Sprundel discovered that a buffer overflow in NSD, an authoritative name service daemon, allowed to crash the server by sending a crafted packet, creating a denial of service.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:13-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T08:00:44.212-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:05:22.502-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:04:03.960-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Platform section" operator="OR">
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Architecture dependent section" operator="AND">
              <criteria comment="Supported architectures section" operator="OR">
                <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
                <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
                <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
                <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
                <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
                <criterion comment="Installed architecture is armel" test_ref="oval:org.mitre.oval:tst:11101"/>
                <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
                <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
                <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
                <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
                <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
                <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
              </criteria>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="nsd3 DPKG is earlier than 3.0.7-3.lenny2" test_ref="oval:org.mitre.oval:tst:19874"/>
                <criterion comment="nsd DPKG is earlier than 2.3.7-1.1+lenny1" test_ref="oval:org.mitre.oval:tst:20552"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 4.0 is installed" definition_ref="oval:org.mitre.oval:def:6461"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Packages section" operator="OR">
              <criterion comment="nsd DPKG is earlier than 2.3.6-1+etch1" test_ref="oval:org.mitre.oval:tst:20410"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:8291" class="patch">
      <metadata>
        <title>DSA-1597 mt-daapd -- multiple vulnerabilities</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 4.0</platform>
          <product>mt-daapd</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2008/dsa-1597" ref_id="DSA-1597"/>
        <description>Three vulnerabilities have been discovered in the mt-daapd DAAP audio server (also known as the Firefly Media Server). The Common Vulnerabilities and Exposures project identifies the following three problems: Insufficient validation and bounds checking of the Authorization: HTTP header enables a heap buffer overflow, potentially enabling the execution of arbitrary code. Format string vulnerabilities in debug logging within the authentication of XML-RPC requests could enable the execution of arbitrary code. An integer overflow weakness in the handling of HTTP POST variables could allow a heap buffer overflow and potentially arbitrary code execution.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:11-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T07:59:38.841-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:05:22.315-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:04:03.758-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Release section" operator="AND">
        <extend_definition comment="Debian 4.0 is installed" definition_ref="oval:org.mitre.oval:def:6461"/>
        <criteria comment="Architecture section" operator="OR">
          <criteria comment="Packages section" operator="OR">
            <criterion comment="mt-daapd DPKG is earlier than 0.2.4+r1376-1.1+etch2" test_ref="oval:org.mitre.oval:tst:18991"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:8289" class="patch">
      <metadata>
        <title>DSA-1935 gnutls13 gnutls26 -- several vulnerabilities</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <platform>Debian GNU/Linux 4.0</platform>
          <product>gnutls13</product>
          <product>gnutls26</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2009/dsa-1935" ref_id="DSA-1935"/>
        <description>Dan Kaminsky and Moxie Marlinspike discovered that gnutls, an implementation of the TLS/SSL protocol, does not properly handle a "\0" character in a domain name in the subject's Common Name or Subject Alternative Name (SAN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority. (CVE-2009-2730) In addition, with this update, certificates with MD2 hash signatures are no longer accepted since they're no longer considered cryptograhically secure. It only affects the oldstable distribution (etch).(CVE-2009-2409)</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:11-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T07:59:14.513-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:05:21.730-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:04:02.964-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Platform section" operator="OR">
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Architecture independent section" operator="AND">
              <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criterion comment="gnutls-doc is earlier than 2.4.2-6+lenny2" test_ref="oval:org.mitre.oval:tst:19120"/>
            </criteria>
            <criteria comment="Architecture dependent section" operator="AND">
              <criteria comment="Supported architectures section" operator="OR">
                <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
                <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
                <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
                <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
                <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
                <criterion comment="Installed architecture is armel" test_ref="oval:org.mitre.oval:tst:11101"/>
                <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
                <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
                <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
                <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
                <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
              </criteria>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="libgnutls-dev DPKG is earlier than 2.4.2-6+lenny2" test_ref="oval:org.mitre.oval:tst:19418"/>
                <criterion comment="libgnutls26-dbg DPKG is earlier than 2.4.2-6+lenny2" test_ref="oval:org.mitre.oval:tst:19207"/>
                <criterion comment="libgnutls26 DPKG is earlier than 2.4.2-6+lenny2" test_ref="oval:org.mitre.oval:tst:18509"/>
                <criterion comment="gnutls-bin DPKG is earlier than 2.4.2-6+lenny2" test_ref="oval:org.mitre.oval:tst:19103"/>
              </criteria>
            </criteria>
            <criteria comment="Packages section" operator="OR">
              <criterion comment="guile-gnutls DPKG is earlier than 2.4.2-6+lenny2" test_ref="oval:org.mitre.oval:tst:18710"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 4.0 is installed" definition_ref="oval:org.mitre.oval:def:6461"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Architecture independent section" operator="AND">
              <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criterion comment="gnutls-doc is earlier than 1.4.4-3+etch5" test_ref="oval:org.mitre.oval:tst:19426"/>
            </criteria>
            <criteria comment="Packages section" operator="OR">
              <criterion comment="libgnutls13 DPKG is earlier than 1.4.4-3+etch5" test_ref="oval:org.mitre.oval:tst:19199"/>
              <criterion comment="gnutls-bin DPKG is earlier than 1.4.4-3+etch5" test_ref="oval:org.mitre.oval:tst:19427"/>
              <criterion comment="libgnutls-dev DPKG is earlier than 1.4.4-3+etch5" test_ref="oval:org.mitre.oval:tst:19377"/>
              <criterion comment="libgnutls13-dbg DPKG is earlier than 1.4.4-3+etch5" test_ref="oval:org.mitre.oval:tst:19467"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:8286" class="patch">
      <metadata>
        <title>DSA-1682 squirrelmail -- insufficient input sanitising</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 4.0</platform>
          <product>squirrelmail</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2008/dsa-1682" ref_id="DSA-1682"/>
        <description>Ivan Markovic discovered that SquirrelMail, a webmail application, did not sufficiently sanitise incoming HTML email, allowing an attacker to perform cross site scripting through sending a malicious HTML email.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:12-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T08:00:27.618-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:05:21.527-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:04:02.750-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Release section" operator="AND">
        <extend_definition comment="Debian 4.0 is installed" definition_ref="oval:org.mitre.oval:def:6461"/>
        <criteria comment="Architecture section" operator="OR">
          <criteria comment="Architecture independent section" operator="AND">
            <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
            <criterion comment="squirrelmail is earlier than 1.4.9a-3" test_ref="oval:org.mitre.oval:tst:20254"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:8285" class="patch">
      <metadata>
        <title>DSA-1894 newt -- buffer overflow</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <platform>Debian GNU/Linux 4.0</platform>
          <product>newt</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2009/dsa-1894" ref_id="DSA-1894"/>
        <description>Miroslav Lichvar discovered that newt, a windowing toolkit, is prone to a buffer overflow in the content processing code, which can lead to the execution of arbitrary code.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:12-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T08:00:04.752-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:05:20.989-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:04:02.242-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Platform section" operator="OR">
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Architecture dependent section" operator="AND">
              <criteria comment="Supported architectures section" operator="OR">
                <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
                <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
                <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
                <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
                <criterion comment="Installed architecture is armel" test_ref="oval:org.mitre.oval:tst:11101"/>
                <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
                <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
                <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
                <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
                <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
                <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
              </criteria>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="libnewt-dev DPKG is earlier than 0.52.2-11.3+lenny1" test_ref="oval:org.mitre.oval:tst:19799"/>
                <criterion comment="libnewt-pic DPKG is earlier than 0.52.2-11.3+lenny1" test_ref="oval:org.mitre.oval:tst:19994"/>
                <criterion comment="whiptail DPKG is earlier than 0.52.2-11.3+lenny1" test_ref="oval:org.mitre.oval:tst:20041"/>
                <criterion comment="libnewt0.52 DPKG is earlier than 0.52.2-11.3+lenny1" test_ref="oval:org.mitre.oval:tst:19853"/>
                <criterion comment="newt-tcl DPKG is earlier than 0.52.2-11.3+lenny1" test_ref="oval:org.mitre.oval:tst:20033"/>
                <criterion comment="python-newt DPKG is earlier than 0.52.2-11.3+lenny1" test_ref="oval:org.mitre.oval:tst:19786"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 4.0 is installed" definition_ref="oval:org.mitre.oval:def:6461"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Architecture dependent section" operator="AND">
              <criteria comment="Supported architectures section" operator="OR">
                <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
                <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
                <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
                <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
                <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
                <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
                <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
                <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
                <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
                <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
              </criteria>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="libnewt-dev DPKG is earlier than 0.52.2-10+etch1" test_ref="oval:org.mitre.oval:tst:19278"/>
                <criterion comment="libnewt-pic DPKG is earlier than 0.52.2-10+etch1" test_ref="oval:org.mitre.oval:tst:19908"/>
                <criterion comment="whiptail DPKG is earlier than 0.52.2-10+etch1" test_ref="oval:org.mitre.oval:tst:19370"/>
                <criterion comment="libnewt0.52 DPKG is earlier than 0.52.2-10+etch1" test_ref="oval:org.mitre.oval:tst:20156"/>
                <criterion comment="newt-tcl DPKG is earlier than 0.52.2-10+etch1" test_ref="oval:org.mitre.oval:tst:20138"/>
                <criterion comment="python-newt DPKG is earlier than 0.52.2-10+etch1" test_ref="oval:org.mitre.oval:tst:20132"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:8284" class="patch">
      <metadata>
        <title>DSA-1890 wxwindows2.4 wxwidgets2.6 wxwidgets2.8 -- integer overflow</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <platform>Debian GNU/Linux 4.0</platform>
          <product>wxwindows2.4</product>
          <product>wxwidgets2.6</product>
          <product>wxwidgets2.8</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2009/dsa-1890" ref_id="DSA-1890"/>
        <description>Tielei Wang has discovered an integer overflow in wxWidgets, the wxWidgets Cross-platform C++ GUI toolkit, which allows the execution of arbitrary code via a crafted JPEG file.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:12-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T08:00:18.597-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:05:19.302-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:04:00.597-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Platform section" operator="OR">
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Architecture independent section" operator="AND">
              <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="wx2.6-doc is earlier than 2.6.3.2.2-3+lenny1" test_ref="oval:org.mitre.oval:tst:19944"/>
                <criterion comment="python-wxversion is earlier than 2.6.3.2.2-3+lenny1" test_ref="oval:org.mitre.oval:tst:20087"/>
                <criterion comment="wx2.8-examples is earlier than 2.8.7.1-1.1+lenny1" test_ref="oval:org.mitre.oval:tst:19226"/>
                <criterion comment="wx2.6-i18n is earlier than 2.6.3.2.2-3+lenny1" test_ref="oval:org.mitre.oval:tst:19678"/>
                <criterion comment="wx2.6-examples is earlier than 2.6.3.2.2-3+lenny1" test_ref="oval:org.mitre.oval:tst:19904"/>
                <criterion comment="wx2.8-doc is earlier than 2.8.7.1-1.1+lenny1" test_ref="oval:org.mitre.oval:tst:19822"/>
                <criterion comment="python-wxtools is earlier than 2.6.3.2.2-3+lenny1" test_ref="oval:org.mitre.oval:tst:20019"/>
                <criterion comment="wx2.8-i18n is earlier than 2.8.7.1-1.1+lenny1" test_ref="oval:org.mitre.oval:tst:19532"/>
              </criteria>
            </criteria>
            <criteria comment="Architecture dependent section" operator="AND">
              <criteria comment="Supported architectures section" operator="OR">
                <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
                <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
                <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
                <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
                <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
                <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
              </criteria>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="python-wxgtk2.8 DPKG is earlier than 2.8.7.1-1.1+lenny1" test_ref="oval:org.mitre.oval:tst:19329"/>
                <criterion comment="python-wxgtk2.6-dbg DPKG is earlier than 2.6.3.2.2-3+lenny1" test_ref="oval:org.mitre.oval:tst:19982"/>
                <criterion comment="libwxbase2.8-dev DPKG is earlier than 2.8.7.1-1.1+lenny1" test_ref="oval:org.mitre.oval:tst:19968"/>
                <criterion comment="libwxbase2.6-dev DPKG is earlier than 2.6.3.2.2-3+lenny1" test_ref="oval:org.mitre.oval:tst:19581"/>
                <criterion comment="python-wxgtk2.8-dbg DPKG is earlier than 2.8.7.1-1.1+lenny1" test_ref="oval:org.mitre.oval:tst:19265"/>
                <criterion comment="libwxbase2.8-dbg DPKG is earlier than 2.8.7.1-1.1+lenny1" test_ref="oval:org.mitre.oval:tst:20125"/>
                <criterion comment="wx-common DPKG is earlier than 2.6.3.2.2-3+lenny1" test_ref="oval:org.mitre.oval:tst:20064"/>
                <criterion comment="libwxgtk2.8-dbg DPKG is earlier than 2.8.7.1-1.1+lenny1" test_ref="oval:org.mitre.oval:tst:20126"/>
                <criterion comment="python-wxgtk2.6 DPKG is earlier than 2.6.3.2.2-3+lenny1" test_ref="oval:org.mitre.oval:tst:19820"/>
                <criterion comment="libwxgtk2.6-0 DPKG is earlier than 2.6.3.2.2-3+lenny1" test_ref="oval:org.mitre.oval:tst:20031"/>
                <criterion comment="libwxgtk2.8-0 DPKG is earlier than 2.8.7.1-1.1+lenny1" test_ref="oval:org.mitre.oval:tst:19700"/>
                <criterion comment="libwxgtk2.6-dev DPKG is earlier than 2.6.3.2.2-3+lenny1" test_ref="oval:org.mitre.oval:tst:19864"/>
                <criterion comment="libwxgtk2.6-dbg DPKG is earlier than 2.6.3.2.2-3+lenny1" test_ref="oval:org.mitre.oval:tst:19652"/>
                <criterion comment="libwxbase2.6-0 DPKG is earlier than 2.6.3.2.2-3+lenny1" test_ref="oval:org.mitre.oval:tst:20043"/>
                <criterion comment="wx2.6-headers DPKG is earlier than 2.6.3.2.2-3+lenny1" test_ref="oval:org.mitre.oval:tst:19591"/>
                <criterion comment="wx2.8-headers DPKG is earlier than 2.8.7.1-1.1+lenny1" test_ref="oval:org.mitre.oval:tst:19454"/>
                <criterion comment="libwxbase2.8-0 DPKG is earlier than 2.8.7.1-1.1+lenny1" test_ref="oval:org.mitre.oval:tst:20070"/>
                <criterion comment="libwxgtk2.8-dev DPKG is earlier than 2.8.7.1-1.1+lenny1" test_ref="oval:org.mitre.oval:tst:19991"/>
                <criterion comment="libwxbase2.6-dbg DPKG is earlier than 2.6.3.2.2-3+lenny1" test_ref="oval:org.mitre.oval:tst:20071"/>
              </criteria>
            </criteria>
            <criteria comment="Architecture dependent section" operator="AND">
              <criteria comment="Supported architectures section" operator="OR">
                <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
              </criteria>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="libwxgtk2.6-dev DPKG is earlier than 2.6.3.2.2-3+lenny1" test_ref="oval:org.mitre.oval:tst:19245"/>
                <criterion comment="libwxbase2.6-dev DPKG is earlier than 2.6.3.2.2-3+lenny1" test_ref="oval:org.mitre.oval:tst:20143"/>
                <criterion comment="wx-common DPKG is earlier than 2.6.3.2.2-3+lenny1" test_ref="oval:org.mitre.oval:tst:19508"/>
                <criterion comment="python-wxgtk2.6 DPKG is earlier than 2.6.3.2.2-3+lenny1" test_ref="oval:org.mitre.oval:tst:20112"/>
                <criterion comment="libwxgtk2.6-0 DPKG is earlier than 2.6.3.2.2-3+lenny1" test_ref="oval:org.mitre.oval:tst:20177"/>
                <criterion comment="libwxgtk2.6-dbg DPKG is earlier than 2.6.3.2.2-3+lenny1" test_ref="oval:org.mitre.oval:tst:19837"/>
                <criterion comment="python-wxgtk2.6-dbg DPKG is earlier than 2.6.3.2.2-3+lenny1" test_ref="oval:org.mitre.oval:tst:20119"/>
                <criterion comment="libwxbase2.6-0 DPKG is earlier than 2.6.3.2.2-3+lenny1" test_ref="oval:org.mitre.oval:tst:20091"/>
                <criterion comment="wx2.6-headers DPKG is earlier than 2.6.3.2.2-3+lenny1" test_ref="oval:org.mitre.oval:tst:20078"/>
                <criterion comment="libwxbase2.6-dbg DPKG is earlier than 2.6.3.2.2-3+lenny1" test_ref="oval:org.mitre.oval:tst:19955"/>
              </criteria>
            </criteria>
            <criteria comment="Architecture depended section" operator="AND">
              <criteria comment="Supported platform section" operator="AND">
                <criterion comment="armel architecture" test_ref="oval:org.mitre.oval:tst:11101"/>
                <criteria comment="Packages section" operator="OR">
                  <criterion comment="libwxgtk2.8-dbg DPKG is earlier than 2.8.7.1-1.1+lenny1" test_ref="oval:org.mitre.oval:tst:19692"/>
                  <criterion comment="libwxbase2.8-dev DPKG is earlier than 2.8.7.1-1.1+lenny1" test_ref="oval:org.mitre.oval:tst:20191"/>
                  <criterion comment="python-wxgtk2.8 DPKG is earlier than 2.8.7.1-1.1+lenny1" test_ref="oval:org.mitre.oval:tst:20165"/>
                  <criterion comment="libwxbase2.8-dbg DPKG is earlier than 2.8.7.1-1.1+lenny1" test_ref="oval:org.mitre.oval:tst:20128"/>
                  <criterion comment="libwxgtk2.8-0 DPKG is earlier than 2.8.7.1-1.1+lenny1" test_ref="oval:org.mitre.oval:tst:20212"/>
                  <criterion comment="libwxgtk2.8-dev DPKG is earlier than 2.8.7.1-1.1+lenny1" test_ref="oval:org.mitre.oval:tst:20211"/>
                  <criterion comment="libwxbase2.8-0 DPKG is earlier than 2.8.7.1-1.1+lenny1" test_ref="oval:org.mitre.oval:tst:19898"/>
                  <criterion comment="python-wxgtk2.8-dbg DPKG is earlier than 2.8.7.1-1.1+lenny1" test_ref="oval:org.mitre.oval:tst:20109"/>
                  <criterion comment="wx2.8-headers DPKG is earlier than 2.8.7.1-1.1+lenny1" test_ref="oval:org.mitre.oval:tst:19683"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 4.0 is installed" definition_ref="oval:org.mitre.oval:def:6461"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Architecture independent section" operator="AND">
              <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="wx2.6-doc is earlier than 2.6.3.2.1.5+etch1" test_ref="oval:org.mitre.oval:tst:19859"/>
                <criterion comment="python-wxversion is earlier than 2.6.3.2.1.5+etch1" test_ref="oval:org.mitre.oval:tst:20140"/>
                <criterion comment="wx2.4-examples is earlier than 2.4.5.1.1+etch1" test_ref="oval:org.mitre.oval:tst:20149"/>
                <criterion comment="wx2.6-i18n is earlier than 2.6.3.2.1.5+etch1" test_ref="oval:org.mitre.oval:tst:19930"/>
                <criterion comment="wx2.6-examples is earlier than 2.6.3.2.1.5+etch1" test_ref="oval:org.mitre.oval:tst:19953"/>
                <criterion comment="python-wxtools is earlier than 2.6.3.2.1.5+etch1" test_ref="oval:org.mitre.oval:tst:19852"/>
                <criterion comment="wx2.4-doc is earlier than 2.4.5.1.1+etch1" test_ref="oval:org.mitre.oval:tst:20198"/>
                <criterion comment="wx2.4-i18n is earlier than 2.4.5.1.1+etch1" test_ref="oval:org.mitre.oval:tst:19998"/>
              </criteria>
            </criteria>
            <criteria comment="Architecture dependent section" operator="AND">
              <criteria comment="Supported architectures section" operator="OR">
                <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
                <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
                <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
                <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
                <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
                <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
                <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
              </criteria>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="libwxgtk2.6-dev DPKG is earlier than 2.6.3.2.1.5+etch1" test_ref="oval:org.mitre.oval:tst:20174"/>
                <criterion comment="libwxbase2.6-dbg DPKG is earlier than 2.6.3.2.1.5+etch1" test_ref="oval:org.mitre.oval:tst:20194"/>
                <criterion comment="libwxgtk2.4-1-contrib DPKG is earlier than 2.4.5.1.1+etch1" test_ref="oval:org.mitre.oval:tst:20027"/>
                <criterion comment="wx-common DPKG is earlier than 2.6.3.2.1.5+etch1" test_ref="oval:org.mitre.oval:tst:19780"/>
                <criterion comment="python-wxgtk2.4 DPKG is earlier than 2.4.5.1.1+etch1" test_ref="oval:org.mitre.oval:tst:20046"/>
                <criterion comment="libwxbase2.4-dev DPKG is earlier than 2.4.5.1.1+etch1" test_ref="oval:org.mitre.oval:tst:20006"/>
                <criterion comment="libwxgtk2.6-0 DPKG is earlier than 2.6.3.2.1.5+etch1" test_ref="oval:org.mitre.oval:tst:20055"/>
                <criterion comment="python-wxgtk2.6 DPKG is earlier than 2.6.3.2.1.5+etch1" test_ref="oval:org.mitre.oval:tst:20053"/>
                <criterion comment="libwxgtk2.4-contrib-dev DPKG is earlier than 2.4.5.1.1+etch1" test_ref="oval:org.mitre.oval:tst:20172"/>
                <criterion comment="libwxgtk2.6-dbg DPKG is earlier than 2.6.3.2.1.5+etch1" test_ref="oval:org.mitre.oval:tst:19856"/>
                <criterion comment="libwxgtk2.4-1 DPKG is earlier than 2.4.5.1.1+etch1" test_ref="oval:org.mitre.oval:tst:19699"/>
                <criterion comment="libwxgtk2.4-dev DPKG is earlier than 2.4.5.1.1+etch1" test_ref="oval:org.mitre.oval:tst:20205"/>
                <criterion comment="libwxbase2.6-0 DPKG is earlier than 2.6.3.2.1.5+etch1" test_ref="oval:org.mitre.oval:tst:19674"/>
                <criterion comment="wx2.6-headers DPKG is earlier than 2.6.3.2.1.5+etch1" test_ref="oval:org.mitre.oval:tst:20184"/>
                <criterion comment="libwxbase2.4-1 DPKG is earlier than 2.4.5.1.1+etch1" test_ref="oval:org.mitre.oval:tst:20093"/>
                <criterion comment="libwxbase2.4-dbg DPKG is earlier than 2.4.5.1.1+etch1" test_ref="oval:org.mitre.oval:tst:20028"/>
                <criterion comment="wx2.4-headers DPKG is earlier than 2.4.5.1.1+etch1" test_ref="oval:org.mitre.oval:tst:20106"/>
                <criterion comment="libwxgtk2.4-dbg DPKG is earlier than 2.4.5.1.1+etch1" test_ref="oval:org.mitre.oval:tst:19730"/>
                <criterion comment="libwxbase2.6-dev DPKG is earlier than 2.6.3.2.1.5+etch1" test_ref="oval:org.mitre.oval:tst:19486"/>
              </criteria>
            </criteria>
            <criteria comment="Architecture dependent section" operator="AND">
              <criteria comment="Supported architectures section" operator="OR">
                <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
              </criteria>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="libwxgtk2.6-dev DPKG is earlier than 2.6.3.2.1.5+etch1" test_ref="oval:org.mitre.oval:tst:19860"/>
                <criterion comment="libwxbase2.6-dbg DPKG is earlier than 2.6.3.2.1.5+etch1" test_ref="oval:org.mitre.oval:tst:20242"/>
                <criterion comment="wx-common DPKG is earlier than 2.6.3.2.1.5+etch1" test_ref="oval:org.mitre.oval:tst:20202"/>
                <criterion comment="python-wxgtk2.6 DPKG is earlier than 2.6.3.2.1.5+etch1" test_ref="oval:org.mitre.oval:tst:19731"/>
                <criterion comment="libwxgtk2.6-0 DPKG is earlier than 2.6.3.2.1.5+etch1" test_ref="oval:org.mitre.oval:tst:20213"/>
                <criterion comment="libwxgtk2.6-dbg DPKG is earlier than 2.6.3.2.1.5+etch1" test_ref="oval:org.mitre.oval:tst:19346"/>
                <criterion comment="libwxbase2.6-0 DPKG is earlier than 2.6.3.2.1.5+etch1" test_ref="oval:org.mitre.oval:tst:19899"/>
                <criterion comment="wx2.6-headers DPKG is earlier than 2.6.3.2.1.5+etch1" test_ref="oval:org.mitre.oval:tst:19753"/>
                <criterion comment="libwxbase2.6-dev DPKG is earlier than 2.6.3.2.1.5+etch1" test_ref="oval:org.mitre.oval:tst:19810"/>
              </criteria>
            </criteria>
            <criteria comment="Architecture depended section" operator="AND">
              <criteria comment="Supported platform section" operator="AND">
                <criterion comment="hppa architecture" test_ref="oval:org.mitre.oval:tst:11164"/>
                <criteria comment="Packages section" operator="OR">
                  <criterion comment="libwxgtk2.4-contrib-dev DPKG is earlier than 2.4.5.1.1+etch1" test_ref="oval:org.mitre.oval:tst:20235"/>
                  <criterion comment="libwxgtk2.4-1-contrib DPKG is earlier than 2.4.5.1.1+etch1" test_ref="oval:org.mitre.oval:tst:20186"/>
                  <criterion comment="libwxbase2.4-dev DPKG is earlier than 2.4.5.1.1+etch1" test_ref="oval:org.mitre.oval:tst:20222"/>
                  <criterion comment="python-wxgtk2.4 DPKG is earlier than 2.4.5.1.1+etch1" test_ref="oval:org.mitre.oval:tst:19892"/>
                  <criterion comment="libwxgtk2.4-1 DPKG is earlier than 2.4.5.1.1+etch1" test_ref="oval:org.mitre.oval:tst:20199"/>
                  <criterion comment="wx2.4-headers DPKG is earlier than 2.4.5.1.1+etch1" test_ref="oval:org.mitre.oval:tst:19909"/>
                  <criterion comment="libwxgtk2.4-dev DPKG is earlier than 2.4.5.1.1+etch1" test_ref="oval:org.mitre.oval:tst:19430"/>
                  <criterion comment="libwxbase2.4-1 DPKG is earlier than 2.4.5.1.1+etch1" test_ref="oval:org.mitre.oval:tst:20230"/>
                  <criterion comment="libwxbase2.4-dbg DPKG is earlier than 2.4.5.1.1+etch1" test_ref="oval:org.mitre.oval:tst:20226"/>
                  <criterion comment="libwxgtk2.4-dbg DPKG is earlier than 2.4.5.1.1+etch1" test_ref="oval:org.mitre.oval:tst:20139"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:8279" class="patch">
      <metadata>
        <title>DSA-1851 gst-plugins-bad0.10 -- integer overflow</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <platform>Debian GNU/Linux 4.0</platform>
          <product>gst-plugins-bad0.10</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2009/dsa-1851" ref_id="DSA-1851"/>
        <description>It was discovered that gst-plugins-bad0.10, the GStreamer plugins from the "bad" set, is prone to an integer overflow when processing a MED file with a crafted song comment or song name.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:11-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T07:58:49.407-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:05:18.815-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:04:00.139-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Platform section" operator="OR">
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Architecture independent section" operator="AND">
              <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criterion comment="gstreamer0.10-plugins-bad-doc is earlier than 0.10.7-2+lenny2" test_ref="oval:org.mitre.oval:tst:19107"/>
            </criteria>
            <criteria comment="Architecture dependent section" operator="AND">
              <criteria comment="Supported architectures section" operator="OR">
                <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
                <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
                <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
                <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
                <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
                <criterion comment="Installed architecture is armel" test_ref="oval:org.mitre.oval:tst:11101"/>
                <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
                <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
                <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
                <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
                <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
                <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
              </criteria>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="gstreamer0.10-plugins-bad-dbg DPKG is earlier than 0.10.7-2+lenny2" test_ref="oval:org.mitre.oval:tst:18287"/>
                <criterion comment="gstreamer0.10-sdl DPKG is earlier than 0.10.7-2+lenny2" test_ref="oval:org.mitre.oval:tst:19111"/>
                <criterion comment="gstreamer0.10-plugins-bad DPKG is earlier than 0.10.7-2+lenny2" test_ref="oval:org.mitre.oval:tst:19266"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 4.0 is installed" definition_ref="oval:org.mitre.oval:def:6461"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Packages section" operator="OR">
              <criterion comment="gstreamer0.10-plugins-bad DPKG is earlier than 0.10.3-3.1+etch3" test_ref="oval:org.mitre.oval:tst:18889"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:8277" class="patch">
      <metadata>
        <title>DSA-1558 xulrunner -- programming error</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 4.0</platform>
          <product>xulrunner</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2008/dsa-1558" ref_id="DSA-1558"/>
        <description>It was discovered that crashes in the Javascript engine of xulrunner, the Gecko engine library, could potentially lead to the execution of arbitrary code.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:10-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T07:58:43.286-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:05:18.246-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:03:59.481-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Release section" operator="AND">
        <extend_definition comment="Debian 4.0 is installed" definition_ref="oval:org.mitre.oval:def:6461"/>
        <criteria comment="Architecture section" operator="OR">
          <criteria comment="Architecture independent section" operator="AND">
            <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
            <criteria comment="Packages section" operator="OR">
              <criterion comment="libnspr4-dev is earlier than 1.8.0.15~pre080323b-0etch2" test_ref="oval:org.mitre.oval:tst:18533"/>
              <criterion comment="libmozjs-dev is earlier than 1.8.0.15~pre080323b-0etch2" test_ref="oval:org.mitre.oval:tst:19170"/>
              <criterion comment="libsmjs1 is earlier than 1.8.0.15~pre080323b-0etch2" test_ref="oval:org.mitre.oval:tst:19110"/>
              <criterion comment="libmozillainterfaces-java is earlier than 1.8.0.15~pre080323b-0etch2" test_ref="oval:org.mitre.oval:tst:18791"/>
              <criterion comment="libxul-common is earlier than 1.8.0.15~pre080323b-0etch2" test_ref="oval:org.mitre.oval:tst:18546"/>
              <criterion comment="libsmjs-dev is earlier than 1.8.0.15~pre080323b-0etch2" test_ref="oval:org.mitre.oval:tst:19115"/>
              <criterion comment="libxul-dev is earlier than 1.8.0.15~pre080323b-0etch2" test_ref="oval:org.mitre.oval:tst:19163"/>
              <criterion comment="libnss3-dev is earlier than 1.8.0.15~pre080323b-0etch2" test_ref="oval:org.mitre.oval:tst:19193"/>
            </criteria>
          </criteria>
          <criteria comment="Architecture dependent section" operator="AND">
            <criteria comment="Supported architectures section" operator="OR">
              <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
              <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
              <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
              <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
              <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
              <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
              <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
              <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
              <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
              <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
            </criteria>
            <criteria comment="Packages section" operator="OR">
              <criterion comment="libxul0d DPKG is earlier than 1.8.0.15~pre080323b-0etch2" test_ref="oval:org.mitre.oval:tst:18948"/>
              <criterion comment="libnss3-0d-dbg DPKG is earlier than 1.8.0.15~pre080323b-0etch2" test_ref="oval:org.mitre.oval:tst:19092"/>
              <criterion comment="libmozjs0d-dbg DPKG is earlier than 1.8.0.15~pre080323b-0etch2" test_ref="oval:org.mitre.oval:tst:19158"/>
              <criterion comment="libnss3-0d DPKG is earlier than 1.8.0.15~pre080323b-0etch2" test_ref="oval:org.mitre.oval:tst:18887"/>
              <criterion comment="spidermonkey-bin DPKG is earlier than 1.8.0.15~pre080323b-0etch2" test_ref="oval:org.mitre.oval:tst:19112"/>
              <criterion comment="libnspr4-0d-dbg DPKG is earlier than 1.8.0.15~pre080323b-0etch2" test_ref="oval:org.mitre.oval:tst:19079"/>
              <criterion comment="xulrunner-gnome-support DPKG is earlier than 1.8.0.15~pre080323b-0etch2" test_ref="oval:org.mitre.oval:tst:19176"/>
              <criterion comment="python-xpcom DPKG is earlier than 1.8.0.15~pre080323b-0etch2" test_ref="oval:org.mitre.oval:tst:18866"/>
              <criterion comment="libxul0d-dbg DPKG is earlier than 1.8.0.15~pre080323b-0etch2" test_ref="oval:org.mitre.oval:tst:19126"/>
              <criterion comment="xulrunner DPKG is earlier than 1.8.0.15~pre080323b-0etch2" test_ref="oval:org.mitre.oval:tst:19119"/>
              <criterion comment="libnss3-tools DPKG is earlier than 1.8.0.15~pre080323b-0etch2" test_ref="oval:org.mitre.oval:tst:18233"/>
              <criterion comment="libmozjs0d DPKG is earlier than 1.8.0.15~pre080323b-0etch2" test_ref="oval:org.mitre.oval:tst:18878"/>
              <criterion comment="libnspr4-0d DPKG is earlier than 1.8.0.15~pre080323b-0etch2" test_ref="oval:org.mitre.oval:tst:18350"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:8263" class="patch">
      <metadata>
        <title>DSA-1779 apt -- several vulnerabilities</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <platform>Debian GNU/Linux 4.0</platform>
          <product>apt</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2009/dsa-1779" ref_id="DSA-1779"/>
        <description>Two vulnerabilities have been discovered in APT, the well-known dpkg frontend. The Common Vulnerabilities and Exposures project identifies the following problems: In time zones where daylight savings time occurs at midnight, the apt cron.daily script fails, stopping new security updates from being applied automatically. A repository that has been signed with an expired or revoked OpenPGP key would still be considered valid by APT.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:10-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T07:58:26.283-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:05:17.716-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:03:58.945-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Platform section" operator="OR">
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Architecture independent section" operator="AND">
              <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="libapt-pkg-doc is earlier than 0.7.20.2+lenny1" test_ref="oval:org.mitre.oval:tst:18385"/>
                <criterion comment="apt-doc is earlier than 0.7.20.2+lenny1" test_ref="oval:org.mitre.oval:tst:18082"/>
              </criteria>
            </criteria>
            <criteria comment="Architecture dependent section" operator="AND">
              <criteria comment="Supported architectures section" operator="OR">
                <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
                <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
                <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
                <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
                <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
                <criterion comment="Installed architecture is armel" test_ref="oval:org.mitre.oval:tst:11101"/>
                <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
                <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
                <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
                <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
                <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
              </criteria>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="apt-utils DPKG is earlier than 0.7.20.2+lenny1" test_ref="oval:org.mitre.oval:tst:18142"/>
                <criterion comment="apt-transport-https DPKG is earlier than 0.7.20.2+lenny1" test_ref="oval:org.mitre.oval:tst:18992"/>
                <criterion comment="libapt-pkg-dev DPKG is earlier than 0.7.20.2+lenny1" test_ref="oval:org.mitre.oval:tst:18930"/>
                <criterion comment="apt DPKG is earlier than 0.7.20.2+lenny1" test_ref="oval:org.mitre.oval:tst:18712"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 4.0 is installed" definition_ref="oval:org.mitre.oval:def:6461"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Architecture independent section" operator="AND">
              <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="libapt-pkg-doc is earlier than 0.6.46.4-0.1+etch1" test_ref="oval:org.mitre.oval:tst:19094"/>
                <criterion comment="apt-doc is earlier than 0.6.46.4-0.1+etch1" test_ref="oval:org.mitre.oval:tst:18921"/>
              </criteria>
            </criteria>
            <criteria comment="Architecture dependent section" operator="AND">
              <criteria comment="Supported architectures section" operator="OR">
                <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
                <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
                <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
                <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
                <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
                <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
                <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
                <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
                <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
                <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
              </criteria>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="apt-utils DPKG is earlier than 0.6.46.4-0.1+etch1" test_ref="oval:org.mitre.oval:tst:18849"/>
                <criterion comment="libapt-pkg-dev DPKG is earlier than 0.6.46.4-0.1+etch1" test_ref="oval:org.mitre.oval:tst:19098"/>
                <criterion comment="apt DPKG is earlier than 0.6.46.4-0.1+etch1" test_ref="oval:org.mitre.oval:tst:19085"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:8262" class="patch">
      <metadata>
        <title>DSA-1741 psi -- integer overflow</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <product>psi</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2009/dsa-1741" ref_id="DSA-1741"/>
        <description>Jesus Olmos Gonzalez discovered that an integer overflow in the PSI Jabber client may lead to remote denial of service. The old stable distribution (etch) is not affected.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:12-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T08:00:00.082-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:05:17.377-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:03:58.594-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Release section" operator="AND">
        <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
        <criteria comment="Architecture section" operator="OR">
          <criteria comment="Architecture dependent section" operator="AND">
            <criteria comment="Supported architectures section" operator="OR">
              <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
              <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
              <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
              <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
              <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
              <criterion comment="Installed architecture is armel" test_ref="oval:org.mitre.oval:tst:11101"/>
              <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
              <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
              <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
              <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
              <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
              <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
            </criteria>
            <criteria comment="Packages section" operator="OR">
              <criterion comment="psi DPKG is earlier than 0.11-9" test_ref="oval:org.mitre.oval:tst:20057"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:8260" class="patch">
      <metadata>
        <title>DSA-1817 ctorrent -- stack-based buffer overflow</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <product>ctorrent</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2009/dsa-1817" ref_id="DSA-1817"/>
        <description>Michael Brooks discovered that ctorrent, a text-mode bittorrent client, does not verify the length of file paths in torrent files. An attacker can exploit this via a crafted torrent that contains a long file path to execute arbitrary code with the rights of the user opening the file. The oldstable distribution (etch) does not contain ctorrent.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:09-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T07:57:35.588-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:05:16.982-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:03:58.252-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Release section" operator="AND">
        <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
        <criteria comment="Architecture section" operator="OR">
          <criteria comment="Architecture dependent section" operator="AND">
            <criteria comment="Supported architectures section" operator="OR">
              <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
              <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
              <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
              <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
              <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
              <criterion comment="Installed architecture is armel" test_ref="oval:org.mitre.oval:tst:11101"/>
              <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
              <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
              <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
              <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
              <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
              <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
            </criteria>
            <criteria comment="Packages section" operator="OR">
              <criterion comment="ctorrent DPKG is earlier than 1.3.4-dnh3.2-1+lenny1" test_ref="oval:org.mitre.oval:tst:18425"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:8258" class="patch">
      <metadata>
        <title>DSA-1891 changetrack -- shell command execution</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <platform>Debian GNU/Linux 4.0</platform>
          <product>changetrack</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2009/dsa-1891" ref_id="DSA-1891"/>
        <description>Marek Grzybowski discovered that changetrack, a program to monitor changes to (configuration) files, is prone to shell command injection via metacharacters in filenames. The behaviour of the program has been adjusted to reject all filenames with metacharacters.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:12-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T08:00:20.353-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:05:16.749-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:03:57.963-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Platform section" operator="OR">
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Architecture independent section" operator="AND">
              <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criterion comment="changetrack is earlier than 4.3-3+lenny1" test_ref="oval:org.mitre.oval:tst:19869"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 4.0 is installed" definition_ref="oval:org.mitre.oval:def:6461"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Architecture independent section" operator="AND">
              <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criterion comment="changetrack is earlier than 4.3-3+etch1" test_ref="oval:org.mitre.oval:tst:19507"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:8256" class="patch">
      <metadata>
        <title>DSA-1771 clamav -- several vulnerabilities</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <platform>Debian GNU/Linux 4.0</platform>
          <product>clamav</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2009/dsa-1771" ref_id="DSA-1771"/>
        <description>Several vulnerabilities have been discovered in the ClamAV anti-virus toolkit: Attackers can cayse a denial of service (crash) via a crafted EXE file that triggers a divide-by-zero error. Attackers can cause a denial of service (infinite loop) via a crafted tar file that causes (1) clamd and (2) clamscan to hang. (no CVE Id yet) Attackers can cause a denial of service (crash) via a crafted EXE file that crashes the UPack unpacker.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:10-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T07:58:20.654-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:05:16.152-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:03:57.229-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Platform section" operator="OR">
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Architecture independent section" operator="AND">
              <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="clamav-docs is earlier than 0.94.dfsg.2-1lenny2" test_ref="oval:org.mitre.oval:tst:18614"/>
                <criterion comment="clamav-testfiles is earlier than 0.94.dfsg.2-1lenny2" test_ref="oval:org.mitre.oval:tst:18644"/>
                <criterion comment="clamav-base is earlier than 0.94.dfsg.2-1lenny2" test_ref="oval:org.mitre.oval:tst:18931"/>
              </criteria>
            </criteria>
            <criteria comment="Architecture dependent section" operator="AND">
              <criteria comment="Supported architectures section" operator="OR">
                <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
                <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
                <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
                <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
                <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
                <criterion comment="Installed architecture is armel" test_ref="oval:org.mitre.oval:tst:11101"/>
                <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
                <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
                <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
                <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
                <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
              </criteria>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="libclamav-dev DPKG is earlier than 0.94.dfsg.2-1lenny2" test_ref="oval:org.mitre.oval:tst:18964"/>
                <criterion comment="clamav DPKG is earlier than 0.94.dfsg.2-1lenny2" test_ref="oval:org.mitre.oval:tst:18946"/>
                <criterion comment="libclamav5 DPKG is earlier than 0.94.dfsg.2-1lenny2" test_ref="oval:org.mitre.oval:tst:18967"/>
                <criterion comment="clamav-dbg DPKG is earlier than 0.94.dfsg.2-1lenny2" test_ref="oval:org.mitre.oval:tst:18859"/>
                <criterion comment="clamav-daemon DPKG is earlier than 0.94.dfsg.2-1lenny2" test_ref="oval:org.mitre.oval:tst:18880"/>
                <criterion comment="clamav-milter DPKG is earlier than 0.94.dfsg.2-1lenny2" test_ref="oval:org.mitre.oval:tst:18391"/>
                <criterion comment="clamav-freshclam DPKG is earlier than 0.94.dfsg.2-1lenny2" test_ref="oval:org.mitre.oval:tst:18790"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 4.0 is installed" definition_ref="oval:org.mitre.oval:def:6461"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Architecture independent section" operator="AND">
              <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="clamav-docs is earlier than 0.90.1dfsg-4etch19" test_ref="oval:org.mitre.oval:tst:18191"/>
                <criterion comment="clamav-testfiles is earlier than 0.90.1dfsg-4etch19" test_ref="oval:org.mitre.oval:tst:18877"/>
                <criterion comment="clamav-base is earlier than 0.90.1dfsg-4etch19" test_ref="oval:org.mitre.oval:tst:18896"/>
              </criteria>
            </criteria>
            <criteria comment="Architecture dependent section" operator="AND">
              <criteria comment="Supported architectures section" operator="OR">
                <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
                <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
                <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
                <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
                <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
                <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
                <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
                <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
                <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
                <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
              </criteria>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="libclamav-dev DPKG is earlier than 0.90.1dfsg-4etch19" test_ref="oval:org.mitre.oval:tst:19054"/>
                <criterion comment="clamav DPKG is earlier than 0.90.1dfsg-4etch19" test_ref="oval:org.mitre.oval:tst:18476"/>
                <criterion comment="clamav-dbg DPKG is earlier than 0.90.1dfsg-4etch19" test_ref="oval:org.mitre.oval:tst:18968"/>
                <criterion comment="libclamav2 DPKG is earlier than 0.90.1dfsg-4etch19" test_ref="oval:org.mitre.oval:tst:19045"/>
                <criterion comment="clamav-daemon DPKG is earlier than 0.90.1dfsg-4etch19" test_ref="oval:org.mitre.oval:tst:18835"/>
                <criterion comment="clamav-milter DPKG is earlier than 0.90.1dfsg-4etch19" test_ref="oval:org.mitre.oval:tst:18544"/>
                <criterion comment="clamav-freshclam DPKG is earlier than 0.90.1dfsg-4etch19" test_ref="oval:org.mitre.oval:tst:18754"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:8254" class="patch">
      <metadata>
        <title>DSA-1819 vlc -- several vulnerabilities</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 4.0</platform>
          <product>vlc</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2009/dsa-1819" ref_id="DSA-1819"/>
        <description>Several vulnerabilities have been discovered in vlc, a multimedia player and streamer. The Common Vulnerabilities and Exposures project identifies the following problems: Drew Yao discovered that multiple integer overflows in the MP4 demuxer, Real demuxer and Cinepak codec can lead to the execution of arbitrary code. Drew Yao discovered that the Cinepak codec is prone to a memory corruption, which can be triggered by a crafted Cinepak file. Luigi Auriemma discovered that it is possible to execute arbitrary code via a long subtitle in an SSA file. It was discovered that vlc is prone to a search path vulnerability, which allows local users to perform privilege escalations. Alin Rad Pop discovered that it is possible to execute arbitrary code when opening a WAV file containing a large fmt chunk. PÃ?nar Yanarda discovered that it is possible to execute arbitrary code when opening a crafted mmst link. Tobias Klein discovered that it is possible to execute arbitrary code when opening a crafted .ty file. Tobias Klein discovered that it is possible to execute arbitrary code when opening an invalid CUE image file with a crafted header.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:10-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T07:57:50.565-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:05:15.512-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:03:56.821-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Release section" operator="AND">
        <extend_definition comment="Debian 4.0 is installed" definition_ref="oval:org.mitre.oval:def:6461"/>
        <criteria comment="Architecture section" operator="OR">
          <criteria comment="Architecture independent section" operator="AND">
            <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
            <criteria comment="Packages section" operator="OR">
              <criterion comment="wxvlc is earlier than 0.8.6-svn20061012.debian-5.1+etch3" test_ref="oval:org.mitre.oval:tst:18606"/>
              <criterion comment="vlc-plugin-alsa is earlier than 0.8.6-svn20061012.debian-5.1+etch3" test_ref="oval:org.mitre.oval:tst:18237"/>
            </criteria>
          </criteria>
          <criteria comment="Packages section" operator="OR">
            <criterion comment="vlc-plugin-arts DPKG is earlier than 0.8.6-svn20061012.debian-5.1+etch3" test_ref="oval:org.mitre.oval:tst:18005"/>
            <criterion comment="vlc DPKG is earlier than 0.8.6-svn20061012.debian-5.1+etch3" test_ref="oval:org.mitre.oval:tst:18694"/>
            <criterion comment="mozilla-plugin-vlc DPKG is earlier than 0.8.6-svn20061012.debian-5.1+etch3" test_ref="oval:org.mitre.oval:tst:18312"/>
            <criterion comment="vlc-plugin-ggi DPKG is earlier than 0.8.6-svn20061012.debian-5.1+etch3" test_ref="oval:org.mitre.oval:tst:18516"/>
            <criterion comment="vlc-plugin-esd DPKG is earlier than 0.8.6-svn20061012.debian-5.1+etch3" test_ref="oval:org.mitre.oval:tst:18379"/>
            <criterion comment="libvlc0-dev DPKG is earlier than 0.8.6-svn20061012.debian-5.1+etch3" test_ref="oval:org.mitre.oval:tst:18696"/>
            <criterion comment="libvlc0 DPKG is earlier than 0.8.6-svn20061012.debian-5.1+etch3" test_ref="oval:org.mitre.oval:tst:18054"/>
            <criterion comment="vlc-nox DPKG is earlier than 0.8.6-svn20061012.debian-5.1+etch3" test_ref="oval:org.mitre.oval:tst:18675"/>
            <criterion comment="vlc-plugin-sdl DPKG is earlier than 0.8.6-svn20061012.debian-5.1+etch3" test_ref="oval:org.mitre.oval:tst:18752"/>
          </criteria>
          <criteria comment="Architecture dependent section" operator="AND">
            <criteria comment="Supported architectures section" operator="OR">
              <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
            </criteria>
            <criteria comment="Packages section" operator="OR">
              <criterion comment="vlc-plugin-glide DPKG is earlier than 0.8.6-svn20061012.debian-5.1+etch3" test_ref="oval:org.mitre.oval:tst:18558"/>
              <criterion comment="vlc-plugin-svgalib DPKG is earlier than 0.8.6-svn20061012.debian-5.1+etch3" test_ref="oval:org.mitre.oval:tst:18620"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:8252" class="patch">
      <metadata>
        <title>DSA-1559 phpgedview -- insufficient input sanitising</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 4.0</platform>
          <product>phpgedview</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2008/dsa-1559" ref_id="DSA-1559"/>
        <description>It was discovered that phpGedView, an application to provide online access to genealogical data, performed insufficient input sanitising on some parameters, making it vulnerable to cross site scripting.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:10-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T07:58:41.197-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:05:15.198-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:03:56.568-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Release section" operator="AND">
        <extend_definition comment="Debian 4.0 is installed" definition_ref="oval:org.mitre.oval:def:6461"/>
        <criteria comment="Architecture section" operator="OR">
          <criteria comment="Architecture independent section" operator="AND">
            <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
            <criteria comment="Packages section" operator="OR">
              <criterion comment="phpgedview-places is earlier than 4.0.2.dfsg-3" test_ref="oval:org.mitre.oval:tst:19081"/>
              <criterion comment="phpgedview-languages is earlier than 4.0.2.dfsg-3" test_ref="oval:org.mitre.oval:tst:19179"/>
              <criterion comment="phpgedview is earlier than 4.0.2.dfsg-3" test_ref="oval:org.mitre.oval:tst:18960"/>
              <criterion comment="phpgedview-themes is earlier than 4.0.2.dfsg-3" test_ref="oval:org.mitre.oval:tst:19195"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:8251" class="patch">
      <metadata>
        <title>DSA-1560 kronolith2 -- insufficient input sanitising</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 4.0</platform>
          <product>kronolith2</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2008/dsa-1560" ref_id="DSA-1560"/>
        <description>"The-0utl4w" discovered that the Kronolith, calendar component for the Horde Framework, didn't properly sanitise URL input, leading to a cross-site scripting vulnerability in the add event screen.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:12-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T08:00:28.140-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:05:14.831-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:03:56.357-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Release section" operator="AND">
        <extend_definition comment="Debian 4.0 is installed" definition_ref="oval:org.mitre.oval:def:6461"/>
        <criteria comment="Architecture section" operator="OR">
          <criteria comment="Architecture independent section" operator="AND">
            <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
            <criterion comment="kronolith2 is earlier than 2.1.4-1etch1" test_ref="oval:org.mitre.oval:tst:19974"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:8247" class="patch">
      <metadata>
        <title>DSA-1527 debian-goodies -- insufficient input sanitising</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 4.0</platform>
          <platform>Debian GNU/Linux 3.1</platform>
          <product>debian-goodies</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2008/dsa-1527" ref_id="DSA-1527"/>
        <description>Thomas de Grenier de Latour discovered that the checkrestart tool in the debian-goodies suite of utilities, allowed local users to gain privileges via shell metacharacters in the name of the executable file for a running process.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:11-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T07:59:02.304-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:05:14.535-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:03:55.841-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Platform section" operator="OR">
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 4.0 is installed" definition_ref="oval:org.mitre.oval:def:6461"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Architecture independent section" operator="AND">
              <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criterion comment="debian-goodies is earlier than 0.27+etch1" test_ref="oval:org.mitre.oval:tst:18838"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 3.1 is installed" definition_ref="oval:org.mitre.oval:def:7692"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Architecture independent section" operator="AND">
              <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criterion comment="debian-goodies is earlier than 0.23+sarge1" test_ref="oval:org.mitre.oval:tst:19128"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:8245" class="patch">
      <metadata>
        <title>DSA-1806 cscope -- buffer overflows</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <product>cscope</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2009/dsa-1806" ref_id="DSA-1806"/>
        <description>Matt Murphy discovered that cscope, a source code browsing tool, does not verify the length of file names sourced in include statements, which may potentially lead to the execution of arbitrary code through specially crafted source code files.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:13-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T08:00:41.564-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:05:14.121-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:03:55.500-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Release section" operator="AND">
        <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
        <criteria comment="Architecture section" operator="OR">
          <criteria comment="Architecture dependent section" operator="AND">
            <criteria comment="Supported architectures section" operator="OR">
              <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
              <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
              <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
              <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
              <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
              <criterion comment="Installed architecture is armel" test_ref="oval:org.mitre.oval:tst:11101"/>
              <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
              <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
              <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
              <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
              <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
              <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
            </criteria>
            <criteria comment="Packages section" operator="OR">
              <criterion comment="cscope DPKG is earlier than 15.6-6+lenny1" test_ref="oval:org.mitre.oval:tst:20472"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:8243" class="patch">
      <metadata>
        <title>DSA-1511 libicu -- various</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 4.0</platform>
          <product>libicu</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2008/dsa-1511" ref_id="DSA-1511"/>
        <description>Several local vulnerabilities have been discovered in libicu, International Components for Unicode, The Common Vulnerabilities and Exposures project identifies the following problems: libicu in International Components for Unicode (ICU) 3.8.1 and earlier attempts to process backreferences to the nonexistent capture group zero (aka \0), which might allow context-dependent attackers to read from, or write to, out-of-bounds memory locations, related to corruption of REStackFrames. Heap-based buffer overflow in the doInterval function in regexcmp.cpp in libicu in International Components for Unicode (ICU) 3.8.1 and earlier allows context-dependent attackers to cause a denial of service (memory consumption) and possibly have unspecified other impact via a regular expression that writes a large amount of data to the backtracking stack.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:09-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T07:57:25.514-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:05:13.524-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:03:55.140-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Release section" operator="AND">
        <extend_definition comment="Debian 4.0 is installed" definition_ref="oval:org.mitre.oval:def:6461"/>
        <criteria comment="Architecture section" operator="OR">
          <criteria comment="Architecture independent section" operator="AND">
            <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
            <criterion comment="icu-doc is earlier than 3.6-2etch1" test_ref="oval:org.mitre.oval:tst:18260"/>
          </criteria>
          <criteria comment="Architecture dependent section" operator="AND">
            <criteria comment="Supported architectures section" operator="OR">
              <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
              <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
              <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
              <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
              <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
              <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
              <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
              <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
              <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
              <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
            </criteria>
            <criteria comment="Packages section" operator="OR">
              <criterion comment="libicu36-dev DPKG is earlier than 3.6-2etch1" test_ref="oval:org.mitre.oval:tst:18368"/>
              <criterion comment="libicu36 DPKG is earlier than 3.6-2etch1" test_ref="oval:org.mitre.oval:tst:18467"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:8241" class="patch">
      <metadata>
        <title>DSA-1642 horde3 -- cross site scripting</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 4.0</platform>
          <product>horde3</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2008/dsa-1642" ref_id="DSA-1642"/>
        <description>Will Drewry discovered that Horde allows remote attackers to send an email with a crafted MIME attachment filename attribute to perform cross site scripting.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:09-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T07:57:16.736-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:05:12.878-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:03:54.856-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Release section" operator="AND">
        <extend_definition comment="Debian 4.0 is installed" definition_ref="oval:org.mitre.oval:def:6461"/>
        <criteria comment="Architecture section" operator="OR">
          <criteria comment="Architecture independent section" operator="AND">
            <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
            <criterion comment="horde3 is earlier than 3.1.3-4etch4" test_ref="oval:org.mitre.oval:tst:18354"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:8239" class="patch">
      <metadata>
        <title>DSA-1775 php-json-ext -- denial of service</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 4.0</platform>
          <product>php-json-ext</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2009/dsa-1775" ref_id="DSA-1775"/>
        <description>It was discovered that php-json-ext, a JSON serialiser for PHP, is prone to a denial of service attack, when receiving a malformed string via the json_decode function.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:10-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T07:58:14.319-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:05:11.978-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:03:54.646-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Release section" operator="AND">
        <extend_definition comment="Debian 4.0 is installed" definition_ref="oval:org.mitre.oval:def:6461"/>
        <criteria comment="Architecture section" operator="OR">
          <criteria comment="Packages section" operator="OR">
            <criterion comment="php5-json DPKG is earlier than 1.2.1-3.2+etch1" test_ref="oval:org.mitre.oval:tst:18886"/>
            <criterion comment="php4-json DPKG is earlier than 1.2.1-3.2+etch1" test_ref="oval:org.mitre.oval:tst:18479"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:8237" class="patch">
      <metadata>
        <title>DSA-1673 wireshark -- several vulnerabilities</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 4.0</platform>
          <product>wireshark</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2008/dsa-1673" ref_id="DSA-1673"/>
        <description>Several remote vulnerabilities have been discovered in network traffic analyzer Wireshark. The Common Vulnerabilities and Exposures project identifies the following problems: The GSM SMS dissector is vulnerable to denial of service. The PANA and KISMET dissectors are vulnerable to denial of service. The RMI dissector could disclose system memory. The packet reassembling module is vulnerable to denial of service. The zlib uncompression module is vulnerable to denial of service. The Bluetooth ACL dissector is vulnerable to denial of service. The PRP and MATE dissectors are vulnerable to denial of service. The Q931 dissector is vulnerable to denial of service.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:10-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T07:58:35.769-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:05:11.554-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:03:54.364-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Release section" operator="AND">
        <extend_definition comment="Debian 4.0 is installed" definition_ref="oval:org.mitre.oval:def:6461"/>
        <criteria comment="Architecture section" operator="OR">
          <criteria comment="Packages section" operator="OR">
            <criterion comment="wireshark-dev DPKG is earlier than 0.99.4-5.etch.3" test_ref="oval:org.mitre.oval:tst:19130"/>
            <criterion comment="tshark DPKG is earlier than 0.99.4-5.etch.3" test_ref="oval:org.mitre.oval:tst:19164"/>
            <criterion comment="ethereal-dev DPKG is earlier than 0.99.4-5.etch.3" test_ref="oval:org.mitre.oval:tst:18212"/>
            <criterion comment="tethereal DPKG is earlier than 0.99.4-5.etch.3" test_ref="oval:org.mitre.oval:tst:19088"/>
            <criterion comment="wireshark-common DPKG is earlier than 0.99.4-5.etch.3" test_ref="oval:org.mitre.oval:tst:18564"/>
            <criterion comment="ethereal DPKG is earlier than 0.99.4-5.etch.3" test_ref="oval:org.mitre.oval:tst:19204"/>
            <criterion comment="ethereal-common DPKG is earlier than 0.99.4-5.etch.3" test_ref="oval:org.mitre.oval:tst:18979"/>
            <criterion comment="wireshark DPKG is earlier than 0.99.4-5.etch.3" test_ref="oval:org.mitre.oval:tst:18453"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:8236" class="patch">
      <metadata>
        <title>DSA-1550 suphp -- programming error</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 4.0</platform>
          <product>suphp</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2008/dsa-1550" ref_id="DSA-1550"/>
        <description>It was discovered that suphp, an Apache module to run PHP scripts with owner permissions handles symlinks insecurely, which may lead to privilege escalation by local users.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:10-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T07:58:37.193-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:05:11.187-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:03:53.986-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Release section" operator="AND">
        <extend_definition comment="Debian 4.0 is installed" definition_ref="oval:org.mitre.oval:def:6461"/>
        <criteria comment="Architecture section" operator="OR">
          <criteria comment="Architecture dependent section" operator="AND">
            <criteria comment="Supported architectures section" operator="OR">
              <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
              <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
              <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
              <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
              <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
              <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
              <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
              <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
              <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
              <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
            </criteria>
            <criteria comment="Packages section" operator="OR">
              <criterion comment="libapache-mod-suphp DPKG is earlier than 0.6.2-1+etch0" test_ref="oval:org.mitre.oval:tst:19095"/>
              <criterion comment="suphp-common DPKG is earlier than 0.6.2-1+etch0" test_ref="oval:org.mitre.oval:tst:18359"/>
              <criterion comment="libapache2-mod-suphp DPKG is earlier than 0.6.2-1+etch0" test_ref="oval:org.mitre.oval:tst:18900"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:8234" class="patch">
      <metadata>
        <title>DSA-1636 linux-2.6.24 -- denial of service/information leak</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 4.0</platform>
          <product>linux-2.6.24</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2008/dsa-1636" ref_id="DSA-1636"/>
        <description>Several vulnerabilities have been discovered in the Linux kernel that may lead to a denial of service or leak sensitive data. The Common Vulnerabilities and Exposures project identifies the following problems: Tobias Klein reported a locally exploitable data leak in the snd_seq_oss_synth_make_info() function. This may allow local users to gain access to sensitive information. Zoltan Sogor discovered a coding error in the VFS that allows local users to exploit a kernel memory leak resulting in a denial of service. Eugene Teo reported an integer overflow in the DCCP subsystem that may allow remote attackers to cause a denial of service in the form of a kernel panic. Eugene Teo reported a missing bounds check in the SCTP subsystem. By exploiting an integer overflow in the SCTP_AUTH_KEY handling code, remote attackers may be able to cause a denial of service in the form of a kernel panic. Kel Modderman reported an issue in the tmpfs filesystem that allows local users to crash a system by triggering a kernel BUG() assertion. Alexey Dobriyan discovered an off-by-one-error in the iov_iter_advance function which can be exploited by local users to crash a system, resulting in a denial of service. Vlad Yasevich reported several NULL pointer reference conditions in the SCTP subsystem that can be triggered by entering sctp-auth codepaths when the AUTH feature is inactive. This may allow attackers to cause a denial of service condition via a system panic. Johann Dahm and David Richter reported an issue in the nfsd subsystem that may allow remote attackers to cause a denial of service via a buffer overflow.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:11-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T07:59:26.448-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:05:10.424-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:03:53.386-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Release section" operator="AND">
        <extend_definition comment="Debian 4.0 is installed" definition_ref="oval:org.mitre.oval:def:6461"/>
        <criteria comment="Architecture section" operator="OR">
          <criteria comment="Architecture independent section" operator="AND">
            <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
            <criteria comment="Packages section" operator="OR">
              <criterion comment="linux-patch-debian-2.6.24 is earlier than 2.6.24-6~etchnhalf.5" test_ref="oval:org.mitre.oval:tst:19309"/>
              <criterion comment="linux-support-2.6.24-etchnhalf.1 is earlier than 2.6.24-6~etchnhalf.5" test_ref="oval:org.mitre.oval:tst:19003"/>
              <criterion comment="linux-doc-2.6.24 is earlier than 2.6.24-6~etchnhalf.5" test_ref="oval:org.mitre.oval:tst:18976"/>
              <criterion comment="linux-tree-2.6.24 is earlier than 2.6.24-6~etchnhalf.5" test_ref="oval:org.mitre.oval:tst:18953"/>
              <criterion comment="linux-source-2.6.24 is earlier than 2.6.24-6~etchnhalf.5" test_ref="oval:org.mitre.oval:tst:19018"/>
              <criterion comment="linux-manual-2.6.24 is earlier than 2.6.24-6~etchnhalf.5" test_ref="oval:org.mitre.oval:tst:19390"/>
            </criteria>
          </criteria>
          <criteria comment="Architecture dependent section" operator="AND">
            <criteria comment="Supported architectures section" operator="OR">
              <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
            </criteria>
            <criteria comment="Packages section" operator="OR">
              <criterion comment="linux-image-2.6.24-etchnhalf.1-s390x DPKG is earlier than 2.6.24-6~etchnhalf.5" test_ref="oval:org.mitre.oval:tst:18833"/>
              <criterion comment="linux-headers-2.6.24-etchnhalf.1-s390 DPKG is earlier than 2.6.24-6~etchnhalf.5" test_ref="oval:org.mitre.oval:tst:19343"/>
              <criterion comment="linux-headers-2.6.24-etchnhalf.1-all-s390 DPKG is earlier than 2.6.24-6~etchnhalf.5" test_ref="oval:org.mitre.oval:tst:19403"/>
              <criterion comment="linux-image-2.6.24-etchnhalf.1-s390 DPKG is earlier than 2.6.24-6~etchnhalf.5" test_ref="oval:org.mitre.oval:tst:19240"/>
              <criterion comment="linux-image-2.6.24-etchnhalf.1-s390-tape DPKG is earlier than 2.6.24-6~etchnhalf.5" test_ref="oval:org.mitre.oval:tst:19209"/>
              <criterion comment="linux-headers-2.6.24-etchnhalf.1-all DPKG is earlier than 2.6.24-6~etchnhalf.5" test_ref="oval:org.mitre.oval:tst:19000"/>
              <criterion comment="linux-headers-2.6.24-etchnhalf.1-common DPKG is earlier than 2.6.24-6~etchnhalf.5" test_ref="oval:org.mitre.oval:tst:19444"/>
              <criterion comment="linux-headers-2.6.24-etchnhalf.1-s390x DPKG is earlier than 2.6.24-6~etchnhalf.5" test_ref="oval:org.mitre.oval:tst:19401"/>
            </criteria>
          </criteria>
          <criteria comment="Architecture dependent section" operator="AND">
            <criteria comment="Supported architectures section" operator="OR">
              <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
              <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
            </criteria>
            <criteria comment="Packages section" operator="OR">
              <criterion comment="linux-headers-2.6.24-etchnhalf.1-amd64 DPKG is earlier than 2.6.24-6~etchnhalf.5" test_ref="oval:org.mitre.oval:tst:19491"/>
              <criterion comment="linux-headers-2.6.24-etchnhalf.1-common DPKG is earlier than 2.6.24-6~etchnhalf.5" test_ref="oval:org.mitre.oval:tst:19449"/>
              <criterion comment="linux-image-2.6.24-etchnhalf.1-amd64 DPKG is earlier than 2.6.24-6~etchnhalf.5" test_ref="oval:org.mitre.oval:tst:19332"/>
              <criterion comment="linux-headers-2.6.24-etchnhalf.1-all DPKG is earlier than 2.6.24-6~etchnhalf.5" test_ref="oval:org.mitre.oval:tst:19314"/>
            </criteria>
          </criteria>
          <criteria comment="Architecture depended section" operator="AND">
            <criteria comment="Supported platform section" operator="AND">
              <criterion comment="hppa architecture" test_ref="oval:org.mitre.oval:tst:11164"/>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="linux-image-2.6.24-etchnhalf.1-parisc64 DPKG is earlier than 2.6.24-6~etchnhalf.5" test_ref="oval:org.mitre.oval:tst:19198"/>
                <criterion comment="linux-image-2.6.24-etchnhalf.1-parisc-smp DPKG is earlier than 2.6.24-6~etchnhalf.5" test_ref="oval:org.mitre.oval:tst:19544"/>
                <criterion comment="linux-headers-2.6.24-etchnhalf.1-parisc-smp DPKG is earlier than 2.6.24-6~etchnhalf.5" test_ref="oval:org.mitre.oval:tst:19267"/>
                <criterion comment="linux-headers-2.6.24-etchnhalf.1-parisc64 DPKG is earlier than 2.6.24-6~etchnhalf.5" test_ref="oval:org.mitre.oval:tst:19572"/>
                <criterion comment="linux-image-2.6.24-etchnhalf.1-parisc DPKG is earlier than 2.6.24-6~etchnhalf.5" test_ref="oval:org.mitre.oval:tst:19512"/>
                <criterion comment="linux-headers-2.6.24-etchnhalf.1-all-hppa DPKG is earlier than 2.6.24-6~etchnhalf.5" test_ref="oval:org.mitre.oval:tst:19584"/>
                <criterion comment="linux-image-2.6.24-etchnhalf.1-parisc64-smp DPKG is earlier than 2.6.24-6~etchnhalf.5" test_ref="oval:org.mitre.oval:tst:18996"/>
                <criterion comment="linux-headers-2.6.24-etchnhalf.1-parisc64-smp DPKG is earlier than 2.6.24-6~etchnhalf.5" test_ref="oval:org.mitre.oval:tst:19391"/>
                <criterion comment="linux-headers-2.6.24-etchnhalf.1-all DPKG is earlier than 2.6.24-6~etchnhalf.5" test_ref="oval:org.mitre.oval:tst:19588"/>
                <criterion comment="linux-headers-2.6.24-etchnhalf.1-common DPKG is earlier than 2.6.24-6~etchnhalf.5" test_ref="oval:org.mitre.oval:tst:19497"/>
                <criterion comment="linux-headers-2.6.24-etchnhalf.1-parisc DPKG is earlier than 2.6.24-6~etchnhalf.5" test_ref="oval:org.mitre.oval:tst:19541"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:8233" class="patch">
      <metadata>
        <title>DSA-1725 websvn -- programming error</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <product>websvn</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2009/dsa-1725" ref_id="DSA-1725"/>
        <description>Bas van Schaik discovered that WebSVN, a tool to view Subversion repositories over the web, did not properly restrict access to private repositories, allowing a remote attacker to read significant parts of their content. The old stable distribution (etch) is not affected by this problem.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:08-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T07:56:31.123-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:05:10.077-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:03:53.162-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Release section" operator="AND">
        <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
        <criteria comment="Architecture section" operator="OR">
          <criteria comment="Architecture independent section" operator="AND">
            <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
            <criterion comment="websvn is earlier than 2.0-4+lenny1" test_ref="oval:org.mitre.oval:tst:17582"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:8232" class="patch">
      <metadata>
        <title>DSA-1515 libnet-dns-perl -- several vulnerabilities</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 4.0</platform>
          <platform>Debian GNU/Linux 3.1</platform>
          <product>libnet-dns-perl</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2008/dsa-1515" ref_id="DSA-1515"/>
        <description>Several remote vulnerabilities have been discovered in libnet-dns-perl. The Common Vulnerabilities and Exposures project identifies the following problems: It was discovered that libnet-dns-perl generates very weak transaction IDs when sending queries (CVE-2007-3377). This update switches transaction ID generation to the Perl random generator, making prediction attacks more difficult. Compression loops in domain names resulted in an infinite loop in the domain name expander written in Perl (CVE-2007-3409). The Debian package uses an expander written in C by default, but this vulnerability has been addressed nevertheless. Decoding malformed A records could lead to a crash (via an uncaught Perl exception) of certain applications using libnet-dns-perl (CVE-2007-6341).</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:09-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T07:57:23.621-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:05:09.725-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:03:52.874-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Platform section" operator="OR">
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 4.0 is installed" definition_ref="oval:org.mitre.oval:def:6461"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Packages section" operator="OR">
              <criterion comment="libnet-dns-perl DPKG is earlier than 0.59-1etch1" test_ref="oval:org.mitre.oval:tst:18130"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 3.1 is installed" definition_ref="oval:org.mitre.oval:def:7692"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Packages section" operator="OR">
              <criterion comment="libnet-dns-perl DPKG is earlier than 0.48-1sarge1" test_ref="oval:org.mitre.oval:tst:18389"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:8231" class="patch">
      <metadata>
        <title>DSA-1677 cupsys -- integer overflow</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 4.0</platform>
          <product>cupsys</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2008/dsa-1677" ref_id="DSA-1677"/>
        <description>An integer overflow has been discovered in the image validation code of cupsys, the Common UNIX Printing System. An attacker could trigger this bug by supplying a malicious graphic that could lead to the execution of arbitrary code.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:10-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T07:58:32.901-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:05:09.348-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:03:52.539-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Release section" operator="AND">
        <extend_definition comment="Debian 4.0 is installed" definition_ref="oval:org.mitre.oval:def:6461"/>
        <criteria comment="Architecture section" operator="OR">
          <criteria comment="Architecture independent section" operator="AND">
            <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
            <criteria comment="Packages section" operator="OR">
              <criterion comment="libcupsys2-gnutls10 is earlier than 1.2.7-4etch6" test_ref="oval:org.mitre.oval:tst:18605"/>
              <criterion comment="cupsys-common is earlier than 1.2.7-4etch6" test_ref="oval:org.mitre.oval:tst:18715"/>
            </criteria>
          </criteria>
          <criteria comment="Packages section" operator="OR">
            <criterion comment="cupsys-bsd DPKG is earlier than 1.2.7-4etch6" test_ref="oval:org.mitre.oval:tst:18529"/>
            <criterion comment="cupsys-client DPKG is earlier than 1.2.7-4etch6" test_ref="oval:org.mitre.oval:tst:19167"/>
            <criterion comment="libcupsys2-dev DPKG is earlier than 1.2.7-4etch6" test_ref="oval:org.mitre.oval:tst:19059"/>
            <criterion comment="libcupsimage2-dev DPKG is earlier than 1.2.7-4etch6" test_ref="oval:org.mitre.oval:tst:18358"/>
            <criterion comment="libcupsimage2 DPKG is earlier than 1.2.7-4etch6" test_ref="oval:org.mitre.oval:tst:19142"/>
            <criterion comment="cupsys-dbg DPKG is earlier than 1.2.7-4etch6" test_ref="oval:org.mitre.oval:tst:18643"/>
            <criterion comment="cupsys DPKG is earlier than 1.2.7-4etch6" test_ref="oval:org.mitre.oval:tst:19171"/>
            <criterion comment="libcupsys2 DPKG is earlier than 1.2.7-4etch6" test_ref="oval:org.mitre.oval:tst:18949"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:8230" class="patch">
      <metadata>
        <title>DSA-1933 cups -- missing input sanitising</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <platform>Debian GNU/Linux 4.0</platform>
          <product>cups</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2009/dsa-1933" ref_id="DSA-1933"/>
        <description>Aaron Siegel discovered that the web interface of cups, the Common UNIX Printing System, is prone to cross-site scripting attacks.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:11-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T07:59:06.967-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:05:08.584-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:03:51.819-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Platform section" operator="OR">
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Architecture independent section" operator="AND">
              <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="cupsys-bsd is earlier than 1.3.8-1+lenny7" test_ref="oval:org.mitre.oval:tst:19285"/>
                <criterion comment="cupsys-client is earlier than 1.3.8-1+lenny7" test_ref="oval:org.mitre.oval:tst:19331"/>
                <criterion comment="libcupsys2-dev is earlier than 1.3.8-1+lenny7" test_ref="oval:org.mitre.oval:tst:19275"/>
                <criterion comment="cupsys-common is earlier than 1.3.8-1+lenny7" test_ref="oval:org.mitre.oval:tst:18394"/>
                <criterion comment="cups-common is earlier than 1.3.8-1+lenny7" test_ref="oval:org.mitre.oval:tst:19068"/>
                <criterion comment="cupsys-dbg is earlier than 1.3.8-1+lenny7" test_ref="oval:org.mitre.oval:tst:19155"/>
                <criterion comment="cupsys is earlier than 1.3.8-1+lenny7" test_ref="oval:org.mitre.oval:tst:18634"/>
                <criterion comment="libcupsys2 is earlier than 1.3.8-1+lenny7" test_ref="oval:org.mitre.oval:tst:19225"/>
              </criteria>
            </criteria>
            <criteria comment="Architecture dependent section" operator="AND">
              <criteria comment="Supported architectures section" operator="OR">
                <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
                <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
                <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
                <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
                <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
                <criterion comment="Installed architecture is armel" test_ref="oval:org.mitre.oval:tst:11101"/>
                <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
                <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
                <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
                <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
                <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
                <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
              </criteria>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="libcups2-dev DPKG is earlier than 1.3.8-1+lenny7" test_ref="oval:org.mitre.oval:tst:19271"/>
                <criterion comment="cups-bsd DPKG is earlier than 1.3.8-1+lenny7" test_ref="oval:org.mitre.oval:tst:18902"/>
                <criterion comment="libcupsimage2-dev DPKG is earlier than 1.3.8-1+lenny7" test_ref="oval:org.mitre.oval:tst:19311"/>
                <criterion comment="libcupsimage2 DPKG is earlier than 1.3.8-1+lenny7" test_ref="oval:org.mitre.oval:tst:19104"/>
                <criterion comment="cups-client DPKG is earlier than 1.3.8-1+lenny7" test_ref="oval:org.mitre.oval:tst:18803"/>
                <criterion comment="libcups2 DPKG is earlier than 1.3.8-1+lenny7" test_ref="oval:org.mitre.oval:tst:18969"/>
                <criterion comment="cups-dbg DPKG is earlier than 1.3.8-1+lenny7" test_ref="oval:org.mitre.oval:tst:18490"/>
                <criterion comment="cups DPKG is earlier than 1.3.8-1+lenny7" test_ref="oval:org.mitre.oval:tst:19288"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 4.0 is installed" definition_ref="oval:org.mitre.oval:def:6461"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Architecture independent section" operator="AND">
              <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="libcupsys2-gnutls10 is earlier than 1.2.7-4+etch9" test_ref="oval:org.mitre.oval:tst:19318"/>
                <criterion comment="cupsys-common is earlier than 1.2.7-4+etch9" test_ref="oval:org.mitre.oval:tst:19277"/>
              </criteria>
            </criteria>
            <criteria comment="Packages section" operator="OR">
              <criterion comment="cupsys-bsd DPKG is earlier than 1.2.7-4+etch9" test_ref="oval:org.mitre.oval:tst:18483"/>
              <criterion comment="cupsys-client DPKG is earlier than 1.2.7-4+etch9" test_ref="oval:org.mitre.oval:tst:19310"/>
              <criterion comment="libcupsys2-dev DPKG is earlier than 1.2.7-4+etch9" test_ref="oval:org.mitre.oval:tst:18521"/>
              <criterion comment="libcupsimage2-dev DPKG is earlier than 1.2.7-4+etch9" test_ref="oval:org.mitre.oval:tst:18729"/>
              <criterion comment="libcupsimage2 DPKG is earlier than 1.2.7-4+etch9" test_ref="oval:org.mitre.oval:tst:19125"/>
              <criterion comment="cupsys-dbg DPKG is earlier than 1.2.7-4+etch9" test_ref="oval:org.mitre.oval:tst:18534"/>
              <criterion comment="cupsys DPKG is earlier than 1.2.7-4+etch9" test_ref="oval:org.mitre.oval:tst:19342"/>
              <criterion comment="libcupsys2 DPKG is earlier than 1.2.7-4+etch9" test_ref="oval:org.mitre.oval:tst:18575"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:8229" class="patch">
      <metadata>
        <title>DSA-1522 unzip -- programming error</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 4.0</platform>
          <platform>Debian GNU/Linux 3.1</platform>
          <product>unzip</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2008/dsa-1522" ref_id="DSA-1522"/>
        <description>Tavis Ormandy discovered that unzip, when processing specially crafted ZIP archives, could pass invalid pointers to the C library"s free routine, potentially leading to arbitrary code execution (CVE-2008-0888).</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:11-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T07:59:03.954-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:05:08.290-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:03:51.571-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Platform section" operator="OR">
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 4.0 is installed" definition_ref="oval:org.mitre.oval:def:6461"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Packages section" operator="OR">
              <criterion comment="unzip DPKG is earlier than 5.52-9etch1" test_ref="oval:org.mitre.oval:tst:18477"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 3.1 is installed" definition_ref="oval:org.mitre.oval:def:7692"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Packages section" operator="OR">
              <criterion comment="unzip DPKG is earlier than 5.52-1sarge5" test_ref="oval:org.mitre.oval:tst:19316"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:8226" class="patch">
      <metadata>
        <title>DSA-1448 eggdrop -- buffer overflow</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 4.0</platform>
          <platform>Debian GNU/Linux 3.1</platform>
          <product>eggdrop</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2008/dsa-1448" ref_id="DSA-1448"/>
        <description>It was discovered that eggdrop, an advanced IRC robot, was vulnerable to a buffer overflow which could result in a remote user executing arbitrary code.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:13-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T08:00:37.102-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:05:07.916-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:03:51.301-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Platform section" operator="OR">
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 4.0 is installed" definition_ref="oval:org.mitre.oval:def:6461"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Architecture independent section" operator="AND">
              <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criterion comment="eggdrop-data is earlier than 1.6.18-1etch1" test_ref="oval:org.mitre.oval:tst:19932"/>
            </criteria>
            <criteria comment="Packages section" operator="OR">
              <criterion comment="eggdrop DPKG is earlier than 1.6.18-1etch1" test_ref="oval:org.mitre.oval:tst:20048"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 3.1 is installed" definition_ref="oval:org.mitre.oval:def:7692"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Architecture independent section" operator="AND">
              <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criterion comment="eggdrop-data is earlier than 1.6.17-3sarge1" test_ref="oval:org.mitre.oval:tst:19800"/>
            </criteria>
            <criteria comment="Packages section" operator="OR">
              <criterion comment="eggdrop DPKG is earlier than 1.6.17-3sarge1" test_ref="oval:org.mitre.oval:tst:20264"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:8225" class="patch">
      <metadata>
        <title>DSA-1936 libgd2 -- several vulnerabilities</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <platform>Debian GNU/Linux 4.0</platform>
          <product>libgd2</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2009/dsa-1936" ref_id="DSA-1936"/>
        <description>Several vulnerabilities have been discovered in libgd2, a library for programmatic graphics creation and manipulation. The Common Vulnerabilities and Exposures project identifies the following problems: Kees Cook discovered a buffer overflow in libgd2"s font renderer. An attacker could cause denial of service (application crash) and possibly execute arbitrary code via a crafted string with a JIS encoded font. This issue only affects the oldstable distribution (etch). Tomas Hoger discovered a boundary error in the "_gdGetColors()" function. An attacker could conduct a buffer overflow or buffer over-read attacks via a crafted GD file.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:11-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T07:59:12.922-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:05:07.316-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:03:50.770-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Platform section" operator="OR">
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Architecture dependent section" operator="AND">
              <criteria comment="Supported architectures section" operator="OR">
                <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
                <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
                <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
                <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
                <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
                <criterion comment="Installed architecture is armel" test_ref="oval:org.mitre.oval:tst:11101"/>
                <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
                <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
                <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
                <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
                <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
                <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
              </criteria>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="libgd2-xpm DPKG is earlier than 2.0.36~rc1~dfsg-3+lenny1" test_ref="oval:org.mitre.oval:tst:19475"/>
                <criterion comment="libgd2-noxpm DPKG is earlier than 2.0.36~rc1~dfsg-3+lenny1" test_ref="oval:org.mitre.oval:tst:19448"/>
                <criterion comment="libgd2-xpm-dev DPKG is earlier than 2.0.36~rc1~dfsg-3+lenny1" test_ref="oval:org.mitre.oval:tst:19143"/>
                <criterion comment="libgd2-noxpm-dev DPKG is earlier than 2.0.36~rc1~dfsg-3+lenny1" test_ref="oval:org.mitre.oval:tst:19013"/>
                <criterion comment="libgd-tools DPKG is earlier than 2.0.36~rc1~dfsg-3+lenny1" test_ref="oval:org.mitre.oval:tst:19135"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 4.0 is installed" definition_ref="oval:org.mitre.oval:def:6461"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Packages section" operator="OR">
              <criterion comment="libgd2-xpm DPKG is earlier than 2.0.33-5.2etch2" test_ref="oval:org.mitre.oval:tst:19482"/>
              <criterion comment="libgd2-noxpm DPKG is earlier than 2.0.33-5.2etch2" test_ref="oval:org.mitre.oval:tst:19026"/>
              <criterion comment="libgd2-xpm-dev DPKG is earlier than 2.0.33-5.2etch2" test_ref="oval:org.mitre.oval:tst:19223"/>
              <criterion comment="libgd-tools DPKG is earlier than 2.0.33-5.2etch2" test_ref="oval:org.mitre.oval:tst:19188"/>
              <criterion comment="libgd2-noxpm-dev DPKG is earlier than 2.0.33-5.2etch2" test_ref="oval:org.mitre.oval:tst:18844"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:8224" class="patch">
      <metadata>
        <title>DSA-1784 freetype -- integer overflows</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <platform>Debian GNU/Linux 4.0</platform>
          <product>freetype</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2009/dsa-1784" ref_id="DSA-1784"/>
        <description>Tavis Ormandy discovered several integer overflows in FreeType, a library to process and access font files, resulting in heap- or stack-based buffer overflows leading to application crashes or the execution of arbitrary code via a crafted font file.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:10-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T07:58:09.079-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:05:06.748-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:03:50.341-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Platform section" operator="OR">
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Architecture dependent section" operator="AND">
              <criteria comment="Supported architectures section" operator="OR">
                <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
                <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
                <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
                <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
                <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
                <criterion comment="Installed architecture is armel" test_ref="oval:org.mitre.oval:tst:11101"/>
                <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
                <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
                <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
                <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
                <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
              </criteria>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="libfreetype6-dev DPKG is earlier than 2.3.7-2+lenny1" test_ref="oval:org.mitre.oval:tst:18520"/>
                <criterion comment="freetype2-demos DPKG is earlier than 2.3.7-2+lenny1" test_ref="oval:org.mitre.oval:tst:18738"/>
                <criterion comment="libfreetype6 DPKG is earlier than 2.3.7-2+lenny1" test_ref="oval:org.mitre.oval:tst:18761"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 4.0 is installed" definition_ref="oval:org.mitre.oval:def:6461"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Packages section" operator="OR">
              <criterion comment="libfreetype6-dev DPKG is earlier than 2.2.1-5+etch4" test_ref="oval:org.mitre.oval:tst:18524"/>
              <criterion comment="freetype2-demos DPKG is earlier than 2.2.1-5+etch4" test_ref="oval:org.mitre.oval:tst:18549"/>
              <criterion comment="libfreetype6 DPKG is earlier than 2.2.1-5+etch4" test_ref="oval:org.mitre.oval:tst:18342"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:8223" class="patch">
      <metadata>
        <title>DSA-1675 phpmyadmin -- insufficient input sanitising</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 4.0</platform>
          <product>phpmyadmin</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2008/dsa-1675" ref_id="DSA-1675"/>
        <description>Masako Oono discovered that phpMyAdmin, a web-based administration interface for MySQL, insufficiently sanitises input allowing a remote attacker to gather sensitive data through cross site scripting, provided that the user uses the Internet Explorer web browser. This update also fixes a regression introduced in DSA 1641, that broke changing of the language and encoding in the login screen.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:10-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T07:58:31.499-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:05:06.454-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:03:50.129-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Release section" operator="AND">
        <extend_definition comment="Debian 4.0 is installed" definition_ref="oval:org.mitre.oval:def:6461"/>
        <criteria comment="Architecture section" operator="OR">
          <criteria comment="Architecture independent section" operator="AND">
            <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
            <criterion comment="phpmyadmin is earlier than 2.9.1.1-9" test_ref="oval:org.mitre.oval:tst:18570"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:8221" class="patch">
      <metadata>
        <title>DSA-1932 pidgin -- programming error</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <product>pidgin</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2009/dsa-1932" ref_id="DSA-1932"/>
        <description>It was discovered that incorrect pointer handling in the purple library, an internal component of the multi-protocol instant messaging client Pidgin, could lead to denial of service or the execution of arbitrary code through malformed contact requests.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:11-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T07:59:08.308-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:05:06.071-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:03:49.794-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Release section" operator="AND">
        <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
        <criteria comment="Architecture section" operator="OR">
          <criteria comment="Architecture independent section" operator="AND">
            <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
            <criteria comment="Packages section" operator="OR">
              <criterion comment="libpurple-dev is earlier than 2.4.3-4lenny5" test_ref="oval:org.mitre.oval:tst:18722"/>
              <criterion comment="finch-dev is earlier than 2.4.3-4lenny5" test_ref="oval:org.mitre.oval:tst:18904"/>
              <criterion comment="pidgin-dev is earlier than 2.4.3-4lenny5" test_ref="oval:org.mitre.oval:tst:18847"/>
              <criterion comment="libpurple-bin is earlier than 2.4.3-4lenny5" test_ref="oval:org.mitre.oval:tst:19352"/>
              <criterion comment="pidgin-data is earlier than 2.4.3-4lenny5" test_ref="oval:org.mitre.oval:tst:19451"/>
            </criteria>
          </criteria>
          <criteria comment="Packages section" operator="OR">
            <criterion comment="libpurple0 DPKG is earlier than 2.4.3-4lenny5" test_ref="oval:org.mitre.oval:tst:18808"/>
            <criterion comment="pidgin-dbg DPKG is earlier than 2.4.3-4lenny5" test_ref="oval:org.mitre.oval:tst:19383"/>
            <criterion comment="pidgin DPKG is earlier than 2.4.3-4lenny5" test_ref="oval:org.mitre.oval:tst:18867"/>
            <criterion comment="finch DPKG is earlier than 2.4.3-4lenny5" test_ref="oval:org.mitre.oval:tst:19231"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:8219" class="patch">
      <metadata>
        <title>DSA-1606 poppler -- programming error</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 4.0</platform>
          <product>poppler</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2008/dsa-1606" ref_id="DSA-1606"/>
        <description>It was discovered that poppler, a PDF rendering library, did not properly handle embedded fonts in PDF files, allowing attackers to execute arbitrary code via a crafted font object.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:10-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T07:57:56.743-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:05:05.531-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:03:49.399-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Release section" operator="AND">
        <extend_definition comment="Debian 4.0 is installed" definition_ref="oval:org.mitre.oval:def:6461"/>
        <criteria comment="Architecture section" operator="OR">
          <criteria comment="Architecture dependent section" operator="AND">
            <criteria comment="Supported architectures section" operator="OR">
              <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
              <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
              <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
              <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
              <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
              <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
              <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
              <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
              <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
              <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
            </criteria>
            <criteria comment="Packages section" operator="OR">
              <criterion comment="poppler-utils DPKG is earlier than 0.4.5-5.1etch3" test_ref="oval:org.mitre.oval:tst:18717"/>
              <criterion comment="libpoppler0c2 DPKG is earlier than 0.4.5-5.1etch3" test_ref="oval:org.mitre.oval:tst:18668"/>
              <criterion comment="libpoppler-dev DPKG is earlier than 0.4.5-5.1etch3" test_ref="oval:org.mitre.oval:tst:18495"/>
              <criterion comment="libpoppler-qt-dev DPKG is earlier than 0.4.5-5.1etch3" test_ref="oval:org.mitre.oval:tst:18763"/>
              <criterion comment="libpoppler0c2-glib DPKG is earlier than 0.4.5-5.1etch3" test_ref="oval:org.mitre.oval:tst:18113"/>
              <criterion comment="libpoppler-glib-dev DPKG is earlier than 0.4.5-5.1etch3" test_ref="oval:org.mitre.oval:tst:18530"/>
              <criterion comment="libpoppler0c2-qt DPKG is earlier than 0.4.5-5.1etch3" test_ref="oval:org.mitre.oval:tst:18447"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:8217" class="patch">
      <metadata>
        <title>DSA-1772 udev -- several vulnerabilities</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <platform>Debian GNU/Linux 4.0</platform>
          <product>udev</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2009/dsa-1772" ref_id="DSA-1772"/>
        <description>Sebastian Kramer discovered two vulnerabilities in udev, the /dev and hotplug management daemon. udev does not check the origin of NETLINK messages, allowing local users to gain root privileges. udev suffers from a buffer overflow condition in path encoding, potentially allowing arbitrary code execution.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:10-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T07:58:24.856-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:05:05.000-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:03:48.925-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Platform section" operator="OR">
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Architecture dependent section" operator="AND">
              <criteria comment="Supported architectures section" operator="OR">
                <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
                <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
                <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
                <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
                <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
                <criterion comment="Installed architecture is armel" test_ref="oval:org.mitre.oval:tst:11101"/>
                <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
                <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
                <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
                <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
                <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
                <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
              </criteria>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="libvolume-id-dev DPKG is earlier than 0.125-7+lenny1" test_ref="oval:org.mitre.oval:tst:18836"/>
                <criterion comment="libvolume-id0 DPKG is earlier than 0.125-7+lenny1" test_ref="oval:org.mitre.oval:tst:18915"/>
                <criterion comment="udev DPKG is earlier than 0.125-7+lenny1" test_ref="oval:org.mitre.oval:tst:18875"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 4.0 is installed" definition_ref="oval:org.mitre.oval:def:6461"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Packages section" operator="OR">
              <criterion comment="libvolume-id-dev DPKG is earlier than 0.105-4etch1" test_ref="oval:org.mitre.oval:tst:18811"/>
              <criterion comment="libvolume-id0 DPKG is earlier than 0.105-4etch1" test_ref="oval:org.mitre.oval:tst:19015"/>
              <criterion comment="udev DPKG is earlier than 0.105-4etch1" test_ref="oval:org.mitre.oval:tst:18997"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:8216" class="patch">
      <metadata>
        <title>DSA-1683 streamripper -- buffer overflow</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 4.0</platform>
          <product>streamripper</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2008/dsa-1683" ref_id="DSA-1683"/>
        <description>Multiple buffer overflows involving HTTP header and playlist parsing have been discovered in streamripper (CVE-2007-4337, CVE-2008-4829). For the stable distribution (etch), these problems have been fixed in version 1.61.27-1+etch1. For the unstable distribution (sid) and the testing distribution (lenny), these problems have been fixed in version 1.63.5-2. We recommend that you upgrade your streamripper package.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:12-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T08:00:25.462-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:05:04.704-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:03:48.724-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Release section" operator="AND">
        <extend_definition comment="Debian 4.0 is installed" definition_ref="oval:org.mitre.oval:def:6461"/>
        <criteria comment="Architecture section" operator="OR">
          <criteria comment="Packages section" operator="OR">
            <criterion comment="streamripper DPKG is earlier than 1.61.27-1+etch1" test_ref="oval:org.mitre.oval:tst:20089"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:8213" class="patch">
      <metadata>
        <title>DSA-1938 php-mail -- programming error</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <platform>Debian GNU/Linux 4.0</platform>
          <product>php-mail</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2009/dsa-1938" ref_id="DSA-1938"/>
        <description>It was discovered that php-mail, a PHP PEAR module for sending email, has insufficient input sanitising, which might be used to obtain sensitive data from the system that uses php-mail.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:11-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T07:59:19.109-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:05:04.464-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:03:48.470-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Platform section" operator="OR">
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Architecture independent section" operator="AND">
              <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criterion comment="php-mail is earlier than 1.1.14-1+lenny1" test_ref="oval:org.mitre.oval:tst:18641"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 4.0 is installed" definition_ref="oval:org.mitre.oval:def:6461"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Architecture independent section" operator="AND">
              <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criterion comment="php-mail is earlier than 1.1.6-2+etch1" test_ref="oval:org.mitre.oval:tst:19439"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:8210" class="patch">
      <metadata>
        <title>DSA-1740 yaws -- denial of service</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <platform>Debian GNU/Linux 4.0</platform>
          <product>yaws</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2009/dsa-1740" ref_id="DSA-1740"/>
        <description>It was discovered that yaws, a high performance HTTP 1.1 webserver, is prone to a denial of service attack via a request with a large HTTP header.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:12-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T07:59:59.561-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:05:03.878-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:03:47.993-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Platform section" operator="OR">
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Architecture independent section" operator="AND">
              <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="yaws-wiki is earlier than 1.77-3+lenny1" test_ref="oval:org.mitre.oval:tst:20039"/>
                <criterion comment="yaws-mail is earlier than 1.77-3+lenny1" test_ref="oval:org.mitre.oval:tst:20038"/>
                <criterion comment="yaws-chat is earlier than 1.77-3+lenny1" test_ref="oval:org.mitre.oval:tst:19750"/>
                <criterion comment="yaws-yapp is earlier than 1.77-3+lenny1" test_ref="oval:org.mitre.oval:tst:20045"/>
              </criteria>
            </criteria>
            <criteria comment="Architecture dependent section" operator="AND">
              <criteria comment="Supported architectures section" operator="OR">
                <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
                <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
                <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
                <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
                <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
                <criterion comment="Installed architecture is armel" test_ref="oval:org.mitre.oval:tst:11101"/>
                <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
                <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
                <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
                <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
                <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
                <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
              </criteria>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="yaws DPKG is earlier than 1.77-3+lenny1" test_ref="oval:org.mitre.oval:tst:20001"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 4.0 is installed" definition_ref="oval:org.mitre.oval:def:6461"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Architecture dependent section" operator="AND">
              <criteria comment="Supported architectures section" operator="OR">
                <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
                <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
                <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
                <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
                <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
                <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
                <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
                <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
                <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
                <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
              </criteria>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="yaws DPKG is earlier than 1.65-4etch1" test_ref="oval:org.mitre.oval:tst:19697"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:8207" class="patch">
      <metadata>
        <title>DSA-1644 mplayer -- integer overflow</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 4.0</platform>
          <product>mplayer</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2008/dsa-1644" ref_id="DSA-1644"/>
        <description>Felipe Andres Manzano discovered that mplayer, a multimedia player, is vulnerable to several integer overflows in the Real video stream demuxing code. These flaws could allow an attacker to cause a denial of service (a crash) or potentially execution of arbitrary code by supplying a maliciously crafted video file.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:08-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T07:56:24.665-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:05:03.544-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:03:47.744-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Release section" operator="AND">
        <extend_definition comment="Debian 4.0 is installed" definition_ref="oval:org.mitre.oval:def:6461"/>
        <criteria comment="Architecture section" operator="OR">
          <criteria comment="Architecture independent section" operator="AND">
            <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
            <criterion comment="mplayer-doc is earlier than 1.0~rc1-12etch5" test_ref="oval:org.mitre.oval:tst:17007"/>
          </criteria>
          <criteria comment="Packages section" operator="OR">
            <criterion comment="mplayer DPKG is earlier than 1.0~rc1-12etch5" test_ref="oval:org.mitre.oval:tst:17243"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:8206" class="patch">
      <metadata>
        <title>DSA-1858 imagemagick -- multiple vulnerabilities</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <platform>Debian GNU/Linux 4.0</platform>
          <product>imagemagick</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2009/dsa-1858" ref_id="DSA-1858"/>
        <description>Several vulnerabilities have been discovered in the imagemagick image manipulation programs which can lead to the execution of arbitrary code, exposure of sensitive information or cause DoS. The Common Vulnerabilities and Exposures project identifies the following problems: Multiple integer overflows in XInitImage function in xwd.c for ImageMagick, allow user-assisted remote attackers to cause a denial of service (crash) or obtain sensitive information via crafted images with large or negative values that trigger a buffer overflow. It only affects the oldstable distribution (etch). Multiple integer overflows allow remote attackers to execute arbitrary code via a crafted DCM image, or the colors or comments field in a crafted XWD image. It only affects the oldstable distribution (etch). A crafted image file can trigger an infinite loop in the ReadDCMImage function or in the ReadXCFImage function. It only affects the oldstable distribution (etch). Multiple integer overflows allow context-dependent attackers to execute arbitrary code via a crafted .dcm, .dib, .xbm, .xcf, or .xwd image file, which triggers a heap-based buffer overflow. It only affects the oldstable distribution (etch). Off-by-one error allows context-dependent attackers to execute arbitrary code via a crafted image file, which triggers the writing of a "\0" character to an out-of-bounds address. It affects only the oldstable distribution (etch). A sign extension error allows context-dependent attackers to execute arbitrary code via a crafted width value in an image file, which triggers an integer overflow and a heap-based buffer overflow. It affects only the oldstable distribution (etch). The load_tile function in the XCF coder allows user-assisted remote attackers to cause a denial of service or possibly execute arbitrary code via a crafted .xcf file that triggers an out-of-bounds heap write. It affects only to oldstable (etch). Heap-based buffer overflow in the PCX coder allows user-assisted remote attackers to cause a denial of service or possibly execute arbitrary code via a crafted .pcx file that triggers incorrect memory allocation for the scanline array, leading to memory corruption. It affects only to oldstable (etch). Integer overflow allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted TIFF file, which triggers a buffer overflow.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:10-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T07:58:45.975-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:05:02.923-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:03:47.155-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Platform section" operator="OR">
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Architecture dependent section" operator="AND">
              <criteria comment="Supported architectures section" operator="OR">
                <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
                <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
                <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
                <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
                <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
                <criterion comment="Installed architecture is armel" test_ref="oval:org.mitre.oval:tst:11101"/>
                <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
                <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
                <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
                <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
                <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
              </criteria>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="imagemagick DPKG is earlier than 6.3.7.9.dfsg2-1~lenny3" test_ref="oval:org.mitre.oval:tst:19229"/>
                <criterion comment="libmagick9-dev DPKG is earlier than 6.3.7.9.dfsg2-1~lenny3" test_ref="oval:org.mitre.oval:tst:18985"/>
                <criterion comment="perlmagick DPKG is earlier than 6.3.7.9.dfsg2-1~lenny3" test_ref="oval:org.mitre.oval:tst:18813"/>
                <criterion comment="libmagick++9-dev DPKG is earlier than 6.3.7.9.dfsg2-1~lenny3" test_ref="oval:org.mitre.oval:tst:19014"/>
                <criterion comment="libmagick++10 DPKG is earlier than 6.3.7.9.dfsg2-1~lenny3" test_ref="oval:org.mitre.oval:tst:19162"/>
                <criterion comment="libmagick10 DPKG is earlier than 6.3.7.9.dfsg2-1~lenny3" test_ref="oval:org.mitre.oval:tst:19187"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 4.0 is installed" definition_ref="oval:org.mitre.oval:def:6461"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Architecture dependent section" operator="AND">
              <criteria comment="Supported architectures section" operator="OR">
                <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
                <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
                <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
                <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
                <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
                <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
                <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
                <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
                <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
                <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
              </criteria>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="libmagick9 DPKG is earlier than 6.2.4.5.dfsg1-0.15+etch1" test_ref="oval:org.mitre.oval:tst:18989"/>
                <criterion comment="imagemagick DPKG is earlier than 6.2.4.5.dfsg1-0.15+etch1" test_ref="oval:org.mitre.oval:tst:18670"/>
                <criterion comment="libmagick9-dev DPKG is earlier than 6.2.4.5.dfsg1-0.15+etch1" test_ref="oval:org.mitre.oval:tst:18832"/>
                <criterion comment="libmagick++9c2a DPKG is earlier than 6.2.4.5.dfsg1-0.15+etch1" test_ref="oval:org.mitre.oval:tst:19185"/>
                <criterion comment="perlmagick DPKG is earlier than 6.2.4.5.dfsg1-0.15+etch1" test_ref="oval:org.mitre.oval:tst:19173"/>
                <criterion comment="libmagick++9-dev DPKG is earlier than 6.2.4.5.dfsg1-0.15+etch1" test_ref="oval:org.mitre.oval:tst:18932"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:8205" class="patch">
      <metadata>
        <title>DSA-1739 mldonkey -- path traversal</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <product>mldonkey</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2009/dsa-1739" ref_id="DSA-1739"/>
        <description>It has been discovered that mldonkey, a client for several P2P networks, allows attackers to download arbitrary files using crafted requests to the HTTP console. The old stable distribution (etch) is not affected by this problem.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:11-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T07:59:19.528-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:05:02.530-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:03:46.742-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Release section" operator="AND">
        <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
        <criteria comment="Architecture section" operator="OR">
          <criteria comment="Architecture dependent section" operator="AND">
            <criteria comment="Supported architectures section" operator="OR">
              <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
              <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
              <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
              <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
              <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
              <criterion comment="Installed architecture is armel" test_ref="oval:org.mitre.oval:tst:11101"/>
              <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
              <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
              <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
              <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
              <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
              <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
            </criteria>
            <criteria comment="Packages section" operator="OR">
              <criterion comment="mldonkey-gui DPKG is earlier than 2.9.5-2+lenny1" test_ref="oval:org.mitre.oval:tst:19392"/>
              <criterion comment="mldonkey-server DPKG is earlier than 2.9.5-2+lenny1" test_ref="oval:org.mitre.oval:tst:19453"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:8204" class="patch">
      <metadata>
        <title>DSA-1454 freetype -- integer overflow</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 4.0</platform>
          <product>freetype</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2008/dsa-1454" ref_id="DSA-1454"/>
        <description>Greg MacManus discovered an integer overflow in the font handling of libfreetype, a FreeType 2 font engine, which might lead to denial of service or possibly the execution of arbitrary code if a user is tricked into opening a malformed font. For the old stable distribution (sarge) this problem will be fixed soon. For the stable distribution (etch), this problem has been fixed in version 2.2.1-5+etch2. For the unstable distribution (sid), this problem has been fixed in version 2.3.5-1. We recommend that you upgrade your freetype packages.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:09-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T07:57:17.216-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:05:02.199-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:03:46.519-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Release section" operator="AND">
        <extend_definition comment="Debian 4.0 is installed" definition_ref="oval:org.mitre.oval:def:6461"/>
        <criteria comment="Architecture section" operator="OR">
          <criteria comment="Packages section" operator="OR">
            <criterion comment="libfreetype6-dev DPKG is earlier than 2.2.1-5+etch2" test_ref="oval:org.mitre.oval:tst:18158"/>
            <criterion comment="freetype2-demos DPKG is earlier than 2.2.1-5+etch2" test_ref="oval:org.mitre.oval:tst:18468"/>
            <criterion comment="libfreetype6 DPKG is earlier than 2.2.1-5+etch2" test_ref="oval:org.mitre.oval:tst:18446"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:8203" class="patch">
      <metadata>
        <title>DSA-1580 phpgedview -- programming error</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 4.0</platform>
          <product>phpgedview</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2008/dsa-1580" ref_id="DSA-1580"/>
        <description>It was discovered that phpGedView, an application to provide online access to genealogical data, allowed remote attackers to gain administrator privileges due to a programming error. Note: this problem was a fundamental design flaw in the interface (API) to connect phpGedView with external programs like content management systems. Resolving this problem was only possible by completely reworking the API, which is not considered appropriate for a security update. Since these are peripheral functions probably not used by the large majority of package users, it was decided to remove these interfaces. If you require that interface nonetheless, you are advised to use a version of phpGedView backported from Debian Lenny, which has a completely redesigned API.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:08-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T07:56:41.942-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:05:01.694-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:03:46.272-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Release section" operator="AND">
        <extend_definition comment="Debian 4.0 is installed" definition_ref="oval:org.mitre.oval:def:6461"/>
        <criteria comment="Architecture section" operator="OR">
          <criteria comment="Architecture independent section" operator="AND">
            <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
            <criteria comment="Packages section" operator="OR">
              <criterion comment="phpgedview-places is earlier than 4.0.2.dfsg-4" test_ref="oval:org.mitre.oval:tst:17671"/>
              <criterion comment="phpgedview-themes is earlier than 4.0.2.dfsg-4" test_ref="oval:org.mitre.oval:tst:17847"/>
              <criterion comment="phpgedview is earlier than 4.0.2.dfsg-4" test_ref="oval:org.mitre.oval:tst:17750"/>
              <criterion comment="phpgedview-languages is earlier than 4.0.2.dfsg-4" test_ref="oval:org.mitre.oval:tst:17895"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:8201" class="patch">
      <metadata>
        <title>DSA-1934 apache2 -- multiple issues</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <platform>Debian GNU/Linux 4.0</platform>
          <product>apache2</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2009/dsa-1934" ref_id="DSA-1934"/>
        <description>A design flaw has been found in the TLS and SSL protocol that allows an attacker to inject arbitrary content at the beginning of a TLS/SSL connection. The attack is related to the way how TLS and SSL handle session renegotiations. CVE-2009-3555 has been assigned to this vulnerability. As a partial mitigation against this attack, this apache2 update disables client-initiated renegotiations. This should fix the vulnerability for the majority of Apache configurations in use. NOTE: This is not a complete fix for the problem. The attack is still possible in configurations where the server initiates the renegotiation. This is the case for the following configurations (the information in the changelog of the updated packages is slightly inaccurate): As a workaround, you may rearrange your configuration in a way that SSLVerifyClient and SSLCipherSuite are only used on the server or virtual host level. A complete fix for the problem will require a protocol change. Further information will be included in a separate announcement about this issue. In addition, this update fixes the following issues in Apache's mod_proxy_ftp: Insufficient input validation in the mod_proxy_ftp module allowed remote FTP servers to cause a denial of service (NULL pointer dereference and child process crash) via a malformed reply to an EPSV command. Insufficient input validation in the mod_proxy_ftp module allowed remote authenticated attackers to bypass intended access restrictions and send arbitrary FTP commands to an FTP server. The oldstable distribution (etch), these problems have been fixed in version 2.2.3-4+etch11.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:11-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T07:59:17.199-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:05:00.808-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:03:45.542-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Platform section" operator="OR">
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Architecture independent section" operator="AND">
              <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="apache2-doc is earlier than 2.2.9-10+lenny6" test_ref="oval:org.mitre.oval:tst:18971"/>
                <criterion comment="apache2-src is earlier than 2.2.9-10+lenny6" test_ref="oval:org.mitre.oval:tst:19402"/>
                <criterion comment="apache2 is earlier than 2.2.9-10+lenny6" test_ref="oval:org.mitre.oval:tst:19459"/>
              </criteria>
            </criteria>
            <criteria comment="Architecture dependent section" operator="AND">
              <criteria comment="Supported architectures section" operator="OR">
                <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
                <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
                <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
                <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
                <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
                <criterion comment="Installed architecture is armel" test_ref="oval:org.mitre.oval:tst:11101"/>
                <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
                <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
                <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
                <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
                <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
                <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
              </criteria>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="apache2-utils DPKG is earlier than 2.2.9-10+lenny6" test_ref="oval:org.mitre.oval:tst:19247"/>
                <criterion comment="apache2-mpm-worker DPKG is earlier than 2.2.9-10+lenny6" test_ref="oval:org.mitre.oval:tst:19133"/>
                <criterion comment="apache2.2-common DPKG is earlier than 2.2.9-10+lenny6" test_ref="oval:org.mitre.oval:tst:19089"/>
                <criterion comment="apache2-suexec-custom DPKG is earlier than 2.2.9-10+lenny6" test_ref="oval:org.mitre.oval:tst:19323"/>
                <criterion comment="apache2-suexec DPKG is earlier than 2.2.9-10+lenny6" test_ref="oval:org.mitre.oval:tst:19222"/>
                <criterion comment="apache2-threaded-dev DPKG is earlier than 2.2.9-10+lenny6" test_ref="oval:org.mitre.oval:tst:18986"/>
                <criterion comment="apache2-dbg DPKG is earlier than 2.2.9-10+lenny6" test_ref="oval:org.mitre.oval:tst:19347"/>
                <criterion comment="apache2-mpm-event DPKG is earlier than 2.2.9-10+lenny6" test_ref="oval:org.mitre.oval:tst:19299"/>
                <criterion comment="apache2-mpm-prefork DPKG is earlier than 2.2.9-10+lenny6" test_ref="oval:org.mitre.oval:tst:19473"/>
                <criterion comment="apache2-prefork-dev DPKG is earlier than 2.2.9-10+lenny6" test_ref="oval:org.mitre.oval:tst:18822"/>
              </criteria>
            </criteria>
            <criteria comment="Architecture dependent section" operator="AND">
              <criteria comment="Supported architectures section" operator="OR">
                <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
                <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
                <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
                <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
                <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
                <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
                <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
                <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
                <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
                <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
                <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
              </criteria>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="apache2-mpm-itk DPKG is earlier than 2.2.6-02-1+lenny2+b2" test_ref="oval:org.mitre.oval:tst:19074"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 4.0 is installed" definition_ref="oval:org.mitre.oval:def:6461"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Architecture independent section" operator="AND">
              <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="apache2-mpm-perchild is earlier than 2.2.3-4+etch11" test_ref="oval:org.mitre.oval:tst:19447"/>
                <criterion comment="apache2-doc is earlier than 2.2.3-4+etch11" test_ref="oval:org.mitre.oval:tst:19425"/>
                <criterion comment="apache2-src is earlier than 2.2.3-4+etch11" test_ref="oval:org.mitre.oval:tst:19160"/>
                <criterion comment="apache2 is earlier than 2.2.3-4+etch11" test_ref="oval:org.mitre.oval:tst:18828"/>
              </criteria>
            </criteria>
            <criteria comment="Packages section" operator="OR">
              <criterion comment="apache2-utils DPKG is earlier than 2.2.3-4+etch11" test_ref="oval:org.mitre.oval:tst:19385"/>
              <criterion comment="apache2-mpm-worker DPKG is earlier than 2.2.3-4+etch11" test_ref="oval:org.mitre.oval:tst:19234"/>
              <criterion comment="apache2.2-common DPKG is earlier than 2.2.3-4+etch11" test_ref="oval:org.mitre.oval:tst:19409"/>
              <criterion comment="apache2-mpm-prefork DPKG is earlier than 2.2.3-4+etch11" test_ref="oval:org.mitre.oval:tst:18829"/>
              <criterion comment="apache2-threaded-dev DPKG is earlier than 2.2.3-4+etch11" test_ref="oval:org.mitre.oval:tst:18734"/>
              <criterion comment="apache2-mpm-event DPKG is earlier than 2.2.3-4+etch11" test_ref="oval:org.mitre.oval:tst:19469"/>
              <criterion comment="apache2-mpm-itk DPKG is earlier than 2.2.3-01-2+etch4+b1" test_ref="oval:org.mitre.oval:tst:18893"/>
              <criterion comment="apache2-prefork-dev DPKG is earlier than 2.2.3-4+etch11" test_ref="oval:org.mitre.oval:tst:19038"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:8200" class="patch">
      <metadata>
        <title>DSA-1825 nagios2, nagios3 -- insufficient input validation</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <platform>Debian GNU/Linux 4.0</platform>
          <product>nagios2</product>
          <product>nagios3</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2009/dsa-1825" ref_id="DSA-1825"/>
        <description>It was discovered that the statuswml.cgi script of nagios, a monitoring and management system for hosts, services and networks, is prone to a command injection vulnerability. Input to the ping and traceroute parameters of the script is not properly validated which allows an attacker to execute arbitrary shell commands by passing a crafted value to these parameters.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:08-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T07:55:54.077-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:04:59.950-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:03:44.997-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Platform section" operator="OR">
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Architecture independent section" operator="AND">
              <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="nagios3-doc is earlier than 3.0.6-4~lenny2" test_ref="oval:org.mitre.oval:tst:16887"/>
                <criterion comment="nagios3-common is earlier than 3.0.6-4~lenny2" test_ref="oval:org.mitre.oval:tst:17329"/>
              </criteria>
            </criteria>
            <criteria comment="Architecture dependent section" operator="AND">
              <criteria comment="Supported architectures section" operator="OR">
                <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
                <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
                <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
                <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
                <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
                <criterion comment="Installed architecture is armel" test_ref="oval:org.mitre.oval:tst:11101"/>
                <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
                <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
                <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
                <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
                <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
                <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
              </criteria>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="nagios3-dbg DPKG is earlier than 3.0.6-4~lenny2" test_ref="oval:org.mitre.oval:tst:17221"/>
                <criterion comment="nagios3 DPKG is earlier than 3.0.6-4~lenny2" test_ref="oval:org.mitre.oval:tst:16380"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 4.0 is installed" definition_ref="oval:org.mitre.oval:def:6461"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Architecture independent section" operator="AND">
              <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="nagios2-common is earlier than 2.6-2+etch3" test_ref="oval:org.mitre.oval:tst:17108"/>
                <criterion comment="nagios2-doc is earlier than 2.6-2+etch3" test_ref="oval:org.mitre.oval:tst:17015"/>
              </criteria>
            </criteria>
            <criteria comment="Packages section" operator="OR">
              <criterion comment="nagios2-dbg DPKG is earlier than 2.6-2+etch3" test_ref="oval:org.mitre.oval:tst:17299"/>
              <criterion comment="nagios2 DPKG is earlier than 2.6-2+etch3" test_ref="oval:org.mitre.oval:tst:17275"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:8199" class="patch">
      <metadata>
        <title>DSA-1463 postgresql-7.4 -- several vulnerabilities</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 4.0</platform>
          <platform>Debian GNU/Linux 3.1</platform>
          <product>postgresql-7.4</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2008/dsa-1463" ref_id="DSA-1463"/>
        <description>Several local vulnerabilities have been discovered in PostgreSQL, an object-relational SQL database. The Common Vulnerabilities and Exposures project identifies the following problems: It was discovered that the DBLink module performed insufficient credential validation. This issue is also tracked as CVE-2007-6601, since the initial upstream fix was incomplete. Tavis Ormandy and Will Drewry discovered that a bug in the handling of back-references inside the regular expressions engine could lead to an out of bounds read, resulting in a crash. This constitutes only a security problem if an application using PostgreSQL processes regular expressions from untrusted sources. Tavis Ormandy and Will Drewry discovered that the optimizer for regular expression could be tricked into an infinite loop, resulting in denial of service. This constitutes only a security problem if an application using PostgreSQL processes regular expressions from untrusted sources. Tavis Ormandy and Will Drewry discovered that the optimizer for regular expression could be tricked massive resource consumption. This constitutes only a security problem if an application using PostgreSQL processes regular expressions from untrusted sources. Functions in index expressions could lead to privilege escalation. For a more in depth explanation please see the upstream announce available at http://www.postgresql.org/about/news.905. For the old stable distribution (sarge), some of these problems have been fixed in version 7.4.7-6sarge6 of the postgresql package. Please note that the fix for CVE-2007-6600 and for the handling of regular expressions havn't been backported due to the intrusiveness of the fix. We recommend to upgrade to the stable distribution if these vulnerabilities affect your setup. For the stable distribution (etch), these problems have been fixed in version 7.4.19-0etch1. The unstable distribution (sid) no longer contains postgres-7.4. We recommend that you upgrade your postgresql-7.4 packages.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:08-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T07:55:51.275-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:04:59.250-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:03:44.415-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Platform section" operator="OR">
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 4.0 is installed" definition_ref="oval:org.mitre.oval:def:6461"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Architecture independent section" operator="AND">
              <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="postgresql-server-dev-7.4 is earlier than 7.4.19-0etch1" test_ref="oval:org.mitre.oval:tst:17219"/>
                <criterion comment="postgresql-doc-7.4 is earlier than 7.4.19-0etch1" test_ref="oval:org.mitre.oval:tst:16331"/>
              </criteria>
            </criteria>
            <criteria comment="Architecture dependent section" operator="AND">
              <criteria comment="Supported architectures section" operator="OR">
                <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
                <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
                <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
                <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
                <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
                <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
                <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
                <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
                <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
                <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
              </criteria>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="postgresql-7.4 DPKG is earlier than 7.4.19-0etch1" test_ref="oval:org.mitre.oval:tst:16934"/>
                <criterion comment="postgresql-plpython-7.4 DPKG is earlier than 7.4.19-0etch1" test_ref="oval:org.mitre.oval:tst:17012"/>
                <criterion comment="postgresql-contrib-7.4 DPKG is earlier than 7.4.19-0etch1" test_ref="oval:org.mitre.oval:tst:16674"/>
                <criterion comment="postgresql-client-7.4 DPKG is earlier than 7.4.19-0etch1" test_ref="oval:org.mitre.oval:tst:17240"/>
                <criterion comment="postgresql-plperl-7.4 DPKG is earlier than 7.4.19-0etch1" test_ref="oval:org.mitre.oval:tst:17175"/>
                <criterion comment="postgresql-pltcl-7.4 DPKG is earlier than 7.4.19-0etch1" test_ref="oval:org.mitre.oval:tst:17285"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 3.1 is installed" definition_ref="oval:org.mitre.oval:def:7692"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Architecture independent section" operator="AND">
              <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criterion comment="postgresql-doc is earlier than 7.4.7-6sarge6" test_ref="oval:org.mitre.oval:tst:17265"/>
            </criteria>
            <criteria comment="Architecture dependent section" operator="AND">
              <criteria comment="Supported architectures section" operator="OR">
                <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
                <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
                <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
                <criterion comment="Installed architecture is m68k" test_ref="oval:org.mitre.oval:tst:13064"/>
                <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
                <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
                <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
                <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
                <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
                <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
                <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
              </criteria>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="libpgtcl DPKG is earlier than 7.4.7-6sarge6" test_ref="oval:org.mitre.oval:tst:17283"/>
                <criterion comment="postgresql DPKG is earlier than 7.4.7-6sarge6" test_ref="oval:org.mitre.oval:tst:17088"/>
                <criterion comment="libecpg4 DPKG is earlier than 7.4.7-6sarge6" test_ref="oval:org.mitre.oval:tst:16878"/>
                <criterion comment="postgresql-contrib DPKG is earlier than 7.4.7-6sarge6" test_ref="oval:org.mitre.oval:tst:17069"/>
                <criterion comment="libpq3 DPKG is earlier than 7.4.7-6sarge6" test_ref="oval:org.mitre.oval:tst:17250"/>
                <criterion comment="libecpg-dev DPKG is earlier than 7.4.7-6sarge6" test_ref="oval:org.mitre.oval:tst:17184"/>
                <criterion comment="libpgtcl-dev DPKG is earlier than 7.4.7-6sarge6" test_ref="oval:org.mitre.oval:tst:16453"/>
                <criterion comment="postgresql-dev DPKG is earlier than 7.4.7-6sarge6" test_ref="oval:org.mitre.oval:tst:17182"/>
                <criterion comment="postgresql-client DPKG is earlier than 7.4.7-6sarge6" test_ref="oval:org.mitre.oval:tst:16435"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:8198" class="patch">
      <metadata>
        <title>DSA-1732 squid3 -- denial of service</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 4.0</platform>
          <product>squid3</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2009/dsa-1732" ref_id="DSA-1732"/>
        <description>Joshua Morin, Mikko Varpiola and Jukka Taimisto discovered an assertion error in squid3, a full featured Web Proxy cache, which could lead to a denial of service attack.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:11-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T07:59:31.836-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:04:58.736-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:03:44.009-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Release section" operator="AND">
        <extend_definition comment="Debian 4.0 is installed" definition_ref="oval:org.mitre.oval:def:6461"/>
        <criteria comment="Architecture section" operator="OR">
          <criteria comment="Architecture independent section" operator="AND">
            <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
            <criterion comment="squid3-common is earlier than 3.0.PRE5-5+etch1" test_ref="oval:org.mitre.oval:tst:19474"/>
          </criteria>
          <criteria comment="Architecture dependent section" operator="AND">
            <criteria comment="Supported architectures section" operator="OR">
              <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
              <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
              <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
              <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
              <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
              <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
              <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
              <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
              <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
            </criteria>
            <criteria comment="Packages section" operator="OR">
              <criterion comment="squid3-cgi DPKG is earlier than 3.0.PRE5-5+etch1" test_ref="oval:org.mitre.oval:tst:19594"/>
              <criterion comment="squid3-client DPKG is earlier than 3.0.PRE5-5+etch1" test_ref="oval:org.mitre.oval:tst:19445"/>
              <criterion comment="squid3 DPKG is earlier than 3.0.PRE5-5+etch1" test_ref="oval:org.mitre.oval:tst:19570"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:8197" class="patch">
      <metadata>
        <title>DSA-1584 libfishsound -- buffer overflow</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 4.0</platform>
          <product>libfishsound</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2008/dsa-1584" ref_id="DSA-1584"/>
        <description>It was discovered that libfishsound, a simple programming interface that wraps Xiph.Org audio codecs, didn't correctly handle negative values in a particular header field. This could allow malicious files to execute arbitrary code.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:08-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T07:56:43.971-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:04:58.405-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:03:43.783-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Release section" operator="AND">
        <extend_definition comment="Debian 4.0 is installed" definition_ref="oval:org.mitre.oval:def:6461"/>
        <criteria comment="Architecture section" operator="OR">
          <criteria comment="Packages section" operator="OR">
            <criterion comment="libfishsound1 DPKG is earlier than 0.7.0-2etch1" test_ref="oval:org.mitre.oval:tst:17149"/>
            <criterion comment="libfishsound1-dbg DPKG is earlier than 0.7.0-2etch1" test_ref="oval:org.mitre.oval:tst:17905"/>
            <criterion comment="libfishsound1-dev DPKG is earlier than 0.7.0-2etch1" test_ref="oval:org.mitre.oval:tst:17965"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:8196" class="patch">
      <metadata>
        <title>DSA-1607 iceweasel -- several vulnerabilities</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 4.0</platform>
          <product>iceweasel</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2008/dsa-1607" ref_id="DSA-1607"/>
        <description>Several remote vulnerabilities have been discovered in the Iceweasel webbrowser, an unbranded version of the Firefox browser. The Common Vulnerabilities and Exposures project identifies the following problems: Devon Hubbard, Jesse Ruderman and Martijn Wargers discovered crashes in the layout engine, which might allow the execution of arbitrary code. Igor Bukanov, Jesse Ruderman and Gary Kwong discovered crashes in the Javascript engine, which might allow the execution of arbitrary code. "moz_bug_r_a4" discovered several cross-site scripting vulnerabilities. Collin Jackson and Adam Barth discovered that Javascript code could be executed in the context of signed JAR archives. "moz_bug_r_a4" discovered that XUL documents can escalate privileges by accessing the pre-compiled "fastload" file. "moz_bug_r_a4" discovered that missing input sanitising in the mozIJSSubScriptLoader.loadSubScript() function could lead to the execution of arbitrary code. Iceweasel itself is not affected, but some addons are. Claudio Santambrogio discovered that missing access validation in DOM parsing allows malicious web sites to force the browser to upload local files to the server, which could lead to information disclosure. Daniel Glazman discovered that a programming error in the code for parsing .properties files could lead to memory content being exposed to addons, which could lead to information disclosure. Masahiro Yamada discovered that file URLS in directory listings were insufficiently escaped. John G. Myers, Frank Benkstein and Nils Toedtmann discovered that alternate names on self-signed certificates were handled insufficiently, which could lead to spoofings secure connections. Greg McManus discovered a crash in the block reflow code, which might allow the execution of arbitrary code.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:10-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T07:57:55.770-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:04:57.879-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:03:43.346-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Release section" operator="AND">
        <extend_definition comment="Debian 4.0 is installed" definition_ref="oval:org.mitre.oval:def:6461"/>
        <criteria comment="Architecture section" operator="OR">
          <criteria comment="Architecture independent section" operator="AND">
            <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
            <criteria comment="Packages section" operator="OR">
              <criterion comment="mozilla-firefox is earlier than 2.0.0.15-0etch1" test_ref="oval:org.mitre.oval:tst:18571"/>
              <criterion comment="firefox is earlier than 2.0.0.15-0etch1" test_ref="oval:org.mitre.oval:tst:18555"/>
              <criterion comment="firefox-dom-inspector is earlier than 2.0.0.15-0etch1" test_ref="oval:org.mitre.oval:tst:18649"/>
              <criterion comment="iceweasel-dom-inspector is earlier than 2.0.0.15-0etch1" test_ref="oval:org.mitre.oval:tst:18677"/>
              <criterion comment="mozilla-firefox-gnome-support is earlier than 2.0.0.15-0etch1" test_ref="oval:org.mitre.oval:tst:18150"/>
              <criterion comment="mozilla-firefox-dom-inspector is earlier than 2.0.0.15-0etch1" test_ref="oval:org.mitre.oval:tst:18583"/>
              <criterion comment="firefox-gnome-support is earlier than 2.0.0.15-0etch1" test_ref="oval:org.mitre.oval:tst:18673"/>
            </criteria>
          </criteria>
          <criteria comment="Architecture dependent section" operator="AND">
            <criteria comment="Supported architectures section" operator="OR">
              <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
              <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
              <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
              <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
              <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
              <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
              <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
              <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
              <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
            </criteria>
            <criteria comment="Packages section" operator="OR">
              <criterion comment="iceweasel-gnome-support DPKG is earlier than 2.0.0.15-0etch1" test_ref="oval:org.mitre.oval:tst:18615"/>
              <criterion comment="iceweasel-dbg DPKG is earlier than 2.0.0.15-0etch1" test_ref="oval:org.mitre.oval:tst:18314"/>
              <criterion comment="iceweasel DPKG is earlier than 2.0.0.15-0etch1" test_ref="oval:org.mitre.oval:tst:18735"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:8195" class="patch">
      <metadata>
        <title>DSA-1582 peercast -- buffer overflow</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 4.0</platform>
          <product>peercast</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2008/dsa-1582" ref_id="DSA-1582"/>
        <description>Nico Golde discovered that PeerCast, a P2P audio and video streaming server, is vulnerable to a buffer overflow in the HTTP Basic Authentication code, allowing a remote attacker to crash PeerCast or execute arbitrary code.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:08-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T07:56:40.809-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:04:57.468-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:03:42.907-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Release section" operator="AND">
        <extend_definition comment="Debian 4.0 is installed" definition_ref="oval:org.mitre.oval:def:6461"/>
        <criteria comment="Architecture section" operator="OR">
          <criteria comment="Architecture independent section" operator="AND">
            <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
            <criterion comment="peercast-handlers is earlier than 0.1217.toots.20060314-1etch1" test_ref="oval:org.mitre.oval:tst:17480"/>
          </criteria>
          <criteria comment="Architecture dependent section" operator="AND">
            <criteria comment="Supported architectures section" operator="OR">
              <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
              <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
              <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
              <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
              <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
              <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
              <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
              <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
              <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
              <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
            </criteria>
            <criteria comment="Packages section" operator="OR">
              <criterion comment="peercast DPKG is earlier than 0.1217.toots.20060314-1etch1" test_ref="oval:org.mitre.oval:tst:17697"/>
              <criterion comment="libpeercast0-dev DPKG is earlier than 0.1217.toots.20060314-1etch1" test_ref="oval:org.mitre.oval:tst:17687"/>
              <criterion comment="libpeercast0 DPKG is earlier than 0.1217.toots.20060314-1etch1" test_ref="oval:org.mitre.oval:tst:17708"/>
              <criterion comment="peercast-servent DPKG is earlier than 0.1217.toots.20060314-1etch1" test_ref="oval:org.mitre.oval:tst:17802"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:8194" class="patch">
      <metadata>
        <title>DSA-1812 apr-util -- denial of service</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <platform>Debian GNU/Linux 4.0</platform>
          <product>apr-util</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2009/dsa-1812" ref_id="DSA-1812"/>
        <description>Apr-util, the Apache Portable Runtime Utility library, is used by Apache 2.x, Subversion, and other applications. Two denial of service vulnerabilities have been found in apr-util: "kcope" discovered a flaw in the handling of internal XML entities in the apr_xml_* interface that can be exploited to use all available memory. This denial of service can be triggered remotely in the Apache mod_dav and mod_dav_svn modules. (No CVE id yet) Matthew Palmer discovered an underflow flaw in the apr_strmatch_precompile function that can be exploited to cause a daemon crash. The vulnerability can be triggered (1) remotely in mod_dav_svn for Apache if the "SVNMasterURI" directive is in use, (2) remotely in mod_apreq2 for Apache or other applications using libapreq2, or (3) locally in Apache by a crafted ".htaccess" file. Other exploit paths in other applications using apr-util may exist. If you use Apache, or if you use svnserve in standalone mode, you need to restart the services after you upgraded the libaprutil1 package. The oldstable distribution (etch), these problems have been fixed in version 1.2.7+dfsg-2+etch2.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:09-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T07:57:40.544-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:04:56.953-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:03:42.469-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Platform section" operator="OR">
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Architecture dependent section" operator="AND">
              <criteria comment="Supported architectures section" operator="OR">
                <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
                <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
                <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
                <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
                <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
                <criterion comment="Installed architecture is armel" test_ref="oval:org.mitre.oval:tst:11101"/>
                <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
                <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
                <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
                <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
                <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
                <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
              </criteria>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="libaprutil1-dbg DPKG is earlier than 1.2.12+dfsg-8+lenny2" test_ref="oval:org.mitre.oval:tst:18469"/>
                <criterion comment="libaprutil1 DPKG is earlier than 1.2.12+dfsg-8+lenny2" test_ref="oval:org.mitre.oval:tst:18330"/>
                <criterion comment="libaprutil1-dev DPKG is earlier than 1.2.12+dfsg-8+lenny2" test_ref="oval:org.mitre.oval:tst:18582"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 4.0 is installed" definition_ref="oval:org.mitre.oval:def:6461"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Packages section" operator="OR">
              <criterion comment="libaprutil1-dbg DPKG is earlier than 1.2.7+dfsg-2+etch2" test_ref="oval:org.mitre.oval:tst:18566"/>
              <criterion comment="libaprutil1 DPKG is earlier than 1.2.7+dfsg-2+etch2" test_ref="oval:org.mitre.oval:tst:17861"/>
              <criterion comment="libaprutil1-dev DPKG is earlier than 1.2.7+dfsg-2+etch2" test_ref="oval:org.mitre.oval:tst:18562"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:8191" class="patch">
      <metadata>
        <title>DSA-1645 lighttpd -- various</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 4.0</platform>
          <product>lighttpd</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2008/dsa-1645" ref_id="DSA-1645"/>
        <description>Several local/remote vulnerabilities have been discovered in lighttpd, a fast webserver with minimal memory footprint. The Common Vulnerabilities and Exposures project identifies the following problems: A memory leak in the http_request_parse function could be used by remote attackers to cause lighttpd to consume memory, and cause a denial of service attack. Inconsistant handling of URL patterns could lead to the disclosure of resources a server administrator did not anticipate when using rewritten URLs. Upon filesystems which don't handle case-insensitive paths differently it might be possible that unanticipated resources could be made available by mod_userdir.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:08-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T07:56:24.138-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:04:56.472-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:03:42.075-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Release section" operator="AND">
        <extend_definition comment="Debian 4.0 is installed" definition_ref="oval:org.mitre.oval:def:6461"/>
        <criteria comment="Architecture section" operator="OR">
          <criteria comment="Architecture independent section" operator="AND">
            <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
            <criterion comment="lighttpd-doc is earlier than 1.4.13-4etch11" test_ref="oval:org.mitre.oval:tst:17508"/>
          </criteria>
          <criteria comment="Architecture dependent section" operator="AND">
            <criteria comment="Supported architectures section" operator="OR">
              <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
              <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
              <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
              <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
              <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
              <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
              <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
              <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
              <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
            </criteria>
            <criteria comment="Packages section" operator="OR">
              <criterion comment="lighttpd-mod-mysql-vhost DPKG is earlier than 1.4.13-4etch11" test_ref="oval:org.mitre.oval:tst:17348"/>
              <criterion comment="lighttpd-mod-magnet DPKG is earlier than 1.4.13-4etch11" test_ref="oval:org.mitre.oval:tst:17635"/>
              <criterion comment="lighttpd DPKG is earlier than 1.4.13-4etch11" test_ref="oval:org.mitre.oval:tst:17424"/>
              <criterion comment="lighttpd-mod-cml DPKG is earlier than 1.4.13-4etch11" test_ref="oval:org.mitre.oval:tst:17657"/>
              <criterion comment="lighttpd-mod-webdav DPKG is earlier than 1.4.13-4etch11" test_ref="oval:org.mitre.oval:tst:17361"/>
              <criterion comment="lighttpd-mod-trigger-b4-dl DPKG is earlier than 1.4.13-4etch11" test_ref="oval:org.mitre.oval:tst:17554"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:8189" class="patch">
      <metadata>
        <title>DSA-1767 multipath-tools -- insecure file permissions</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <platform>Debian GNU/Linux 4.0</platform>
          <product>multipath-tools</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2009/dsa-1767" ref_id="DSA-1767"/>
        <description>It was discovered that multipathd of multipath-tools, a tool-chain to manage disk multipath device maps, uses insecure permissions on its unix domain control socket which enables local attackers to issue commands to multipathd prevent access to storage devices or corrupt file system data.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:07-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T07:54:59.553-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:04:55.974-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:03:41.611-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Platform section" operator="OR">
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Architecture independent section" operator="AND">
              <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criterion comment="multipath-tools-boot is earlier than 0.4.8-14+lenny1" test_ref="oval:org.mitre.oval:tst:16216"/>
            </criteria>
            <criteria comment="Architecture dependent section" operator="AND">
              <criteria comment="Supported architectures section" operator="OR">
                <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
                <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
                <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
                <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
                <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
                <criterion comment="Installed architecture is armel" test_ref="oval:org.mitre.oval:tst:11101"/>
                <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
                <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
                <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
                <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
                <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
                <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
              </criteria>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="kpartx DPKG is earlier than 0.4.8-14+lenny1" test_ref="oval:org.mitre.oval:tst:16625"/>
                <criterion comment="multipath-tools DPKG is earlier than 0.4.8-14+lenny1" test_ref="oval:org.mitre.oval:tst:16626"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 4.0 is installed" definition_ref="oval:org.mitre.oval:def:6461"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Architecture dependent section" operator="AND">
              <criteria comment="Supported architectures section" operator="OR">
                <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
                <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
                <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
                <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
                <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
                <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
                <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
                <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
                <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
              </criteria>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="multipath-tools DPKG is earlier than 0.4.7-1.1etch2" test_ref="oval:org.mitre.oval:tst:16582"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:8187" class="patch">
      <metadata>
        <title>DSA-1609 lighttpd -- various</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 4.0</platform>
          <product>lighttpd</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2008/dsa-1609" ref_id="DSA-1609"/>
        <description>Several local/remote vulnerabilities have been discovered in lighttpd, a fast webserver with minimal memory footprint. The Common Vulnerabilities and Exposures project identifies the following problems: lighttpd 1.4.18, and possibly other versions before 1.5.0, does not properly calculate the size of a file descriptor array, which allows remote attackers to cause a denial of service (crash) via a large number of connections, which triggers an out-of-bounds access. connections.c in lighttpd before 1.4.16 might accept more connections than the configured maximum, which allows remote attackers to cause a denial of service (failed assertion) via a large number of connection attempts.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:10-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T07:57:51.418-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:04:55.469-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:03:41.213-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Release section" operator="AND">
        <extend_definition comment="Debian 4.0 is installed" definition_ref="oval:org.mitre.oval:def:6461"/>
        <criteria comment="Architecture section" operator="OR">
          <criteria comment="Architecture independent section" operator="AND">
            <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
            <criterion comment="lighttpd-doc is earlier than 1.4.13-4etch9" test_ref="oval:org.mitre.oval:tst:18656"/>
          </criteria>
          <criteria comment="Architecture dependent section" operator="AND">
            <criteria comment="Supported architectures section" operator="OR">
              <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
              <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
              <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
              <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
              <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
              <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
              <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
              <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
              <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
            </criteria>
            <criteria comment="Packages section" operator="OR">
              <criterion comment="lighttpd-mod-mysql-vhost DPKG is earlier than 1.4.13-4etch9" test_ref="oval:org.mitre.oval:tst:18622"/>
              <criterion comment="lighttpd-mod-magnet DPKG is earlier than 1.4.13-4etch9" test_ref="oval:org.mitre.oval:tst:18149"/>
              <criterion comment="lighttpd DPKG is earlier than 1.4.13-4etch9" test_ref="oval:org.mitre.oval:tst:18117"/>
              <criterion comment="lighttpd-mod-cml DPKG is earlier than 1.4.13-4etch9" test_ref="oval:org.mitre.oval:tst:18702"/>
              <criterion comment="lighttpd-mod-webdav DPKG is earlier than 1.4.13-4etch9" test_ref="oval:org.mitre.oval:tst:18746"/>
              <criterion comment="lighttpd-mod-trigger-b4-dl DPKG is earlier than 1.4.13-4etch9" test_ref="oval:org.mitre.oval:tst:18707"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:8185" class="patch">
      <metadata>
        <title>DSA-1764 tunapie -- several vulnerabilities</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <product>tunapie</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2009/dsa-1764" ref_id="DSA-1764"/>
        <description>Several vulnerabilities have been discovered in Tunapie, a GUI frontend to video and radio streams. The Common Vulnerabilities and Exposures project identifies the following problems: Kees Cook discovered that insecure handling of temporary files may lead to local denial of service through symlink attacks. Mike Coleman discovered that insufficient escaping of stream URLs may lead to the execution of arbitrary commands if a user is tricked into opening a malformed stream URL.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:07-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T07:55:00.076-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:04:54.638-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:03:40.965-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Release section" operator="AND">
        <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
        <criteria comment="Architecture section" operator="OR">
          <criteria comment="Architecture independent section" operator="AND">
            <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
            <criterion comment="tunapie is earlier than 2.1.8-2" test_ref="oval:org.mitre.oval:tst:16706"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:8184" class="patch">
      <metadata>
        <title>DSA-1774 ejabberd -- insufficient input sanitising</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <product>ejabberd</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2009/dsa-1774" ref_id="DSA-1774"/>
        <description>It was discovered that ejabberd, a distributed, fault-tolerant Jabber/XMPP server, does not sufficiently sanitise MUC logs, allowing remote attackers to perform cross-site scripting (XSS) attacks. The oldstable distribution (etch) is not affected by this issue.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:10-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T07:58:14.591-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:04:54.148-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:03:40.636-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Release section" operator="AND">
        <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
        <criteria comment="Architecture section" operator="OR">
          <criteria comment="Architecture dependent section" operator="AND">
            <criteria comment="Supported architectures section" operator="OR">
              <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
              <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
              <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
              <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
              <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
              <criterion comment="Installed architecture is armel" test_ref="oval:org.mitre.oval:tst:11101"/>
              <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
              <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
              <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
              <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
              <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
            </criteria>
            <criteria comment="Packages section" operator="OR">
              <criterion comment="ejabberd DPKG is earlier than 2.0.1-6+lenny1" test_ref="oval:org.mitre.oval:tst:18688"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:8183" class="patch">
      <metadata>
        <title>DSA-1630 linux-2.6 -- denial of service/information leak</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 4.0</platform>
          <product>linux-2.6</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2008/dsa-1630" ref_id="DSA-1630"/>
        <description>Several vulnerabilities have been discovered in the Linux kernel that may lead to a denial of service or arbitrary code execution. The Common Vulnerabilities and Exposures project identifies the following problems: Dirk Nehring discovered a vulnerability in the IPsec code that allows remote users to cause a denial of service by sending a specially crafted ESP packet. Tavis Ormandy discovered a vulnerability that allows local users to access uninitialized kernel memory, possibly leaking sensitive data. This issue is specific to the amd64-flavour kernel images. Andi Kleen discovered an issue where uninitialized kernel memory was being leaked to userspace during an exception. This issue may allow local users to gain access to sensitive data. Only the amd64-flavour Debian kernel images are affected. Alan Cox discovered an issue in multiple tty drivers that allows local users to trigger a denial of service (NULL pointer dereference) and possibly obtain elevated privileges. Gabriel Campana discovered an integer overflow in the sctp code that can be exploited by local users to cause a denial of service. Miklos Szeredi reported a missing privilege check in the do_change_type() function. This allows local, unprivileged users to change the properties of mount points. Tobias Klein reported a locally exploitable data leak in the snd_seq_oss_synth_make_info() function. This may allow local users to gain access to sensitive information. Zoltan Sogor discovered a coding error in the VFS that allows local users to exploit a kernel memory leak resulting in a denial of service.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:05-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T07:53:34.090-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:04:52.994-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:03:39.779-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Release section" operator="AND">
        <extend_definition comment="Debian 4.0 is installed" definition_ref="oval:org.mitre.oval:def:6461"/>
        <criteria comment="Architecture section" operator="OR">
          <criteria comment="Architecture independent section" operator="AND">
            <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
            <criteria comment="Packages section" operator="OR">
              <criterion comment="linux-support-2.6.18-6 is earlier than 2.6.18.dfsg.1-22etch2" test_ref="oval:org.mitre.oval:tst:15111"/>
              <criterion comment="linux-patch-debian-2.6.18 is earlier than 2.6.18.dfsg.1-22etch2" test_ref="oval:org.mitre.oval:tst:15385"/>
              <criterion comment="linux-source-2.6.18 is earlier than 2.6.18.dfsg.1-22etch2" test_ref="oval:org.mitre.oval:tst:15351"/>
              <criterion comment="linux-manual-2.6.18 is earlier than 2.6.18.dfsg.1-22etch2" test_ref="oval:org.mitre.oval:tst:15411"/>
              <criterion comment="linux-tree-2.6.18 is earlier than 2.6.18.dfsg.1-22etch2" test_ref="oval:org.mitre.oval:tst:15283"/>
              <criterion comment="linux-doc-2.6.18 is earlier than 2.6.18.dfsg.1-22etch2" test_ref="oval:org.mitre.oval:tst:15316"/>
            </criteria>
          </criteria>
          <criteria comment="Architecture dependent section" operator="AND">
            <criteria comment="Supported architectures section" operator="OR">
              <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
            </criteria>
            <criteria comment="Packages section" operator="OR">
              <criterion comment="linux-headers-2.6.18-6-vserver-s390x DPKG is earlier than 2.6.18.dfsg.1-22etch2" test_ref="oval:org.mitre.oval:tst:15445"/>
              <criterion comment="linux-headers-2.6.18-6-s390 DPKG is earlier than 2.6.18.dfsg.1-22etch2" test_ref="oval:org.mitre.oval:tst:15414"/>
              <criterion comment="linux-headers-2.6.18-6-all DPKG is earlier than 2.6.18.dfsg.1-22etch2" test_ref="oval:org.mitre.oval:tst:14663"/>
              <criterion comment="linux-image-2.6.18-6-s390x DPKG is earlier than 2.6.18.dfsg.1-22etch2" test_ref="oval:org.mitre.oval:tst:15430"/>
              <criterion comment="linux-image-2.6.18-6-vserver-s390x DPKG is earlier than 2.6.18.dfsg.1-22etch2" test_ref="oval:org.mitre.oval:tst:15090"/>
              <criterion comment="linux-image-2.6.18-6-s390-tape DPKG is earlier than 2.6.18.dfsg.1-22etch2" test_ref="oval:org.mitre.oval:tst:15468"/>
              <criterion comment="linux-image-2.6.18-6-s390 DPKG is earlier than 2.6.18.dfsg.1-22etch2" test_ref="oval:org.mitre.oval:tst:14920"/>
              <criterion comment="linux-headers-2.6.18-6-vserver DPKG is earlier than 2.6.18.dfsg.1-22etch2" test_ref="oval:org.mitre.oval:tst:14486"/>
              <criterion comment="linux-headers-2.6.18-6-all-s390 DPKG is earlier than 2.6.18.dfsg.1-22etch2" test_ref="oval:org.mitre.oval:tst:15127"/>
              <criterion comment="linux-headers-2.6.18-6 DPKG is earlier than 2.6.18.dfsg.1-22etch2" test_ref="oval:org.mitre.oval:tst:15371"/>
              <criterion comment="linux-headers-2.6.18-6-s390x DPKG is earlier than 2.6.18.dfsg.1-22etch2" test_ref="oval:org.mitre.oval:tst:15427"/>
            </criteria>
          </criteria>
          <criteria comment="Architecture dependent section" operator="AND">
            <criteria comment="Supported architectures section" operator="OR">
              <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
            </criteria>
            <criteria comment="Packages section" operator="OR">
              <criterion comment="linux-image-2.6.18-6-xen-amd64 DPKG is earlier than 2.6.18.dfsg.1-22etch2" test_ref="oval:org.mitre.oval:tst:15045"/>
              <criterion comment="linux-headers-2.6.18-6-all DPKG is earlier than 2.6.18.dfsg.1-22etch2" test_ref="oval:org.mitre.oval:tst:15342"/>
              <criterion comment="fai-kernels DPKG is earlier than 1.17+etch.22etch2" test_ref="oval:org.mitre.oval:tst:14630"/>
              <criterion comment="xen-linux-system-2.6.18-6-xen-amd64 DPKG is earlier than 2.6.18.dfsg.1-22etch2" test_ref="oval:org.mitre.oval:tst:15398"/>
              <criterion comment="linux-image-2.6.18-6-amd64 DPKG is earlier than 2.6.18.dfsg.1-22etch2" test_ref="oval:org.mitre.oval:tst:15110"/>
              <criterion comment="linux-image-2.6.18-6-vserver-amd64 DPKG is earlier than 2.6.18.dfsg.1-22etch2" test_ref="oval:org.mitre.oval:tst:15415"/>
              <criterion comment="linux-image-2.6.18-6-xen-vserver-amd64 DPKG is earlier than 2.6.18.dfsg.1-22etch2" test_ref="oval:org.mitre.oval:tst:15218"/>
              <criterion comment="linux-headers-2.6.18-6-xen-amd64 DPKG is earlier than 2.6.18.dfsg.1-22etch2" test_ref="oval:org.mitre.oval:tst:15405"/>
              <criterion comment="xen-linux-system-2.6.18-6-xen-vserver-amd64 DPKG is earlier than 2.6.18.dfsg.1-22etch2" test_ref="oval:org.mitre.oval:tst:14513"/>
              <criterion comment="linux-headers-2.6.18-6-amd64 DPKG is earlier than 2.6.18.dfsg.1-22etch2" test_ref="oval:org.mitre.oval:tst:15424"/>
              <criterion comment="linux-headers-2.6.18-6-xen DPKG is earlier than 2.6.18.dfsg.1-22etch2" test_ref="oval:org.mitre.oval:tst:14915"/>
              <criterion comment="linux-headers-2.6.18-6-xen-vserver-amd64 DPKG is earlier than 2.6.18.dfsg.1-22etch2" test_ref="oval:org.mitre.oval:tst:15093"/>
              <criterion comment="linux-headers-2.6.18-6-vserver DPKG is earlier than 2.6.18.dfsg.1-22etch2" test_ref="oval:org.mitre.oval:tst:15292"/>
              <criterion comment="linux-headers-2.6.18-6-vserver-amd64 DPKG is earlier than 2.6.18.dfsg.1-22etch2" test_ref="oval:org.mitre.oval:tst:15246"/>
              <criterion comment="linux-headers-2.6.18-6-all-amd64 DPKG is earlier than 2.6.18.dfsg.1-22etch2" test_ref="oval:org.mitre.oval:tst:15268"/>
              <criterion comment="linux-headers-2.6.18-6 DPKG is earlier than 2.6.18.dfsg.1-22etch2" test_ref="oval:org.mitre.oval:tst:15477"/>
              <criterion comment="linux-modules-2.6.18-6-xen-amd64 DPKG is earlier than 2.6.18.dfsg.1-22etch2" test_ref="oval:org.mitre.oval:tst:15232"/>
              <criterion comment="linux-headers-2.6.18-6-xen-vserver DPKG is earlier than 2.6.18.dfsg.1-22etch2" test_ref="oval:org.mitre.oval:tst:15506"/>
              <criterion comment="linux-modules-2.6.18-6-xen-vserver-amd64 DPKG is earlier than 2.6.18.dfsg.1-22etch2" test_ref="oval:org.mitre.oval:tst:15224"/>
            </criteria>
          </criteria>
          <criteria comment="Architecture depended section" operator="AND">
            <criteria comment="Supported platform section" operator="AND">
              <criterion comment="hppa architecture" test_ref="oval:org.mitre.oval:tst:11164"/>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="linux-headers-2.6.18-6-parisc64 DPKG is earlier than 2.6.18.dfsg.1-22etch2" test_ref="oval:org.mitre.oval:tst:15271"/>
                <criterion comment="linux-image-2.6.18-6-parisc64-smp DPKG is earlier than 2.6.18.dfsg.1-22etch2" test_ref="oval:org.mitre.oval:tst:15304"/>
                <criterion comment="linux-headers-2.6.18-6-all DPKG is earlier than 2.6.18.dfsg.1-22etch2" test_ref="oval:org.mitre.oval:tst:15092"/>
                <criterion comment="linux-headers-2.6.18-6-parisc DPKG is earlier than 2.6.18.dfsg.1-22etch2" test_ref="oval:org.mitre.oval:tst:15154"/>
                <criterion comment="linux-image-2.6.18-6-parisc64 DPKG is earlier than 2.6.18.dfsg.1-22etch2" test_ref="oval:org.mitre.oval:tst:15210"/>
                <criterion comment="linux-headers-2.6.18-6-parisc-smp DPKG is earlier than 2.6.18.dfsg.1-22etch2" test_ref="oval:org.mitre.oval:tst:14567"/>
                <criterion comment="linux-image-2.6.18-6-parisc DPKG is earlier than 2.6.18.dfsg.1-22etch2" test_ref="oval:org.mitre.oval:tst:14741"/>
                <criterion comment="linux-headers-2.6.18-6 DPKG is earlier than 2.6.18.dfsg.1-22etch2" test_ref="oval:org.mitre.oval:tst:15285"/>
                <criterion comment="linux-headers-2.6.18-6-parisc64-smp DPKG is earlier than 2.6.18.dfsg.1-22etch2" test_ref="oval:org.mitre.oval:tst:15501"/>
                <criterion comment="linux-headers-2.6.18-6-all-hppa DPKG is earlier than 2.6.18.dfsg.1-22etch2" test_ref="oval:org.mitre.oval:tst:15227"/>
                <criterion comment="linux-image-2.6.18-6-parisc-smp DPKG is earlier than 2.6.18.dfsg.1-22etch2" test_ref="oval:org.mitre.oval:tst:15284"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:8182" class="patch">
      <metadata>
        <title>DSA-1924 mahara -- several vulnerabilities</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <product>mahara</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2009/dsa-1924" ref_id="DSA-1924"/>
        <description>Two vulnerabilities have been discovered in mahara, an electronic portfolio, weblog, and resume builder. The Common Vulnerabilities and Exposures project identifies the following problems: Ruslan Kabalin discovered a issue with resetting passwords, which could lead to a privilege escalation of an institutional administrator account. Sven Vetsch discovered a cross-site scripting vulnerability via the resume fields.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:08-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T07:56:03.911-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:04:52.727-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:03:39.551-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Release section" operator="AND">
        <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
        <criteria comment="Architecture section" operator="OR">
          <criteria comment="Architecture independent section" operator="AND">
            <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
            <criteria comment="Packages section" operator="OR">
              <criterion comment="mahara-apache2 is earlier than 1.0.4-4+lenny4" test_ref="oval:org.mitre.oval:tst:16733"/>
              <criterion comment="mahara is earlier than 1.0.4-4+lenny4" test_ref="oval:org.mitre.oval:tst:17305"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:8181" class="patch">
      <metadata>
        <title>DSA-1766 krb5 -- several vulnerabilities</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <platform>Debian GNU/Linux 4.0</platform>
          <product>krb5</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2009/dsa-1766" ref_id="DSA-1766"/>
        <description>Several vulnerabilities have been found in the MIT reference implementation of Kerberos V5, a system for authenticating users and services on a network. The Common Vulnerabilities and Exposures project identified the following problems: The Apple Product Security team discovered that the SPNEGO GSS-API mechanism suffers of a missing bounds check when reading a network input buffer which results in an invalid read crashing the application or possibly leaking information. Under certain conditions the SPNEGO GSS-API mechanism references a null pointer which crashes the application using the library. An incorrect length check inside the ASN.1 decoder of the MIT krb5 implementation allows an unauthenticated remote attacker to crash of the kinit or KDC program. Under certain conditions the the ASN.1 decoder of the MIT krb5 implementation frees an uninitialized pointer which could lead to denial of service and possibly arbitrary code execution.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:07-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T07:54:58.295-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:04:51.621-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:03:38.825-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Platform section" operator="OR">
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Architecture independent section" operator="AND">
              <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criterion comment="krb5-doc is earlier than 1.6.dfsg.4~beta1-5lenny1" test_ref="oval:org.mitre.oval:tst:16278"/>
            </criteria>
            <criteria comment="Architecture dependent section" operator="AND">
              <criteria comment="Supported architectures section" operator="OR">
                <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
                <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
                <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
                <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
                <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
                <criterion comment="Installed architecture is armel" test_ref="oval:org.mitre.oval:tst:11101"/>
                <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
                <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
                <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
                <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
                <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
              </criteria>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="krb5-rsh-server DPKG is earlier than 1.6.dfsg.4~beta1-5lenny1" test_ref="oval:org.mitre.oval:tst:16590"/>
                <criterion comment="krb5-kdc-ldap DPKG is earlier than 1.6.dfsg.4~beta1-5lenny1" test_ref="oval:org.mitre.oval:tst:16660"/>
                <criterion comment="krb5-telnetd DPKG is earlier than 1.6.dfsg.4~beta1-5lenny1" test_ref="oval:org.mitre.oval:tst:16148"/>
                <criterion comment="libkrb5-dev DPKG is earlier than 1.6.dfsg.4~beta1-5lenny1" test_ref="oval:org.mitre.oval:tst:16839"/>
                <criterion comment="libkrb53 DPKG is earlier than 1.6.dfsg.4~beta1-5lenny1" test_ref="oval:org.mitre.oval:tst:16583"/>
                <criterion comment="krb5-ftpd DPKG is earlier than 1.6.dfsg.4~beta1-5lenny1" test_ref="oval:org.mitre.oval:tst:16462"/>
                <criterion comment="krb5-pkinit DPKG is earlier than 1.6.dfsg.4~beta1-5lenny1" test_ref="oval:org.mitre.oval:tst:16027"/>
                <criterion comment="libkadm55 DPKG is earlier than 1.6.dfsg.4~beta1-5lenny1" test_ref="oval:org.mitre.oval:tst:16050"/>
                <criterion comment="libkrb5-dbg DPKG is earlier than 1.6.dfsg.4~beta1-5lenny1" test_ref="oval:org.mitre.oval:tst:16266"/>
                <criterion comment="krb5-user DPKG is earlier than 1.6.dfsg.4~beta1-5lenny1" test_ref="oval:org.mitre.oval:tst:16819"/>
                <criterion comment="krb5-kdc DPKG is earlier than 1.6.dfsg.4~beta1-5lenny1" test_ref="oval:org.mitre.oval:tst:15852"/>
                <criterion comment="krb5-clients DPKG is earlier than 1.6.dfsg.4~beta1-5lenny1" test_ref="oval:org.mitre.oval:tst:16836"/>
                <criterion comment="krb5-admin-server DPKG is earlier than 1.6.dfsg.4~beta1-5lenny1" test_ref="oval:org.mitre.oval:tst:16407"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 4.0 is installed" definition_ref="oval:org.mitre.oval:def:6461"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Architecture independent section" operator="AND">
              <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criterion comment="krb5-doc is earlier than 1.4.4-7etch7" test_ref="oval:org.mitre.oval:tst:15857"/>
            </criteria>
            <criteria comment="Packages section" operator="OR">
              <criterion comment="krb5-rsh-server DPKG is earlier than 1.4.4-7etch7" test_ref="oval:org.mitre.oval:tst:16837"/>
              <criterion comment="krb5-telnetd DPKG is earlier than 1.4.4-7etch7" test_ref="oval:org.mitre.oval:tst:15941"/>
              <criterion comment="libkrb5-dev DPKG is earlier than 1.4.4-7etch7" test_ref="oval:org.mitre.oval:tst:16754"/>
              <criterion comment="libkrb53 DPKG is earlier than 1.4.4-7etch7" test_ref="oval:org.mitre.oval:tst:16814"/>
              <criterion comment="krb5-ftpd DPKG is earlier than 1.4.4-7etch7" test_ref="oval:org.mitre.oval:tst:16694"/>
              <criterion comment="krb5-admin-server DPKG is earlier than 1.4.4-7etch7" test_ref="oval:org.mitre.oval:tst:16636"/>
              <criterion comment="libkadm55 DPKG is earlier than 1.4.4-7etch7" test_ref="oval:org.mitre.oval:tst:16477"/>
              <criterion comment="libkrb5-dbg DPKG is earlier than 1.4.4-7etch7" test_ref="oval:org.mitre.oval:tst:16798"/>
              <criterion comment="krb5-user DPKG is earlier than 1.4.4-7etch7" test_ref="oval:org.mitre.oval:tst:16842"/>
              <criterion comment="krb5-clients DPKG is earlier than 1.4.4-7etch7" test_ref="oval:org.mitre.oval:tst:16768"/>
              <criterion comment="krb5-kdc DPKG is earlier than 1.4.4-7etch7" test_ref="oval:org.mitre.oval:tst:16170"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:8180" class="patch">
      <metadata>
        <title>DSA-1461 libxml2 -- missing input validation</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 4.0</platform>
          <platform>Debian GNU/Linux 3.1</platform>
          <product>libxml2</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2008/dsa-1461" ref_id="DSA-1461"/>
        <description>Brad Fitzpatrick discovered that the UTF-8 decoding functions of libxml2, the GNOME XML library, validate UTF-8 correctness insufficiently, which may lead to denial of service by forcing libxml2 into an infinite loop. For the old stable distribution (sarge), this problem has been fixed in version 2.6.16-7sarge1. For the stable distribution (etch), this problem has been fixed in version 2.6.27.dfsg-2. For the unstable distribution (sid), this problem will be fixed soon. We recommend that you upgrade your libxml2 packages.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:08-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T07:55:47.527-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:04:50.935-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:03:38.289-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Platform section" operator="OR">
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 4.0 is installed" definition_ref="oval:org.mitre.oval:def:6461"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Architecture independent section" operator="AND">
              <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criterion comment="libxml2-doc is earlier than 2.6.27.dfsg-2" test_ref="oval:org.mitre.oval:tst:16665"/>
            </criteria>
            <criteria comment="Architecture dependent section" operator="AND">
              <criteria comment="Supported architectures section" operator="OR">
                <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
                <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
                <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
                <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
                <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
                <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
                <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
                <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
                <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
                <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
              </criteria>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="libxml2 DPKG is earlier than 2.6.27.dfsg-2" test_ref="oval:org.mitre.oval:tst:17072"/>
                <criterion comment="libxml2-dev DPKG is earlier than 2.6.27.dfsg-2" test_ref="oval:org.mitre.oval:tst:17016"/>
                <criterion comment="libxml2-dbg DPKG is earlier than 2.6.27.dfsg-2" test_ref="oval:org.mitre.oval:tst:16623"/>
                <criterion comment="python-libxml2 DPKG is earlier than 2.6.27.dfsg-2" test_ref="oval:org.mitre.oval:tst:17216"/>
                <criterion comment="libxml2-utils DPKG is earlier than 2.6.27.dfsg-2" test_ref="oval:org.mitre.oval:tst:16589"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 3.1 is installed" definition_ref="oval:org.mitre.oval:def:7692"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Architecture independent section" operator="AND">
              <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="python-libxml2 is earlier than 2.6.16-7sarge1" test_ref="oval:org.mitre.oval:tst:16769"/>
                <criterion comment="libxml2-doc is earlier than 2.6.16-7sarge1" test_ref="oval:org.mitre.oval:tst:17020"/>
                <criterion comment="libxml2-python2.3 is earlier than 2.6.16-7sarge1" test_ref="oval:org.mitre.oval:tst:17114"/>
              </criteria>
            </criteria>
            <criteria comment="Architecture dependent section" operator="AND">
              <criteria comment="Supported architectures section" operator="OR">
                <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
                <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
                <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
                <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
                <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
                <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
                <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
                <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
                <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
                <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
              </criteria>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="python2.2-libxml2 DPKG is earlier than 2.6.16-7sarge1" test_ref="oval:org.mitre.oval:tst:17080"/>
                <criterion comment="libxml2-utils DPKG is earlier than 2.6.16-7sarge1" test_ref="oval:org.mitre.oval:tst:16854"/>
                <criterion comment="libxml2 DPKG is earlier than 2.6.16-7sarge1" test_ref="oval:org.mitre.oval:tst:16681"/>
                <criterion comment="python2.3-libxml2 DPKG is earlier than 2.6.16-7sarge1" test_ref="oval:org.mitre.oval:tst:17090"/>
                <criterion comment="python2.4-libxml2 DPKG is earlier than 2.6.16-7sarge1" test_ref="oval:org.mitre.oval:tst:16880"/>
                <criterion comment="libxml2-dev DPKG is earlier than 2.6.16-7sarge1" test_ref="oval:org.mitre.oval:tst:16630"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:8178" class="patch">
      <metadata>
        <title>DSA-1917 mimetex -- several vulnerabilities</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 4.0</platform>
          <product>mimetex</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2009/dsa-1917" ref_id="DSA-1917"/>
        <description>Several vulnerabilities have been discovered in mimetex, a lightweight alternative to MathML. The Common Vulnerabilities and Exposures project identifies the following problems: Chris Evans and Damien Miller, discovered multiple stack-based buffer overflow. An attacker could execute arbitrary code via a TeX file with long picture, circle, input tags. Chris Evans discovered that mimeTeX contained certain directives that may be unsuitable for handling untrusted user input. A remote attacker can obtain sensitive information.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:07-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T07:54:22.516-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:04:50.644-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:03:38.004-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Release section" operator="AND">
        <extend_definition comment="Debian 4.0 is installed" definition_ref="oval:org.mitre.oval:def:6461"/>
        <criteria comment="Architecture section" operator="OR">
          <criteria comment="Packages section" operator="OR">
            <criterion comment="mimetex DPKG is earlier than 1.50-1+etch1" test_ref="oval:org.mitre.oval:tst:15455"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:8177" class="patch">
      <metadata>
        <title>DSA-1544 pdns-recursor -- design flaw</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 4.0</platform>
          <product>pdns-recursor</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2008/dsa-1544" ref_id="DSA-1544"/>
        <description>Amit Klein discovered that pdns-recursor, a caching DNS resolver, uses a weak random number generator to create DNS transaction IDs and UDP source port numbers. As a result, cache poisoning attacks were simplified. (CVE-2008-1637 and CVE-2008-3217)</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:07-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T07:55:18.867-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:04:50.241-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:03:37.734-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Release section" operator="AND">
        <extend_definition comment="Debian 4.0 is installed" definition_ref="oval:org.mitre.oval:def:6461"/>
        <criteria comment="Architecture section" operator="OR">
          <criteria comment="Architecture dependent section" operator="AND">
            <criteria comment="Supported architectures section" operator="OR">
              <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
              <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
              <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
              <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
              <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
              <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
            </criteria>
            <criteria comment="Packages section" operator="OR">
              <criterion comment="pdns-recursor DPKG is earlier than 3.1.4-1+etch2" test_ref="oval:org.mitre.oval:tst:16956"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:8176" class="patch">
      <metadata>
        <title>DSA-1729 gst-plugins-bad0.10 -- several vulnerabilities</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 4.0</platform>
          <product>gst-plugins-bad0.10</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2009/dsa-1729" ref_id="DSA-1729"/>
        <description>Several vulnerabilities have been found in gst-plugins-bad0.10, a collection of various GStreamer plugins. The Common Vulnerabilities and Exposures project identifies the following problems: Tobias Klein discovered a buffer overflow in the quicktime stream demuxer (qtdemux), which could potentially lead to the execution of arbitrary code via crafted .mov files. Tobias Klein discovered an array index error in the quicktime stream demuxer (qtdemux), which could potentially lead to the execution of arbitrary code via crafted .mov files. Tobias Klein discovered a buffer overflow in the quicktime stream demuxer (qtdemux) similar to the issue reported in CVE-2009-0386, which could also lead to the execution of arbitrary code via crafted .mov files.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:08-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T07:56:29.074-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:04:49.263-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:03:37.325-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Release section" operator="AND">
        <extend_definition comment="Debian 4.0 is installed" definition_ref="oval:org.mitre.oval:def:6461"/>
        <criteria comment="Architecture section" operator="OR">
          <criteria comment="Architecture dependent section" operator="AND">
            <criteria comment="Supported architectures section" operator="OR">
              <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
              <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
              <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
              <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
              <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
              <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
              <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
              <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
              <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
              <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
            </criteria>
            <criteria comment="Packages section" operator="OR">
              <criterion comment="gstreamer0.10-plugins-bad DPKG is earlier than 0.10.3-3.1+etch1" test_ref="oval:org.mitre.oval:tst:17506"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:8174" class="patch">
      <metadata>
        <title>DSA-1828 ocsinventory-agent -- insecure module search path</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <product>ocsinventory-agent</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2009/dsa-1828" ref_id="DSA-1828"/>
        <description>It was discovered that the ocsinventory-agent which is part of the ocsinventory suite, a hardware and software configuration indexing service, is prone to an insecure perl module search path. As the agent is started via cron and the current directory (/ in this case) is included in the default perl module path the agent scans every directory on the system for its perl modules. This enables an attacker to execute arbitrary code via a crafted ocsinventory-agent perl module placed on the system. The oldstable distribution (etch) does not contain ocsinventory-agent.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:08-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T07:55:53.191-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:04:48.957-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:03:37.118-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Release section" operator="AND">
        <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
        <criteria comment="Architecture section" operator="OR">
          <criteria comment="Architecture independent section" operator="AND">
            <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
            <criterion comment="ocsinventory-agent is earlier than 0.0.9.2repack1-4lenny1" test_ref="oval:org.mitre.oval:tst:17225"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:8173" class="patch">
      <metadata>
        <title>DSA-1478 mysql-dfsg-5.0 -- buffer overflows</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 4.0</platform>
          <product>mysql-dfsg-5.0</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2008/dsa-1478" ref_id="DSA-1478"/>
        <description>Luigi Auriemma discovered two buffer overflows in YaSSL, an SSL implementation included in the MySQL database package, which could lead to denial of service and possibly the execution of arbitrary code. The old stable distribution (sarge) doesn't contain mysql-dfsg-5.0.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:07-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T07:54:35.327-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:04:48.654-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:03:36.767-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Release section" operator="AND">
        <extend_definition comment="Debian 4.0 is installed" definition_ref="oval:org.mitre.oval:def:6461"/>
        <criteria comment="Architecture section" operator="OR">
          <criteria comment="Architecture independent section" operator="AND">
            <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
            <criteria comment="Packages section" operator="OR">
              <criterion comment="mysql-client is earlier than 5.0.32-7etch5" test_ref="oval:org.mitre.oval:tst:16489"/>
              <criterion comment="mysql-common is earlier than 5.0.32-7etch5" test_ref="oval:org.mitre.oval:tst:15777"/>
              <criterion comment="mysql-server is earlier than 5.0.32-7etch5" test_ref="oval:org.mitre.oval:tst:16418"/>
            </criteria>
          </criteria>
          <criteria comment="Packages section" operator="OR">
            <criterion comment="libmysqlclient15-dev DPKG is earlier than 5.0.32-7etch5" test_ref="oval:org.mitre.oval:tst:16494"/>
            <criterion comment="mysql-server-4.1 DPKG is earlier than 5.0.32-7etch5" test_ref="oval:org.mitre.oval:tst:16427"/>
            <criterion comment="mysql-client-5.0 DPKG is earlier than 5.0.32-7etch5" test_ref="oval:org.mitre.oval:tst:16197"/>
            <criterion comment="mysql-server-5.0 DPKG is earlier than 5.0.32-7etch5" test_ref="oval:org.mitre.oval:tst:16158"/>
            <criterion comment="libmysqlclient15off DPKG is earlier than 5.0.32-7etch5" test_ref="oval:org.mitre.oval:tst:16381"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:8172" class="patch">
      <metadata>
        <title>DSA-1464 syslog-ng -- null pointer dereference</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 4.0</platform>
          <product>syslog-ng</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2008/dsa-1464" ref_id="DSA-1464"/>
        <description>Oriol Carreras discovered that syslog-ng, a next generation logging daemon can be tricked into dereferencing a NULL pointer through malformed timestamps, which can lead to denial of service and the disguise of an subsequent attack, which would otherwise be logged. The old stable distribution (sarge) is not affected. For the stable distribution (etch), this problem has been fixed in version 2.0.0-1etch1. For the unstable distribution (sid), this problem has been fixed in version 2.0.6-1. We recommend that you upgrade your syslog-ng package.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:07-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T07:55:30.913-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:04:48.431-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:03:36.562-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Release section" operator="AND">
        <extend_definition comment="Debian 4.0 is installed" definition_ref="oval:org.mitre.oval:def:6461"/>
        <criteria comment="Architecture section" operator="OR">
          <criteria comment="Packages section" operator="OR">
            <criterion comment="syslog-ng DPKG is earlier than 2.0.0-1etch1" test_ref="oval:org.mitre.oval:tst:16675"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:8171" class="patch">
      <metadata>
        <title>DSA-1931 nspr -- several vulnerabilities</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <product>nspr</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2009/dsa-1931" ref_id="DSA-1931"/>
        <description>Several vulnerabilities have been discovered in the NetScape Portable Runtime Library, which may lead to the execution of arbitrary code. The Common Vulnerabilities and Exposures project identifies the following problems: A programming error in the string handling code may lead to the execution of arbitrary code. An integer overflow in the Base64 decoding functions may lead to the execution of arbitrary code. The old stable distribution (etch) doesn't contain nspr.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:11-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T07:59:08.789-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:04:47.959-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:03:36.196-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Release section" operator="AND">
        <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
        <criteria comment="Architecture section" operator="OR">
          <criteria comment="Architecture dependent section" operator="AND">
            <criteria comment="Supported architectures section" operator="OR">
              <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
              <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
              <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
              <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
              <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
              <criterion comment="Installed architecture is armel" test_ref="oval:org.mitre.oval:tst:11101"/>
              <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
              <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
              <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
              <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
              <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
              <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
            </criteria>
            <criteria comment="Packages section" operator="OR">
              <criterion comment="libnspr4-dev DPKG is earlier than 4.7.1-5" test_ref="oval:org.mitre.oval:tst:19338"/>
              <criterion comment="libnspr4-0d-dbg DPKG is earlier than 4.7.1-5" test_ref="oval:org.mitre.oval:tst:19456"/>
              <criterion comment="libnspr4-0d DPKG is earlier than 4.7.1-5" test_ref="oval:org.mitre.oval:tst:19452"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:8170" class="patch">
      <metadata>
        <title>DSA-1656 cupsys -- several vulnerabilities</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 4.0</platform>
          <product>cupsys</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2008/dsa-1656" ref_id="DSA-1656"/>
        <description>Several local vulnerabilities have been discovered in the Common UNIX Printing System. The Common Vulnerabilities and Exposures project identifies the following problems: It was discovered that insufficient bounds checking in the SGI image filter may lead to the execution of arbitrary code. It was discovered that an integer overflow in the Postscript conversion tool texttops may lead to the execution of arbitrary code. It was discovered that insufficient bounds checking in the HPGL filter may lead to the execution of arbitrary code.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:05-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T07:53:25.529-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:04:47.450-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:03:35.722-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Release section" operator="AND">
        <extend_definition comment="Debian 4.0 is installed" definition_ref="oval:org.mitre.oval:def:6461"/>
        <criteria comment="Architecture section" operator="OR">
          <criteria comment="Architecture independent section" operator="AND">
            <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
            <criteria comment="Packages section" operator="OR">
              <criterion comment="libcupsys2-gnutls10 is earlier than 1.2.7-4etch5" test_ref="oval:org.mitre.oval:tst:14443"/>
              <criterion comment="cupsys-common is earlier than 1.2.7-4etch5" test_ref="oval:org.mitre.oval:tst:14808"/>
            </criteria>
          </criteria>
          <criteria comment="Architecture dependent section" operator="AND">
            <criteria comment="Supported architectures section" operator="OR">
              <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
              <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
              <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
              <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
              <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
              <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
              <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
              <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
              <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
              <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
            </criteria>
            <criteria comment="Packages section" operator="OR">
              <criterion comment="cupsys-bsd DPKG is earlier than 1.2.7-4etch5" test_ref="oval:org.mitre.oval:tst:15186"/>
              <criterion comment="cupsys-client DPKG is earlier than 1.2.7-4etch5" test_ref="oval:org.mitre.oval:tst:14992"/>
              <criterion comment="libcupsimage2 DPKG is earlier than 1.2.7-4etch5" test_ref="oval:org.mitre.oval:tst:15145"/>
              <criterion comment="libcupsimage2-dev DPKG is earlier than 1.2.7-4etch5" test_ref="oval:org.mitre.oval:tst:14501"/>
              <criterion comment="libcupsys2-dev DPKG is earlier than 1.2.7-4etch5" test_ref="oval:org.mitre.oval:tst:15212"/>
              <criterion comment="cupsys-dbg DPKG is earlier than 1.2.7-4etch5" test_ref="oval:org.mitre.oval:tst:14229"/>
              <criterion comment="cupsys DPKG is earlier than 1.2.7-4etch5" test_ref="oval:org.mitre.oval:tst:14910"/>
              <criterion comment="libcupsys2 DPKG is earlier than 1.2.7-4etch5" test_ref="oval:org.mitre.oval:tst:15073"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:8168" class="patch">
      <metadata>
        <title>DSA-1872 linux-2.6 -- denial of service/privilege escalation/information leak</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 4.0</platform>
          <product>linux-2.6</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2009/dsa-1872" ref_id="DSA-1872"/>
        <description>Several vulnerabilities have been discovered in the Linux kernel that may lead to denial of service, privilege escalation or a leak of sensitive memory. The Common Vulnerabilities and Exposures project identifies the following problems: Herbert Xu discovered an issue in the way UDP tracks corking status that could allow local users to cause a denial of service (system crash). Tavis Ormandy and Julien Tinnes discovered that this issue could also be used by local users to gain elevated privileges. Michael Buesch noticed a typing issue in the eisa-eeprom driver for the hppa architecture. Local users could exploit this issue to gain access to restricted memory. Ulrich Drepper noticed an issue in the do_sigalstack routine on 64-bit systems. This issue allows local users to gain access to potentially sensitive memory on the kernel stack. Eric Dumazet discovered an issue in the execve path, where the clear_child_tid variable was not being properly cleared. Local users could exploit this issue to cause a denial of service (memory corruption). Neil Brown discovered an issue in the sysfs interface to md devices. When md arrays are not active, local users can exploit this vulnerability to cause a denial of service (oops).</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:06-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T07:53:46.885-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:04:46.444-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:03:34.864-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Release section" operator="AND">
        <extend_definition comment="Debian 4.0 is installed" definition_ref="oval:org.mitre.oval:def:6461"/>
        <criteria comment="Architecture section" operator="OR">
          <criteria comment="Architecture independent section" operator="AND">
            <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
            <criteria comment="Packages section" operator="OR">
              <criterion comment="linux-support-2.6.18-6 is earlier than 2.6.18.dfsg.1-24etch4" test_ref="oval:org.mitre.oval:tst:15594"/>
              <criterion comment="linux-patch-debian-2.6.18 is earlier than 2.6.18.dfsg.1-24etch4" test_ref="oval:org.mitre.oval:tst:15556"/>
              <criterion comment="linux-source-2.6.18 is earlier than 2.6.18.dfsg.1-24etch4" test_ref="oval:org.mitre.oval:tst:15577"/>
              <criterion comment="linux-manual-2.6.18 is earlier than 2.6.18.dfsg.1-24etch4" test_ref="oval:org.mitre.oval:tst:15549"/>
              <criterion comment="linux-tree-2.6.18 is earlier than 2.6.18.dfsg.1-24etch4" test_ref="oval:org.mitre.oval:tst:15524"/>
              <criterion comment="linux-doc-2.6.18 is earlier than 2.6.18.dfsg.1-24etch4" test_ref="oval:org.mitre.oval:tst:15441"/>
            </criteria>
          </criteria>
          <criteria comment="Architecture dependent section" operator="AND">
            <criteria comment="Supported architectures section" operator="OR">
              <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
            </criteria>
            <criteria comment="Packages section" operator="OR">
              <criterion comment="linux-headers-2.6.18-6-vserver-s390x DPKG is earlier than 2.6.18.dfsg.1-24etch4" test_ref="oval:org.mitre.oval:tst:14626"/>
              <criterion comment="linux-image-2.6.18-6-s390-tape DPKG is earlier than 2.6.18.dfsg.1-24etch4" test_ref="oval:org.mitre.oval:tst:15567"/>
              <criterion comment="linux-headers-2.6.18-6-all DPKG is earlier than 2.6.18.dfsg.1-24etch4" test_ref="oval:org.mitre.oval:tst:15499"/>
              <criterion comment="linux-image-2.6.18-6-s390x DPKG is earlier than 2.6.18.dfsg.1-24etch4" test_ref="oval:org.mitre.oval:tst:15467"/>
              <criterion comment="linux-image-2.6.18-6-vserver-s390x DPKG is earlier than 2.6.18.dfsg.1-24etch4" test_ref="oval:org.mitre.oval:tst:15590"/>
              <criterion comment="linux-image-2.6.18-6-s390 DPKG is earlier than 2.6.18.dfsg.1-24etch4" test_ref="oval:org.mitre.oval:tst:15587"/>
              <criterion comment="linux-headers-2.6.18-6-vserver DPKG is earlier than 2.6.18.dfsg.1-24etch4" test_ref="oval:org.mitre.oval:tst:15485"/>
              <criterion comment="linux-headers-2.6.18-6-all-s390 DPKG is earlier than 2.6.18.dfsg.1-24etch4" test_ref="oval:org.mitre.oval:tst:15599"/>
              <criterion comment="linux-headers-2.6.18-6 DPKG is earlier than 2.6.18.dfsg.1-24etch4" test_ref="oval:org.mitre.oval:tst:15432"/>
              <criterion comment="linux-headers-2.6.18-6-s390x DPKG is earlier than 2.6.18.dfsg.1-24etch4" test_ref="oval:org.mitre.oval:tst:15245"/>
              <criterion comment="linux-headers-2.6.18-6-s390 DPKG is earlier than 2.6.18.dfsg.1-24etch4" test_ref="oval:org.mitre.oval:tst:14976"/>
            </criteria>
          </criteria>
          <criteria comment="Architecture dependent section" operator="AND">
            <criteria comment="Supported architectures section" operator="OR">
              <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
            </criteria>
            <criteria comment="Packages section" operator="OR">
              <criterion comment="linux-image-2.6.18-6-xen-amd64 DPKG is earlier than 2.6.18.dfsg.1-24etch4" test_ref="oval:org.mitre.oval:tst:15482"/>
              <criterion comment="fai-kernels DPKG is earlier than 1.17+etch.24etch4" test_ref="oval:org.mitre.oval:tst:15563"/>
              <criterion comment="linux-headers-2.6.18-6-all DPKG is earlier than 2.6.18.dfsg.1-24etch4" test_ref="oval:org.mitre.oval:tst:15288"/>
              <criterion comment="xen-linux-system-2.6.18-6-xen-amd64 DPKG is earlier than 2.6.18.dfsg.1-24etch4" test_ref="oval:org.mitre.oval:tst:15275"/>
              <criterion comment="linux-image-2.6.18-6-amd64 DPKG is earlier than 2.6.18.dfsg.1-24etch4" test_ref="oval:org.mitre.oval:tst:15444"/>
              <criterion comment="linux-modules-2.6.18-6-xen-vserver-amd64 DPKG is earlier than 2.6.18.dfsg.1-24etch4" test_ref="oval:org.mitre.oval:tst:15311"/>
              <criterion comment="linux-image-2.6.18-6-xen-vserver-amd64 DPKG is earlier than 2.6.18.dfsg.1-24etch4" test_ref="oval:org.mitre.oval:tst:15548"/>
              <criterion comment="linux-headers-2.6.18-6-xen-amd64 DPKG is earlier than 2.6.18.dfsg.1-24etch4" test_ref="oval:org.mitre.oval:tst:15608"/>
              <criterion comment="xen-linux-system-2.6.18-6-xen-vserver-amd64 DPKG is earlier than 2.6.18.dfsg.1-24etch4" test_ref="oval:org.mitre.oval:tst:15241"/>
              <criterion comment="linux-headers-2.6.18-6-amd64 DPKG is earlier than 2.6.18.dfsg.1-24etch4" test_ref="oval:org.mitre.oval:tst:15403"/>
              <criterion comment="linux-headers-2.6.18-6-xen DPKG is earlier than 2.6.18.dfsg.1-24etch4" test_ref="oval:org.mitre.oval:tst:15349"/>
              <criterion comment="linux-headers-2.6.18-6-xen-vserver-amd64 DPKG is earlier than 2.6.18.dfsg.1-24etch4" test_ref="oval:org.mitre.oval:tst:15564"/>
              <criterion comment="linux-headers-2.6.18-6-vserver DPKG is earlier than 2.6.18.dfsg.1-24etch4" test_ref="oval:org.mitre.oval:tst:15585"/>
              <criterion comment="linux-headers-2.6.18-6-vserver-amd64 DPKG is earlier than 2.6.18.dfsg.1-24etch4" test_ref="oval:org.mitre.oval:tst:15457"/>
              <criterion comment="linux-headers-2.6.18-6-all-amd64 DPKG is earlier than 2.6.18.dfsg.1-24etch4" test_ref="oval:org.mitre.oval:tst:15382"/>
              <criterion comment="linux-headers-2.6.18-6 DPKG is earlier than 2.6.18.dfsg.1-24etch4" test_ref="oval:org.mitre.oval:tst:15323"/>
              <criterion comment="linux-modules-2.6.18-6-xen-amd64 DPKG is earlier than 2.6.18.dfsg.1-24etch4" test_ref="oval:org.mitre.oval:tst:15616"/>
              <criterion comment="linux-headers-2.6.18-6-xen-vserver DPKG is earlier than 2.6.18.dfsg.1-24etch4" test_ref="oval:org.mitre.oval:tst:15069"/>
              <criterion comment="linux-image-2.6.18-6-vserver-amd64 DPKG is earlier than 2.6.18.dfsg.1-24etch4" test_ref="oval:org.mitre.oval:tst:15540"/>
            </criteria>
          </criteria>
          <criteria comment="Architecture depended section" operator="AND">
            <criteria comment="Supported platform section" operator="AND">
              <criterion comment="hppa architecture" test_ref="oval:org.mitre.oval:tst:11164"/>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="linux-headers-2.6.18-6-all DPKG is earlier than 2.6.18.dfsg.1-24etch4" test_ref="oval:org.mitre.oval:tst:15572"/>
                <criterion comment="linux-headers-2.6.18-6-parisc64 DPKG is earlier than 2.6.18.dfsg.1-24etch4" test_ref="oval:org.mitre.oval:tst:15657"/>
                <criterion comment="linux-headers-2.6.18-6-parisc DPKG is earlier than 2.6.18.dfsg.1-24etch4" test_ref="oval:org.mitre.oval:tst:15544"/>
                <criterion comment="linux-headers-2.6.18-6-all-hppa DPKG is earlier than 2.6.18.dfsg.1-24etch4" test_ref="oval:org.mitre.oval:tst:15632"/>
                <criterion comment="linux-headers-2.6.18-6-parisc64-smp DPKG is earlier than 2.6.18.dfsg.1-24etch4" test_ref="oval:org.mitre.oval:tst:15622"/>
                <criterion comment="linux-headers-2.6.18-6-parisc-smp DPKG is earlier than 2.6.18.dfsg.1-24etch4" test_ref="oval:org.mitre.oval:tst:15710"/>
                <criterion comment="linux-image-2.6.18-6-parisc64-smp DPKG is earlier than 2.6.18.dfsg.1-24etch4" test_ref="oval:org.mitre.oval:tst:14763"/>
                <criterion comment="linux-image-2.6.18-6-parisc64 DPKG is earlier than 2.6.18.dfsg.1-24etch4" test_ref="oval:org.mitre.oval:tst:15617"/>
                <criterion comment="linux-headers-2.6.18-6 DPKG is earlier than 2.6.18.dfsg.1-24etch4" test_ref="oval:org.mitre.oval:tst:15667"/>
                <criterion comment="linux-image-2.6.18-6-parisc DPKG is earlier than 2.6.18.dfsg.1-24etch4" test_ref="oval:org.mitre.oval:tst:15763"/>
                <criterion comment="linux-image-2.6.18-6-parisc-smp DPKG is earlier than 2.6.18.dfsg.1-24etch4" test_ref="oval:org.mitre.oval:tst:15761"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:8167" class="patch">
      <metadata>
        <title>DSA-1827 ipplan -- insufficient input sanitising</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <product>ipplan</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2009/dsa-1827" ref_id="DSA-1827"/>
        <description>It was discovered that ipplan, a web-based IP address manager and tracker, does not sufficiently escape certain input parameters, which allows remote attackers to conduct cross-site scripting attacks. The oldstable distribution (etch) does not contain ipplan.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:08-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T07:55:54.950-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:04:46.171-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:03:34.638-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Release section" operator="AND">
        <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
        <criteria comment="Architecture section" operator="OR">
          <criteria comment="Architecture independent section" operator="AND">
            <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
            <criterion comment="ipplan is earlier than 4.86a-7+lenny1" test_ref="oval:org.mitre.oval:tst:17358"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:8166" class="patch">
      <metadata>
        <title>DSA-1853 memcached -- heap-based buffer overflow</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <platform>Debian GNU/Linux 4.0</platform>
          <product>memcached</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2009/dsa-1853" ref_id="DSA-1853"/>
        <description>Ronald Volgers discovered that memcached, a high-performance memory object caching system, is vulnerable to several heap-based buffer overflows due to integer conversions when parsing certain length attributes. An attacker can use this to execute arbitrary code on the system running memcached (on etch with root privileges).</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:11-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T07:58:50.782-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:04:45.645-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:03:34.256-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Platform section" operator="OR">
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Architecture dependent section" operator="AND">
              <criteria comment="Supported architectures section" operator="OR">
                <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
                <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
                <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
                <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
                <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
                <criterion comment="Installed architecture is armel" test_ref="oval:org.mitre.oval:tst:11101"/>
                <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
                <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
                <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
                <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
                <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
                <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
              </criteria>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="memcached DPKG is earlier than 1.2.2-1+lenny1" test_ref="oval:org.mitre.oval:tst:18974"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 4.0 is installed" definition_ref="oval:org.mitre.oval:def:6461"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Packages section" operator="OR">
              <criterion comment="memcached DPKG is earlier than 1.1.12-1+etch1" test_ref="oval:org.mitre.oval:tst:19151"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:8165" class="patch">
      <metadata>
        <title>DSA-1765 horde3 -- Multiple vulnerabilities</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 4.0</platform>
          <product>horde3</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2009/dsa-1765" ref_id="DSA-1765"/>
        <description>Several vulnerabilities have been found in horde3, the horde web application framework. The Common Vulnerabilities and Exposures project identifies the following problems: Gunnar Wrobel discovered a directory traversal vulnerability, which allows attackers to include and execute arbitrary local files via the driver parameter in Horde_Image. It was discovered that an attacker could perform a cross-site scripting attack via the contact name, which allows attackers to inject arbitrary html code. This requires that the attacker has access to create contacts. It was discovered that the horde XSS filter is prone to a cross-site scripting attack, which allows attackers to inject arbitrary html code. This is only exploitable when Internet Explorer is used.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:07-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T07:55:00.323-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:04:45.397-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:03:34.039-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Release section" operator="AND">
        <extend_definition comment="Debian 4.0 is installed" definition_ref="oval:org.mitre.oval:def:6461"/>
        <criteria comment="Architecture section" operator="OR">
          <criteria comment="Architecture independent section" operator="AND">
            <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
            <criterion comment="horde3 is earlier than 3.1.3-4etch5" test_ref="oval:org.mitre.oval:tst:16725"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:8164" class="patch">
      <metadata>
        <title>DSA-1789 php5 -- several vulnerabilities</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <platform>Debian GNU/Linux 4.0</platform>
          <product>php5</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2009/dsa-1789" ref_id="DSA-1789"/>
        <description>Several remote vulnerabilities have been discovered in the PHP5 hypertext preprocessor. The Common Vulnerabilities and Exposures project identifies the following problems. The following four vulnerabilities have already been fixed in the stable (lenny) version of php5 prior to the release of lenny. This update now addresses them for etch (oldstable) as well: The GENERATE_SEED macro has several problems that make predicting generated random numbers easier, facilitating attacks against measures that use rand() or mt_rand() as part of a protection. A buffer overflow in the mbstring extension allows attackers to execute arbitrary code via a crafted string containing an HTML entity. The page_uid and page_gid variables are not correctly set, allowing use of some functionality intended to be restricted to root. Directory traversal vulnerability in the ZipArchive::extractTo function allows attackers to write arbitrary files via a ZIP file with a file whose name contains .. (dot dot) sequences. This update also addresses the following three vulnerabilities for both oldstable (etch) and stable (lenny): Cross-site scripting (XSS) vulnerability, when display_errors is enabled, allows remote attackers to inject arbitrary web script or HTML. When running on Apache, PHP allows local users to modify behavior of other sites hosted on the same web server by modifying the mbstring.func_overload setting within .htaccess, which causes this setting to be applied to other virtual hosts on the same server. The JSON_parser function allows a denial of service (segmentation fault) via a malformed string to the json_decode API function. Furthermore, two updates originally scheduled for the next point update for oldstable are included in the etch package: Let PHP use the system timezone database instead of the embedded timezone database which is out of date. From the source tarball, the unused "dbase" module has been removed which contained licensing problems.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:10-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T07:58:01.765-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:04:43.998-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:03:32.939-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Platform section" operator="OR">
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Architecture independent section" operator="AND">
              <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="php5 is earlier than 5.2.6.dfsg.1-1+lenny3" test_ref="oval:org.mitre.oval:tst:18001"/>
                <criterion comment="php-pear is earlier than 5.2.6.dfsg.1-1+lenny3" test_ref="oval:org.mitre.oval:tst:18225"/>
              </criteria>
            </criteria>
            <criteria comment="Architecture dependent section" operator="AND">
              <criteria comment="Supported architectures section" operator="OR">
                <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
                <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
                <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
                <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
                <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
                <criterion comment="Installed architecture is armel" test_ref="oval:org.mitre.oval:tst:11101"/>
                <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
                <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
                <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
                <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
                <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
                <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
              </criteria>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="php5-recode DPKG is earlier than 5.2.6.dfsg.1-1+lenny3" test_ref="oval:org.mitre.oval:tst:18659"/>
                <criterion comment="php5-cgi DPKG is earlier than 5.2.6.dfsg.1-1+lenny3" test_ref="oval:org.mitre.oval:tst:18192"/>
                <criterion comment="php5-curl DPKG is earlier than 5.2.6.dfsg.1-1+lenny3" test_ref="oval:org.mitre.oval:tst:18630"/>
                <criterion comment="php5-snmp DPKG is earlier than 5.2.6.dfsg.1-1+lenny3" test_ref="oval:org.mitre.oval:tst:18567"/>
                <criterion comment="php5-mysql DPKG is earlier than 5.2.6.dfsg.1-1+lenny3" test_ref="oval:org.mitre.oval:tst:18718"/>
                <criterion comment="php5-odbc DPKG is earlier than 5.2.6.dfsg.1-1+lenny3" test_ref="oval:org.mitre.oval:tst:18657"/>
                <criterion comment="php5-xsl DPKG is earlier than 5.2.6.dfsg.1-1+lenny3" test_ref="oval:org.mitre.oval:tst:18372"/>
                <criterion comment="php5-gd DPKG is earlier than 5.2.6.dfsg.1-1+lenny3" test_ref="oval:org.mitre.oval:tst:18163"/>
                <criterion comment="libapache2-mod-php5 DPKG is earlier than 5.2.6.dfsg.1-1+lenny3" test_ref="oval:org.mitre.oval:tst:17817"/>
                <criterion comment="php5-mhash DPKG is earlier than 5.2.6.dfsg.1-1+lenny3" test_ref="oval:org.mitre.oval:tst:18642"/>
                <criterion comment="php5-tidy DPKG is earlier than 5.2.6.dfsg.1-1+lenny3" test_ref="oval:org.mitre.oval:tst:18774"/>
                <criterion comment="php5-mcrypt DPKG is earlier than 5.2.6.dfsg.1-1+lenny3" test_ref="oval:org.mitre.oval:tst:18728"/>
                <criterion comment="php5-dev DPKG is earlier than 5.2.6.dfsg.1-1+lenny3" test_ref="oval:org.mitre.oval:tst:18611"/>
                <criterion comment="php5-pgsql DPKG is earlier than 5.2.6.dfsg.1-1+lenny3" test_ref="oval:org.mitre.oval:tst:18785"/>
                <criterion comment="php5-gmp DPKG is earlier than 5.2.6.dfsg.1-1+lenny3" test_ref="oval:org.mitre.oval:tst:18560"/>
                <criterion comment="php5-xmlrpc DPKG is earlier than 5.2.6.dfsg.1-1+lenny3" test_ref="oval:org.mitre.oval:tst:18766"/>
                <criterion comment="php5-imap DPKG is earlier than 5.2.6.dfsg.1-1+lenny3" test_ref="oval:org.mitre.oval:tst:18537"/>
                <criterion comment="php5-sqlite DPKG is earlier than 5.2.6.dfsg.1-1+lenny3" test_ref="oval:org.mitre.oval:tst:17824"/>
                <criterion comment="php5-ldap DPKG is earlier than 5.2.6.dfsg.1-1+lenny3" test_ref="oval:org.mitre.oval:tst:18059"/>
                <criterion comment="php5-cli DPKG is earlier than 5.2.6.dfsg.1-1+lenny3" test_ref="oval:org.mitre.oval:tst:18553"/>
                <criterion comment="php5-sybase DPKG is earlier than 5.2.6.dfsg.1-1+lenny3" test_ref="oval:org.mitre.oval:tst:18375"/>
                <criterion comment="php5-pspell DPKG is earlier than 5.2.6.dfsg.1-1+lenny3" test_ref="oval:org.mitre.oval:tst:18590"/>
                <criterion comment="libapache2-mod-php5filter DPKG is earlier than 5.2.6.dfsg.1-1+lenny3" test_ref="oval:org.mitre.oval:tst:18825"/>
                <criterion comment="php5-common DPKG is earlier than 5.2.6.dfsg.1-1+lenny3" test_ref="oval:org.mitre.oval:tst:18473"/>
                <criterion comment="php5-dbg DPKG is earlier than 5.2.6.dfsg.1-1+lenny3" test_ref="oval:org.mitre.oval:tst:18498"/>
              </criteria>
            </criteria>
            <criteria comment="Architecture dependent section" operator="AND">
              <criteria comment="Supported architectures section" operator="OR">
                <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
                <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
                <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
                <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
              </criteria>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="php5-interbase DPKG is earlier than 5.2.6.dfsg.1-1+lenny3" test_ref="oval:org.mitre.oval:tst:18293"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 4.0 is installed" definition_ref="oval:org.mitre.oval:def:6461"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Architecture independent section" operator="AND">
              <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="php5 is earlier than 5.2.0+dfsg-8+etch15" test_ref="oval:org.mitre.oval:tst:18666"/>
                <criterion comment="php-pear is earlier than 5.2.0+dfsg-8+etch15" test_ref="oval:org.mitre.oval:tst:18784"/>
              </criteria>
            </criteria>
            <criteria comment="Packages section" operator="OR">
              <criterion comment="libapache-mod-php5 DPKG is earlier than 5.2.0+dfsg-8+etch15" test_ref="oval:org.mitre.oval:tst:18781"/>
              <criterion comment="php5-recode DPKG is earlier than 5.2.0+dfsg-8+etch15" test_ref="oval:org.mitre.oval:tst:18782"/>
              <criterion comment="php5-xmlrpc DPKG is earlier than 5.2.0+dfsg-8+etch15" test_ref="oval:org.mitre.oval:tst:18691"/>
              <criterion comment="php5-curl DPKG is earlier than 5.2.0+dfsg-8+etch15" test_ref="oval:org.mitre.oval:tst:18671"/>
              <criterion comment="php5-snmp DPKG is earlier than 5.2.0+dfsg-8+etch15" test_ref="oval:org.mitre.oval:tst:18384"/>
              <criterion comment="php5-mysql DPKG is earlier than 5.2.0+dfsg-8+etch15" test_ref="oval:org.mitre.oval:tst:17857"/>
              <criterion comment="php5-odbc DPKG is earlier than 5.2.0+dfsg-8+etch15" test_ref="oval:org.mitre.oval:tst:18799"/>
              <criterion comment="php5-xsl DPKG is earlier than 5.2.0+dfsg-8+etch15" test_ref="oval:org.mitre.oval:tst:18823"/>
              <criterion comment="php5-gd DPKG is earlier than 5.2.0+dfsg-8+etch15" test_ref="oval:org.mitre.oval:tst:18681"/>
              <criterion comment="libapache2-mod-php5 DPKG is earlier than 5.2.0+dfsg-8+etch15" test_ref="oval:org.mitre.oval:tst:18858"/>
              <criterion comment="php5-mhash DPKG is earlier than 5.2.0+dfsg-8+etch15" test_ref="oval:org.mitre.oval:tst:18618"/>
              <criterion comment="php5-tidy DPKG is earlier than 5.2.0+dfsg-8+etch15" test_ref="oval:org.mitre.oval:tst:18827"/>
              <criterion comment="php5-mcrypt DPKG is earlier than 5.2.0+dfsg-8+etch15" test_ref="oval:org.mitre.oval:tst:18697"/>
              <criterion comment="php5-dev DPKG is earlier than 5.2.0+dfsg-8+etch15" test_ref="oval:org.mitre.oval:tst:18856"/>
              <criterion comment="php5-pgsql DPKG is earlier than 5.2.0+dfsg-8+etch15" test_ref="oval:org.mitre.oval:tst:18783"/>
              <criterion comment="php5-cgi DPKG is earlier than 5.2.0+dfsg-8+etch15" test_ref="oval:org.mitre.oval:tst:18777"/>
              <criterion comment="php5-imap DPKG is earlier than 5.2.0+dfsg-8+etch15" test_ref="oval:org.mitre.oval:tst:18640"/>
              <criterion comment="php5-sqlite DPKG is earlier than 5.2.0+dfsg-8+etch15" test_ref="oval:org.mitre.oval:tst:18721"/>
              <criterion comment="php5-ldap DPKG is earlier than 5.2.0+dfsg-8+etch15" test_ref="oval:org.mitre.oval:tst:18787"/>
              <criterion comment="php5-cli DPKG is earlier than 5.2.0+dfsg-8+etch15" test_ref="oval:org.mitre.oval:tst:18837"/>
              <criterion comment="php5-sybase DPKG is earlier than 5.2.0+dfsg-8+etch15" test_ref="oval:org.mitre.oval:tst:18730"/>
              <criterion comment="php5-pspell DPKG is earlier than 5.2.0+dfsg-8+etch15" test_ref="oval:org.mitre.oval:tst:18701"/>
              <criterion comment="php5-common DPKG is earlier than 5.2.0+dfsg-8+etch15" test_ref="oval:org.mitre.oval:tst:18658"/>
            </criteria>
            <criteria comment="Architecture dependent section" operator="AND">
              <criteria comment="Supported architectures section" operator="OR">
                <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
                <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
              </criteria>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="php5-interbase DPKG is earlier than 5.2.0+dfsg-8+etch15" test_ref="oval:org.mitre.oval:tst:18732"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:8163" class="patch">
      <metadata>
        <title>DSA-1722 libpam-heimdal -- programming error</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 4.0</platform>
          <product>libpam-heimdal</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2009/dsa-1722" ref_id="DSA-1722"/>
        <description>Derek Chan discovered that the PAM module for the Heimdal Kerberos implementation allows reinitialisation of user credentials when run from a setuid context, resulting in potential local denial of service by overwriting the credential cache file or to local privilege escalation.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:08-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T07:56:31.386-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:04:43.212-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:03:32.604-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Release section" operator="AND">
        <extend_definition comment="Debian 4.0 is installed" definition_ref="oval:org.mitre.oval:def:6461"/>
        <criteria comment="Architecture section" operator="OR">
          <criteria comment="Architecture dependent section" operator="AND">
            <criteria comment="Supported architectures section" operator="OR">
              <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
              <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
              <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
              <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
              <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
              <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
              <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
              <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
              <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
              <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
            </criteria>
            <criteria comment="Packages section" operator="OR">
              <criterion comment="libpam-heimdal DPKG is earlier than 2.5-1etch1" test_ref="oval:org.mitre.oval:tst:17653"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:8162" class="patch">
      <metadata>
        <title>DSA-1506 iceape -- several vulnerabilities</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 4.0</platform>
          <product>iceape</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2008/dsa-1506" ref_id="DSA-1506"/>
        <description>Several remote vulnerabilities have been discovered in the Iceape internet suite, an unbranded version of the Seamonkey Internet Suite. The Common Vulnerabilities and Exposures project identifies the following problems: Jesse Ruderman, Kai Engert, Martijn Wargers, Mats Palmgren and Paul Nickerson discovered crashes in the layout engine, which might allow the execution of arbitrary code. Carsten Book, Wesley Garland, Igor Bukanov, moz_bug_r_a4, shutdown, Philip Taylor and tgirmann discovered crashes in the Javascript engine, which might allow the execution of arbitrary code. hong and Gregory Fleischer discovered that file input focus vulnerabilities in the file upload control could allow information disclosure of local files. moz_bug_r_a4 and Boris Zbarsky discovered several vulnerabilities in Javascript handling, which could allow privilege escalation. Justin Dolske discovered that the password storage mechanism could be abused by malicious web sites to corrupt existing saved passwords. Gerry Eisenhaur and moz_bug_r_a4 discovered that a directory traversal vulnerability in chrome: URI handling could lead to information disclosure. David Bloom discovered a race condition in the image handling of designMode elements, which can lead to information disclosure and potentially the execution of arbitrary code. Michal Zalewski discovered that timers protecting security-sensitive dialogs (by disabling dialog elements until a timeout is reached) could be bypassed by window focus changes through Javascript. It was discovered that malformed content declarations of saved attachments could prevent a user in the opening local files with a .txt file name, resulting in minor denial of service. Martin Straka discovered that insecure stylesheet handling during redirects could lead to information disclosure. Emil Ljungdahl and Lars-Olof Moilanen discovered that phishing protections could be bypassed with div elements. The Mozilla products from the old stable distribution (sarge) are no longer supported with security updates.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:06-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T07:53:59.963-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:04:42.483-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:03:32.179-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Release section" operator="AND">
        <extend_definition comment="Debian 4.0 is installed" definition_ref="oval:org.mitre.oval:def:6461"/>
        <criteria comment="Architecture section" operator="OR">
          <criteria comment="Architecture independent section" operator="AND">
            <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
            <criteria comment="Packages section" operator="OR">
              <criterion comment="mozilla-js-debugger is earlier than 1.8+1.0.12~pre080131b-0etch1" test_ref="oval:org.mitre.oval:tst:16013"/>
              <criterion comment="mozilla-chatzilla is earlier than 1.8+1.0.12~pre080131b-0etch1" test_ref="oval:org.mitre.oval:tst:15696"/>
              <criterion comment="iceape is earlier than 1.0.12~pre080131b-0etch1" test_ref="oval:org.mitre.oval:tst:16016"/>
              <criterion comment="iceape-chatzilla is earlier than 1.0.12~pre080131b-0etch1" test_ref="oval:org.mitre.oval:tst:16007"/>
              <criterion comment="mozilla is earlier than 1.8+1.0.12~pre080131b-0etch1" test_ref="oval:org.mitre.oval:tst:16070"/>
              <criterion comment="mozilla-psm is earlier than 1.8+1.0.12~pre080131b-0etch1" test_ref="oval:org.mitre.oval:tst:15927"/>
              <criterion comment="mozilla-mailnews is earlier than 1.8+1.0.12~pre080131b-0etch1" test_ref="oval:org.mitre.oval:tst:15921"/>
              <criterion comment="mozilla-dom-inspector is earlier than 1.8+1.0.12~pre080131b-0etch1" test_ref="oval:org.mitre.oval:tst:16006"/>
              <criterion comment="mozilla-calendar is earlier than 1.8+1.0.12~pre080131b-0etch1" test_ref="oval:org.mitre.oval:tst:16021"/>
              <criterion comment="mozilla-browser is earlier than 1.8+1.0.12~pre080131b-0etch1" test_ref="oval:org.mitre.oval:tst:15575"/>
              <criterion comment="mozilla-dev is earlier than 1.8+1.0.12~pre080131b-0etch1" test_ref="oval:org.mitre.oval:tst:15849"/>
              <criterion comment="iceape-dev is earlier than 1.0.12~pre080131b-0etch1" test_ref="oval:org.mitre.oval:tst:15747"/>
            </criteria>
          </criteria>
          <criteria comment="Packages section" operator="OR">
            <criterion comment="iceape-dbg DPKG is earlier than 1.0.12~pre080131b-0etch1" test_ref="oval:org.mitre.oval:tst:15976"/>
            <criterion comment="iceape-dom-inspector DPKG is earlier than 1.0.12~pre080131b-0etch1" test_ref="oval:org.mitre.oval:tst:16041"/>
            <criterion comment="iceape-mailnews DPKG is earlier than 1.0.12~pre080131b-0etch1" test_ref="oval:org.mitre.oval:tst:16014"/>
            <criterion comment="iceape-browser DPKG is earlier than 1.0.12~pre080131b-0etch1" test_ref="oval:org.mitre.oval:tst:16093"/>
            <criterion comment="iceape-calendar DPKG is earlier than 1.0.12~pre080131b-0etch1" test_ref="oval:org.mitre.oval:tst:15934"/>
            <criterion comment="iceape-gnome-support DPKG is earlier than 1.0.12~pre080131b-0etch1" test_ref="oval:org.mitre.oval:tst:15714"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:8161" class="patch">
      <metadata>
        <title>DSA-1911 pygresql -- missing escape function</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <platform>Debian GNU/Linux 4.0</platform>
          <product>pygresql</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2009/dsa-1911" ref_id="DSA-1911"/>
        <description>It was discovered that pygresql, a PostgreSQL module for Python, was missing a function to call PQescapeStringConn(). This is needed, because PQescapeStringConn() honours the charset of the connection and prevents insufficient escaping, when certain multibyte character encodings are used. The new function is called pg_escape_string(), which takes the database connection as a first argument. The old function escape_string() has been preserved as well for backwards compatibility. Developers using these bindings are encouraged to adjust their code to use the new function.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:07-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T07:54:12.896-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:04:42.097-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:03:31.740-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Platform section" operator="OR">
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Architecture dependent section" operator="AND">
              <criteria comment="Supported architectures section" operator="OR">
                <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
                <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
                <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
                <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
                <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
                <criterion comment="Installed architecture is armel" test_ref="oval:org.mitre.oval:tst:11101"/>
                <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
                <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
                <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
                <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
                <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
                <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
              </criteria>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="python-pygresql DPKG is earlier than 3.8.1-3+lenny1" test_ref="oval:org.mitre.oval:tst:15228"/>
                <criterion comment="python-pygresql-dbg DPKG is earlier than 3.8.1-3+lenny1" test_ref="oval:org.mitre.oval:tst:15800"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 4.0 is installed" definition_ref="oval:org.mitre.oval:def:6461"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Architecture dependent section" operator="AND">
              <criteria comment="Supported architectures section" operator="OR">
                <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
                <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
                <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
                <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
                <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
                <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
                <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
                <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
                <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
                <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
              </criteria>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="python-pygresql DPKG is earlier than 3.8.1-1etch2" test_ref="oval:org.mitre.oval:tst:16147"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:8160" class="patch">
      <metadata>
        <title>DSA-1854 apr, apr-util -- heap buffer overflow</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <platform>Debian GNU/Linux 4.0</platform>
          <product>apr</product>
          <product>apr-util</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2009/dsa-1854" ref_id="DSA-1854"/>
        <description>Matt Lewis discovered that the memory management code in the Apache Portable Runtime (APR) library does not guard against a wrap-around during size computations. This could cause the library to return a memory area which smaller than requested, resulting a heap overflow and possibly arbitrary code execution.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:11-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T07:58:52.593-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:04:41.369-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:03:31.187-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Platform section" operator="OR">
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Architecture dependent section" operator="AND">
              <criteria comment="Supported architectures section" operator="OR">
                <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
                <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
                <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
                <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
                <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
                <criterion comment="Installed architecture is armel" test_ref="oval:org.mitre.oval:tst:11101"/>
                <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
                <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
                <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
                <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
                <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
                <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
              </criteria>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="libapr1-dbg DPKG is earlier than 1.2.12-5+lenny1" test_ref="oval:org.mitre.oval:tst:18819"/>
                <criterion comment="libapr1 DPKG is earlier than 1.2.12-5+lenny1" test_ref="oval:org.mitre.oval:tst:19194"/>
                <criterion comment="libaprutil1 DPKG is earlier than 1.2.12+dfsg-8+lenny4" test_ref="oval:org.mitre.oval:tst:19070"/>
                <criterion comment="libapr1-dev DPKG is earlier than 1.2.12-5+lenny1" test_ref="oval:org.mitre.oval:tst:19214"/>
                <criterion comment="libaprutil1-dbg DPKG is earlier than 1.2.12+dfsg-8+lenny4" test_ref="oval:org.mitre.oval:tst:18920"/>
                <criterion comment="libaprutil1-dev DPKG is earlier than 1.2.12+dfsg-8+lenny4" test_ref="oval:org.mitre.oval:tst:18334"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 4.0 is installed" definition_ref="oval:org.mitre.oval:def:6461"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Architecture dependent section" operator="AND">
              <criteria comment="Supported architectures section" operator="OR">
                <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
                <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
                <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
                <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
                <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
                <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
                <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
                <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
                <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
                <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
              </criteria>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="libapr1-dbg DPKG is earlier than 1.2.7-9" test_ref="oval:org.mitre.oval:tst:19213"/>
                <criterion comment="libapr1 DPKG is earlier than 1.2.7-9" test_ref="oval:org.mitre.oval:tst:18954"/>
                <criterion comment="libaprutil1 DPKG is earlier than 1.2.7+dfsg-2+etch3" test_ref="oval:org.mitre.oval:tst:19235"/>
                <criterion comment="libapr1-dev DPKG is earlier than 1.2.7-9" test_ref="oval:org.mitre.oval:tst:19281"/>
                <criterion comment="libaprutil1-dbg DPKG is earlier than 1.2.7+dfsg-2+etch3" test_ref="oval:org.mitre.oval:tst:19330"/>
                <criterion comment="libaprutil1-dev DPKG is earlier than 1.2.7+dfsg-2+etch3" test_ref="oval:org.mitre.oval:tst:19147"/>
              </criteria>
            </criteria>
            <criteria comment="Architecture dependent section" operator="AND">
              <criteria comment="Supported architectures section" operator="OR">
                <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
              </criteria>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="libaprutil1-dbg DPKG is earlier than 1.2.7+dfsg-2+etch3" test_ref="oval:org.mitre.oval:tst:18655"/>
                <criterion comment="libaprutil1 DPKG is earlier than 1.2.7+dfsg-2+etch3" test_ref="oval:org.mitre.oval:tst:19166"/>
                <criterion comment="libaprutil1-dev DPKG is earlier than 1.2.7+dfsg-2+etch3" test_ref="oval:org.mitre.oval:tst:19218"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:8158" class="patch">
      <metadata>
        <title>DSA-1541 openldap2.3 -- several vulnerabilities</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 4.0</platform>
          <product>openldap2.3</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2008/dsa-1541" ref_id="DSA-1541"/>
        <description>Several remote vulnerabilities have been discovered in OpenLDAP, a free implementation of the Lightweight Directory Access Protocol. The Common Vulnerabilities and Exposures project identifies the following problems: Thomas Sesselmann discovered that slapd could be crashed by a malformed modify requests. Toby Blade discovered that incorrect memory handling in slapo-pcache could lead to denial of service through crafted search requests. It was discovered that a programming error in the interface to the BDB storage backend could lead to denial of service through crafted modify requests. It was discovered that a programming error in the interface to the BDB storage backend could lead to denial of service through crafted modrdn requests.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:07-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T07:55:24.339-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:04:41.099-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:03:30.925-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Release section" operator="AND">
        <extend_definition comment="Debian 4.0 is installed" definition_ref="oval:org.mitre.oval:def:6461"/>
        <criteria comment="Architecture section" operator="OR">
          <criteria comment="Packages section" operator="OR">
            <criterion comment="libldap-2.3-0 DPKG is earlier than 2.3.30-5+etch1" test_ref="oval:org.mitre.oval:tst:16817"/>
            <criterion comment="ldap-utils DPKG is earlier than 2.3.30-5+etch1" test_ref="oval:org.mitre.oval:tst:16430"/>
            <criterion comment="slapd DPKG is earlier than 2.3.30-5+etch1" test_ref="oval:org.mitre.oval:tst:17029"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:8157" class="patch">
      <metadata>
        <title>DSA-1508 diatheke -- insufficient input sanitising</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 4.0</platform>
          <platform>Debian GNU/Linux 3.1</platform>
          <product>diatheke</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2008/dsa-1508" ref_id="DSA-1508"/>
        <description>Dan Dennison discovered that Diatheke, a CGI program to make a bible website, performs insufficient sanitising of a parameter, allowing a remote attacker to execute arbitrary shell commands as the web server user.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:06-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T07:54:08.133-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:04:40.734-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:03:30.644-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Platform section" operator="OR">
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 4.0 is installed" definition_ref="oval:org.mitre.oval:def:6461"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Packages section" operator="OR">
              <criterion comment="libsword-dev DPKG is earlier than 1.5.9-2etch1" test_ref="oval:org.mitre.oval:tst:15846"/>
              <criterion comment="libsword6 DPKG is earlier than 1.5.9-2etch1" test_ref="oval:org.mitre.oval:tst:15879"/>
              <criterion comment="diatheke DPKG is earlier than 1.5.9-2etch1" test_ref="oval:org.mitre.oval:tst:15560"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 3.1 is installed" definition_ref="oval:org.mitre.oval:def:7692"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Packages section" operator="OR">
              <criterion comment="libsword4 DPKG is earlier than 1.5.7-7sarge1" test_ref="oval:org.mitre.oval:tst:15816"/>
              <criterion comment="libsword-dev DPKG is earlier than 1.5.7-7sarge1" test_ref="oval:org.mitre.oval:tst:15624"/>
              <criterion comment="diatheke DPKG is earlier than 1.5.7-7sarge1" test_ref="oval:org.mitre.oval:tst:15435"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:8155" class="patch">
      <metadata>
        <title>DSA-1641 phpmyadmin -- several vulnerabilities</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 4.0</platform>
          <product>phpmyadmin</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2008/dsa-1641" ref_id="DSA-1641"/>
        <description>Several remote vulnerabilities have been discovered in phpMyAdmin, a tool to administrate MySQL databases over the web. The Common Vulnerabilities and Exposures project identifies the following problems: Remote authenticated users could execute arbitrary code on the host running phpMyAdmin through manipulation of a script parameter. Cross site scripting through the setup script was possible in rare circumstances. Protection has been added against remote websites loading phpMyAdmin into a frameset. Cross site request forgery allowed remote attackers to create a new database, but not perform any other action on it.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:08-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T07:56:27.889-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:04:40.445-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:03:30.439-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Release section" operator="AND">
        <extend_definition comment="Debian 4.0 is installed" definition_ref="oval:org.mitre.oval:def:6461"/>
        <criteria comment="Architecture section" operator="OR">
          <criteria comment="Architecture independent section" operator="AND">
            <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
            <criterion comment="phpmyadmin is earlier than 2.9.1.1-8" test_ref="oval:org.mitre.oval:tst:17573"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:8152" class="patch">
      <metadata>
        <title>DSA-1551 python2.4 -- several vulnerabilities</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 4.0</platform>
          <product>python2.4</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2008/dsa-1551" ref_id="DSA-1551"/>
        <description>Several vulnerabilities have been discovered in the interpreter for the Python language. The Common Vulnerabilities and Exposures project identifies the following problems: Piotr Engelking discovered that the strxfrm() function of the locale module miscalculates the length of an internal buffer, which may result in a minor information disclosure. It was discovered that several integer overflows in the imageop module may lead to the execution of arbitrary code, if a user is tricked into processing malformed images. This issue is also tracked as CVE-2008-1679 due to an initially incomplete patch. Justin Ferguson discovered that a buffer overflow in the zlib module may lead to the execution of arbitrary code. Justin Ferguson discovered that insufficient input validation in PyString_FromStringAndSize() may lead to the execution of arbitrary code.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:10-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T07:58:36.498-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:04:39.850-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:03:29.990-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Release section" operator="AND">
        <extend_definition comment="Debian 4.0 is installed" definition_ref="oval:org.mitre.oval:def:6461"/>
        <criteria comment="Architecture section" operator="OR">
          <criteria comment="Architecture independent section" operator="AND">
            <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
            <criteria comment="Packages section" operator="OR">
              <criterion comment="python2.4-examples is earlier than 2.4.4-3+etch1" test_ref="oval:org.mitre.oval:tst:18883"/>
              <criterion comment="idle-python2.4 is earlier than 2.4.4-3+etch1" test_ref="oval:org.mitre.oval:tst:18598"/>
            </criteria>
          </criteria>
          <criteria comment="Architecture dependent section" operator="AND">
            <criteria comment="Supported architectures section" operator="OR">
              <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
              <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
              <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
              <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
              <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
              <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
              <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
              <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
              <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
              <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
            </criteria>
            <criteria comment="Packages section" operator="OR">
              <criterion comment="python2.4-minimal DPKG is earlier than 2.4.4-3+etch1" test_ref="oval:org.mitre.oval:tst:18472"/>
              <criterion comment="python2.4 DPKG is earlier than 2.4.4-3+etch1" test_ref="oval:org.mitre.oval:tst:19101"/>
              <criterion comment="python2.4-dbg DPKG is earlier than 2.4.4-3+etch1" test_ref="oval:org.mitre.oval:tst:18637"/>
              <criterion comment="python2.4-dev DPKG is earlier than 2.4.4-3+etch1" test_ref="oval:org.mitre.oval:tst:19178"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:8151" class="patch">
      <metadata>
        <title>DSA-1679 awstats -- cross-site scripting</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 4.0</platform>
          <product>awstats</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2008/dsa-1679" ref_id="DSA-1679"/>
        <description>Morgan Todd discovered a cross-site scripting vulnerability in awstats, a log file analyzer, involving the "config" request parameter (and possibly others; CVE-2008-3714).</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:10-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T07:58:30.897-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:04:39.627-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:03:29.778-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Release section" operator="AND">
        <extend_definition comment="Debian 4.0 is installed" definition_ref="oval:org.mitre.oval:def:6461"/>
        <criteria comment="Architecture section" operator="OR">
          <criteria comment="Architecture independent section" operator="AND">
            <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
            <criterion comment="awstats is earlier than 6.5+dfsg-1+etch1" test_ref="oval:org.mitre.oval:tst:18572"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:8150" class="patch">
      <metadata>
        <title>DSA-1650 openldap2.3 -- denial of service</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 4.0</platform>
          <product>openldap2.3</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2008/dsa-1650" ref_id="DSA-1650"/>
        <description>Cameron Hotchkies discovered that the OpenLDAP server slapd, a free implementation of the Lightweight Directory Access Protocol, could be crashed by sending malformed ASN1 requests.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:05-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T07:53:22.770-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:04:38.974-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:03:29.562-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Release section" operator="AND">
        <extend_definition comment="Debian 4.0 is installed" definition_ref="oval:org.mitre.oval:def:6461"/>
        <criteria comment="Architecture section" operator="OR">
          <criteria comment="Packages section" operator="OR">
            <criterion comment="libldap-2.3-0 DPKG is earlier than 2.3.30-5+etch2" test_ref="oval:org.mitre.oval:tst:14836"/>
            <criterion comment="ldap-utils DPKG is earlier than 2.3.30-5+etch2" test_ref="oval:org.mitre.oval:tst:14971"/>
            <criterion comment="slapd DPKG is earlier than 2.3.30-5+etch2" test_ref="oval:org.mitre.oval:tst:15010"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:8149" class="patch">
      <metadata>
        <title>DSA-1721 libpam-krb5 -- several vulnerabilities</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 4.0</platform>
          <product>libpam-krb5</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2009/dsa-1721" ref_id="DSA-1721"/>
        <description>Several local vulnerabilities have been discovered in the PAM module for MIT Kerberos. The Common Vulnerabilities and Exposures project identifies the following problems: Russ Allbery discovered that the Kerberos PAM module parsed configuration settings from enviromnent variables when run from a setuid context. This could lead to local privilege escalation if an attacker points a setuid program using PAM authentication to a Kerberos setup under her control. Derek Chan discovered that the Kerberos PAM module allows reinitialisation of user credentials when run from a setuid context, resulting in potential local denial of service by overwriting the credential cache file or to privilege escalation.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:08-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T07:56:32.394-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:04:38.654-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:03:29.365-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Release section" operator="AND">
        <extend_definition comment="Debian 4.0 is installed" definition_ref="oval:org.mitre.oval:def:6461"/>
        <criteria comment="Architecture section" operator="OR">
          <criteria comment="Packages section" operator="OR">
            <criterion comment="libpam-krb5 DPKG is earlier than 2.6-1etch1" test_ref="oval:org.mitre.oval:tst:16905"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:8148" class="patch">
      <metadata>
        <title>DSA-1873 xulrunner -- programming error</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <product>xulrunner</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2009/dsa-1873" ref_id="DSA-1873"/>
        <description>Juan Pablo Lopez Yacubian discovered that incorrect handling of invalid URLs could be used for spoofing the location bar and the SSL certificate status of a web page. Xulrunner is no longer supported for the old stable distribution (etch).</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:06-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T07:53:48.496-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:04:37.966-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:03:28.851-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Release section" operator="AND">
        <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
        <criteria comment="Architecture section" operator="OR">
          <criteria comment="Architecture independent section" operator="AND">
            <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
            <criterion comment="libmozillainterfaces-java is earlier than 1.9.0.13-0lenny1" test_ref="oval:org.mitre.oval:tst:15630"/>
          </criteria>
          <criteria comment="Architecture dependent section" operator="AND">
            <criteria comment="Supported architectures section" operator="OR">
              <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
              <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
              <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
              <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
              <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
              <criterion comment="Installed architecture is armel" test_ref="oval:org.mitre.oval:tst:11101"/>
              <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
              <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
              <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
              <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
              <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
              <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
            </criteria>
            <criteria comment="Packages section" operator="OR">
              <criterion comment="libmozjs-dev DPKG is earlier than 1.9.0.13-0lenny1" test_ref="oval:org.mitre.oval:tst:15738"/>
              <criterion comment="spidermonkey-bin DPKG is earlier than 1.9.0.13-0lenny1" test_ref="oval:org.mitre.oval:tst:15458"/>
              <criterion comment="xulrunner-1.9-gnome-support DPKG is earlier than 1.9.0.13-0lenny1" test_ref="oval:org.mitre.oval:tst:15600"/>
              <criterion comment="xulrunner-1.9 DPKG is earlier than 1.9.0.13-0lenny1" test_ref="oval:org.mitre.oval:tst:15674"/>
              <criterion comment="libmozjs1d-dbg DPKG is earlier than 1.9.0.13-0lenny1" test_ref="oval:org.mitre.oval:tst:15664"/>
              <criterion comment="libmozjs1d DPKG is earlier than 1.9.0.13-0lenny1" test_ref="oval:org.mitre.oval:tst:15569"/>
              <criterion comment="python-xpcom DPKG is earlier than 1.9.0.13-0lenny1" test_ref="oval:org.mitre.oval:tst:15687"/>
              <criterion comment="xulrunner-1.9-dbg DPKG is earlier than 1.9.0.13-0lenny1" test_ref="oval:org.mitre.oval:tst:15691"/>
              <criterion comment="xulrunner-dev DPKG is earlier than 1.9.0.13-0lenny1" test_ref="oval:org.mitre.oval:tst:15155"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:8147" class="patch">
      <metadata>
        <title>DSA-1855 subversion -- heap overflow</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <platform>Debian GNU/Linux 4.0</platform>
          <product>subversion</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2009/dsa-1855" ref_id="DSA-1855"/>
        <description>Matt Lewis discovered that Subversion performs insufficient input validation of svndiff streams. Malicious servers could cause heap overflows in clients, and malicious clients with commit access could cause heap overflows in servers, possibly leading to arbitrary code execution in both cases.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:11-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T07:58:55.675-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:04:36.994-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:03:28.200-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Platform section" operator="OR">
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Architecture independent section" operator="AND">
              <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="subversion-tools is earlier than 1.5.1dfsg1-4" test_ref="oval:org.mitre.oval:tst:19283"/>
                <criterion comment="libsvn-doc is earlier than 1.5.1dfsg1-4" test_ref="oval:org.mitre.oval:tst:19251"/>
                <criterion comment="libsvn-ruby is earlier than 1.5.1dfsg1-4" test_ref="oval:org.mitre.oval:tst:19289"/>
              </criteria>
            </criteria>
            <criteria comment="Architecture dependent section" operator="AND">
              <criteria comment="Supported architectures section" operator="OR">
                <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
                <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
                <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
                <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
                <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
                <criterion comment="Installed architecture is armel" test_ref="oval:org.mitre.oval:tst:11101"/>
                <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
                <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
                <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
                <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
                <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
                <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
              </criteria>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="libsvn-dev DPKG is earlier than 1.5.1dfsg1-4" test_ref="oval:org.mitre.oval:tst:18830"/>
                <criterion comment="libapache2-svn DPKG is earlier than 1.5.1dfsg1-4" test_ref="oval:org.mitre.oval:tst:19326"/>
                <criterion comment="libsvn-ruby1.8 DPKG is earlier than 1.5.1dfsg1-4" test_ref="oval:org.mitre.oval:tst:18672"/>
                <criterion comment="python-subversion DPKG is earlier than 1.5.1dfsg1-4" test_ref="oval:org.mitre.oval:tst:19307"/>
                <criterion comment="libsvn1 DPKG is earlier than 1.5.1dfsg1-4" test_ref="oval:org.mitre.oval:tst:19300"/>
                <criterion comment="subversion DPKG is earlier than 1.5.1dfsg1-4" test_ref="oval:org.mitre.oval:tst:19248"/>
                <criterion comment="libsvn-perl DPKG is earlier than 1.5.1dfsg1-4" test_ref="oval:org.mitre.oval:tst:18862"/>
              </criteria>
            </criteria>
            <criteria comment="Architecture dependent section" operator="AND">
              <criteria comment="Supported architectures section" operator="OR">
                <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
                <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
                <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
                <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
                <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
                <criterion comment="Installed architecture is armel" test_ref="oval:org.mitre.oval:tst:11101"/>
                <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
              </criteria>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="libsvn-java DPKG is earlier than 1.5.1dfsg1-4" test_ref="oval:org.mitre.oval:tst:19273"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 4.0 is installed" definition_ref="oval:org.mitre.oval:def:6461"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Architecture independent section" operator="AND">
              <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="subversion-tools is earlier than 1.4.2dfsg1-3" test_ref="oval:org.mitre.oval:tst:19256"/>
                <criterion comment="libsvn-doc is earlier than 1.4.2dfsg1-3" test_ref="oval:org.mitre.oval:tst:19276"/>
                <criterion comment="libsvn-javahl is earlier than 1.4.2dfsg1-3" test_ref="oval:org.mitre.oval:tst:18913"/>
                <criterion comment="libsvn-ruby is earlier than 1.4.2dfsg1-3" test_ref="oval:org.mitre.oval:tst:19036"/>
              </criteria>
            </criteria>
            <criteria comment="Architecture dependent section" operator="AND">
              <criteria comment="Supported architectures section" operator="OR">
                <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
                <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
                <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
                <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
                <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
                <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
                <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
                <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
              </criteria>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="libsvn-dev DPKG is earlier than 1.4.2dfsg1-3" test_ref="oval:org.mitre.oval:tst:18959"/>
                <criterion comment="libapache2-svn DPKG is earlier than 1.4.2dfsg1-3" test_ref="oval:org.mitre.oval:tst:19230"/>
                <criterion comment="libsvn-ruby1.8 DPKG is earlier than 1.4.2dfsg1-3" test_ref="oval:org.mitre.oval:tst:19333"/>
                <criterion comment="python-subversion DPKG is earlier than 1.4.2dfsg1-3" test_ref="oval:org.mitre.oval:tst:19239"/>
                <criterion comment="libsvn1 DPKG is earlier than 1.4.2dfsg1-3" test_ref="oval:org.mitre.oval:tst:19087"/>
                <criterion comment="subversion DPKG is earlier than 1.4.2dfsg1-3" test_ref="oval:org.mitre.oval:tst:19211"/>
                <criterion comment="libsvn-perl DPKG is earlier than 1.4.2dfsg1-3" test_ref="oval:org.mitre.oval:tst:19078"/>
              </criteria>
            </criteria>
            <criteria comment="Architecture dependent section" operator="AND">
              <criteria comment="Supported architectures section" operator="OR">
                <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
                <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
                <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
                <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
                <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
              </criteria>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="libsvn-java DPKG is earlier than 1.4.2dfsg1-3" test_ref="oval:org.mitre.oval:tst:19232"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:8145" class="patch">
      <metadata>
        <title>DSA-1723 phpmyadmin -- insufficient input sanitising</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 4.0</platform>
          <product>phpmyadmin</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2009/dsa-1723" ref_id="DSA-1723"/>
        <description>Michael Brooks discovered that phpMyAdmin, a tool to administrate MySQL over the web, performs insufficient input sanitising allowing a user assisted remote attacker to execute code on the webserver.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:08-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T07:56:31.736-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:04:36.690-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:03:27.929-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Release section" operator="AND">
        <extend_definition comment="Debian 4.0 is installed" definition_ref="oval:org.mitre.oval:def:6461"/>
        <criteria comment="Architecture section" operator="OR">
          <criteria comment="Architecture independent section" operator="AND">
            <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
            <criterion comment="phpmyadmin is earlier than 2.9.1.1-10" test_ref="oval:org.mitre.oval:tst:17115"/>
          </cri
