<?xml version="1.0" encoding="UTF-8"?>
<oval_definitions xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-definitions-5 oval-definitions-schema.xsd http://oval.mitre.org/XMLSchema/oval-definitions-5#linux linux-definitions-schema.xsd http://oval.mitre.org/XMLSchema/oval-definitions-5#independent independent-definitions-schema.xsd http://oval.mitre.org/XMLSchema/oval-common-5 oval-common-schema.xsd http://oval.mitre.org/XMLSchema/oval-definitions-5#unix unix-definitions-schema.xsd" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:oval="http://oval.mitre.org/XMLSchema/oval-common-5" xmlns:oval-def="http://oval.mitre.org/XMLSchema/oval-definitions-5">
  <generator>
    <oval:product_name>The OVAL Repository</oval:product_name>
    <oval:schema_version>5.9</oval:schema_version>
    <oval:timestamp>2012-01-27T05:04:37.481-05:00</oval:timestamp>
  </generator>
  <definitions>
    <definition id="oval:org.mitre.oval:def:13073" version="3" class="patch">
      <metadata>
        <title>DSA-2276-1 asterisk -- multiple denial of service</title>
        <affected family="unix">
          <platform>Debian 5.0</platform>
          <platform>Debian 6.0</platform>
          <product>asterisk</product>
        </affected>
        <reference source="VENDOR" ref_url="http://lists.debian.org/debian-security-announce/2011/msg00148.html" ref_id="DSA-2276-1"/>
        <description>Paul Belanger reported a vulnerability in Asterisk identified as AST-2011-008  through which an unauthenticated attacker may crash an Asterisk server remotely. A package containing a null char causes the SIP header parser to alter unrelated memory structures. Jared Mauch reported a vulnerability in Asterisk identified as AST-2011-009 through which an unauthenticated attacker may crash an Asterisk server remotely. If a user sends a package with a Contact header with a missing left angle bracket  the server will crash. A possible workaround is to disable chan_sip. The vulnerability identified as AST-2011-010  reported about an input validation error in the IAX2 channel driver. An unauthenticated attacker may crash an Asterisk server remotely by sending a crafted option control frame.</description>
        <oval_repository>
          <dates>
            <submitted date="2011-09-22T23:16:35-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2011-09-22T12:03:45.266-04:00">DRAFT</status_change>
            <status_change date="2011-10-10T04:00:53.360-04:00">INTERIM</status_change>
            <status_change date="2011-10-31T04:01:32.860-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Release section">
          <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
          <criteria operator="OR" comment="Architecture section">
            <criteria operator="AND" comment="Architecture independent section">
              <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criterion comment="asterisk DPKG is earlier than 1.4.21.2~dfsg-3+lenny3" test_ref="oval:org.mitre.oval:tst:44024"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Release section">
          <extend_definition comment="Debian 6.0 is installed" definition_ref="oval:org.mitre.oval:def:12959"/>
          <criteria operator="OR" comment="Architecture section">
            <criteria operator="AND" comment="Architecture independent section">
              <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criterion comment="asterisk DPKG is earlier than 1.6.2.9-2+squeeze3" test_ref="oval:org.mitre.oval:tst:44143"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:13067" version="3" class="patch">
      <metadata>
        <title>DSA-2237-2 apr -- denial of service</title>
        <affected family="unix">
          <platform>Debian 5.0</platform>
          <platform>Debian 6.0</platform>
          <product>apr</product>
        </affected>
        <reference source="VENDOR" ref_url="http://lists.debian.org/debian-security-announce/2011/msg00108.html" ref_id="DSA-2237-2"/>
        <description>The recent APR update DSA-2237-1 introduced a regression that could lead to an endless loop in the apr_fnmatch function, causing a denial of service. This update fixes this problem . For reference, the description of the original DSA, which fixed CVE-2011-0419: A flaw was found in the APR library, which could be exploited through Apache HTTPD"s mod_autoindex. If a directory indexed by mod_autoindex contained files with sufficiently long names, a remote attacker could send a carefully crafted request which would cause excessive CPU usage. This could be used in a denial of service attack.</description>
        <oval_repository>
          <dates>
            <submitted date="2011-09-22T19:54:06-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2011-09-22T12:03:33.689-04:00">DRAFT</status_change>
            <status_change date="2011-10-10T04:00:53.107-04:00">INTERIM</status_change>
            <status_change date="2011-10-31T04:01:31.575-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Release section">
          <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
          <criteria operator="OR" comment="Architecture section">
            <criteria operator="AND" comment="Architecture independent section">
              <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criterion comment="apr DPKG is earlier than 1.2.12-5+lenny4" test_ref="oval:org.mitre.oval:tst:44037"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Release section">
          <extend_definition comment="Debian 6.0 is installed" definition_ref="oval:org.mitre.oval:def:12959"/>
          <criteria operator="OR" comment="Architecture section">
            <criteria operator="AND" comment="Architecture independent section">
              <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criterion comment="apr DPKG is earlier than 1.4.2-6+squeeze2" test_ref="oval:org.mitre.oval:tst:43152"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:13066" version="3" class="patch">
      <metadata>
        <title>DSA-2254-1 oprofile -- command injection</title>
        <affected family="unix">
          <platform>Debian 5.0</platform>
          <platform>Debian 6.0</platform>
          <product>oprofile</product>
        </affected>
        <reference source="VENDOR" ref_url="http://lists.debian.org/debian-security-announce/2011/msg00124.html" ref_id="DSA-2254-1"/>
        <description>OProfile is a performance profiling tool which is configurable by opcontrol, its control utility. Stephane Chauveau reported several ways to inject arbitrary commands in the arguments of this utility. If a local unprivileged user is authorized by sudoers file to run opcontrol as root, this user could use the flaw to escalate his privileges.</description>
        <oval_repository>
          <dates>
            <submitted date="2011-09-22T16:43:55-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2011-09-22T12:03:37.325-04:00">DRAFT</status_change>
            <status_change date="2011-10-10T04:00:52.819-04:00">INTERIM</status_change>
            <status_change date="2011-10-31T04:01:31.311-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Release section">
          <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
          <criteria operator="OR" comment="Architecture section">
            <criteria operator="AND" comment="Architecture independent section">
              <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criterion comment="oprofile DPKG is earlier than 0.9.3-2+lenny1" test_ref="oval:org.mitre.oval:tst:44007"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Release section">
          <extend_definition comment="Debian 6.0 is installed" definition_ref="oval:org.mitre.oval:def:12959"/>
          <criteria operator="OR" comment="Architecture section">
            <criteria operator="AND" comment="Architecture independent section">
              <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criterion comment="oprofile DPKG is earlier than 0.9.6-1.1+squeeze1" test_ref="oval:org.mitre.oval:tst:44141"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:13063" version="3" class="patch">
      <metadata>
        <title>DSA-2281-1 opie -- several</title>
        <affected family="unix">
          <platform>Debian 5.0</platform>
          <platform>Debian 6.0</platform>
          <product>opie</product>
        </affected>
        <reference source="VENDOR" ref_url="http://lists.debian.org/debian-security-announce/2011/msg00155.html" ref_id="DSA-2281-1"/>
        <description>Sebastian Krahmer discovered that opie, a system that makes it simple to use One-Time passwords in applications, is prone to a privilege escalation  and an off-by-one error, which can lead to the execution of arbitrary code . Adam Zabrocki and Maksymilian Arciemowicz also discovered another off-by-one error , which only affects the lenny version as the fix was already included for squeeze.</description>
        <oval_repository>
          <dates>
            <submitted date="2011-09-22T14:58:45-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2011-09-22T12:03:46.522-04:00">DRAFT</status_change>
            <status_change date="2011-10-10T04:00:52.341-04:00">INTERIM</status_change>
            <status_change date="2011-10-31T04:01:30.734-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Release section">
          <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
          <criteria operator="OR" comment="Architecture section">
            <criteria operator="AND" comment="Architecture independent section">
              <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criterion comment="opie DPKG is earlier than 2.32-10.2+lenny2" test_ref="oval:org.mitre.oval:tst:43968"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Release section">
          <extend_definition comment="Debian 6.0 is installed" definition_ref="oval:org.mitre.oval:def:12959"/>
          <criteria operator="OR" comment="Architecture section">
            <criteria operator="AND" comment="Architecture independent section">
              <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criterion comment="opie DPKG is earlier than 2.32.dfsg.1-0.2+squeeze1" test_ref="oval:org.mitre.oval:tst:44058"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:13053" version="3" class="patch">
      <metadata>
        <title>DSA-2275-1 openoffice.org -- stack-based buffer overflow</title>
        <affected family="unix">
          <platform>Debian 6.0</platform>
          <product>openoffice.org</product>
        </affected>
        <reference source="VENDOR" ref_url="http://lists.debian.org/debian-security-announce/2011/msg00147.html" ref_id="DSA-2275-1"/>
        <description>Will Dormann and Jared Allar discovered that the Lotus Word Pro import filter of OpenOffice.org, a full-featured office productivity suite that provides a near drop-in replacement for Microsoft Office, is not properly handling object ids in the &amp;quot;.lwp&amp;quot; file format. An attacker can exploit this with a specially crafted file and execute arbitrary code with the rights of the victim importing the file. The oldstable distribution  is not affected by this problem.</description>
        <oval_repository>
          <dates>
            <submitted date="2011-09-22T15:18:19-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2011-09-22T12:03:44.785-04:00">DRAFT</status_change>
            <status_change date="2011-10-10T04:00:51.840-04:00">INTERIM</status_change>
            <status_change date="2011-10-31T04:01:28.373-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Debian 6.0 is installed" definition_ref="oval:org.mitre.oval:def:12959"/>
        <criteria operator="OR" comment="Architecture section">
          <criteria operator="AND" comment="Architecture independent section">
            <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
            <criterion comment="openoffice.org DPKG is earlier than 1:3.2.1-11+squeeze3" test_ref="oval:org.mitre.oval:tst:43449"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:13047" version="3" class="patch">
      <metadata>
        <title>DSA-2265-1 perl -- lack of tainted flag propagation</title>
        <affected family="unix">
          <platform>Debian 5.0</platform>
          <platform>Debian 6.0</platform>
          <product>perl</product>
        </affected>
        <reference source="VENDOR" ref_url="http://lists.debian.org/debian-security-announce/2011/msg00135.html" ref_id="DSA-2265-1"/>
        <description>Mark Martinec discovered that Perl incorrectly clears the tainted flag on values returned by case conversion functions such as &amp;quot;lc&amp;quot;. This may expose preexisting vulnerabilities in applications which use these functions while processing untrusted input. No such applications are known at this stage. Such applications will cease to work when this security update is applied because taint checks are designed to prevent such unsafe use of untrusted input data.</description>
        <oval_repository>
          <dates>
            <submitted date="2011-09-22T14:18:20-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2011-09-22T12:03:41.529-04:00">DRAFT</status_change>
            <status_change date="2011-10-10T04:00:51.581-04:00">INTERIM</status_change>
            <status_change date="2011-10-31T04:01:28.109-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Release section">
          <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
          <criteria operator="OR" comment="Architecture section">
            <criteria operator="AND" comment="Architecture independent section">
              <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criterion comment="perl DPKG is earlier than 5.10.0-19lenny4" test_ref="oval:org.mitre.oval:tst:44085"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Release section">
          <extend_definition comment="Debian 6.0 is installed" definition_ref="oval:org.mitre.oval:def:12959"/>
          <criteria operator="OR" comment="Architecture section">
            <criteria operator="AND" comment="Architecture independent section">
              <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criterion comment="perl DPKG is earlier than 5.10.1-17squeeze1" test_ref="oval:org.mitre.oval:tst:44040"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:13046" version="3" class="patch">
      <metadata>
        <title>DSA-2246-1 mahara -- several vulnerabilities</title>
        <affected family="unix">
          <platform>Debian 5.0</platform>
          <platform>Debian 6.0</platform>
          <product>mahara</product>
        </affected>
        <reference source="VENDOR" ref_url="http://lists.debian.org/debian-security-announce/2011/msg00116.html" ref_id="DSA-2246-1"/>
        <description>Several vulnerabilities were discovered in mahara, an electronic portfolio, weblog, and resume builder. The following Common Vulnerabilities and Exposures project ids identify them: CVE-2011-1402 It was discovered that previous versions of Mahara did not check user credentials before adding a secret URL to a view or suspending a user. CVE-2011-1403 Due to a misconfiguration of the Pieform package in Mahara, the cross-site request forgery protection mechanism that Mahara relies on to harden its form was not working and was essentially disabled. This is a critical vulnerability which could allow attackers to trick other users  into performing malicious actions on behalf of the attacker. Most Mahara forms are vulnerable. CVE-2011-1404 Many of the JSON structures returned by Mahara for its AJAX interactions included more information than what ought to be disclosed to the logged in user. New versions of Mahara limit this information to what is necessary for each page. CVE-2011-1405 Previous versions of Mahara did not escape the contents of HTML emails sent to users. Depending on the filters enabled in one"s mail reader, it could lead to cross-site scripting attacks. CVE-2011-1406 It has been pointed out to us that if Mahara is configured  to use HTTPS, it will happily let users login via the HTTP version of the site if the web server is configured to serve content over both protocol. The new version of Mahara will, when the wwwroot points to an HTTPS URL, automatically redirect to HTTPS if it detects that it is being run over HTTP. We recommend that sites wanting to run Mahara over HTTPS make sure that their web server configuration does not allow the serving of content over HTTP and merely redirects to the secure version. We also suggest that site administrators consider adding the HSTS headers  to their web server configuration.</description>
        <oval_repository>
          <dates>
            <submitted date="2011-09-22T22:24:47-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2011-09-22T12:03:38.197-04:00">DRAFT</status_change>
            <status_change date="2011-10-10T04:00:51.329-04:00">INTERIM</status_change>
            <status_change date="2011-10-31T04:01:27.761-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Release section">
          <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
          <criteria operator="OR" comment="Architecture section">
            <criteria operator="AND" comment="Architecture independent section">
              <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criterion comment="mahara DPKG is earlier than 1.0.4-4+lenny10" test_ref="oval:org.mitre.oval:tst:43973"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Release section">
          <extend_definition comment="Debian 6.0 is installed" definition_ref="oval:org.mitre.oval:def:12959"/>
          <criteria operator="OR" comment="Architecture section">
            <criteria operator="AND" comment="Architecture independent section">
              <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criterion comment="mahara DPKG is earlier than 1.2.6-2+squeeze2" test_ref="oval:org.mitre.oval:tst:43731"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:13043" version="3" class="patch">
      <metadata>
        <title>DSA-2224-1 openjdk-6 -- several</title>
        <affected family="unix">
          <platform>Debian 5.0</platform>
          <platform>Debian 6.0</platform>
          <product>openjdk-6</product>
        </affected>
        <reference source="VENDOR" ref_url="http://lists.debian.org/debian-security-announce/2011/msg00093.html" ref_id="DSA-2224-1"/>
        <description>Several security vulnerabilities were discovered in OpenJDK, an implementation of the Java platform. CVE-2010-4351 The JNLP SecurityManager returns from the checkPermission method instead of throwing an exception in certain circumstances, which might allow context-dependent attackers to bypass the intended security policy by creating instances of ClassLoader. CVE-2010-4448 Malicious applets can perform DNS cache poisoning. CVE-2010-4450 An empty  LD_LIBRARY_PATH environment variable results in a misconstructed library search path, resulting in code execution from possibly untrusted sources. CVE-2010-4465 Malicious applets can extend their privileges by abusing Swing timers. CVE-2010-4469 The Hotspot just-in-time compiler miscompiles crafted byte sequences, resulting in heap corruption. CVE-2010-4470 JAXP can be exploited by untrusted code to elevate privileges. CVE-2010-4471 Java2D can be exploited by untrusted code to elevate privileges. CVE-2010-4472 Untrusted code can replace the XML DSIG implementation. CVE-2011-0025 Signatures on JAR files are not properly verified, which allows remote attackers to trick users into executing code that appears to come from a trusted source. CVE-2011-0706 The JNLPClassLoader class allows remote attackers to gain privileges via unknown vectors related to multiple signers and the assignment of &amp;quot;an inappropriate security descriptor In addition, this security update contains stability fixes, such as switching to the recommended Hotspot version  for this particular version of OpenJDK.</description>
        <oval_repository>
          <dates>
            <submitted date="2011-09-22T22:52:08-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2011-09-22T12:03:38.702-04:00">DRAFT</status_change>
            <status_change date="2011-10-10T04:00:51.077-04:00">INTERIM</status_change>
            <status_change date="2011-10-31T04:01:24.680-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Release section">
          <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
          <criteria operator="OR" comment="Architecture section">
            <criteria operator="AND" comment="Architecture independent section">
              <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criterion comment="openjdk-6 DPKG is earlier than 6b18-1.8.7-2~lenny1" test_ref="oval:org.mitre.oval:tst:44053"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Release section">
          <extend_definition comment="Debian 6.0 is installed" definition_ref="oval:org.mitre.oval:def:12959"/>
          <criteria operator="OR" comment="Architecture section">
            <criteria operator="AND" comment="Architecture independent section">
              <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criterion comment="openjdk-6 DPKG is earlier than 6b18-1.8.7-2~squeeze1" test_ref="oval:org.mitre.oval:tst:43745"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:13038" version="3" class="patch">
      <metadata>
        <title>DSA-2279-1 libapache2-mod-authnz-external -- SQL injection</title>
        <affected family="unix">
          <platform>Debian 6.0</platform>
          <product>libapache2-mod-authnz-external</product>
        </affected>
        <reference source="VENDOR" ref_url="http://lists.debian.org/debian-security-announce/2011/msg00153.html" ref_id="DSA-2279-1"/>
        <description>It was discovered that libapache2-mod-authnz-external, an apache authentication module, is prone to an SQL injection via the $user paramter.</description>
        <oval_repository>
          <dates>
            <submitted date="2011-09-22T15:13:11-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2011-09-22T12:03:47.110-04:00">DRAFT</status_change>
            <status_change date="2011-10-10T04:00:50.831-04:00">INTERIM</status_change>
            <status_change date="2011-10-31T04:01:24.084-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Debian 6.0 is installed" definition_ref="oval:org.mitre.oval:def:12959"/>
        <criteria operator="OR" comment="Architecture section">
          <criteria operator="AND" comment="Architecture independent section">
            <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
            <criterion comment="libapache2-mod-authnz-external DPKG is earlier than 3.2.4-2+squeeze1" test_ref="oval:org.mitre.oval:tst:44188"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:13034" version="3" class="patch">
      <metadata>
        <title>DSA-2268-1 iceweasel -- several</title>
        <affected family="unix">
          <platform>Debian 5.0</platform>
          <platform>Debian 6.0</platform>
          <product>iceweasel</product>
        </affected>
        <reference source="VENDOR" ref_url="http://lists.debian.org/debian-security-announce/2011/msg00139.html" ref_id="DSA-2268-1"/>
        <description>Several vulnerabilities have been found in Iceweasel, a web browser based on Firefox: CVE-2011-0083 / CVE-2011-2363 &amp;quot;regenrecht&amp;quot; discovered two use-after-frees in SVG processing, which could lead to the execution of arbitrary code. CVE-2011-0085 &amp;quot;regenrecht&amp;quot; discovered a use-after-free in XUL processing, which could lead to the execution of arbitrary code. CVE-2011-2362 David Chan discovered that cookies were insufficiently isolated. CVE-2011-2371 Chris Rohlf and Yan Ivnitskiy discovered an integer overflow in the Javascript engine, which could lead to the execution of arbitrary code. CVE-2011-2373 Martin Barbella discovered a use-after-free in XUL processing, which could lead to the execution of arbitrary code. CVE-2011-2374 Bob Clary, Kevin Brosnan, Nils, Gary Kwong, Jesse Ruderman and Christian Biesinger discovered memory corruption bugs, which may lead to the execution of arbitrary code. CVE-2011-2376 Luke Wagner and Gary Kwong discovered memory corruption bugs, which may lead to the execution of arbitrary code.</description>
        <oval_repository>
          <dates>
            <submitted date="2011-09-22T14:03:48-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2011-09-22T12:03:42.995-04:00">DRAFT</status_change>
            <status_change date="2011-10-10T04:00:50.584-04:00">INTERIM</status_change>
            <status_change date="2011-10-31T04:01:23.802-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Release section">
          <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
          <criteria operator="OR" comment="Architecture section">
            <criteria operator="AND" comment="Architecture independent section">
              <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criterion comment="iceweasel DPKG is earlier than 1.9.0.19-12" test_ref="oval:org.mitre.oval:tst:43819"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Release section">
          <extend_definition comment="Debian 6.0 is installed" definition_ref="oval:org.mitre.oval:def:12959"/>
          <criteria operator="OR" comment="Architecture section">
            <criteria operator="AND" comment="Architecture independent section">
              <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criterion comment="iceweasel DPKG is earlier than 3.5.16-9" test_ref="oval:org.mitre.oval:tst:43658"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:13030" version="3" class="patch">
      <metadata>
        <title>DSA-2267-1 perl -- restriction bypass</title>
        <affected family="unix">
          <platform>Debian 5.0</platform>
          <platform>Debian 6.0</platform>
          <product>perl</product>
        </affected>
        <reference source="VENDOR" ref_url="http://lists.debian.org/debian-security-announce/2011/msg00138.html" ref_id="DSA-2267-1"/>
        <description>It was discovered that Perl"s Safe module - a module to compile and execute code in restricted compartments - could by bypassed. Please note that this update is known to break Petal, an XML-based templating engine . A fix is not yet available. If you use Petal, you might consider to put the previous Perl packages on hold.</description>
        <oval_repository>
          <dates>
            <submitted date="2011-09-22T14:25:17-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2011-09-22T12:03:43.716-04:00">DRAFT</status_change>
            <status_change date="2011-10-10T04:00:50.326-04:00">INTERIM</status_change>
            <status_change date="2011-10-31T04:01:23.556-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Release section">
          <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
          <criteria operator="OR" comment="Architecture section">
            <criteria operator="AND" comment="Architecture independent section">
              <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criterion comment="perl DPKG is earlier than 5.10.0-19lenny5" test_ref="oval:org.mitre.oval:tst:44229"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Release section">
          <extend_definition comment="Debian 6.0 is installed" definition_ref="oval:org.mitre.oval:def:12959"/>
          <criteria operator="OR" comment="Architecture section">
            <criteria operator="AND" comment="Architecture independent section">
              <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criterion comment="perl DPKG is earlier than 5.10.1-17squeeze2" test_ref="oval:org.mitre.oval:tst:44087"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:13028" version="3" class="patch">
      <metadata>
        <title>DSA-2272-1 bind9 -- denial of service</title>
        <affected family="unix">
          <platform>Debian 5.0</platform>
          <platform>Debian 6.0</platform>
          <product>bind9</product>
        </affected>
        <reference source="VENDOR" ref_url="http://lists.debian.org/debian-security-announce/2011/msg00144.html" ref_id="DSA-2272-1"/>
        <description>It was discovered that BIND, a DNS server, does not correctly process certain UPDATE requests, resulting in a server crash and a denial of service. This vulnerability affects BIND installations even if they do not actually use dynamic DNS updates.</description>
        <oval_repository>
          <dates>
            <submitted date="2011-09-22T10:53:59-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2011-09-22T12:03:44.257-04:00">DRAFT</status_change>
            <status_change date="2011-10-10T04:00:50.062-04:00">INTERIM</status_change>
            <status_change date="2011-10-31T04:01:23.304-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Release section">
          <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
          <criteria operator="OR" comment="Architecture section">
            <criteria operator="AND" comment="Architecture independent section">
              <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criterion comment="bind9 DPKG is earlier than 1:9.6.ESV.R4+dfsg-0+lenny3" test_ref="oval:org.mitre.oval:tst:44183"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Release section">
          <extend_definition comment="Debian 6.0 is installed" definition_ref="oval:org.mitre.oval:def:12959"/>
          <criteria operator="OR" comment="Architecture section">
            <criteria operator="AND" comment="Architecture independent section">
              <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criterion comment="bind9 DPKG is earlier than 1:9.7.3.dfsg-1~squeeze3" test_ref="oval:org.mitre.oval:tst:44080"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:13022" version="3" class="patch">
      <metadata>
        <title>DSA-2280-1 libvirt -- several</title>
        <affected family="unix">
          <platform>Debian 5.0</platform>
          <platform>Debian 6.0</platform>
          <product>libvirt</product>
        </affected>
        <reference source="VENDOR" ref_url="http://lists.debian.org/debian-security-announce/2011/msg00154.html" ref_id="DSA-2280-1"/>
        <description>It was discovered that libvirt, a library for interfacing with different virtualization systems, is prone to an integer overflow . Additionally, the stable version is prone to a denial of service, because its error reporting is not thread-safe . For the stable distribution , these problems have been fixed in version 0.8.3-5+squeeze2.</description>
        <oval_repository>
          <dates>
            <submitted date="2011-09-22T14:44:19-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2011-09-22T12:03:45.873-04:00">DRAFT</status_change>
            <status_change date="2011-10-10T04:00:49.774-04:00">INTERIM</status_change>
            <status_change date="2011-10-31T04:01:22.529-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Release section">
          <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
          <criteria operator="OR" comment="Architecture section">
            <criteria operator="AND" comment="Architecture independent section">
              <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criterion comment="libvirt DPKG is earlier than 0.4.6-10+lenny2" test_ref="oval:org.mitre.oval:tst:43931"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Release section">
          <extend_definition comment="Debian 6.0 is installed" definition_ref="oval:org.mitre.oval:def:12959"/>
          <criteria operator="OR" comment="Architecture section">
            <criteria operator="AND" comment="Architecture independent section">
              <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criterion comment="libvirt DPKG is earlier than 0.8.3-5+squeeze2" test_ref="oval:org.mitre.oval:tst:44180"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:13020" version="3" class="patch">
      <metadata>
        <title>DSA-2210-1 tiff -- several</title>
        <affected family="unix">
          <platform>Debian 6.0</platform>
          <product>tiff</product>
        </affected>
        <reference source="VENDOR" ref_url="http://lists.debian.org/debian-security-announce/2011/msg00079.html" ref_id="DSA-2210-1"/>
        <description>Several vulnearbilities were discovered in the TIFF manipulation and conversion library: CVE-2011-0191 A buffer overflow allows to execute arbitrary code or cause a denial of service via a crafted TIFF image with JPEG encoding. This issue affects the Debian 5.0 Lenny package only. CVE-2011-0192 A buffer overflow allows to execute arbitrary code or cause a denial of service via a crafted TIFF Internet Fax image file that has been compressed using CCITT Group 4 encoding. CVE-2011-1167 Heap-based buffer overflow in the thunder  decoder allows to execute arbitrary code via a TIFF file that has an unexpected BitsPerSample value.</description>
        <oval_repository>
          <dates>
            <submitted date="2011-09-22T20:21:26-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2011-09-22T12:03:39.585-04:00">DRAFT</status_change>
            <status_change date="2011-10-10T04:00:49.557-04:00">INTERIM</status_change>
            <status_change date="2011-10-31T04:01:21.879-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Debian 6.0 is installed" definition_ref="oval:org.mitre.oval:def:12959"/>
        <criteria operator="OR" comment="Architecture section">
          <criteria operator="AND" comment="Architecture independent section">
            <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
            <criterion comment="tiff DPKG is earlier than 3.9.4-5+squeeze1" test_ref="oval:org.mitre.oval:tst:44118"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:13019" version="3" class="patch">
      <metadata>
        <title>DSA-2233-1 postfix -- several</title>
        <affected family="unix">
          <platform>Debian 5.0</platform>
          <platform>Debian 6.0</platform>
          <product>postfix</product>
        </affected>
        <reference source="VENDOR" ref_url="http://lists.debian.org/debian-security-announce/2011/msg00102.html" ref_id="DSA-2233-1"/>
        <description>Several vulnerabilities were discovered in Postfix, a mail transfer agent. The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2009-2939 The postinst script grants the postfix user write access to /var/spool/postfix/pid, which might allow local users to conduct symlink attacks that overwrite arbitrary files. CVE-2011-0411 The STARTTLS implementation does not properly restrict I/O buffering, which allows man-in-the-middle attackers to insert commands into encrypted SMTP sessions by sending a cleartext command that is processed after TLS is in place. CVE-2011-1720 A heap-based read-only buffer overflow allows malicious clients to crash the smtpd server process using a crafted SASL authentication request.</description>
        <oval_repository>
          <dates>
            <submitted date="2011-09-22T11:47:01-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2011-09-22T12:03:32.331-04:00">DRAFT</status_change>
            <status_change date="2011-10-10T04:00:49.299-04:00">INTERIM</status_change>
            <status_change date="2011-10-31T04:01:21.622-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Release section">
          <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
          <criteria operator="OR" comment="Architecture section">
            <criteria operator="AND" comment="Architecture independent section">
              <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criterion comment="postfix DPKG is earlier than 2.5.5-1.1+lenny1" test_ref="oval:org.mitre.oval:tst:44041"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Release section">
          <extend_definition comment="Debian 6.0 is installed" definition_ref="oval:org.mitre.oval:def:12959"/>
          <criteria operator="OR" comment="Architecture section">
            <criteria operator="AND" comment="Architecture independent section">
              <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criterion comment="postfix DPKG is earlier than 2.7.1-1+squeeze1" test_ref="oval:org.mitre.oval:tst:43894"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:13017" version="3" class="patch">
      <metadata>
        <title>DSA-2226-1 libmodplug -- buffer overflow</title>
        <affected family="unix">
          <platform>Debian 5.0</platform>
          <platform>Debian 6.0</platform>
          <product>libmodplug</product>
        </affected>
        <reference source="VENDOR" ref_url="http://lists.debian.org/debian-security-announce/2011/msg00095.html" ref_id="DSA-2226-1"/>
        <description>M. Lucinskij and P. Tumenas discovered a buffer overflow in the code for processing S3M tracker files in the Modplug tracker music library, which may result in the execution of arbitrary code.</description>
        <oval_repository>
          <dates>
            <submitted date="2011-09-22T12:37:10-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2011-09-22T12:03:29.999-04:00">DRAFT</status_change>
            <status_change date="2011-10-10T04:00:48.993-04:00">INTERIM</status_change>
            <status_change date="2011-10-31T04:01:20.950-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Release section">
          <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
          <criteria operator="OR" comment="Architecture section">
            <criteria operator="AND" comment="Architecture independent section">
              <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criterion comment="libmodplug DPKG is earlier than 0.8.4-1+lenny2" test_ref="oval:org.mitre.oval:tst:43864"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Release section">
          <extend_definition comment="Debian 6.0 is installed" definition_ref="oval:org.mitre.oval:def:12959"/>
          <criteria operator="OR" comment="Architecture section">
            <criteria operator="AND" comment="Architecture independent section">
              <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criterion comment="libmodplug DPKG is earlier than 1:0.8.8.1-1+squeeze1" test_ref="oval:org.mitre.oval:tst:43925"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:13013" version="3" class="patch">
      <metadata>
        <title>DSA-2240-1 linux-2.6 -- privilege escalation/denial of service/information leak</title>
        <affected family="unix">
          <platform>Debian 6.0</platform>
          <product>linux-2.6</product>
        </affected>
        <reference source="VENDOR" ref_url="http://lists.debian.org/debian-security-announce/2011/msg00111.html" ref_id="DSA-2240-1"/>
        <description>CVE-2010-3875 Vasiliy Kulikov discovered an issue in the Linux implementation of the Amateur Radio AX.25 Level 2 protocol. Local users may obtain access to sensitive kernel memory. CVE-2011-0695 Jens Kuehnel reported an issue in the InfiniBand stack. Remote attackers can exploit a race condition to cause a denial of service . CVE-2011-0711 Dan Rosenberg reported an issue in the XFS filesystem. Local users may obtain access to sensitive kernel memory. CVE-2011-0726 Kees Cook reported an issue in the /proc/pid/stat implementation. Local users could learn the text location of a process, defeating protections provided by address space layout randomization . CVE-2011-1016 Marek Ol&amp;#x161;&amp;#xE1;k discovered an issue in the driver for ATI/AMD Radeon video chips. Local users could pass arbitrary values to video memory and the graphics translation table, resulting in denial of service or escalated privileges. On default Debian installations, this is exploitable only by members of the "video" group. CVE-2011-1078 Vasiliy Kulikov discovered an issue in the Bluetooth subsystem. Local users can obtain access to sensitive kernel memory. CVE-2011-1079 Vasiliy Kulikov discovered an issue in the Bluetooth subsystem. Local users with the CAP_NET_ADMIN capability can cause a denial of service . CVE-2011-1080 Vasiliy Kulikov discovered an issue in the Netfilter subsystem. Local users can obtain access to sensitive kernel memory. CVE-2011-1090 Neil Horman discovered a memory leak in the setacl call on NFSv4 filesystems. Local users can explot this to cause a denial of service . CVE-2011-1160 Peter Huewe reported an issue in the Linux kernel"s support for TPM security chips. Local users with permission to open the device can gain access to sensitive kernel memory. CVE-2011-1163 Timo Warns reported an issue in the kernel support for Alpha OSF format disk partitions. Users with physical access can gain access to sensitive kernel memory by adding a storage device with a specially crafted OSF partition. CVE-2011-1170 Vasiliy Kulikov reported an issue in the Netfilter arp table implementation. Local users with the CAP_NET_ADMIN capability can gain access to sensitive kernel memory. CVE-2011-1171 Vasiliy Kulikov reported an issue in the Netfilter IP table implementation. Local users with the CAP_NET_ADMIN capability can gain access to sensitive kernel memory. CVE-2011-1172 Vasiliy Kulikov reported an issue in the Netfilter IP6 table implementation. Local users with the CAP_NET_ADMIN capability can gain access to sensitive kernel memory. CVE-2011-1173 Vasiliy Kulikov reported an issue in the Acorn Econet protocol implementation. Local users can obtain access to sensitive kernel memory on systems that use this rare hardware. CVE-2011-1180 Dan Rosenberg reported a buffer overflow in the Information Access Service of the IrDA protocol, used for Infrared devices. Remote attackers within IR device range can cause a denial of service or possibly gain elevated privileges. CVE-2011-1182 Julien Tinnes reported an issue in the rt_sigqueueinfo interface. Local users can generate signals with falsified source pid and uid information. CVE-2011-1476 Dan Rosenberg reported issues in the Open Sound System MIDI interface that allow local users to cause a denial of service. This issue does not affect official Debian Linux image packages as they no longer provide support for OSS. However, custom kernels built from Debians linux-source-2.6.32 may have enabled this configuration and would therefore be vulnerable. CVE-2011-1477 Dan Rosenberg reported issues in the Open Sound System driver for cards that include a Yamaha FM synthesizer chip. Local users can cause memory corruption resulting in a denial of service. This issue does not affect official Debian Linux image packages as they no longer provide support for OSS. However, custom kernels built from Debians linux-source-2.6.32 may have enabled this configuration and would therefore be vulnerable. CVE-2011-1478 Ryan Sweat reported an issue in the Generic Receive Offload  support in the Linux networking subsystem. If an interface has GRO enabled and is running in promiscuous mode, remote users can cause a denial of service  by sending packets on an unknown VLAN. CVE-2011-1493 Dan Rosenburg reported two issues in the Linux implementation of the Amateur Radio X.25 PLP  protocol. A remote user can cause a denial of service by providing specially crafted facilities fields. CVE-2011-1494 Dan Rosenberg reported an issue in the /dev/mpt2ctl interface provided by the driver for LSI MPT Fusion SAS 2.0 controllers. Local users can obtain elevated privileges by specially crafted ioctl calls. On default Debian installations this is not exploitable as this interface is only accessible to root. CVE-2011-1495 Dan Rosenberg reported two additional issues in the /dev/mpt2ctl interface provided by the driver for LSI MPT Fusion SAS 2.0 controllers. Local users can obtain elevated privileges and ready arbitrary kernel memory by using specially crafted ioctl calls. On default Debian installations this is not exploitable as this interface is only accessible to root. CVE-2011-1585 Jeff Layton reported an issue in the Common Internet File System . Local users can bypass authentication requirements for shares that are already mounted by another user. CVE-2011-1593 Robert Swiecki reported a signednes issue in the next_pidmap function, which can be exploited my local users to cause a denial of service. CVE-2011-1598 Dave Jones reported an issue in the Broadcast Manager Controller Area Network  protocol that may allow local users to cause a NULL pointer dereference, resulting in a denial of service. CVE-2011-1745 Vasiliy Kulikov reported an issue in the Linux support for AGP devices. Local users can obtain elevated privileges or cause a denial of service due to missing bounds checking in the AGPIOC_BIND ioctl. On default Debian installations, this is exploitable only by users in the video group. CVE-2011-1746 Vasiliy Kulikov reported an issue in the Linux support for AGP devices. Local users can obtain elevated privileges or cause a denial of service due to missing bounds checking in the agp_allocate_memory and agp_create_user_memory. On default Debian installations, this is exploitable only by users in the video group. CVE-2011-1748 Oliver Kartkopp reported an issue in the Controller Area Network  raw socket implementation which permits ocal users to cause a NULL pointer dereference, resulting in a denial of service. CVE-2011-1759 Dan Rosenberg reported an issue in the support for executing &amp;quot;old ABI&amp;quot; binaries on ARM processors. Local users can obtain elevated privileges due to insufficient bounds checking in the semtimedop system call. CVE-2011-1767 Alexecy Dobriyan reported an issue in the GRE over IP implementation. Remote users can cause a denial of service by sending a packet during module initialization. CVE-2011-1770 Dan Rosenberg reported an issue in the Datagram Congestion Control Protocol . Remote users can cause a denial of service or potentially obtain access to sensitive kernel memory. CVE-2011-1776 Timo Warns reported an issue in the Linux implementation for GUID partitions. Users with physical access can gain access to sensitive kernel memory by adding a storage device with a specially crafted corrupted invalid partition table. CVE-2011-2022 Vasiliy Kulikov reported an issue in the Linux support for AGP devices. Local users can obtain elevated privileges or cause a denial of service due to missing bounds checking in the AGPIOC_UNBIND ioctl. On default Debian installations, this is exploitable only by users in the video group. This update also includes changes queued for the next point release of Debian 6.0, which also fix various non-security issues</description>
        <oval_repository>
          <dates>
            <submitted date="2011-09-22T22:03:46-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2011-09-22T12:03:37.896-04:00">DRAFT</status_change>
            <status_change date="2011-10-10T04:00:48.777-04:00">INTERIM</status_change>
            <status_change date="2011-10-31T04:01:20.741-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Debian 6.0 is installed" definition_ref="oval:org.mitre.oval:def:12959"/>
        <criteria operator="OR" comment="Architecture section">
          <criteria operator="AND" comment="Architecture independent section">
            <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
            <criterion comment="linux-2.6 DPKG is earlier than 2.6.32-34squeeze1" test_ref="oval:org.mitre.oval:tst:44106"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:13008" version="3" class="patch">
      <metadata>
        <title>DSA-2288-1 libsndfile -- integer overflow</title>
        <affected family="unix">
          <platform>Debian 5.0</platform>
          <platform>Debian 6.0</platform>
          <product>libsndfile</product>
        </affected>
        <reference source="VENDOR" ref_url="http://lists.debian.org/debian-security-announce/2011/msg00162.html" ref_id="DSA-2288-1"/>
        <description>Hossein Lotfi discovered an integer overflow in libsndfile"s code to parse Paris Audio files, which could potentially lead to the execution of arbitrary code.</description>
        <oval_repository>
          <dates>
            <submitted date="2011-09-22T19:51:34-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2011-09-22T12:03:48.626-04:00">DRAFT</status_change>
            <status_change date="2011-10-10T04:00:48.506-04:00">INTERIM</status_change>
            <status_change date="2011-10-31T04:01:20.492-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Release section">
          <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
          <criteria operator="OR" comment="Architecture section">
            <criteria operator="AND" comment="Architecture independent section">
              <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criterion comment="libsndfile DPKG is earlier than 1.0.17-4+lenny3" test_ref="oval:org.mitre.oval:tst:44079"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Release section">
          <extend_definition comment="Debian 6.0 is installed" definition_ref="oval:org.mitre.oval:def:12959"/>
          <criteria operator="OR" comment="Architecture section">
            <criteria operator="AND" comment="Architecture independent section">
              <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criterion comment="libsndfile DPKG is earlier than 1.0.21-3+squeeze1" test_ref="oval:org.mitre.oval:tst:43537"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:13007" version="3" class="patch">
      <metadata>
        <title>DSA-2227-1 iceape -- several</title>
        <affected family="unix">
          <platform>Debian 6.0</platform>
          <product>iceape</product>
        </affected>
        <reference source="VENDOR" ref_url="http://lists.debian.org/debian-security-announce/2011/msg00096.html" ref_id="DSA-2227-1"/>
        <description>Several vulnerabilities have been found in the Iceape internet suite, an unbranded version of Seamonkey: CVE-2011-0069 CVE-2011-0070 CVE-2011-0072 CVE-2011-0074 CVE-2011-0075 CVE-2011-0077 CVE-2011-0078 CVE-2011-0080 CVE-2011-0081 &amp;quot;Scoobidiver&amp;quot;, Ian Beer Bob Clary, Henri Sivonen, Marco Bonardo, Mats Palmgren, Jesse Ruderman, Aki Kelin and Martin Barbella discovered memory corruption bugs, which may lead to the execution of arbitrary code. CVE-2011-0065 CVE-2011-0066 CVE-2011-0073 &amp;quot;regenrecht&amp;quot; discovered several dangling pointer vulnerabilities, which may lead to the execution of arbitrary code. CVE-2011-0067 Paul Stone discovered that Java applets could steal information from the autocompletion history. CVE-2011-0071 Soroush Dalili discovered a directory traversal vulnerability in handling resource URIs. The oldstable distribution  is not affected. The iceape package only provides the XPCOM code.</description>
        <oval_repository>
          <dates>
            <submitted date="2011-09-22T16:57:13-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2011-09-22T12:03:31.363-04:00">DRAFT</status_change>
            <status_change date="2011-10-10T04:00:48.290-04:00">INTERIM</status_change>
            <status_change date="2011-10-31T04:01:20.269-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Debian 6.0 is installed" definition_ref="oval:org.mitre.oval:def:12959"/>
        <criteria operator="OR" comment="Architecture section">
          <criteria operator="AND" comment="Architecture independent section">
            <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
            <criterion comment="iceape DPKG is earlier than 2.0.11-5" test_ref="oval:org.mitre.oval:tst:44089"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:13006" version="3" class="patch">
      <metadata>
        <title>DSA-2285-1 mapserver -- several</title>
        <affected family="unix">
          <platform>Debian 5.0</platform>
          <platform>Debian 6.0</platform>
          <product>mapserver</product>
        </affected>
        <reference source="VENDOR" ref_url="http://lists.debian.org/debian-security-announce/2011/msg00159.html" ref_id="DSA-2285-1"/>
        <description>Several vulnerabilities have been discovered in mapserver, a CGI-based web framework to publish spatial data and interactive mapping applications. The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2011-2703 Several instances of insufficient escaping of user input, leading to SQL injection attacks via OGC filter encoding . CVE-2011-2704 Missing length checks in the processing of OGC filter encoding that can lead to stack-based buffer overflows and the execution of arbitrary code.</description>
        <oval_repository>
          <dates>
            <submitted date="2011-09-22T19:29:06-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2011-09-22T12:03:47.796-04:00">DRAFT</status_change>
            <status_change date="2011-10-10T04:00:47.950-04:00">INTERIM</status_change>
            <status_change date="2011-10-31T04:01:19.951-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Release section">
          <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
          <criteria operator="OR" comment="Architecture section">
            <criteria operator="AND" comment="Architecture independent section">
              <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criterion comment="mapserver DPKG is earlier than 5.0.3-3+lenny7" test_ref="oval:org.mitre.oval:tst:43959"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Release section">
          <extend_definition comment="Debian 6.0 is installed" definition_ref="oval:org.mitre.oval:def:12959"/>
          <criteria operator="OR" comment="Architecture section">
            <criteria operator="AND" comment="Architecture independent section">
              <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criterion comment="mapserver DPKG is earlier than 5.6.5-2+squeeze2" test_ref="oval:org.mitre.oval:tst:43855"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:13004" version="3" class="patch">
      <metadata>
        <title>DSA-2271-1 curl -- improper delegation of client credentials</title>
        <affected family="unix">
          <platform>Debian 5.0</platform>
          <platform>Debian 6.0</platform>
          <product>curl</product>
        </affected>
        <reference source="VENDOR" ref_url="http://lists.debian.org/debian-security-announce/2011/msg00143.html" ref_id="DSA-2271-1"/>
        <description>Richard Silverman discovered that when doing GSSAPI authentication, libcurl unconditionally performs credential delegation. This hands the server a copy of the client"s security credentials, allowing the server to impersonate the client to any other using the same GSSAPI mechanism. This is obviously a very sensitive operation, which should only be done when the user explicitly so directs.</description>
        <oval_repository>
          <dates>
            <submitted date="2011-09-22T13:56:24-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2011-09-22T12:03:42.695-04:00">DRAFT</status_change>
            <status_change date="2011-10-10T04:00:47.689-04:00">INTERIM</status_change>
            <status_change date="2011-10-31T04:01:19.687-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Release section">
          <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
          <criteria operator="OR" comment="Architecture section">
            <criteria operator="AND" comment="Architecture independent section">
              <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criterion comment="curl DPKG is earlier than 7.18.2-8lenny5" test_ref="oval:org.mitre.oval:tst:44036"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Release section">
          <extend_definition comment="Debian 6.0 is installed" definition_ref="oval:org.mitre.oval:def:12959"/>
          <criteria operator="OR" comment="Architecture section">
            <criteria operator="AND" comment="Architecture independent section">
              <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criterion comment="curl DPKG is earlier than 7.21.0-2" test_ref="oval:org.mitre.oval:tst:44197"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:13003" version="3" class="patch">
      <metadata>
        <title>DSA-2229-1 spip -- programming error</title>
        <affected family="unix">
          <platform>Debian 6.0</platform>
          <product>spip</product>
        </affected>
        <reference source="VENDOR" ref_url="http://lists.debian.org/debian-security-announce/2011/msg00098.html" ref_id="DSA-2229-1"/>
        <description>A vulnerability has been found in SPIP, a website engine for publishing, which allows a malicious registered author to disconnect the website from its database, resulting in denial of service. The oldstable distribution  doesn"t include spip.</description>
        <oval_repository>
          <dates>
            <submitted date="2011-09-22T16:53:21-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2011-09-22T12:03:31.146-04:00">DRAFT</status_change>
            <status_change date="2011-10-10T04:00:47.469-04:00">INTERIM</status_change>
            <status_change date="2011-10-31T04:01:19.452-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Debian 6.0 is installed" definition_ref="oval:org.mitre.oval:def:12959"/>
        <criteria operator="OR" comment="Architecture section">
          <criteria operator="AND" comment="Architecture independent section">
            <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
            <criterion comment="spip DPKG is earlier than 2.1.1-3squeeze1" test_ref="oval:org.mitre.oval:tst:43927"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:13001" version="3" class="patch">
      <metadata>
        <title>DSA-2245-1 chromium-browser -- several vulnerabilities</title>
        <affected family="unix">
          <platform>Debian 6.0</platform>
          <product>chromium-browser</product>
        </affected>
        <reference source="VENDOR" ref_url="http://lists.debian.org/debian-security-announce/2011/msg00115.html" ref_id="DSA-2245-1"/>
        <description>Several vulnerabilities were discovered in the Chromium browser. The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2011-1292 Use-after-free vulnerability in the frame-loader implementation in Google Chrome allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors. CVE-2011-1293 Use-after-free vulnerability in the HTMLCollection implementation in Google Chrome allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors. CVE-2011-1440 Use-after-free vulnerability in Google Chrome allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to the ruby element and Cascading Style Sheets  token sequences. CVE-2011-1444 Race condition in the sandbox launcher implementation in Google Chrome on Linux allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors. CVE-2011-1797 Google Chrome does not properly render tables, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors that lead to a &amp;quot;stale pointer.&amp;quot; CVE-2011-1799 Google Chrome does not properly perform casts of variables during interaction with the WebKit engine, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2011-09-22T22:45:19-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2011-09-22T12:03:38.437-04:00">DRAFT</status_change>
            <status_change date="2011-10-10T04:00:47.251-04:00">INTERIM</status_change>
            <status_change date="2011-10-31T04:01:19.224-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Debian 6.0 is installed" definition_ref="oval:org.mitre.oval:def:12959"/>
        <criteria operator="OR" comment="Architecture section">
          <criteria operator="AND" comment="Architecture independent section">
            <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
            <criterion comment="chromium-browser DPKG is earlier than 6.0.472.63~r59945-5+squeeze5" test_ref="oval:org.mitre.oval:tst:44166"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:12999" version="3" class="patch">
      <metadata>
        <title>DSA-2222-1 tinyproxy -- incorrect ACL processing</title>
        <affected family="unix">
          <platform>Debian 6.0</platform>
          <product>tinyproxy</product>
        </affected>
        <reference source="VENDOR" ref_url="http://lists.debian.org/debian-security-announce/2011/msg00091.html" ref_id="DSA-2222-1"/>
        <description>Christoph Martin discovered that incorrect ACL processing in TinyProxy, a lightweight, non-caching, optionally anonymizing http proxy could lead to unintended network access rights. The oldstable distribution  is not affected.</description>
        <oval_repository>
          <dates>
            <submitted date="2011-09-22T17:22:21-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2011-09-22T12:03:29.722-04:00">DRAFT</status_change>
            <status_change date="2011-10-10T04:00:46.789-04:00">INTERIM</status_change>
            <status_change date="2011-10-31T04:01:17.934-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Debian 6.0 is installed" definition_ref="oval:org.mitre.oval:def:12959"/>
        <criteria operator="OR" comment="Architecture section">
          <criteria operator="AND" comment="Architecture independent section">
            <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
            <criterion comment="tinyproxy DPKG is earlier than 1.8.2-1squeeze1" test_ref="oval:org.mitre.oval:tst:44055"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:12993" version="3" class="patch">
      <metadata>
        <title>DSA-2238-1 vino -- several</title>
        <affected family="unix">
          <platform>Debian 6.0</platform>
          <product>vino</product>
        </affected>
        <reference source="VENDOR" ref_url="http://lists.debian.org/debian-security-announce/2011/msg00107.html" ref_id="DSA-2238-1"/>
        <description>Kevin Chen discovered that incorrect processing of framebuffer requests in the Vino VNC server could lead to denial of service.</description>
        <oval_repository>
          <dates>
            <submitted date="2011-09-22T19:51:42-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2011-09-22T12:03:33.358-04:00">DRAFT</status_change>
            <status_change date="2011-10-10T04:00:46.339-04:00">INTERIM</status_change>
            <status_change date="2011-10-31T04:01:16.751-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Debian 6.0 is installed" definition_ref="oval:org.mitre.oval:def:12959"/>
        <criteria operator="OR" comment="Architecture section">
          <criteria operator="AND" comment="Architecture independent section">
            <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
            <criterion comment="vino DPKG is earlier than 2.28.2-2+squeeze1" test_ref="oval:org.mitre.oval:tst:43809"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:12989" version="3" class="patch">
      <metadata>
        <title>DSA-2204-1 imp4 -- Insufficient input sanitising</title>
        <affected family="unix">
          <platform>Debian 5.0</platform>
          <platform>Debian 6.0</platform>
          <product>imp4</product>
        </affected>
        <reference source="VENDOR" ref_url="http://lists.debian.org/debian-security-announce/2011/msg00072.html" ref_id="DSA-2204-1"/>
        <description>Moritz Naumann discovered that imp4, a webmail component for the horde framework, is prone to cross-site scripting attacks by a lack of input sanitising of certain fetchmail information.</description>
        <oval_repository>
          <dates>
            <submitted date="2011-09-22T10:41:22-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2011-09-22T12:03:25.533-04:00">DRAFT</status_change>
            <status_change date="2011-10-10T04:00:46.087-04:00">INTERIM</status_change>
            <status_change date="2011-10-31T04:01:16.085-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Release section">
          <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
          <criteria operator="OR" comment="Architecture section">
            <criteria operator="AND" comment="Architecture independent section">
              <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criterion comment="imp4 DPKG is earlier than 4.2-4lenny3" test_ref="oval:org.mitre.oval:tst:43083"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Release section">
          <extend_definition comment="Debian 6.0 is installed" definition_ref="oval:org.mitre.oval:def:12959"/>
          <criteria operator="OR" comment="Architecture section">
            <criteria operator="AND" comment="Architecture independent section">
              <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criterion comment="imp4 DPKG is earlier than 4.3.7+debian0-2.1" test_ref="oval:org.mitre.oval:tst:43953"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:12987" version="3" class="patch">
      <metadata>
        <title>DSA-2230-1 qemu-kvm -- several</title>
        <affected family="unix">
          <platform>Debian 6.0</platform>
          <product>qemu-kvm</product>
        </affected>
        <reference source="VENDOR" ref_url="http://lists.debian.org/debian-security-announce/2011/msg00099.html" ref_id="DSA-2230-1"/>
        <description>Two vulnerabilities have been discovered in KVM, a solution for full virtualization on x86 hardware: CVE-2011-0011 Setting the VNC password to an empty string silently disabled all authentication. CVE-2011-1750 The virtio-blk driver performed insufficient validation of read/write I/O from the guest instance, which could lead to denial of service or privilege escalation. The oldstable distribution  is not affected by this problem.</description>
        <oval_repository>
          <dates>
            <submitted date="2011-09-22T16:49:30-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2011-09-22T12:03:30.786-04:00">DRAFT</status_change>
            <status_change date="2011-10-10T04:00:45.846-04:00">INTERIM</status_change>
            <status_change date="2011-10-31T04:01:15.831-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Debian 6.0 is installed" definition_ref="oval:org.mitre.oval:def:12959"/>
        <criteria operator="OR" comment="Architecture section">
          <criteria operator="AND" comment="Architecture independent section">
            <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
            <criterion comment="qemu-kvm DPKG is earlier than 0.12.5+dfsg-5+squeeze1" test_ref="oval:org.mitre.oval:tst:44030"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:12986" version="3" class="patch">
      <metadata>
        <title>DSA-2187-1 icedove -- several</title>
        <affected family="unix">
          <platform>Debian 6.0</platform>
          <product>icedove</product>
        </affected>
        <reference source="VENDOR" ref_url="http://lists.debian.org/debian-security-announce/2011/msg00054.html" ref_id="DSA-2187-1"/>
        <description>Several vulnerabilities have been discovered in Icedove, an unbranded version of the Thunderbird mail/news client. CVE-2010-1585 Roberto Suggi Liverani discovered that the sanitising performed by ParanoidFragmentSink was incomplete. CVE-2011-0053 Crashes in the layout engine may lead to the execution of arbitrary code. CVE-2011-0051 Zach Hoffmann discovered that incorrect parsing of recursive eval calls could lead to attackers forcing acceptance of a confirmation dialogue. CVE-2011-0054, CVE-2010-0056 Christian Holler discovered buffer overflows in the Javascript engine, which could allow the execution of arbitrary code. CVE-2011-0055 &amp;quot;regenrecht&amp;quot; and Igor Bukanov discovered a use-after-free error in the JSON-Implementation, which could lead to the execution of arbitrary code. CVE-2011-0057 Daniel Kozlowski discovered that incorrect memory handling the web workers implementation could lead to the execution of arbitrary code. CVE-2011-0059 Peleus Uhley discovered a cross-site request forgery risk in the plugin code. As indicated in the Lenny  release notes, security support for the Icedove packages in the oldstable needed to be stopped before the end of the regular Lenny security maintenance life cycle. You are strongly encouraged to upgrade to stable or switch to a different mail client.</description>
        <oval_repository>
          <dates>
            <submitted date="2011-09-22T09:01:20-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2011-09-22T12:03:22.370-04:00">DRAFT</status_change>
            <status_change date="2011-10-10T04:00:45.629-04:00">INTERIM</status_change>
            <status_change date="2011-10-31T04:01:15.615-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Debian 6.0 is installed" definition_ref="oval:org.mitre.oval:def:12959"/>
        <criteria operator="OR" comment="Architecture section">
          <criteria operator="AND" comment="Architecture independent section">
            <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
            <criterion comment="icedove DPKG is earlier than 3.0.11-1+squeeze1" test_ref="oval:org.mitre.oval:tst:43883"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:12985" version="3" class="patch">
      <metadata>
        <title>DSA-2218-1 vlc -- heap-based buffer overflow</title>
        <affected family="unix">
          <platform>Debian 6.0</platform>
          <product>vlc</product>
        </affected>
        <reference source="VENDOR" ref_url="http://lists.debian.org/debian-security-announce/2011/msg00087.html" ref_id="DSA-2218-1"/>
        <description>Aliz Hammond discovered that the MP4 decoder plugin of vlc, a multimedia player and streamer, is vulnerable to a heap-based buffer overflow. This has been introduced by a wrong data type being used for a size calculation. An attacker could use this flaw to trick a victim into opening a specially crafted MP4 file and possibly execute arbitrary code or crash the media player. The oldstable distribution  is not affected by this problem.</description>
        <oval_repository>
          <dates>
            <submitted date="2011-09-22T11:41:05-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2011-09-22T12:03:28.677-04:00">DRAFT</status_change>
            <status_change date="2011-10-10T04:00:45.413-04:00">INTERIM</status_change>
            <status_change date="2011-10-31T04:01:15.405-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Debian 6.0 is installed" definition_ref="oval:org.mitre.oval:def:12959"/>
        <criteria operator="OR" comment="Architecture section">
          <criteria operator="AND" comment="Architecture independent section">
            <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
            <criterion comment="vlc DPKG is earlier than 1.1.3-1squeeze5" test_ref="oval:org.mitre.oval:tst:43958"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:12980" version="3" class="patch">
      <metadata>
        <title>DSA-2181-1 subversion -- denial of service</title>
        <affected family="unix">
          <platform>Debian 5.0</platform>
          <platform>Debian 6.0</platform>
          <product>subversion</product>
        </affected>
        <reference source="VENDOR" ref_url="http://lists.debian.org/debian-security-announce/2011/msg00048.html" ref_id="DSA-2181-1"/>
        <description>Philip Martin discovered that HTTP-based Subversion servers crash when processing lock requests on repositories which support unauthenticated read access.</description>
        <oval_repository>
          <dates>
            <submitted date="2011-09-22T16:52:31-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2011-09-22T12:03:21.607-04:00">DRAFT</status_change>
            <status_change date="2011-10-10T04:00:45.155-04:00">INTERIM</status_change>
            <status_change date="2011-10-31T04:01:15.160-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Release section">
          <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
          <criteria operator="OR" comment="Architecture section">
            <criteria operator="AND" comment="Architecture independent section">
              <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criterion comment="subversion DPKG is earlier than 1.5.1dfsg1-6" test_ref="oval:org.mitre.oval:tst:44015"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Release section">
          <extend_definition comment="Debian 6.0 is installed" definition_ref="oval:org.mitre.oval:def:12959"/>
          <criteria operator="OR" comment="Architecture section">
            <criteria operator="AND" comment="Architecture independent section">
              <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criterion comment="subversion DPKG is earlier than 1.6.12dfsg-5" test_ref="oval:org.mitre.oval:tst:44033"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:12978" version="3" class="patch">
      <metadata>
        <title>DSA-2252-1 dovecot -- programming error</title>
        <affected family="unix">
          <platform>Debian 6.0</platform>
          <product>dovecot</product>
        </affected>
        <reference source="VENDOR" ref_url="http://lists.debian.org/debian-security-announce/2011/msg00122.html" ref_id="DSA-2252-1"/>
        <description>It was discovered that the message header parser in the Dovecot mail server parsed NUL characters incorrectly, which could lead to denial of service through malformed mail headers. The oldstable distribution  is not affected.</description>
        <oval_repository>
          <dates>
            <submitted date="2011-09-22T20:04:46-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2011-09-22T12:03:36.796-04:00">DRAFT</status_change>
            <status_change date="2011-10-10T04:00:44.902-04:00">INTERIM</status_change>
            <status_change date="2011-10-31T04:01:14.906-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Debian 6.0 is installed" definition_ref="oval:org.mitre.oval:def:12959"/>
        <criteria operator="OR" comment="Architecture section">
          <criteria operator="AND" comment="Architecture independent section">
            <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
            <criterion comment="dovecot DPKG is earlier than 1.2.15-7" test_ref="oval:org.mitre.oval:tst:44066"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:12975" version="3" class="patch">
      <metadata>
        <title>DSA-2178-1 pango1.0 -- NULL pointer dereference</title>
        <affected family="unix">
          <platform>Debian 6.0</platform>
          <product>pango1.0</product>
        </affected>
        <reference source="VENDOR" ref_url="http://lists.debian.org/debian-security-announce/2011/msg00045.html" ref_id="DSA-2178-1"/>
        <description>It was discovered that pango did not check for memory allocation failures, causing a NULL pointer dereference with an adjustable offset. This can lead to application crashes and potentially arbitrary code execution. The oldstable distribution  is not affected by this problem.</description>
        <oval_repository>
          <dates>
            <submitted date="2011-09-22T16:31:58-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2011-09-22T12:03:19.744-04:00">DRAFT</status_change>
            <status_change date="2011-10-10T04:00:44.680-04:00">INTERIM</status_change>
            <status_change date="2011-10-31T04:01:14.582-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Debian 6.0 is installed" definition_ref="oval:org.mitre.oval:def:12959"/>
        <criteria operator="OR" comment="Architecture section">
          <criteria operator="AND" comment="Architecture independent section">
            <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
            <criterion comment="pango1.0 DPKG is earlier than 1.28.3-1+squeeze2" test_ref="oval:org.mitre.oval:tst:43717"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:12967" version="3" class="patch">
      <metadata>
        <title>DSA-2210-2 tiff -- several</title>
        <affected family="unix">
          <platform>Debian 5.0</platform>
          <platform>Debian 6.0</platform>
          <product>tiff</product>
        </affected>
        <reference source="VENDOR" ref_url="http://lists.debian.org/debian-security-announce/2011/msg00136.html" ref_id="DSA-2210-2"/>
        <description>The recent tiff update DSA-2210-1 introduced a regression that could lead to encoding problems of tiff files. This update fixes this problem . For reference, the description of the original DSA, which fixed CVE-2011-0191 CVE-2011-0192 CVE-2011-1167 CVE-2011-0191 A buffer overflow allows to execute arbitrary code or cause a denial of service via a crafted TIFF image with JPEG encoding. This issue affects the Debian 5.0 Lenny package only. CVE-2011-0192 A buffer overflow allows to execute arbitrary code or cause a denial of service via a crafted TIFF Internet Fax image file that has been compressed using CCITT Group 4 encoding. CVE-2011-1167 Heap-based buffer overflow in the thunder  decoder allows to execute arbitrary code via a TIFF file that has an unexpected BitsPerSample value.</description>
        <oval_repository>
          <dates>
            <submitted date="2011-09-22T12:17:01-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2011-09-22T12:03:42.382-04:00">DRAFT</status_change>
            <status_change date="2011-10-10T04:00:43.601-04:00">INTERIM</status_change>
            <status_change date="2011-10-31T04:01:12.899-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Release section">
          <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
          <criteria operator="OR" comment="Architecture section">
            <criteria operator="AND" comment="Architecture independent section">
              <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criterion comment="tiff DPKG is earlier than 3.8.2-11.5" test_ref="oval:org.mitre.oval:tst:44236"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Release section">
          <extend_definition comment="Debian 6.0 is installed" definition_ref="oval:org.mitre.oval:def:12959"/>
          <criteria operator="OR" comment="Architecture section">
            <criteria operator="AND" comment="Architecture independent section">
              <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criterion comment="tiff DPKG is earlier than 3.9.4-5+squeeze3" test_ref="oval:org.mitre.oval:tst:44113"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:12966" version="3" class="patch">
      <metadata>
        <title>DSA-2190-1 wordpress -- several</title>
        <affected family="unix">
          <platform>Debian 6.0</platform>
          <product>wordpress</product>
        </affected>
        <reference source="VENDOR" ref_url="http://lists.debian.org/debian-security-announce/2011/msg00057.html" ref_id="DSA-2190-1"/>
        <description><![CDATA[Two XSS bugs and one potential information disclosure issue were discovered in wordpress, a weblog manager. The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2011-0700 Input passed via the post title when performing a &quot;Quick Edit&quot; or &quot;Bulk Edit&quot; action and via the &quot;post_status&quot;, &quot;comment_status&quot;, and &quot;ping_status&quot; parameters is not properly sanitised before being used. Certain input passed via tags in the tags meta-box is not properly sanitised before being returned to the user. CVE-2011-0701 Wordpress incorrectly enforces user access restrictions when accessing posts via the media uploader and can be exploited to disclose the contents of e.g. private or draft posts. The oldstable distribution  is not affected by these problems.]]></description>
        <oval_repository>
          <dates>
            <submitted date="2011-09-22T21:48:10-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2011-09-22T12:03:24.925-04:00">DRAFT</status_change>
            <status_change date="2011-10-10T04:00:43.236-04:00">INTERIM</status_change>
            <status_change date="2011-10-31T04:01:12.673-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Debian 6.0 is installed" definition_ref="oval:org.mitre.oval:def:12959"/>
        <criteria operator="OR" comment="Architecture section">
          <criteria operator="AND" comment="Architecture independent section">
            <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
            <criterion comment="wordpress DPKG is earlier than 3.0.5+dfsg-0+squeeze1" test_ref="oval:org.mitre.oval:tst:44047"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:12965" version="3" class="patch">
      <metadata>
        <title>DSA-2184-1 isc-dhcp -- denial of service</title>
        <affected family="unix">
          <platform>Debian 6.0</platform>
          <product>isc-dhcp</product>
        </affected>
        <reference source="VENDOR" ref_url="http://lists.debian.org/debian-security-announce/2011/msg00051.html" ref_id="DSA-2184-1"/>
        <description>It was discovered that the ISC DHCPv6 server does not correctly process requests which come from unexpected source addresses, leading to an assertion failure and a daemon crash. The oldstable distribution  is not affected by this problem.</description>
        <oval_repository>
          <dates>
            <submitted date="2011-09-22T16:56:49-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2011-09-22T12:03:21.859-04:00">DRAFT</status_change>
            <status_change date="2011-10-10T04:00:42.987-04:00">INTERIM</status_change>
            <status_change date="2011-10-31T04:01:12.462-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Debian 6.0 is installed" definition_ref="oval:org.mitre.oval:def:12959"/>
        <criteria operator="OR" comment="Architecture section">
          <criteria operator="AND" comment="Architecture independent section">
            <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
            <criterion comment="isc-dhcp DPKG is earlier than 4.1.1-P1-15+squeeze1" test_ref="oval:org.mitre.oval:tst:43880"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:12960" version="3" class="patch">
      <metadata>
        <title>DSA-2282-1 qemu-kvm -- several</title>
        <affected family="unix">
          <platform>Debian 6.0</platform>
          <product>qemu-kvm</product>
        </affected>
        <reference source="VENDOR" ref_url="http://lists.debian.org/debian-security-announce/2011/msg00156.html" ref_id="DSA-2282-1"/>
        <description>Two vulnerabilities have been discovered in KVM, a solution for full virtualization on x86 hardware: CVE-2011-2212 Nelson Elhage discovered a buffer overflow in the virtio subsystem, which could lead to denial of service or privilege escalation. CVE-2011-2527 Andrew Griffiths discovered that group privileges were insufficiently dropped when started with -runas option, resulting in privilege escalation.</description>
        <oval_repository>
          <dates>
            <submitted date="2011-09-22T19:36:39-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2011-09-22T12:03:48.054-04:00">DRAFT</status_change>
            <status_change date="2011-10-10T04:00:42.585-04:00">INTERIM</status_change>
            <status_change date="2011-10-31T04:01:11.597-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Debian 6.0 is installed" definition_ref="oval:org.mitre.oval:def:12959"/>
        <criteria operator="OR" comment="Architecture section">
          <criteria operator="AND" comment="Architecture independent section">
            <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
            <criterion comment="qemu-kvm DPKG is earlier than 0.12.5+dfsg-5+squeeze6" test_ref="oval:org.mitre.oval:tst:44115"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:12957" version="3" class="patch">
      <metadata>
        <title>DSA-2198-1 tex-common -- insufficient input sanitization</title>
        <affected family="unix">
          <platform>Debian 6.0</platform>
          <product>tex-common</product>
        </affected>
        <reference source="VENDOR" ref_url="http://lists.debian.org/debian-security-announce/2011/msg00066.html" ref_id="DSA-2198-1"/>
        <description>Mathias Svensson discovered that tex-common, a package shipping a number of scripts and configuration files necessary for TeX, contains insecure settings for the &amp;quot;shell_escape_commands&amp;quot; directive. Depending on the scenario, this may result in arbitrary code execution when a victim is tricked into processing a malicious tex-file or this is done in an automated fashion. The oldstable distribution  is not affected by this problem due to shell_escape being disabled.</description>
        <oval_repository>
          <dates>
            <submitted date="2011-09-22T10:30:47-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2011-09-22T12:03:24.528-04:00">DRAFT</status_change>
            <status_change date="2011-10-10T04:00:42.224-04:00">INTERIM</status_change>
            <status_change date="2011-10-31T04:01:11.369-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Debian 6.0 is installed" definition_ref="oval:org.mitre.oval:def:12959"/>
        <criteria operator="OR" comment="Architecture section">
          <criteria operator="AND" comment="Architecture independent section">
            <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
            <criterion comment="tex-common DPKG is earlier than 2.08.1" test_ref="oval:org.mitre.oval:tst:43942"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:12951" version="3" class="patch">
      <metadata>
        <title>DSA-2237-1 apr -- denial of service</title>
        <affected family="unix">
          <platform>Debian 5.0</platform>
          <platform>Debian 6.0</platform>
          <product>apr</product>
        </affected>
        <reference source="VENDOR" ref_url="http://lists.debian.org/debian-security-announce/2011/msg00106.html" ref_id="DSA-2237-1"/>
        <description>A flaw was found in the APR library, which could be exploited through Apache HTTPD"s mod_autoindex. If a directory indexed by mod_autoindex contained files with sufficiently long names, a remote attacker could send a carefully crafted request which would cause excessive CPU usage. This could be used in a denial of service attack.</description>
        <oval_repository>
          <dates>
            <submitted date="2011-09-22T22:12:26-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2011-09-22T12:03:33.106-04:00">DRAFT</status_change>
            <status_change date="2011-10-10T04:00:41.071-04:00">INTERIM</status_change>
            <status_change date="2011-10-31T04:01:10.012-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Release section">
          <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
          <criteria operator="OR" comment="Architecture section">
            <criteria operator="AND" comment="Architecture independent section">
              <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criterion comment="apr DPKG is earlier than 1.2.12-5+lenny3" test_ref="oval:org.mitre.oval:tst:44029"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Release section">
          <extend_definition comment="Debian 6.0 is installed" definition_ref="oval:org.mitre.oval:def:12959"/>
          <criteria operator="OR" comment="Architecture section">
            <criteria operator="AND" comment="Architecture independent section">
              <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criterion comment="apr DPKG is earlier than 1.4.2-6+squeeze1" test_ref="oval:org.mitre.oval:tst:43933"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:12949" version="3" class="patch">
      <metadata>
        <title>DSA-2213-1 x11-xserver-utils -- missing input sanitization</title>
        <affected family="unix">
          <platform>Debian 6.0</platform>
          <product>x11-xserver-utils</product>
        </affected>
        <reference source="VENDOR" ref_url="http://lists.debian.org/debian-security-announce/2011/msg00082.html" ref_id="DSA-2213-1"/>
        <description>Sebastian Krahmer discovered that the xrdb utility of x11-xserver-utils, a X server resource database utility, is not properly filtering crafted hostnames. This allows a remote attacker to execute arbitrary code with root privileges given that either remote logins via xdmcp are allowed or the attacker is able to place a rogue DHCP server into the victims network. The oldstable distribution , this problem has been fixed in version 7.3+6.</description>
        <oval_repository>
          <dates>
            <submitted date="2011-09-22T12:08:27-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2011-09-22T12:03:28.267-04:00">DRAFT</status_change>
            <status_change date="2011-10-10T04:00:40.843-04:00">INTERIM</status_change>
            <status_change date="2011-10-31T04:01:09.783-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Debian 6.0 is installed" definition_ref="oval:org.mitre.oval:def:12959"/>
        <criteria operator="OR" comment="Architecture section">
          <criteria operator="AND" comment="Architecture independent section">
            <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
            <criterion comment="x11-xserver-utils DPKG is earlier than 7.5+3" test_ref="oval:org.mitre.oval:tst:44107"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:12946" version="3" class="patch">
      <metadata>
        <title>DSA-2248-1 ejabberd -- denial of service</title>
        <affected family="unix">
          <platform>Debian 5.0</platform>
          <platform>Debian 6.0</platform>
          <product>ejabberd</product>
        </affected>
        <reference source="VENDOR" ref_url="http://lists.debian.org/debian-security-announce/2011/msg00118.html" ref_id="DSA-2248-1"/>
        <description>Wouter Coekaerts discovered that ejabberd, a distributed XMPP/Jabber server written in Erlang, is vulnerable to the so-called &amp;quot;billion laughs&amp;quot; attack because it does not prevent entity expansion on received data. This allows an attacker to perform denial of service attacks against the service by sending specially crafted XML data to it.</description>
        <oval_repository>
          <dates>
            <submitted date="2011-09-22T21:44:13-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2011-09-22T12:03:35.877-04:00">DRAFT</status_change>
            <status_change date="2011-10-10T04:00:40.609-04:00">INTERIM</status_change>
            <status_change date="2011-10-31T04:01:09.306-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Release section">
          <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
          <criteria operator="OR" comment="Architecture section">
            <criteria operator="AND" comment="Architecture independent section">
              <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criterion comment="ejabberd DPKG is earlier than 2.0.1-6+lenny3" test_ref="oval:org.mitre.oval:tst:44139"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Release section">
          <extend_definition comment="Debian 6.0 is installed" definition_ref="oval:org.mitre.oval:def:12959"/>
          <criteria operator="OR" comment="Architecture section">
            <criteria operator="AND" comment="Architecture independent section">
              <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criterion comment="ejabberd DPKG is earlier than 2.1.5-3+squeeze1" test_ref="oval:org.mitre.oval:tst:44131"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:12932" version="3" class="patch">
      <metadata>
        <title>DSA-2162-1 openssl -- invalid memory access</title>
        <affected family="unix">
          <platform>Debian 6.0</platform>
          <product>openssl</product>
        </affected>
        <reference source="VENDOR" ref_url="http://lists.debian.org/debian-security-announce/2011/msg00027.html" ref_id="DSA-2162-1"/>
        <description>Neel Mehta discovered that an incorrectly formatted ClientHello handshake message could cause OpenSSL to parse past the end of the message. This allows an attacker to crash an application using OpenSSL by triggering an invalid memory access. Additionally, some applications may be vulnerable to expose contents of a parsed OCSP nonce extension. Packages in the oldstable distribution  are not affected by this problem.</description>
        <oval_repository>
          <dates>
            <submitted date="2011-09-22T16:21:43-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2011-09-22T12:03:16.155-04:00">DRAFT</status_change>
            <status_change date="2011-10-10T04:00:40.212-04:00">INTERIM</status_change>
            <status_change date="2011-10-31T04:01:08.768-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Debian 6.0 is installed" definition_ref="oval:org.mitre.oval:def:12959"/>
        <criteria operator="OR" comment="Architecture section">
          <criteria operator="AND" comment="Architecture independent section">
            <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
            <criterion comment="openssl DPKG is earlier than 0.9.8o-4squeeze1" test_ref="oval:org.mitre.oval:tst:43771"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:12924" version="3" class="patch">
      <metadata>
        <title>DSA-2208-1 bind9 -- denial of service</title>
        <affected family="unix">
          <platform>Debian 6.0</platform>
          <product>bind9</product>
        </affected>
        <reference source="VENDOR" ref_url="http://lists.debian.org/debian-security-announce/2011/msg00076.html" ref_id="DSA-2208-1"/>
        <description>It was discovered that BIND, a DNS server, contains a race condition when processing zones updates in an authoritative server, either through dynamic DNS updates or incremental zone transfer . Such an update while processing a query could result in deadlock and denial of service.  In addition, this security update addresses a defect related to the processing of new DNSSEC DS records by the caching resolver, which may lead to name resolution failures in the delegated zone. If DNSSEC validation is enabled, this issue can make domains ending in .COM unavailable when the DS record for .COM is added to the DNS root zone on March 31st, 2011. An unpatched server which is affected by this issue can be restarted, thus re-enabling resolution of .COM domains. This workaround applies to the version in oldstable, too. Configurations not using DNSSEC validations are not affected by this second issue.</description>
        <oval_repository>
          <dates>
            <submitted date="2011-09-22T20:23:19-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2011-09-22T12:03:26.554-04:00">DRAFT</status_change>
            <status_change date="2011-10-10T04:00:39.754-04:00">INTERIM</status_change>
            <status_change date="2011-10-31T04:01:07.574-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Debian 6.0 is installed" definition_ref="oval:org.mitre.oval:def:12959"/>
        <criteria operator="OR" comment="Architecture section">
          <criteria operator="AND" comment="Architecture independent section">
            <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
            <criterion comment="bind9 DPKG is earlier than 1:9.7.3.dfsg-1~squeeze1" test_ref="oval:org.mitre.oval:tst:43696"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:12914" version="3" class="patch">
      <metadata>
        <title>DSA-2225-1 asterisk -- several</title>
        <affected family="unix">
          <platform>Debian 5.0</platform>
          <platform>Debian 6.0</platform>
          <product>asterisk</product>
        </affected>
        <reference source="VENDOR" ref_url="http://lists.debian.org/debian-security-announce/2011/msg00094.html" ref_id="DSA-2225-1"/>
        <description>Several vulnerabilities have been discovered in Asterisk, an Open Source PBX and telephony toolkit. CVE-2011-1147 Matthew Nicholson discovered that incorrect handling of UDPTL packets may lead to denial of service of the execution of arbitrary code. CVE-2011-1174 Blake Cornell discovered that incorrect connection handling in the manager interface may lead to denial of service. CVE-2011-1175 Blake Cornell and Chris May discovered that incorrect TCP connection handling may lead to denial of service. CVE-2011-1507 Tzafrir Cohen discovered that insufficient limitation of connection requests in several TCP based services may lead to denial of service. CVE-2011-1599 Matthew Nicholson discovered a privilege escalation vulnerability in the manager interface.</description>
        <oval_repository>
          <dates>
            <submitted date="2011-09-22T12:40:18-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2011-09-22T12:03:30.336-04:00">DRAFT</status_change>
            <status_change date="2011-10-10T04:00:39.498-04:00">INTERIM</status_change>
            <status_change date="2011-10-31T04:01:07.010-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Release section">
          <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
          <criteria operator="OR" comment="Architecture section">
            <criteria operator="AND" comment="Architecture independent section">
              <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criterion comment="asterisk DPKG is earlier than 1:1.4.21.2~dfsg-3+lenny2.1" test_ref="oval:org.mitre.oval:tst:43839"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Release section">
          <extend_definition comment="Debian 6.0 is installed" definition_ref="oval:org.mitre.oval:def:12959"/>
          <criteria operator="OR" comment="Architecture section">
            <criteria operator="AND" comment="Architecture independent section">
              <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criterion comment="asterisk DPKG is earlier than 1:1.6.2.9-2+squeeze2" test_ref="oval:org.mitre.oval:tst:44018"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:12900" version="3" class="patch">
      <metadata>
        <title>DSA-2175-1 samba -- missing input sanisiting</title>
        <affected family="unix">
          <platform>Debian 5.0</platform>
          <platform>Debian 6.0</platform>
          <product>samba</product>
        </affected>
        <reference source="VENDOR" ref_url="http://lists.debian.org/debian-security-announce/2011/msg00041.html" ref_id="DSA-2175-1"/>
        <description>Volker Lendecke discovered that missing range checks in Samba"s file descriptor handling could lead to memory corruption, resulting in denial of service.</description>
        <oval_repository>
          <dates>
            <submitted date="2011-09-22T15:48:51-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2011-09-22T12:03:18.237-04:00">DRAFT</status_change>
            <status_change date="2011-10-10T04:00:37.972-04:00">INTERIM</status_change>
            <status_change date="2011-10-31T04:01:04.929-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Release section">
          <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
          <criteria operator="OR" comment="Architecture section">
            <criteria operator="AND" comment="Architecture independent section">
              <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criterion comment="samba DPKG is earlier than 3.2.5-4lenny14" test_ref="oval:org.mitre.oval:tst:43710"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Release section">
          <extend_definition comment="Debian 6.0 is installed" definition_ref="oval:org.mitre.oval:def:12959"/>
          <criteria operator="OR" comment="Architecture section">
            <criteria operator="AND" comment="Architecture independent section">
              <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criterion comment="samba DPKG is earlier than 3.5.6~dfsg-3squeeze2" test_ref="oval:org.mitre.oval:tst:43089"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:12895" version="3" class="patch">
      <metadata>
        <title>DSA-2166-1 chromium-browser -- several</title>
        <affected family="unix">
          <platform>Debian 6.0</platform>
          <product>chromium-browser</product>
        </affected>
        <reference source="VENDOR" ref_url="http://lists.debian.org/debian-security-announce/2011/msg00032.html" ref_id="DSA-2166-1"/>
        <description><![CDATA[Several vulnerabilities were discovered in the Chromium browser. The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2011-0777 Use-after-free vulnerability in Google Chrome before 9.0.597.84 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to image loading CVE-2011-0778 Google Chrome before 9.0.597.84 does not properly restrict drag and drop operations, which might allow remote attackers to bypass the Same Origin Policy via unspecified vectors CVE-2011-0783 Unspecified vulnerability in Google Chrome before 9.0.597.84 allows user-assisted remote attackers to cause a denial of service  via vectors involving a &quot;bad volume setting.&quot; CVE-2011-0983 Google Chrome before 9.0.597.94 does not properly handle anonymous blocks, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors that lead to a &quot;stale pointer.&quot; CVE-2011-0981 Google Chrome before 9.0.597.94 does not properly perform event handling for animations, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors that lead to a &quot;stale pointer.&quot; CVE-2011-0984 Google Chrome before 9.0.597.94 does not properly handle plug-ins, which allows remote attackers to cause a denial of service  via unspecified vectors CVE-2011-0985 Google Chrome before 9.0.597.94 does not properly perform process termination upon memory exhaustion, which has unspecified impact and remote attack vectors.]]></description>
        <oval_repository>
          <dates>
            <submitted date="2011-09-22T22:38:34-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2011-09-22T12:03:17.695-04:00">DRAFT</status_change>
            <status_change date="2011-10-10T04:00:37.750-04:00">INTERIM</status_change>
            <status_change date="2011-10-31T04:01:03.998-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Debian 6.0 is installed" definition_ref="oval:org.mitre.oval:def:12959"/>
        <criteria operator="OR" comment="Architecture section">
          <criteria operator="AND" comment="Architecture independent section">
            <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
            <criterion comment="chromium-browser DPKG is earlier than 6.0.472.63~r59945-5+squeeze2" test_ref="oval:org.mitre.oval:tst:43012"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:12894" version="3" class="patch">
      <metadata>
        <title>DSA-2160-1 tomcat6 -- several</title>
        <affected family="unix">
          <platform>Debian 6.0</platform>
          <product>tomcat6</product>
        </affected>
        <reference source="VENDOR" ref_url="http://lists.debian.org/debian-security-announce/2011/msg00025.html" ref_id="DSA-2160-1"/>
        <description>Several vulnerabilities were discovered in the Tomcat Servlet and JSP engine: CVE-2010-3718 It was discovered that the SecurityManager insufficiently restricted the working directory. CVE-2011-0013 It was discovered that the HTML manager interface is affected by cross-site scripting. CVE-2011-0534 It was discovered that NIO connector performs insufficient validation of the HTTP headers, which could lead to denial of service. The oldstable distribution  is not affected by these issues.</description>
        <oval_repository>
          <dates>
            <submitted date="2011-09-22T16:19:41-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2011-09-22T12:03:15.904-04:00">DRAFT</status_change>
            <status_change date="2011-10-10T04:00:37.528-04:00">INTERIM</status_change>
            <status_change date="2011-10-31T04:01:03.771-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Debian 6.0 is installed" definition_ref="oval:org.mitre.oval:def:12959"/>
        <criteria operator="OR" comment="Architecture section">
          <criteria operator="AND" comment="Architecture independent section">
            <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
            <criterion comment="tomcat6 DPKG is earlier than 6.0.28-9+squeeze1" test_ref="oval:org.mitre.oval:tst:43699"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:12893" version="3" class="patch">
      <metadata>
        <title>DSA-2247-1 rails -- several vulnerabilities</title>
        <affected family="unix">
          <platform>Debian 5.0</platform>
          <platform>Debian 6.0</platform>
          <product>rails</product>
        </affected>
        <reference source="VENDOR" ref_url="http://lists.debian.org/debian-security-announce/2011/msg00117.html" ref_id="DSA-2247-1"/>
        <description>Several vulnerabilities have been discovered in Rails, the Ruby web application framework. The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2011-0446 Multiple cross-site scripting  vulnerabilities when JavaScript encoding is used, allow remote attackers to inject arbitrary web script or HTML. CVE-2011-0447 Rails does not properly validate HTTP requests that contain an X-Requested-With header, which makes it easier for remote attackers to conduct cross-site request forgery  attacks.</description>
        <oval_repository>
          <dates>
            <submitted date="2011-09-22T21:51:09-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2011-09-22T12:03:36.226-04:00">DRAFT</status_change>
            <status_change date="2011-10-10T04:00:37.264-04:00">INTERIM</status_change>
            <status_change date="2011-10-31T04:01:03.502-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Release section">
          <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
          <criteria operator="OR" comment="Architecture section">
            <criteria operator="AND" comment="Architecture independent section">
              <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criterion comment="rails DPKG is earlier than 2.1.0-7+lenny0.1" test_ref="oval:org.mitre.oval:tst:43384"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Release section">
          <extend_definition comment="Debian 6.0 is installed" definition_ref="oval:org.mitre.oval:def:12959"/>
          <criteria operator="OR" comment="Architecture section">
            <criteria operator="AND" comment="Architecture independent section">
              <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criterion comment="rails DPKG is earlier than 2.3.5-1.2+squeeze0.1" test_ref="oval:org.mitre.oval:tst:43242"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:12891" version="3" class="patch">
      <metadata>
        <title>DSA-2284-1 opensaml2 -- implementation error</title>
        <affected family="unix">
          <platform>Debian 5.0</platform>
          <platform>Debian 6.0</platform>
          <product>opensaml2</product>
        </affected>
        <reference source="VENDOR" ref_url="http://lists.debian.org/debian-security-announce/2011/msg00158.html" ref_id="DSA-2284-1"/>
        <description>Juraj Somorovsky, Andreas Mayer, Meiko Jensen, Florian Kohlar, Marco Kampmann and Joerg Schwenk discovered that Shibboleth, a federated web single sign-on system is vulnerable to XML signature wrapping attacks</description>
        <oval_repository>
          <dates>
            <submitted date="2011-09-22T19:59:13-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2011-09-22T12:03:48.920-04:00">DRAFT</status_change>
            <status_change date="2011-10-10T04:00:36.922-04:00">INTERIM</status_change>
            <status_change date="2011-10-31T04:01:03.226-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Release section">
          <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
          <criteria operator="OR" comment="Architecture section">
            <criteria operator="AND" comment="Architecture independent section">
              <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criterion comment="opensaml2 DPKG is earlier than 2.0-2+lenny3" test_ref="oval:org.mitre.oval:tst:44144"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Release section">
          <extend_definition comment="Debian 6.0 is installed" definition_ref="oval:org.mitre.oval:def:12959"/>
          <criteria operator="OR" comment="Architecture section">
            <criteria operator="AND" comment="Architecture independent section">
              <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criterion comment="opensaml2 DPKG is earlier than 2.3-2+squeeze1" test_ref="oval:org.mitre.oval:tst:44247"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:12882" version="3" class="patch">
      <metadata>
        <title>DSA-2263-1 movabletype-opensource -- several</title>
        <affected family="unix">
          <platform>Debian 6.0</platform>
          <product>movabletype-opensource</product>
        </affected>
        <reference source="VENDOR" ref_url="http://lists.debian.org/debian-security-announce/2011/msg00133.html" ref_id="DSA-2263-1"/>
        <description>It was discovered that Movable Type, a weblog publishing system, contains several security vulnerabilities: A remote attacker could execute arbitrary code in a logged-in users" web browser. A remote attacker could read or modify the contents in the system under certain circumstances.</description>
        <oval_repository>
          <dates>
            <submitted date="2011-09-22T11:06:33-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2011-09-22T12:03:41.162-04:00">DRAFT</status_change>
            <status_change date="2011-10-10T04:00:36.172-04:00">INTERIM</status_change>
            <status_change date="2011-10-31T04:01:01.262-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Debian 6.0 is installed" definition_ref="oval:org.mitre.oval:def:12959"/>
        <criteria operator="OR" comment="Architecture section">
          <criteria operator="AND" comment="Architecture independent section">
            <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
            <criterion comment="movabletype-opensource DPKG is earlier than 4.3.5+dfsg-2+squeeze2" test_ref="oval:org.mitre.oval:tst:43758"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:12879" version="3" class="patch">
      <metadata>
        <title>DSA-2161-1 openjdk-6 -- denial of service</title>
        <affected family="unix">
          <platform>Debian 6.0</platform>
          <product>openjdk-6</product>
        </affected>
        <reference source="VENDOR" ref_url="http://lists.debian.org/debian-security-announce/2011/msg00026.html" ref_id="DSA-2161-1"/>
        <description>It was discovered that the floating point parser in OpenJDK, an implementation of the Java platform, can enter an infinite loop when processing certain input strings. Such input strings represent valid numbers and can be contained in data supplied by an attacker over the network, leading to a denial-of-service attack.</description>
        <oval_repository>
          <dates>
            <submitted date="2011-09-22T15:46:50-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2011-09-22T12:03:15.163-04:00">DRAFT</status_change>
            <status_change date="2011-10-10T04:00:35.666-04:00">INTERIM</status_change>
            <status_change date="2011-10-31T04:01:00.363-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Debian 6.0 is installed" definition_ref="oval:org.mitre.oval:def:12959"/>
        <criteria operator="OR" comment="Architecture section">
          <criteria operator="AND" comment="Architecture independent section">
            <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
            <criterion comment="openjdk-6 DPKG is earlier than 6b18-1.8.3-2+squeeze1" test_ref="oval:org.mitre.oval:tst:43938"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:12869" version="3" class="patch">
      <metadata>
        <title>DSA-2250-1 citadel -- denial of service</title>
        <affected family="unix">
          <platform>Debian 5.0</platform>
          <platform>Debian 6.0</platform>
          <product>citadel</product>
        </affected>
        <reference source="VENDOR" ref_url="http://lists.debian.org/debian-security-announce/2011/msg00120.html" ref_id="DSA-2250-1"/>
        <description>Wouter Coekaerts discovered that the jabber server component of citadel, a complete and feature-rich groupware server, is vulnerable to the so-called &amp;quot;billion laughs&amp;quot; attack because it does not prevent entity expansion on received data. This allows an attacker to perform denial of service attacks against the service by sending specially crafted XML data to it.</description>
        <oval_repository>
          <dates>
            <submitted date="2011-09-22T21:37:17-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2011-09-22T12:03:35.558-04:00">DRAFT</status_change>
            <status_change date="2011-10-10T04:00:34.370-04:00">INTERIM</status_change>
            <status_change date="2011-10-31T04:00:58.976-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Release section">
          <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
          <criteria operator="OR" comment="Architecture section">
            <criteria operator="AND" comment="Architecture independent section">
              <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criterion comment="citadel DPKG is earlier than 7.37-8+lenny1" test_ref="oval:org.mitre.oval:tst:43909"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Release section">
          <extend_definition comment="Debian 6.0 is installed" definition_ref="oval:org.mitre.oval:def:12959"/>
          <criteria operator="OR" comment="Architecture section">
            <criteria operator="AND" comment="Architecture independent section">
              <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criterion comment="citadel DPKG is earlier than 7.83-2squeeze2" test_ref="oval:org.mitre.oval:tst:44182"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:12867" version="3" class="patch">
      <metadata>
        <title>DSA-2235-1 icedove -- several</title>
        <affected family="unix">
          <platform>Debian 6.0</platform>
          <product>icedove</product>
        </affected>
        <reference source="VENDOR" ref_url="http://lists.debian.org/debian-security-announce/2011/msg00104.html" ref_id="DSA-2235-1"/>
        <description>Several vulnerabilities have been discovered in Icedove, an unbranded version of the Thunderbird mail/news client. CVE-2011-0069 CVE-2011-0070 CVE-2011-0072 CVE-2011-0074 CVE-2011-0075 CVE-2011-0077 CVE-2011-0078 CVE-2011-0080 CVE-2011-0081 &amp;quot;Scoobidiver&amp;quot;, Ian Beer Bob Clary, Henri Sivonen, Marco Bonardo, Mats Palmgren, Jesse Ruderman, Aki Kelin and Martin Barbella discovered memory corruption bugs, which may lead to the execution of arbitrary code. CVE-2011-0065 CVE-2011-0066 CVE-2011-0073 &amp;quot;regenrecht&amp;quot; discovered several dangling pointer vulnerabilities, which may lead to the execution of arbitrary code. CVE-2011-0067 Paul Stone discovered that Java applets could steal information from the autocompletion history. CVE-2011-0071 Soroush Dalili discovered a directory traversal vulnerability in handling resource URIs. As indicated in the Lenny  release notes, security support for the Icedove packages in the oldstable needed to be stopped before the end of the regular Lenny security maintenance life cycle. You are strongly encouraged to upgrade to stable or switch to a different mail client.</description>
        <oval_repository>
          <dates>
            <submitted date="2011-09-22T11:41:38-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2011-09-22T12:03:32.005-04:00">DRAFT</status_change>
            <status_change date="2011-10-10T04:00:34.147-04:00">INTERIM</status_change>
            <status_change date="2011-10-31T04:00:58.745-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Debian 6.0 is installed" definition_ref="oval:org.mitre.oval:def:12959"/>
        <criteria operator="OR" comment="Architecture section">
          <criteria operator="AND" comment="Architecture independent section">
            <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
            <criterion comment="icedove DPKG is earlier than 3.0.11-1+squeeze2" test_ref="oval:org.mitre.oval:tst:43403"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:12861" version="3" class="patch">
      <metadata>
        <title>DSA-2209-1 tgt -- double free</title>
        <affected family="unix">
          <platform>Debian 6.0</platform>
          <product>tgt</product>
        </affected>
        <reference source="VENDOR" ref_url="http://lists.debian.org/debian-security-announce/2011/msg00078.html" ref_id="DSA-2209-1"/>
        <description>Emmanuel Bouillon discovered a double free in tgt, the Linux SCSI target user-space tools, which could lead to denial of service. The oldstable distribution  doesn"t include tgt.</description>
        <oval_repository>
          <dates>
            <submitted date="2011-09-22T11:51:42-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2011-09-22T12:03:26.776-04:00">DRAFT</status_change>
            <status_change date="2011-10-10T04:00:33.516-04:00">INTERIM</status_change>
            <status_change date="2011-10-31T04:00:57.700-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Debian 6.0 is installed" definition_ref="oval:org.mitre.oval:def:12959"/>
        <criteria operator="OR" comment="Architecture section">
          <criteria operator="AND" comment="Architecture independent section">
            <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
            <criterion comment="tgt DPKG is earlier than 1:1.0.4-2squeeze1" test_ref="oval:org.mitre.oval:tst:44011"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:12859" version="3" class="patch">
      <metadata>
        <title>DSA-2203-1 nss -- none in nss</title>
        <affected family="unix">
          <platform>Debian 5.0</platform>
          <platform>Debian 6.0</platform>
          <product>nss</product>
        </affected>
        <reference source="VENDOR" ref_url="http://lists.debian.org/debian-security-announce/2011/msg00071.html" ref_id="DSA-2203-1"/>
        <description>This update for the Network Security Service libraries marks several fraudulent HTTPS certificates as unstrusted.</description>
        <oval_repository>
          <dates>
            <submitted date="2011-09-22T10:45:56-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2011-09-22T12:03:26.086-04:00">DRAFT</status_change>
            <status_change date="2011-10-10T04:00:33.126-04:00">INTERIM</status_change>
            <status_change date="2011-10-31T04:00:57.430-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Release section">
          <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
          <criteria operator="OR" comment="Architecture section">
            <criteria operator="AND" comment="Architecture independent section">
              <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criterion comment="nss DPKG is earlier than 3.12.3.1-0lenny4" test_ref="oval:org.mitre.oval:tst:43108"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Release section">
          <extend_definition comment="Debian 6.0 is installed" definition_ref="oval:org.mitre.oval:def:12959"/>
          <criteria operator="OR" comment="Architecture section">
            <criteria operator="AND" comment="Architecture independent section">
              <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criterion comment="nss DPKG is earlier than 3.12.8-1+squeeze1" test_ref="oval:org.mitre.oval:tst:43490"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:12857" version="3" class="patch">
      <metadata>
        <title>DSA-2186-1 iceweasel -- several</title>
        <affected family="unix">
          <platform>Debian 5.0</platform>
          <platform>Debian 6.0</platform>
          <product>iceweasel</product>
        </affected>
        <reference source="VENDOR" ref_url="http://lists.debian.org/debian-security-announce/2011/msg00053.html" ref_id="DSA-2186-1"/>
        <description>Several vulnerabilities have been discovered in Iceweasel, a web browser based on Firefox. The included XULRunner library provides rendering services for several other applications included in Debian. CVE-2010-1585 Roberto Suggi Liverani discovered that the sanitising performed by ParanoidFragmentSink was incomplete. CVE-2011-0053 Crashes in the layout engine may lead to the execution of arbitrary code. CVE-2011-0051 Zach Hoffmann discovered that incorrect parsing of recursive eval calls could lead to attackers forcing acceptance of a confirmation dialogue. CVE-2011-0054, CVE-2010-0056 Christian Holler discovered buffer overflows in the Javascript engine, which could allow the execution of arbitrary code. CVE-2011-0055 &amp;quot;regenrecht&amp;quot; and Igor Bukanov discovered a use-after-free error in the JSON-Implementation, which could lead to the execution of arbitrary code. CVE-2011-0057 Daniel Kozlowski discovered that incorrect memory handling the web workers implementation could lead to the execution of arbitrary code. CVE-2011-0059 Peleus Uhley discovered a cross-site request forgery risk in the plugin code.</description>
        <oval_repository>
          <dates>
            <submitted date="2011-09-22T09:03:22-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2011-09-22T12:03:22.641-04:00">DRAFT</status_change>
            <status_change date="2011-10-10T04:00:32.447-04:00">INTERIM</status_change>
            <status_change date="2011-10-31T04:00:56.872-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Release section">
          <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
          <criteria operator="OR" comment="Architecture section">
            <criteria operator="AND" comment="Architecture independent section">
              <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criterion comment="iceweasel DPKG is earlier than 1.9.0.19-8" test_ref="oval:org.mitre.oval:tst:44014"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Release section">
          <extend_definition comment="Debian 6.0 is installed" definition_ref="oval:org.mitre.oval:def:12959"/>
          <criteria operator="OR" comment="Architecture section">
            <criteria operator="AND" comment="Architecture independent section">
              <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criterion comment="iceweasel DPKG is earlier than 3.5.16-5" test_ref="oval:org.mitre.oval:tst:43650"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:12855" version="3" class="patch">
      <metadata>
        <title>DSA-2164-1 shadow -- insufficient input sanitization</title>
        <affected family="unix">
          <platform>Debian 6.0</platform>
          <product>shadow</product>
        </affected>
        <reference source="VENDOR" ref_url="http://lists.debian.org/debian-security-announce/2011/msg00030.html" ref_id="DSA-2164-1"/>
        <description>Kees Cook discovered that the chfn and chsh utilities do not properly sanitize user input that includes newlines. An attacker could use this to to corrupt passwd entries and may create users or groups in NIS environments. Packages in the oldstable distribution  are not affected by this problem.</description>
        <oval_repository>
          <dates>
            <submitted date="2011-09-22T16:44:09-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2011-09-22T12:03:16.792-04:00">DRAFT</status_change>
            <status_change date="2011-10-10T04:00:32.231-04:00">INTERIM</status_change>
            <status_change date="2011-10-31T04:00:56.637-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Debian 6.0 is installed" definition_ref="oval:org.mitre.oval:def:12959"/>
        <criteria operator="OR" comment="Architecture section">
          <criteria operator="AND" comment="Architecture independent section">
            <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
            <criterion comment="shadow DPKG is earlier than 1:4.1.4.2+svn3283-2+squeeze1" test_ref="oval:org.mitre.oval:tst:43951"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:12846" version="3" class="patch">
      <metadata>
        <title>DSA-2182-1 logwatch -- shell command injection</title>
        <affected family="unix">
          <platform>Debian 5.0</platform>
          <platform>Debian 6.0</platform>
          <product>logwatch</product>
        </affected>
        <reference source="VENDOR" ref_url="http://lists.debian.org/debian-security-announce/2011/msg00049.html" ref_id="DSA-2182-1"/>
        <description>Dominik George discovered that logwatch does not guard against shell meta-characters in crafted log file names . As a result, an attacker might be able to execute shell commands on the system running logwatch.</description>
        <oval_repository>
          <dates>
            <submitted date="2011-09-22T16:29:50-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2011-09-22T12:03:21.289-04:00">DRAFT</status_change>
            <status_change date="2011-10-10T04:00:31.883-04:00">INTERIM</status_change>
            <status_change date="2011-10-31T04:00:55.774-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Release section">
          <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
          <criteria operator="OR" comment="Architecture section">
            <criteria operator="AND" comment="Architecture independent section">
              <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criterion comment="logwatch DPKG is earlier than 7.3.6.cvs20080702-2lenny1" test_ref="oval:org.mitre.oval:tst:43638"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Release section">
          <extend_definition comment="Debian 6.0 is installed" definition_ref="oval:org.mitre.oval:def:12959"/>
          <criteria operator="OR" comment="Architecture section">
            <criteria operator="AND" comment="Architecture independent section">
              <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criterion comment="logwatch DPKG is earlier than 7.3.6.cvs20090906-1squeeze1" test_ref="oval:org.mitre.oval:tst:43381"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:12843" version="3" class="patch">
      <metadata>
        <title>DSA-2180-1 iceape -- several</title>
        <affected family="unix">
          <platform>Debian 6.0</platform>
          <product>iceape</product>
        </affected>
        <reference source="VENDOR" ref_url="http://lists.debian.org/debian-security-announce/2011/msg00047.html" ref_id="DSA-2180-1"/>
        <description>Several vulnerabilities have been found in the Iceape internet suite, an unbranded version of Seamonkey: CVE-2010-1585 Roberto Suggi Liverani discovered that the sanitising performed by ParanoidFragmentSink was incomplete. CVE-2011-0051 Zach Hoffmann discovered that incorrect parsing of recursive eval calls could lead to attackers forcing acceptance of a confirmation dialogue. CVE-2011-0053 Crashes in the layout engine may lead to the execution of arbitrary code. CVE-2011-0054 Christian Holler discovered buffer overflows in the Javascript engine, which could allow the execution of arbitrary code. CVE-2010-0056 Christian Holler discovered buffer overflows in the Javascript engine, which could allow the execution of arbitrary code. CVE-2011-0055 &amp;quot;regenrecht&amp;quot; and Igor Bukanov discovered a use-after-free error in the JSON-Implementation, which could lead to the execution of arbitrary code. CVE-2011-0057 Daniel Kozlowski discovered that incorrect memory handling the web workers implementation could lead to the execution of arbitrary code. CVE-2011-0059 Peleus Uhley discovered a cross-site request forgery risk in the plugin code. The oldstable distribution  is not affected. The iceape package only provides the XPCOM code.</description>
        <oval_repository>
          <dates>
            <submitted date="2011-09-22T16:09:31-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2011-09-22T12:03:20.988-04:00">DRAFT</status_change>
            <status_change date="2011-10-10T04:00:31.450-04:00">INTERIM</status_change>
            <status_change date="2011-10-31T04:00:55.319-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Debian 6.0 is installed" definition_ref="oval:org.mitre.oval:def:12959"/>
        <criteria operator="OR" comment="Architecture section">
          <criteria operator="AND" comment="Architecture independent section">
            <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
            <criterion comment="iceape DPKG is earlier than 2.0.11-3" test_ref="oval:org.mitre.oval:tst:43841"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:12839" version="3" class="patch">
      <metadata>
        <title>DSA-2254-2 oprofile -- command injection</title>
        <affected family="unix">
          <platform>Debian 5.0</platform>
          <platform>Debian 6.0</platform>
          <product>oprofile</product>
        </affected>
        <reference source="VENDOR" ref_url="http://lists.debian.org/debian-security-announce/2011/msg00151.html" ref_id="DSA-2254-2"/>
        <description>Jamie Strandboge noticed that the patch propoused to fix CVE-2011-1760 in OProfile has been incomplete. For reference, the description of the original DSA, is: OProfile is a performance profiling tool which is configurable by opcontrol, its control utility. Stephane Chauveau reported several ways to inject arbitrary commands in the arguments of this utility. If a local unprivileged user is authorized by sudoers file to run opcontrol as root, this user could use the flaw to escalate his privileges.</description>
        <oval_repository>
          <dates>
            <submitted date="2011-09-22T14:51:33-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2011-09-22T12:03:46.209-04:00">DRAFT</status_change>
            <status_change date="2011-10-10T04:00:31.192-04:00">INTERIM</status_change>
            <status_change date="2011-10-31T04:00:54.667-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Release section">
          <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
          <criteria operator="OR" comment="Architecture section">
            <criteria operator="AND" comment="Architecture independent section">
              <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criterion comment="oprofile DPKG is earlier than 0.9.3-2+lenny2" test_ref="oval:org.mitre.oval:tst:44102"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Release section">
          <extend_definition comment="Debian 6.0 is installed" definition_ref="oval:org.mitre.oval:def:12959"/>
          <criteria operator="OR" comment="Architecture section">
            <criteria operator="AND" comment="Architecture independent section">
              <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criterion comment="oprofile DPKG is earlier than 0.9.6-1.1+squeeze2" test_ref="oval:org.mitre.oval:tst:43621"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:12831" version="3" class="patch">
      <metadata>
        <title>DSA-2220-1 request-tracker3.6, request-tracker3.8 -- several</title>
        <affected family="unix">
          <platform>Debian 5.0</platform>
          <platform>Debian 6.0</platform>
          <product>request-tracker3.6, request-tracker3.8</product>
        </affected>
        <reference source="VENDOR" ref_url="http://lists.debian.org/debian-security-announce/2011/msg00089.html" ref_id="DSA-2220-1"/>
        <description>Several vulnerabilities were in Request Tracker, an issue tracking system. CVE-2011-1685 If the external custom field feature is enabled, Request Tracker allows authenticated users to execute arbitrary code with the permissions of the web server, possible triggered by a cross-site request forgery attack.  CVE-2011-1686 Multiple SQL injection attacks allow authenticated users to obtain data from the database in an unauthorized way. CVE-2011-1687 An information leak allows an authenticated privileged user to obtain sensitive information, such as encrypted passwords, via the search interface. CVE-2011-1688 When running under certain web servers , Request Tracker is vulnerable to a directory traversal attack, allowing attackers to read any files accessible to the web server. Request Tracker instances running under Apache or Nginx are not affected. CVE-2011-1689 Request Tracker contains multiple cross-site scripting vulnerabilities. CVE-2011-1690 Request Tracker enables attackers to redirect authentication credentials supplied by legitimate users to third-party servers.</description>
        <oval_repository>
          <dates>
            <submitted date="2011-09-22T21:13:05-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2011-09-22T12:03:37.644-04:00">DRAFT</status_change>
            <status_change date="2011-10-10T04:00:29.825-04:00">INTERIM</status_change>
            <status_change date="2011-10-31T04:00:53.317-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Release section">
          <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
          <criteria operator="OR" comment="Architecture section">
            <criteria operator="AND" comment="Architecture independent section">
              <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criterion comment="request-tracker3.6, request-tracker3.8 DPKG is earlier than 3.6.7-5+lenny6" test_ref="oval:org.mitre.oval:tst:44125"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Release section">
          <extend_definition comment="Debian 6.0 is installed" definition_ref="oval:org.mitre.oval:def:12959"/>
          <criteria operator="OR" comment="Architecture section">
            <criteria operator="AND" comment="Architecture independent section">
              <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criterion comment="request-tracker3.6, request-tracker3.8 DPKG is earlier than 3.8.8-7+squeeze1" test_ref="oval:org.mitre.oval:tst:43862"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:12828" version="3" class="patch">
      <metadata>
        <title>DSA-2283-1 krb5-appl -- programming error</title>
        <affected family="unix">
          <platform>Debian 6.0</platform>
          <product>krb5-appl</product>
        </affected>
        <reference source="VENDOR" ref_url="http://lists.debian.org/debian-security-announce/2011/msg00157.html" ref_id="DSA-2283-1"/>
        <description>Tim Zingelmann discovered that due an incorrect configure script the kerborised FTP server failed to set the effective GID correctly, resulting in privilege escalation. The oldstable distribution  is not affected.</description>
        <oval_repository>
          <dates>
            <submitted date="2011-09-22T19:14:16-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2011-09-22T12:03:47.321-04:00">DRAFT</status_change>
            <status_change date="2011-10-10T04:00:29.590-04:00">INTERIM</status_change>
            <status_change date="2011-10-31T04:00:52.794-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Debian 6.0 is installed" definition_ref="oval:org.mitre.oval:def:12959"/>
        <criteria operator="OR" comment="Architecture section">
          <criteria operator="AND" comment="Architecture independent section">
            <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
            <criterion comment="krb5-appl DPKG is earlier than 1.0.1-1.1" test_ref="oval:org.mitre.oval:tst:43792"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:12826" version="3" class="patch">
      <metadata>
        <title>DSA-2205-1 gdm3 -- privilege escalation</title>
        <affected family="unix">
          <platform>Debian 6.0</platform>
          <product>gdm3</product>
        </affected>
        <reference source="VENDOR" ref_url="http://lists.debian.org/debian-security-announce/2011/msg00073.html" ref_id="DSA-2205-1"/>
        <description>Sebastian Krahmer discovered that the gdm3, the GNOME Desktop Manager, does not properly drop privileges when manipulating files related to the logged-in user. As a result, local users can gain root privileges. The oldstable distribution  does not contain a gdm3 package. The gdm package is not affected by this issue.</description>
        <oval_repository>
          <dates>
            <submitted date="2011-09-22T10:43:43-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2011-09-22T12:03:25.791-04:00">DRAFT</status_change>
            <status_change date="2011-10-10T04:00:29.336-04:00">INTERIM</status_change>
            <status_change date="2011-10-31T04:00:52.571-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Debian 6.0 is installed" definition_ref="oval:org.mitre.oval:def:12959"/>
        <criteria operator="OR" comment="Architecture section">
          <criteria operator="AND" comment="Architecture independent section">
            <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
            <criterion comment="gdm3 DPKG is earlier than 2.30.5-6squeeze2" test_ref="oval:org.mitre.oval:tst:43587"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:12821" version="3" class="patch">
      <metadata>
        <title>DSA-2192-1 chromium-browser -- several</title>
        <affected family="unix">
          <platform>Debian 6.0</platform>
          <product>chromium-browser</product>
        </affected>
        <reference source="VENDOR" ref_url="http://lists.debian.org/debian-security-announce/2011/msg00059.html" ref_id="DSA-2192-1"/>
        <description>Several vulnerabilities were discovered in the Chromium browser. The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2011-0779 Google Chrome before 9.0.597.84 does not properly handle a missing key in an extension, which allows remote attackers to cause a denial of service  via a crafted extension. CVE-2011-1290 Integer overflow in WebKit allows remote attackers to execute arbitrary code via unknown vectors, as demonstrated by Vincenzo Iozzo, Willem Pinckaers, and Ralf-Philipp Weinmann during a Pwn2Own competition at CanSecWest 2011.</description>
        <oval_repository>
          <dates>
            <submitted date="2011-09-22T21:41:08-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2011-09-22T12:03:24.726-04:00">DRAFT</status_change>
            <status_change date="2011-10-10T04:00:28.838-04:00">INTERIM</status_change>
            <status_change date="2011-10-31T04:00:52.134-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Debian 6.0 is installed" definition_ref="oval:org.mitre.oval:def:12959"/>
        <criteria operator="OR" comment="Architecture section">
          <criteria operator="AND" comment="Architecture independent section">
            <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
            <criterion comment="chromium-browser DPKG is earlier than 6.0.472.63~r59945-5+squeeze4" test_ref="oval:org.mitre.oval:tst:43533"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:12818" version="3" class="patch">
      <metadata>
        <title>DSA-2256-1 tiff -- buffer overflow</title>
        <affected family="unix">
          <platform>Debian 6.0</platform>
          <product>tiff</product>
        </affected>
        <reference source="VENDOR" ref_url="http://lists.debian.org/debian-security-announce/2011/msg00126.html" ref_id="DSA-2256-1"/>
        <description>Tavis Ormandy discovered that the Tag Image File Format  library is vulnerable to a buffer overflow triggered by a crafted OJPEG file which allows for a crash and potentially execution of arbitrary code. The oldstable distribution  is not affected by this problem.</description>
        <oval_repository>
          <dates>
            <submitted date="2011-09-22T13:03:40-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2011-09-22T12:03:39.964-04:00">DRAFT</status_change>
            <status_change date="2011-10-10T04:00:28.393-04:00">INTERIM</status_change>
            <status_change date="2011-10-31T04:00:51.672-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Debian 6.0 is installed" definition_ref="oval:org.mitre.oval:def:12959"/>
        <criteria operator="OR" comment="Architecture section">
          <criteria operator="AND" comment="Architecture independent section">
            <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
            <criterion comment="tiff DPKG is earlier than 3.9.4-5+squeeze2" test_ref="oval:org.mitre.oval:tst:43616"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:12816" version="3" class="patch">
      <metadata>
        <title>DSA-2278-1 horde3 -- several</title>
        <affected family="unix">
          <platform>Debian 5.0</platform>
          <platform>Debian 6.0</platform>
          <product>horde3</product>
        </affected>
        <reference source="VENDOR" ref_url="http://lists.debian.org/debian-security-announce/2011/msg00152.html" ref_id="DSA-2278-1"/>
        <description>It was discovered that horde3, the horde web application framework, is prone to a cross-site scripting attack and a cross-site request forgery.</description>
        <oval_repository>
          <dates>
            <submitted date="2011-09-22T15:05:58-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2011-09-22T12:03:46.823-04:00">DRAFT</status_change>
            <status_change date="2011-10-10T04:00:28.129-04:00">INTERIM</status_change>
            <status_change date="2011-10-31T04:00:51.401-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Release section">
          <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
          <criteria operator="OR" comment="Architecture section">
            <criteria operator="AND" comment="Architecture independent section">
              <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criterion comment="horde3 DPKG is earlier than 3.2.2+debian0-2+lenny3" test_ref="oval:org.mitre.oval:tst:44069"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Release section">
          <extend_definition comment="Debian 6.0 is installed" definition_ref="oval:org.mitre.oval:def:12959"/>
          <criteria operator="OR" comment="Architecture section">
            <criteria operator="AND" comment="Architecture independent section">
              <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criterion comment="horde3 DPKG is earlier than 3.3.8+debian0-2" test_ref="oval:org.mitre.oval:tst:44172"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:12814" version="3" class="patch">
      <metadata>
        <title>DSA-2185-1 proftpd-dfsg -- integer overflow</title>
        <affected family="unix">
          <platform>Debian 6.0</platform>
          <product>proftpd-dfsg</product>
        </affected>
        <reference source="VENDOR" ref_url="http://lists.debian.org/debian-security-announce/2011/msg00052.html" ref_id="DSA-2185-1"/>
        <description>It was discovered that an integer overflow in the SFTP file transfer module of the ProFTPD daemon could lead to denial of service. The oldstable distribution  is not affected.</description>
        <oval_repository>
          <dates>
            <submitted date="2011-09-22T21:24:01-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2011-09-22T12:03:22.142-04:00">DRAFT</status_change>
            <status_change date="2011-10-10T04:00:27.858-04:00">INTERIM</status_change>
            <status_change date="2011-10-31T04:00:51.172-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Debian 6.0 is installed" definition_ref="oval:org.mitre.oval:def:12959"/>
        <criteria operator="OR" comment="Architecture section">
          <criteria operator="AND" comment="Architecture independent section">
            <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
            <criterion comment="proftpd-dfsg DPKG is earlier than 1.3.3a-6squeeze1" test_ref="oval:org.mitre.oval:tst:43929"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:12808" version="3" class="patch">
      <metadata>
        <title>DSA-2195-1 php5 -- several</title>
        <affected family="unix">
          <platform>Debian 5.0</platform>
          <platform>Debian 6.0</platform>
          <product>php5</product>
        </affected>
        <reference source="VENDOR" ref_url="http://lists.debian.org/debian-security-announce/2011/msg00063.html" ref_id="DSA-2195-1"/>
        <description>Stephane Chazelas discovered that the cronjob of the PHP 5 package in Debian suffers from a race condition which might be used to remove arbitrary files from a system . When upgrading your php5-common package take special care to _accept_ the changes to the /etc/cron.d/php5 file. Ignoring them would leave the system vulnerable.</description>
        <oval_repository>
          <dates>
            <submitted date="2011-09-22T20:47:57-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2011-09-22T12:03:24.066-04:00">DRAFT</status_change>
            <status_change date="2011-10-10T04:00:27.589-04:00">INTERIM</status_change>
            <status_change date="2011-10-31T04:00:50.849-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Release section">
          <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
          <criteria operator="OR" comment="Architecture section">
            <criteria operator="AND" comment="Architecture independent section">
              <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criterion comment="php5 DPKG is earlier than 5.2.6.dfsg.1-1+lenny10" test_ref="oval:org.mitre.oval:tst:43754"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Release section">
          <extend_definition comment="Debian 6.0 is installed" definition_ref="oval:org.mitre.oval:def:12959"/>
          <criteria operator="OR" comment="Architecture section">
            <criteria operator="AND" comment="Architecture independent section">
              <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criterion comment="php5 DPKG is earlier than 5.3.3-7+squeeze1" test_ref="oval:org.mitre.oval:tst:43817"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:12805" version="3" class="patch">
      <metadata>
        <title>DSA-2236-1 exim4 -- command injection</title>
        <affected family="unix">
          <platform>Debian 6.0</platform>
          <product>exim4</product>
        </affected>
        <reference source="VENDOR" ref_url="http://lists.debian.org/debian-security-announce/2011/msg00105.html" ref_id="DSA-2236-1"/>
        <description>It was discovered that Exim, Debian"s default mail transfer agent, is vulnerable to command injection attacks in its DKIM processing code, leading to arbitrary code execution.  The default configuration supplied by Debian does not expose this vulnerability. The oldstable distribution  is not affected by this problem.</description>
        <oval_repository>
          <dates>
            <submitted date="2011-09-22T21:26:02-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2011-09-22T12:03:32.799-04:00">DRAFT</status_change>
            <status_change date="2011-10-10T04:00:27.361-04:00">INTERIM</status_change>
            <status_change date="2011-10-31T04:00:50.570-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Debian 6.0 is installed" definition_ref="oval:org.mitre.oval:def:12959"/>
        <criteria operator="OR" comment="Architecture section">
          <criteria operator="AND" comment="Architecture independent section">
            <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
            <criterion comment="exim4 DPKG is earlier than 4.72-6+squeeze2" test_ref="oval:org.mitre.oval:tst:43944"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:12793" version="3" class="patch">
      <metadata>
        <title>DSA-2189-1 chromium-browser -- several</title>
        <affected family="unix">
          <platform>Debian 6.0</platform>
          <product>chromium-browser</product>
        </affected>
        <reference source="VENDOR" ref_url="http://lists.debian.org/debian-security-announce/2011/msg00056.html" ref_id="DSA-2189-1"/>
        <description><![CDATA[Several vulnerabilities were discovered in the Chromium browser. The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2011-1108 Google Chrome before 9.0.597.107 does not properly implement JavaScript dialogs, which allows remote attackers to cause a denial of service  or possibly have unspecified other impact via a crafted HTML document. CVE-2011-1109 Google Chrome before 9.0.597.107 does not properly process nodes in Cascading Style Sheets  stylesheets, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors that lead to a &quot;stale pointer.&quot; CVE-2011-1113 Google Chrome before 9.0.597.107 on 64-bit Linux platforms does not properly perform pickle deserialization, which allows remote attackers to cause a denial of service  via unspecified vectors. CVE-2011-1114 Google Chrome before 9.0.597.107 does not properly handle tables, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors that lead to a &quot;stale node.&quot; CVE-2011-1115 Google Chrome before 9.0.597.107 does not properly render tables, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors that lead to a &quot;stale pointer.&quot; CVE-2011-1121 Integer overflow in Google Chrome before 9.0.597.107 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors involving a TEXTAREA element. CVE-2011-1122 The WebGL implementation in Google Chrome before 9.0.597.107 allows remote attackers to cause a denial of service  via unspecified vectors, aka Issue 71960. In addition, this upload fixes the following issues : Out-of-bounds read in text searching [69640] Memory corruption in SVG fonts. [72134] Memory corruption with counter nodes. [69628] Stale node in box layout. [70027] Cross-origin error message leak with workers. [70336] Stale pointer in table painting. [72028] Stale pointer with SVG cursors. [73746]]]></description>
        <oval_repository>
          <dates>
            <submitted date="2011-09-22T22:10:48-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2011-09-22T12:03:23.139-04:00">DRAFT</status_change>
            <status_change date="2011-10-10T04:00:26.821-04:00">INTERIM</status_change>
            <status_change date="2011-10-31T04:00:49.765-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Debian 6.0 is installed" definition_ref="oval:org.mitre.oval:def:12959"/>
        <criteria operator="OR" comment="Architecture section">
          <criteria operator="AND" comment="Architecture independent section">
            <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
            <criterion comment="chromium-browser DPKG is earlier than 6.0.472.63~r59945-5+squeeze3" test_ref="oval:org.mitre.oval:tst:43189"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:12791" version="3" class="patch">
      <metadata>
        <title>DSA-2244-1 bind9 -- incorrect boundary condition</title>
        <affected family="unix">
          <platform>Debian 5.0</platform>
          <platform>Debian 6.0</platform>
          <product>bind9</product>
        </affected>
        <reference source="VENDOR" ref_url="http://lists.debian.org/debian-security-announce/2011/msg00114.html" ref_id="DSA-2244-1"/>
        <description>It was discovered that BIND, an implementation of the DNS protocol, does not correctly process certain large RRSIG record sets in DNSSEC responses. The resulting assertion failure causes the name server process to crash, making name resolution unavailable.  In addition, this update fixes handling of certain signed/unsigned zone combinations when a DLV service is used. Previously, data from certain affected zones could become unavailable from the resolver.</description>
        <oval_repository>
          <dates>
            <submitted date="2011-09-22T12:40:23-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2011-09-22T12:03:34.975-04:00">DRAFT</status_change>
            <status_change date="2011-10-10T04:00:26.557-04:00">INTERIM</status_change>
            <status_change date="2011-10-31T04:00:49.520-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Release section">
          <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
          <criteria operator="OR" comment="Architecture section">
            <criteria operator="AND" comment="Architecture independent section">
              <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criterion comment="bind9 DPKG is earlier than 1:9.6.ESV.R4+dfsg-0+lenny2" test_ref="oval:org.mitre.oval:tst:44063"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Release section">
          <extend_definition comment="Debian 6.0 is installed" definition_ref="oval:org.mitre.oval:def:12959"/>
          <criteria operator="OR" comment="Architecture section">
            <criteria operator="AND" comment="Architecture independent section">
              <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criterion comment="bind9 DPKG is earlier than 1:9.7.3.dfsg-1~squeeze2" test_ref="oval:org.mitre.oval:tst:43217"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:12781" version="3" class="patch">
      <metadata>
        <title>DSA-2269-1 iceape -- several</title>
        <affected family="unix">
          <platform>Debian 6.0</platform>
          <product>iceape</product>
        </affected>
        <reference source="VENDOR" ref_url="http://lists.debian.org/debian-security-announce/2011/msg00141.html" ref_id="DSA-2269-1"/>
        <description>Several vulnerabilities have been found in the Iceape internet suite, an unbranded version of Seamonkey: CVE-2011-0083 / CVE-2011-2363 &amp;quot;regenrecht&amp;quot; discovered two use-after-frees in SVG processing, which could lead to the execution of arbitrary code. CVE-2011-0085 &amp;quot;regenrecht&amp;quot; discovered a use-after-free in XUL processing, which could lead to the execution of arbitrary code. CVE-2011-2362 David Chan discovered that cookies were insufficiently isolated. CVE-2011-2371 Chris Rohlf and Yan Ivnitskiy discovered an integer overflow in the Javascript engine, which could lead to the execution of arbitrary code. CVE-2011-2373 Martin Barbella discovered a use-after-free in XUL processing, which could lead to the execution of arbitrary code. CVE-2011-2374 Bob Clary, Kevin Brosnan, Nils, Gary Kwong, Jesse Ruderman and Christian Biesinger discovered memory corruption bugs, which may lead to the execution of arbitrary code. CVE-2011-2376 Luke Wagner and Gary Kwong discovered memory corruption bugs, which may lead to the execution of arbitrary code. The oldstable distribution  is not affected. The iceape package only provides the XPCOM code.</description>
        <oval_repository>
          <dates>
            <submitted date="2011-09-22T14:18:16-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2011-09-22T12:03:43.463-04:00">DRAFT</status_change>
            <status_change date="2011-10-10T04:00:25.661-04:00">INTERIM</status_change>
            <status_change date="2011-10-31T04:00:47.428-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Debian 6.0 is installed" definition_ref="oval:org.mitre.oval:def:12959"/>
        <criteria operator="OR" comment="Architecture section">
          <criteria operator="AND" comment="Architecture independent section">
            <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
            <criterion comment="iceape DPKG is earlier than 2.0.11-6" test_ref="oval:org.mitre.oval:tst:44039"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:12776" version="3" class="patch">
      <metadata>
        <title>DSA-2231-1 otrs2 -- cross-site scripting</title>
        <affected family="unix">
          <platform>Debian 6.0</platform>
          <product>otrs2</product>
        </affected>
        <reference source="VENDOR" ref_url="http://lists.debian.org/debian-security-announce/2011/msg00100.html" ref_id="DSA-2231-1"/>
        <description>Multiple cross-site scripting vulnerabilities were discovered in Open Ticket Request System , a trouble-ticket system.  In addition, this security update a failure when upgrading the package from lenny to squeeze. The oldstable distribution  is not affected by this problem.</description>
        <oval_repository>
          <dates>
            <submitted date="2011-09-22T14:16:13-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2011-09-22T12:03:31.591-04:00">DRAFT</status_change>
            <status_change date="2011-10-10T04:00:25.247-04:00">INTERIM</status_change>
            <status_change date="2011-10-31T04:00:45.789-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Debian 6.0 is installed" definition_ref="oval:org.mitre.oval:def:12959"/>
        <criteria operator="OR" comment="Architecture section">
          <criteria operator="AND" comment="Architecture independent section">
            <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
            <criterion comment="otrs2 DPKG is earlier than 2.4.9+dfsg1-3+squeeze1" test_ref="oval:org.mitre.oval:tst:43873"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:12775" version="3" class="patch">
      <metadata>
        <title>DSA-2223-1 doctrine -- SQL injection</title>
        <affected family="unix">
          <platform>Debian 6.0</platform>
          <product>doctrine</product>
        </affected>
        <reference source="VENDOR" ref_url="http://lists.debian.org/debian-security-announce/2011/msg00092.html" ref_id="DSA-2223-1"/>
        <description>It was discovered that Doctrine, a PHP library for implementing object persistence, contains SQL injection vulnerabilities.  The exact impact depends on the application which uses the Doctrine library.</description>
        <oval_repository>
          <dates>
            <submitted date="2011-09-22T17:17:13-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2011-09-22T12:03:29.176-04:00">DRAFT</status_change>
            <status_change date="2011-10-10T04:00:24.966-04:00">INTERIM</status_change>
            <status_change date="2011-10-31T04:00:45.561-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Debian 6.0 is installed" definition_ref="oval:org.mitre.oval:def:12959"/>
        <criteria operator="OR" comment="Architecture section">
          <criteria operator="AND" comment="Architecture independent section">
            <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
            <criterion comment="doctrine DPKG is earlier than 1.2.2-2+squeeze1" test_ref="oval:org.mitre.oval:tst:43946"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:12760" version="3" class="patch">
      <metadata>
        <title>DSA-2168-1 openafs -- several</title>
        <affected family="unix">
          <platform>Debian 5.0</platform>
          <platform>Debian 6.0</platform>
          <product>openafs</product>
        </affected>
        <reference source="VENDOR" ref_url="http://lists.debian.org/debian-security-announce/2011/msg00034.html" ref_id="DSA-2168-1"/>
        <description>Two vulnerabilities were discovered the distributed filesystem AFS: CVE-2011-0430 Andrew Deason discovered that a double free in the Rx server process could lead to denial of service or the execution of arbitrary code. CVE-2011-0431 It was discovered that insufficient error handling in the kernel module could lead to denial of service.</description>
        <oval_repository>
          <dates>
            <submitted date="2011-09-22T15:51:01-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2011-09-22T12:03:15.434-04:00">DRAFT</status_change>
            <status_change date="2011-10-10T04:00:24.510-04:00">INTERIM</status_change>
            <status_change date="2011-10-31T04:00:43.923-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Release section">
          <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
          <criteria operator="OR" comment="Architecture section">
            <criteria operator="AND" comment="Architecture independent section">
              <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criterion comment="openafs DPKG is earlier than 1.4.7.dfsg1-6+lenny4" test_ref="oval:org.mitre.oval:tst:43681"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Release section">
          <extend_definition comment="Debian 6.0 is installed" definition_ref="oval:org.mitre.oval:def:12959"/>
          <criteria operator="OR" comment="Architecture section">
            <criteria operator="AND" comment="Architecture independent section">
              <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criterion comment="openafs DPKG is earlier than 1.4.12.1+dfsg-4" test_ref="oval:org.mitre.oval:tst:43979"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:12757" version="3" class="patch">
      <metadata>
        <title>DSA-2257-1 kolab-cyrus-imapd -- implementation error</title>
        <affected family="unix">
          <platform>Debian 5.0</platform>
          <platform>Debian 6.0</platform>
          <product>kolab-cyrus-imapd</product>
        </affected>
        <reference source="VENDOR" ref_url="http://lists.debian.org/debian-security-announce/2011/msg00128.html" ref_id="DSA-2257-1"/>
        <description>It was discovered that the STARTTLS implementation of the Kolab Cyrus IMAP server does not properly restrict I/O buffering, which allows man-in-the-middle attackers to insert commands into encrypted IMAP, LMTP, NNTP and POP3 sessions by sending a cleartext command that is processed after TLS is in place.</description>
        <oval_repository>
          <dates>
            <submitted date="2011-09-22T13:19:19-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2011-09-22T12:03:40.250-04:00">DRAFT</status_change>
            <status_change date="2011-10-10T04:00:24.244-04:00">INTERIM</status_change>
            <status_change date="2011-10-31T04:00:43.495-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Release section">
          <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
          <criteria operator="OR" comment="Architecture section">
            <criteria operator="AND" comment="Architecture independent section">
              <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criterion comment="kolab-cyrus-imapd DPKG is earlier than 2.2.13-5+lenny3" test_ref="oval:org.mitre.oval:tst:43429"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Release section">
          <extend_definition comment="Debian 6.0 is installed" definition_ref="oval:org.mitre.oval:def:12959"/>
          <criteria operator="OR" comment="Architecture section">
            <criteria operator="AND" comment="Architecture independent section">
              <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criterion comment="kolab-cyrus-imapd DPKG is earlier than 2.2.13-9.1" test_ref="oval:org.mitre.oval:tst:43559"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:12752" version="3" class="patch">
      <metadata>
        <title>DSA-2219-1 xmlsec1 -- arbitrary file overwrite</title>
        <affected family="unix">
          <platform>Debian 5.0</platform>
          <platform>Debian 6.0</platform>
          <product>xmlsec1</product>
        </affected>
        <reference source="VENDOR" ref_url="http://lists.debian.org/debian-security-announce/2011/msg00088.html" ref_id="DSA-2219-1"/>
        <description>Nicolas Gregoire discovered that the XML Security Library xmlsec allowed remote attackers to create or overwrite arbitrary files through specially crafted XML files using the libxslt output extension and a ds:Transform element during signature verification.</description>
        <oval_repository>
          <dates>
            <submitted date="2011-09-22T17:19:43-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2011-09-22T12:03:29.459-04:00">DRAFT</status_change>
            <status_change date="2011-10-10T04:00:23.768-04:00">INTERIM</status_change>
            <status_change date="2011-10-31T04:00:42.997-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Release section">
          <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
          <criteria operator="OR" comment="Architecture section">
            <criteria operator="AND" comment="Architecture independent section">
              <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criterion comment="xmlsec1 DPKG is earlier than 1.2.9-5+lenny1" test_ref="oval:org.mitre.oval:tst:44073"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Release section">
          <extend_definition comment="Debian 6.0 is installed" definition_ref="oval:org.mitre.oval:def:12959"/>
          <criteria operator="OR" comment="Architecture section">
            <criteria operator="AND" comment="Architecture independent section">
              <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criterion comment="xmlsec1 DPKG is earlier than 1.2.14-1+squeeze1" test_ref="oval:org.mitre.oval:tst:44135"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:12744" version="3" class="patch">
      <metadata>
        <title>DSA-2286-1 phpymadmin -- several</title>
        <affected family="unix">
          <platform>Debian 6.0</platform>
          <product>phpymadmin</product>
        </affected>
        <reference source="VENDOR" ref_url="http://lists.debian.org/debian-security-announce/2011/msg00160.html" ref_id="DSA-2286-1"/>
        <description>Several vulnerabilities were discovered in phpMyAdmin, a tool to administrate MySQL over the web. The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2011-2505 Possible session manipulation in Swekey authentication. CVE-2011-2506 Possible code injection in setup script, in case session variables are compromised. CVE-2011-2507 Regular expression quoting issue in Synchronize code. CVE-2011-2508 Possible directory traversal in MIME-type transformation. CVE-2011-2642 Cross site scripting in table Print view when the attacker can create crafted table names. No CVE name yet Possible superglobal and local variables manipulation in Swekey authentication.  The oldstable distribution  is only affected by CVE-2011-2642, which has been fixed in version 2.11.8.1-5+lenny9.</description>
        <oval_repository>
          <dates>
            <submitted date="2011-09-22T19:21:42-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2011-09-22T12:03:47.531-04:00">DRAFT</status_change>
            <status_change date="2011-10-10T04:00:23.554-04:00">INTERIM</status_change>
            <status_change date="2011-10-31T04:00:41.927-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Debian 6.0 is installed" definition_ref="oval:org.mitre.oval:def:12959"/>
        <criteria operator="OR" comment="Architecture section">
          <criteria operator="AND" comment="Architecture independent section">
            <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
            <criterion comment="phpymadmin DPKG is earlier than 3.3.7-6" test_ref="oval:org.mitre.oval:tst:44198"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:12735" version="3" class="patch">
      <metadata>
        <title>DSA-2259-1 fex -- authentication bypass</title>
        <affected family="unix">
          <platform>Debian 6.0</platform>
          <product>fex</product>
        </affected>
        <reference source="VENDOR" ref_url="http://lists.debian.org/debian-security-announce/2011/msg00129.html" ref_id="DSA-2259-1"/>
        <description>It was discovered that fex, a web service for transferring very large, files, is not properly validating authentication IDs. While the service properly validates existing authentication IDs, an attacker who is not specifying any authentication ID at all, can bypass the authentication procedure. The oldstable distribution  does not include fex.</description>
        <oval_repository>
          <dates>
            <submitted date="2011-09-22T13:26:25-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2011-09-22T12:03:40.496-04:00">DRAFT</status_change>
            <status_change date="2011-10-10T04:00:23.115-04:00">INTERIM</status_change>
            <status_change date="2011-10-31T04:00:41.505-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Debian 6.0 is installed" definition_ref="oval:org.mitre.oval:def:12959"/>
        <criteria operator="OR" comment="Architecture section">
          <criteria operator="AND" comment="Architecture independent section">
            <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
            <criterion comment="fex DPKG is earlier than 20100208+debian1-1+squeeze1" test_ref="oval:org.mitre.oval:tst:43924"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:12728" version="3" class="patch">
      <metadata>
        <title>DSA-2212-1 tmux -- privilege escalation</title>
        <affected family="unix">
          <platform>Debian 6.0</platform>
          <product>tmux</product>
        </affected>
        <reference source="VENDOR" ref_url="http://lists.debian.org/debian-security-announce/2011/msg00081.html" ref_id="DSA-2212-1"/>
        <description>Daniel Danner discovered that tmux, a terminal multiplexer, is not properly dropping group privileges. Due to a patch introduced by Debian, when invoked with the -S option, tmux is not dropping permissions obtained through its setgid installation. The oldstable distribution  is not affected by this problem, it does not include tmux.</description>
        <oval_repository>
          <dates>
            <submitted date="2011-09-22T12:03:55-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2011-09-22T12:03:27.774-04:00">DRAFT</status_change>
            <status_change date="2011-10-10T04:00:22.508-04:00">INTERIM</status_change>
            <status_change date="2011-10-31T04:00:41.063-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Debian 6.0 is installed" definition_ref="oval:org.mitre.oval:def:12959"/>
        <criteria operator="OR" comment="Architecture section">
          <criteria operator="AND" comment="Architecture independent section">
            <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
            <criterion comment="tmux DPKG is earlier than 1.3-2+squeeze1" test_ref="oval:org.mitre.oval:tst:44077"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:12718" version="3" class="patch">
      <metadata>
        <title>DSA-2159-1 vlc -- missing input sanitising</title>
        <affected family="unix">
          <platform>Debian 6.0</platform>
          <product>vlc</product>
        </affected>
        <reference source="VENDOR" ref_url="http://lists.debian.org/debian-security-announce/2011/msg00024.html" ref_id="DSA-2159-1"/>
        <description>Dan Rosenberg discovered that insufficient input validation in VLC"s processing of Matroska/WebM containers could lead to the execution of arbitrary code.</description>
        <oval_repository>
          <dates>
            <submitted date="2011-09-22T16:40:06-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2011-09-22T12:03:14.004-04:00">DRAFT</status_change>
            <status_change date="2011-10-10T04:00:22.077-04:00">INTERIM</status_change>
            <status_change date="2011-10-31T04:00:40.593-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Debian 6.0 is installed" definition_ref="oval:org.mitre.oval:def:12959"/>
        <criteria operator="OR" comment="Architecture section">
          <criteria operator="AND" comment="Architecture independent section">
            <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
            <criterion comment="vlc DPKG is earlier than 1.1.3-1squeeze3" test_ref="oval:org.mitre.oval:tst:43954"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:12713" version="3" class="patch">
      <metadata>
        <title>DSA-2251-1 subversion -- several</title>
        <affected family="unix">
          <platform>Debian 5.0</platform>
          <platform>Debian 6.0</platform>
          <product>subversion</product>
        </affected>
        <reference source="VENDOR" ref_url="http://lists.debian.org/debian-security-announce/2011/msg00121.html" ref_id="DSA-2251-1"/>
        <description>Several vulnerabilities were discovered in Subversion, the version control system. The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2011-1752 The mod_dav_svn Apache HTTPD server module can be crashed though when asked to deliver baselined WebDAV resources. CVE-2011-1783 The mod_dav_svn Apache HTTPD server module can trigger a loop which consumes all available memory on the system. CVE-2011-1921 The mod_dav_svn Apache HTTPD server module may leak to remote users the file contents of files configured to be unreadable by those users.</description>
        <oval_repository>
          <dates>
            <submitted date="2011-09-22T19:59:17-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2011-09-22T12:03:36.532-04:00">DRAFT</status_change>
            <status_change date="2011-10-10T04:00:21.536-04:00">INTERIM</status_change>
            <status_change date="2011-10-31T04:00:40.132-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Release section">
          <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
          <criteria operator="OR" comment="Architecture section">
            <criteria operator="AND" comment="Architecture independent section">
              <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criterion comment="subversion DPKG is earlier than 1.5.1dfsg1-7" test_ref="oval:org.mitre.oval:tst:44059"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Release section">
          <extend_definition comment="Debian 6.0 is installed" definition_ref="oval:org.mitre.oval:def:12959"/>
          <criteria operator="OR" comment="Architecture section">
            <criteria operator="AND" comment="Architecture independent section">
              <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criterion comment="subversion DPKG is earlier than 1.6.12dfsg-6" test_ref="oval:org.mitre.oval:tst:44025"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:12695" version="3" class="patch">
      <metadata>
        <title>DSA-2193-1 libcgroup -- several</title>
        <affected family="unix">
          <platform>Debian 6.0</platform>
          <product>libcgroup</product>
        </affected>
        <reference source="VENDOR" ref_url="http://lists.debian.org/debian-security-announce/2011/msg00060.html" ref_id="DSA-2193-1"/>
        <description>Several issues have been discovered in libcgroup, a library to control and monitor control groups: CVE-2011-1006 Heap-based buffer overflow by converting list of controllers for given task into an array of strings could lead to privilege escalation by a local attacker. CVE-2011-1022 libcgroup did not properly check the origin of Netlink messages, allowing a local attacker to send crafted Netlink messages which could lead to privilege escalation. The oldstable distribution  does not contain libgroup packages.</description>
        <oval_repository>
          <dates>
            <submitted date="2011-09-22T10:11:28-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2011-09-22T12:03:23.560-04:00">DRAFT</status_change>
            <status_change date="2011-10-10T04:00:21.092-04:00">INTERIM</status_change>
            <status_change date="2011-10-31T04:00:38.671-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Debian 6.0 is installed" definition_ref="oval:org.mitre.oval:def:12959"/>
        <criteria operator="OR" comment="Architecture section">
          <criteria operator="AND" comment="Architecture independent section">
            <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
            <criterion comment="libcgroup DPKG is earlier than 0.36.2-3+squeeze1" test_ref="oval:org.mitre.oval:tst:43872"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:12683" version="3" class="patch">
      <metadata>
        <title>DSA-2228-1 iceweasel -- several</title>
        <affected family="unix">
          <platform>Debian 6.0</platform>
          <product>iceweasel</product>
        </affected>
        <reference source="VENDOR" ref_url="http://lists.debian.org/debian-security-announce/2011/msg00097.html" ref_id="DSA-2228-1"/>
        <description>Several vulnerabilities have been found in Iceweasel, a web browser based on Firefox: CVE-2011-0069 CVE-2011-0070 CVE-2011-0072 CVE-2011-0074 CVE-2011-0075 CVE-2011-0077 CVE-2011-0078 CVE-2011-0080 CVE-2011-0081 &amp;quot;Scoobidiver&amp;quot;, Ian Beer Bob Clary, Henri Sivonen, Marco Bonardo, Mats Palmgren, Jesse Ruderman, Aki Kelin and Martin Barbella discovered memory corruption bugs, which may lead to the execution of arbitrary code. CVE-2011-0065 CVE-2011-0066 CVE-2011-0073 &amp;quot;regenrecht&amp;quot; discovered several dangling pointer vulnerabilities, which may lead to the execution of arbitrary code. CVE-2011-0067 Paul Stone discovered that Java applets could steal information from the autocompletion history. CVE-2011-0071 Soroush Dalili discovered a directory traversal vulnerability in handling resource URIs.</description>
        <oval_repository>
          <dates>
            <submitted date="2011-09-22T16:45:38-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2011-09-22T12:03:30.569-04:00">DRAFT</status_change>
            <status_change date="2011-10-10T04:00:19.784-04:00">INTERIM</status_change>
            <status_change date="2011-10-31T04:00:37.404-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Debian 6.0 is installed" definition_ref="oval:org.mitre.oval:def:12959"/>
        <criteria operator="OR" comment="Architecture section">
          <criteria operator="AND" comment="Architecture independent section">
            <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
            <criterion comment="iceweasel DPKG is earlier than 3.5.16-7" test_ref="oval:org.mitre.oval:tst:44072"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:12682" version="3" class="patch">
      <metadata>
        <title>DSA-2163-2 dajaxice -- multiple</title>
        <affected family="unix">
          <platform>Debian 6.0</platform>
          <product>dajaxice</product>
        </affected>
        <reference source="VENDOR" ref_url="http://lists.debian.org/debian-security-announce/2011/msg00042.html" ref_id="DSA-2163-2"/>
        <description>The changes in python-django DSA-2163 necessary to fix the issues CVE-2011-0696 and CVE-2011-0697 introduced an unavoidable backward incompatibility, which caused a regression in dajaxice, which depends on python-django. This update supplies fixed packages for dajaxice.</description>
        <oval_repository>
          <dates>
            <submitted date="2011-09-22T15:38:42-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2011-09-22T12:03:14.892-04:00">DRAFT</status_change>
            <status_change date="2011-10-10T04:00:19.555-04:00">INTERIM</status_change>
            <status_change date="2011-10-31T04:00:37.194-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Debian 6.0 is installed" definition_ref="oval:org.mitre.oval:def:12959"/>
        <criteria operator="OR" comment="Architecture section">
          <criteria operator="AND" comment="Architecture independent section">
            <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
            <criterion comment="dajaxice DPKG is earlier than 0.1.5-1squeeze1" test_ref="oval:org.mitre.oval:tst:43971"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:12678" version="3" class="patch">
      <metadata>
        <title>DSA-2221-1 libmojolicious-perl -- directory traversal</title>
        <affected family="unix">
          <platform>Debian 6.0</platform>
          <product>libmojolicious-perl</product>
        </affected>
        <reference source="VENDOR" ref_url="http://lists.debian.org/debian-security-announce/2011/msg00090.html" ref_id="DSA-2221-1"/>
        <description>Viacheslav Tykhanovskyi discovered a directory traversal vulnerability in Mojolicious, a Perl Web Application Framework. The oldstable distribution  doesn"t contain libmojolicious-perl.</description>
        <oval_repository>
          <dates>
            <submitted date="2011-09-22T17:14:42-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2011-09-22T12:03:28.898-04:00">DRAFT</status_change>
            <status_change date="2011-10-10T04:00:19.323-04:00">INTERIM</status_change>
            <status_change date="2011-10-31T04:00:36.930-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Debian 6.0 is installed" definition_ref="oval:org.mitre.oval:def:12959"/>
        <criteria operator="OR" comment="Architecture section">
          <criteria operator="AND" comment="Architecture independent section">
            <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
            <criterion comment="libmojolicious-perl DPKG is earlier than 0.999926-1+squeeze1" test_ref="oval:org.mitre.oval:tst:43139"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:12667" version="3" class="patch">
      <metadata>
        <title>DSA-2241-1 qemu-kvm -- implementation error</title>
        <affected family="unix">
          <platform>Debian 6.0</platform>
          <product>qemu-kvm</product>
        </affected>
        <reference source="VENDOR" ref_url="http://lists.debian.org/debian-security-announce/2011/msg00110.html" ref_id="DSA-2241-1"/>
        <description>Nelson Elhage discovered that incorrect memory handling during the removal of ISA devices in KVM, a solution for full virtualization on x86 hardware, could lead to denial of service of the execution of arbitrary code.</description>
        <oval_repository>
          <dates>
            <submitted date="2011-09-22T20:14:41-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2011-09-22T12:03:33.929-04:00">DRAFT</status_change>
            <status_change date="2011-10-10T04:00:18.286-04:00">INTERIM</status_change>
            <status_change date="2011-10-31T04:00:35.960-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Debian 6.0 is installed" definition_ref="oval:org.mitre.oval:def:12959"/>
        <criteria operator="OR" comment="Architecture section">
          <criteria operator="AND" comment="Architecture independent section">
            <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
            <criterion comment="qemu-kvm DPKG is earlier than 0.12.5+dfsg-5+squeeze2" test_ref="oval:org.mitre.oval:tst:44134"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:12666" version="3" class="patch">
      <metadata>
        <title>DSA-2173-1 pam-pgsql -- buffer overflow</title>
        <affected family="unix">
          <platform>Debian 5.0</platform>
          <platform>Debian 6.0</platform>
          <product>pam-pgsql</product>
        </affected>
        <reference source="VENDOR" ref_url="http://lists.debian.org/debian-security-announce/2011/msg00039.html" ref_id="DSA-2173-1"/>
        <description>It was discovered that pam-pgsql, a PAM module to authenticate using a PostgreSQL database, was vulnerable to a buffer overflow in supplied IP-addresses.</description>
        <oval_repository>
          <dates>
            <submitted date="2011-09-22T20:34:59-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2011-09-22T12:03:20.406-04:00">DRAFT</status_change>
            <status_change date="2011-10-10T04:00:17.992-04:00">INTERIM</status_change>
            <status_change date="2011-10-31T04:00:35.695-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Release section">
          <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
          <criteria operator="OR" comment="Architecture section">
            <criteria operator="AND" comment="Architecture independent section">
              <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criterion comment="pam-pgsql DPKG is earlier than 0.6.3-2+lenny1" test_ref="oval:org.mitre.oval:tst:43073"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Release section">
          <extend_definition comment="Debian 6.0 is installed" definition_ref="oval:org.mitre.oval:def:12959"/>
          <criteria operator="OR" comment="Architecture section">
            <criteria operator="AND" comment="Architecture independent section">
              <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criterion comment="pam-pgsql DPKG is earlier than 0.7.1-4+squeeze1" test_ref="oval:org.mitre.oval:tst:43826"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:12641" version="3" class="patch">
      <metadata>
        <title>DSA-2249-1 jabberd14 -- denial of service</title>
        <affected family="unix">
          <platform>Debian 6.0</platform>
          <product>jabberd14</product>
        </affected>
        <reference source="VENDOR" ref_url="http://lists.debian.org/debian-security-announce/2011/msg00119.html" ref_id="DSA-2249-1"/>
        <description>Wouter Coekaerts discovered that jabberd14, an instant messaging server using the Jabber/XMPP protocol, is vulnerable to the so-called &amp;quot;billion laughs&amp;quot; attack because it does not prevent entity expansion on received data. This allows an attacker to perform denial of service attacks against the service by sending specially crafted XML data to it. The oldstable distribution , does not contain jabberd14.</description>
        <oval_repository>
          <dates>
            <submitted date="2011-09-22T21:30:34-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2011-09-22T12:03:35.269-04:00">DRAFT</status_change>
            <status_change date="2011-10-10T04:00:17.320-04:00">INTERIM</status_change>
            <status_change date="2011-10-31T04:00:27.381-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Debian 6.0 is installed" definition_ref="oval:org.mitre.oval:def:12959"/>
        <criteria operator="OR" comment="Architecture section">
          <criteria operator="AND" comment="Architecture independent section">
            <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
            <criterion comment="jabberd14 DPKG is earlier than 1.6.1.1-5+squeeze1" test_ref="oval:org.mitre.oval:tst:44109"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:12639" version="3" class="patch">
      <metadata>
        <title>DSA-2255-1 libxml2 -- buffer overflow</title>
        <affected family="unix">
          <platform>Debian 5.0</platform>
          <platform>Debian 6.0</platform>
          <product>libxml2</product>
        </affected>
        <reference source="VENDOR" ref_url="http://lists.debian.org/debian-security-announce/2011/msg00125.html" ref_id="DSA-2255-1"/>
        <description>Chris Evans discovered that libxml was vulnerable to buffer overflows, which allowed a crafted XML input file to potentially execute arbitrary code.</description>
        <oval_repository>
          <dates>
            <submitted date="2011-09-22T20:14:24-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2011-09-22T12:03:39.342-04:00">DRAFT</status_change>
            <status_change date="2011-10-10T04:00:17.057-04:00">INTERIM</status_change>
            <status_change date="2011-10-31T04:00:27.019-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Release section">
          <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
          <criteria operator="OR" comment="Architecture section">
            <criteria operator="AND" comment="Architecture independent section">
              <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criterion comment="libxml2 DPKG is earlier than 2.6.32.dfsg-5+lenny4" test_ref="oval:org.mitre.oval:tst:44230"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Release section">
          <extend_definition comment="Debian 6.0 is installed" definition_ref="oval:org.mitre.oval:def:12959"/>
          <criteria operator="OR" comment="Architecture section">
            <criteria operator="AND" comment="Architecture independent section">
              <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criterion comment="libxml2 DPKG is earlier than 2.7.8.dfsg-2+squeeze1" test_ref="oval:org.mitre.oval:tst:44210"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:12605" version="3" class="patch">
      <metadata>
        <title>DSA-2242-1 cyrus-imapd-2.2 -- implementation error</title>
        <affected family="unix">
          <platform>Debian 5.0</platform>
          <platform>Debian 6.0</platform>
          <product>cyrus-imapd-2.2</product>
        </affected>
        <reference source="VENDOR" ref_url="http://lists.debian.org/debian-security-announce/2011/msg00112.html" ref_id="DSA-2242-1"/>
        <description>It was discovered that the STARTTLS implementation of the Cyrus IMAP server does not properly restrict I/O buffering, which allows man-in-the-middle attackers to insert commands into encrypted IMAP, LMTP, NNTP and POP3 sessions by sending a cleartext command that is processed after TLS is in place.</description>
        <oval_repository>
          <dates>
            <submitted date="2011-09-22T20:03:15-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2011-09-22T12:03:34.464-04:00">DRAFT</status_change>
            <status_change date="2011-10-10T04:00:15.748-04:00">INTERIM</status_change>
            <status_change date="2011-10-31T04:00:25.346-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Release section">
          <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
          <criteria operator="OR" comment="Architecture section">
            <criteria operator="AND" comment="Architecture independent section">
              <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criterion comment="cyrus-imapd-2.2 DPKG is earlier than 2.2.13-14+lenny4" test_ref="oval:org.mitre.oval:tst:43975"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Release section">
          <extend_definition comment="Debian 6.0 is installed" definition_ref="oval:org.mitre.oval:def:12959"/>
          <criteria operator="OR" comment="Architecture section">
            <criteria operator="AND" comment="Architecture independent section">
              <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criterion comment="cyrus-imapd-2.2 DPKG is earlier than 2.2.13-19+squeeze1" test_ref="oval:org.mitre.oval:tst:43881"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:12603" version="3" class="patch">
      <metadata>
        <title>DSA-2194-1 libvirt -- insufficient checks</title>
        <affected family="unix">
          <platform>Debian 6.0</platform>
          <product>libvirt</product>
        </affected>
        <reference source="VENDOR" ref_url="http://lists.debian.org/debian-security-announce/2011/msg00061.html" ref_id="DSA-2194-1"/>
        <description>It was discovered that libvirt, a library for interfacing with different virtualization systems, did not properly check for read-only connections. This allowed a local attacker to perform a denial of service  or possibly escalate privileges. The oldstable distribution  is not affected by this problem.</description>
        <oval_repository>
          <dates>
            <submitted date="2011-09-22T20:50:13-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2011-09-22T12:03:24.311-04:00">DRAFT</status_change>
            <status_change date="2011-10-10T04:00:15.512-04:00">INTERIM</status_change>
            <status_change date="2011-10-31T04:00:25.098-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Debian 6.0 is installed" definition_ref="oval:org.mitre.oval:def:12959"/>
        <criteria operator="OR" comment="Architecture section">
          <criteria operator="AND" comment="Architecture independent section">
            <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
            <criterion comment="libvirt DPKG is earlier than 0.8.3-5+squeeze1" test_ref="oval:org.mitre.oval:tst:43981"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:12599" version="3" class="patch">
      <metadata>
        <title>DSA-2177-1 pywebdav -- SQL injection</title>
        <affected family="unix">
          <platform>Debian 6.0</platform>
          <product>pywebdav</product>
        </affected>
        <reference source="VENDOR" ref_url="http://lists.debian.org/debian-security-announce/2011/msg00044.html" ref_id="DSA-2177-1"/>
        <description>It was discovered that python-webdav, a WebDAV server implementation, contains several SQL injection vulnerabilities in the processing of user credentials. The oldstable distribution  does not contain a python-webdav package.</description>
        <oval_repository>
          <dates>
            <submitted date="2011-09-22T16:23:44-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2011-09-22T12:03:19.510-04:00">DRAFT</status_change>
            <status_change date="2011-10-10T04:00:15.299-04:00">INTERIM</status_change>
            <status_change date="2011-10-31T04:00:24.806-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Debian 6.0 is installed" definition_ref="oval:org.mitre.oval:def:12959"/>
        <criteria operator="OR" comment="Architecture section">
          <criteria operator="AND" comment="Architecture independent section">
            <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
            <criterion comment="pywebdav DPKG is earlier than 0.9.4-1+squeeze1" test_ref="oval:org.mitre.oval:tst:43961"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:12578" version="3" class="patch">
      <metadata>
        <title>DSA-2287-1 libpng -- several</title>
        <affected family="unix">
          <platform>Debian 5.0</platform>
          <platform>Debian 6.0</platform>
          <product>libpng</product>
        </affected>
        <reference source="VENDOR" ref_url="http://lists.debian.org/debian-security-announce/2011/msg00161.html" ref_id="DSA-2287-1"/>
        <description>The PNG library libpng has been affected by several vulnerabilities. The most critical one is the identified as CVE-2011-2690. Using this vulnerability, an attacker is able to overwrite memory with an arbitrary amount of data controlled by her via a crafted PNG image. The other vulnerabilities are less critical and allow an attacker to cause a crash in the program  via a crafted PNG image.</description>
        <oval_repository>
          <dates>
            <submitted date="2011-09-22T19:43:59-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2011-09-22T12:03:48.312-04:00">DRAFT</status_change>
            <status_change date="2011-10-10T04:00:14.528-04:00">INTERIM</status_change>
            <status_change date="2011-10-31T04:00:23.589-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Release section">
          <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
          <criteria operator="OR" comment="Architecture section">
            <criteria operator="AND" comment="Architecture independent section">
              <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criterion comment="libpng DPKG is earlier than 1.2.27-2+lenny5" test_ref="oval:org.mitre.oval:tst:44187"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Release section">
          <extend_definition comment="Debian 6.0 is installed" definition_ref="oval:org.mitre.oval:def:12959"/>
          <criteria operator="OR" comment="Architecture section">
            <criteria operator="AND" comment="Architecture independent section">
              <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criterion comment="libpng DPKG is earlier than 1.2.44-1+squeeze1" test_ref="oval:org.mitre.oval:tst:43887"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:12564" version="3" class="patch">
      <metadata>
        <title>DSA-2174-1 avahi -- denial of service</title>
        <affected family="unix">
          <platform>Debian 5.0</platform>
          <platform>Debian 6.0</platform>
          <product>avahi</product>
        </affected>
        <reference source="VENDOR" ref_url="http://lists.debian.org/debian-security-announce/2011/msg00040.html" ref_id="DSA-2174-1"/>
        <description>It was discovered that avahi, an implementation of the zeroconf protocol, can be crashed remotely by a single UDP packet, which may result in a denial of service.</description>
        <oval_repository>
          <dates>
            <submitted date="2011-09-22T15:55:12-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2011-09-22T12:03:18.549-04:00">DRAFT</status_change>
            <status_change date="2011-10-10T04:00:14.004-04:00">INTERIM</status_change>
            <status_change date="2011-10-31T04:00:22.928-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Release section">
          <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
          <criteria operator="OR" comment="Architecture section">
            <criteria operator="AND" comment="Architecture independent section">
              <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criterion comment="avahi DPKG is earlier than 0.6.23-3lenny3" test_ref="oval:org.mitre.oval:tst:43469"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Release section">
          <extend_definition comment="Debian 6.0 is installed" definition_ref="oval:org.mitre.oval:def:12959"/>
          <criteria operator="OR" comment="Architecture section">
            <criteria operator="AND" comment="Architecture independent section">
              <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criterion comment="avahi DPKG is earlier than 0.6.27-2+squeeze1" test_ref="oval:org.mitre.oval:tst:43998"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:12560" version="3" class="patch">
      <metadata>
        <title>DSA-2206-1 mahara -- several</title>
        <affected family="unix">
          <platform>Debian 5.0</platform>
          <platform>Debian 6.0</platform>
          <product>mahara</product>
        </affected>
        <reference source="VENDOR" ref_url="http://lists.debian.org/debian-security-announce/2011/msg00074.html" ref_id="DSA-2206-1"/>
        <description>Two security vulnerabilities have been discovered in Mahara, a fully featured electronic portfolio, weblog, resume builder and social networking system: CVE-2011-0439 A security review commissioned by a Mahara user discovered that Mahara processes unsanitized input which can lead to cross-site scripting . CVE-2011-0440 Mahara Developers discovered that Mahara doesn"t check the session key under certain circumstances which can be exploited as cross-site request forgery  and can lead to the deletion of blogs.</description>
        <oval_repository>
          <dates>
            <submitted date="2011-09-22T19:49:38-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2011-09-22T12:03:39.002-04:00">DRAFT</status_change>
            <status_change date="2011-10-10T04:00:13.735-04:00">INTERIM</status_change>
            <status_change date="2011-10-31T04:00:22.657-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Release section">
          <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
          <criteria operator="OR" comment="Architecture section">
            <criteria operator="AND" comment="Architecture independent section">
              <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criterion comment="mahara DPKG is earlier than 1.0.4-4+lenny8" test_ref="oval:org.mitre.oval:tst:44114"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Release section">
          <extend_definition comment="Debian 6.0 is installed" definition_ref="oval:org.mitre.oval:def:12959"/>
          <criteria operator="OR" comment="Architecture section">
            <criteria operator="AND" comment="Architecture independent section">
              <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criterion comment="mahara DPKG is earlier than 1.2.6-2+squeeze1" test_ref="oval:org.mitre.oval:tst:44132"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:12479" version="3" class="patch">
      <metadata>
        <title>DSA-2277-1 xml-security-c -- stack-based buffer overflow</title>
        <affected family="unix">
          <platform>Debian 5.0</platform>
          <platform>Debian 6.0</platform>
          <product>xml-security-c</product>
        </affected>
        <reference source="VENDOR" ref_url="http://lists.debian.org/debian-security-announce/2011/msg00149.html" ref_id="DSA-2277-1"/>
        <description>It has been discovered that xml-security-c, an implementation of the XML Digital Signature and Encryption specifications, is not properly handling RSA keys of sizes on the order of 8192 or more bits. This allows an attacker to crash applications using this functionality or potentially execute arbitrary code by tricking an application into verifying a signature created with a sufficiently long RSA key.</description>
        <oval_repository>
          <dates>
            <submitted date="2011-09-22T23:25:42-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2011-09-22T12:03:45.579-04:00">DRAFT</status_change>
            <status_change date="2011-10-10T04:00:12.386-04:00">INTERIM</status_change>
            <status_change date="2011-10-31T04:00:21.434-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Release section">
          <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
          <criteria operator="OR" comment="Architecture section">
            <criteria operator="AND" comment="Architecture independent section">
              <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criterion comment="xml-security-c DPKG is earlier than 1.4.0-3+lenny3" test_ref="oval:org.mitre.oval:tst:44211"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Release section">
          <extend_definition comment="Debian 6.0 is installed" definition_ref="oval:org.mitre.oval:def:12959"/>
          <criteria operator="OR" comment="Architecture section">
            <criteria operator="AND" comment="Architecture independent section">
              <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criterion comment="xml-security-c DPKG is earlier than 1.5.1-3+squeeze1" test_ref="oval:org.mitre.oval:tst:43273"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:12471" version="3" class="patch">
      <metadata>
        <title>DSA-2197-1 quagga -- denial of service</title>
        <affected family="unix">
          <platform>Debian 5.0</platform>
          <platform>Debian 6.0</platform>
          <product>quagga</product>
        </affected>
        <reference source="VENDOR" ref_url="http://lists.debian.org/debian-security-announce/2011/msg00065.html" ref_id="DSA-2197-1"/>
        <description>It has been discovered that the Quagga routing daemon contains two denial-of-service vulnerabilities in its BGP implementation: CVE-2010-1674 A crafted Extended Communities attribute triggers a null pointer dereference which causes the BGP daemon to crash. The crafted attributes are not propagated by the Internet core, so only explicitly configured direct peers are able to exploit this vulnerability in typical configurations. CVE-2010-1675 The BGP daemon resets BGP sessions when it encounters malformed AS_PATHLIMIT attributes, introducing a distributed BGP session reset vulnerability which disrupts packet forwarding. Such malformed attributes are propagated by the Internet core, and exploitation of this vulnerability is not restricted to directly configured BGP peers. This security update removes AS_PATHLIMIT processing from the BGP implementation, preserving the configuration statements for backwards compatibility</description>
        <oval_repository>
          <dates>
            <submitted date="2011-09-22T22:17:42-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2011-09-22T12:03:25.226-04:00">DRAFT</status_change>
            <status_change date="2011-10-10T04:00:12.107-04:00">INTERIM</status_change>
            <status_change date="2011-10-31T04:00:21.168-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Release section">
          <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
          <criteria operator="OR" comment="Architecture section">
            <criteria operator="AND" comment="Architecture independent section">
              <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criterion comment="quagga DPKG is earlier than 0.99.10-1lenny5" test_ref="oval:org.mitre.oval:tst:43815"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Release section">
          <extend_definition comment="Debian 6.0 is installed" definition_ref="oval:org.mitre.oval:def:12959"/>
          <criteria operator="OR" comment="Architecture section">
            <criteria operator="AND" comment="Architecture independent section">
              <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criterion comment="quagga DPKG is earlier than 0.99.17-2+squeeze2" test_ref="oval:org.mitre.oval:tst:44061"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:12470" version="3" class="patch">
      <metadata>
        <title>DSA-2171-1 asterisk -- buffer overflow</title>
        <affected family="unix">
          <platform>Debian 5.0</platform>
          <platform>Debian 6.0</platform>
          <product>asterisk</product>
        </affected>
        <reference source="VENDOR" ref_url="http://lists.debian.org/debian-security-announce/2011/msg00037.html" ref_id="DSA-2171-1"/>
        <description>Matthew Nicholson discovered a buffer overflow in the SIP channel driver of Asterisk, an open source PBX and telephony toolkit, which could lead to the execution of arbitrary code.</description>
        <oval_repository>
          <dates>
            <submitted date="2011-09-22T16:46:11-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2011-09-22T12:03:20.099-04:00">DRAFT</status_change>
            <status_change date="2011-10-10T04:00:11.632-04:00">INTERIM</status_change>
            <status_change date="2011-10-31T04:00:20.839-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Release section">
          <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
          <criteria operator="OR" comment="Architecture section">
            <criteria operator="AND" comment="Architecture independent section">
              <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criterion comment="asterisk DPKG is earlier than 1.4.21.2~dfsg-3+lenny2" test_ref="oval:org.mitre.oval:tst:43291"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Release section">
          <extend_definition comment="Debian 6.0 is installed" definition_ref="oval:org.mitre.oval:def:12959"/>
          <criteria operator="OR" comment="Architecture section">
            <criteria operator="AND" comment="Architecture independent section">
              <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criterion comment="asterisk DPKG is earlier than 1.6.2.9-2+squeeze1" test_ref="oval:org.mitre.oval:tst:43882"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:12421" version="3" class="patch">
      <metadata>
        <title>DSA-2270-1 qemu-kvm -- programming error</title>
        <affected family="unix">
          <platform>Debian 6.0</platform>
          <product>qemu-kvm</product>
        </affected>
        <reference source="VENDOR" ref_url="http://lists.debian.org/debian-security-announce/2011/msg00142.html" ref_id="DSA-2270-1"/>
        <description>It was discovered that incorrect sanitising of virtio queue commands in KVM, a solution for full virtualization on x86 hardware, could lead to denial of service of the execution of arbitrary code. The oldstable distribution  is not affected by this problem.</description>
        <oval_repository>
          <dates>
            <submitted date="2011-09-22T14:11:06-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2011-09-22T12:03:43.265-04:00">DRAFT</status_change>
            <status_change date="2011-10-10T04:00:11.403-04:00">INTERIM</status_change>
            <status_change date="2011-10-31T04:00:20.317-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Debian 6.0 is installed" definition_ref="oval:org.mitre.oval:def:12959"/>
        <criteria operator="OR" comment="Architecture section">
          <criteria operator="AND" comment="Architecture independent section">
            <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
            <criterion comment="qemu-kvm DPKG is earlier than 0.12.5+dfsg-5+squeeze4" test_ref="oval:org.mitre.oval:tst:44101"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:12419" version="3" class="patch">
      <metadata>
        <title>DSA-2163-1 python-django -- multiple</title>
        <affected family="unix">
          <platform>Debian 6.0</platform>
          <product>python-django</product>
        </affected>
        <reference source="VENDOR" ref_url="http://lists.debian.org/debian-security-announce/2011/msg00028.html" ref_id="DSA-2163-1"/>
        <description>Several vulnerabilities were discovered in the django web development framework: CVE-2011-0696 For several reasons the internal CSRF protection was not used to validate ajax requests in the past. However, it was discovered that this exception can be exploited with a combination of browser plugins and redirects and thus is not sufficient. CVE-2011-0697 It was discovered that the file upload form is prone to cross-site scripting attacks via the file name. It is important to note that this update introduces minor backward incompatibilities due to the fixes for the above issues. Packages in the oldstable distribution  are not affected by these problems.</description>
        <oval_repository>
          <dates>
            <submitted date="2011-09-22T15:53:10-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2011-09-22T12:03:15.686-04:00">DRAFT</status_change>
            <status_change date="2011-10-10T04:00:11.155-04:00">INTERIM</status_change>
            <status_change date="2011-10-31T04:00:20.074-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Debian 6.0 is installed" definition_ref="oval:org.mitre.oval:def:12959"/>
        <criteria operator="OR" comment="Architecture section">
          <criteria operator="AND" comment="Architecture independent section">
            <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
            <criterion comment="python-django DPKG is earlier than 1.2.3-3+squeeze1" test_ref="oval:org.mitre.oval:tst:43453"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:12399" version="3" class="patch">
      <metadata>
        <title>DSA-2167-1 phpmyadmin -- sql injection</title>
        <affected family="unix">
          <platform>Debian 5.0</platform>
          <platform>Debian 6.0</platform>
          <product>phpmyadmin</product>
        </affected>
        <reference source="VENDOR" ref_url="http://lists.debian.org/debian-security-announce/2011/msg00033.html" ref_id="DSA-2167-1"/>
        <description>It was discovered that phpMyAdmin, a a tool to administer MySQL over the web, when the bookmarks feature is enabled, allowed to create a bookmarked query which would be executed unintentionally by other users.</description>
        <oval_repository>
          <dates>
            <submitted date="2011-09-22T16:50:23-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2011-09-22T12:03:17.117-04:00">DRAFT</status_change>
            <status_change date="2011-10-10T04:00:10.614-04:00">INTERIM</status_change>
            <status_change date="2011-10-31T04:00:19.497-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Release section">
          <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
          <criteria operator="OR" comment="Architecture section">
            <criteria operator="AND" comment="Architecture independent section">
              <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criterion comment="phpmyadmin DPKG is earlier than 4:2.11.8.1-5+lenny8" test_ref="oval:org.mitre.oval:tst:43955"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Release section">
          <extend_definition comment="Debian 6.0 is installed" definition_ref="oval:org.mitre.oval:def:12959"/>
          <criteria operator="OR" comment="Architecture section">
            <criteria operator="AND" comment="Architecture independent section">
              <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criterion comment="phpmyadmin DPKG is earlier than 4:3.3.7-5" test_ref="oval:org.mitre.oval:tst:42996"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:12397" version="3" class="patch">
      <metadata>
        <title>DSA-2170-1 mailman -- several</title>
        <affected family="unix">
          <platform>Debian 6.0</platform>
          <product>mailman</product>
        </affected>
        <reference source="VENDOR" ref_url="http://lists.debian.org/debian-security-announce/2011/msg00036.html" ref_id="DSA-2170-1"/>
        <description>Two cross site scripting vulnerabilities were been discovered in Mailman, a web-based mailing list manager. These allowed an attacker to retreive session cookies via inserting crafted JavaScript into confirmation messages  and in the list admin interface .</description>
        <oval_repository>
          <dates>
            <submitted date="2011-09-22T15:42:46-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2011-09-22T12:03:17.924-04:00">DRAFT</status_change>
            <status_change date="2011-10-10T04:00:10.389-04:00">INTERIM</status_change>
            <status_change date="2011-10-31T04:00:19.258-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Debian 6.0 is installed" definition_ref="oval:org.mitre.oval:def:12959"/>
        <criteria operator="OR" comment="Architecture section">
          <criteria operator="AND" comment="Architecture independent section">
            <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
            <criterion comment="mailman DPKG is earlier than 1:2.1.13-5" test_ref="oval:org.mitre.oval:tst:43986"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:12388" version="3" class="patch">
      <metadata>
        <title>DSA-2266-1 php5 -- several</title>
        <affected family="unix">
          <platform>Debian 5.0</platform>
          <platform>Debian 6.0</platform>
          <product>php5</product>
        </affected>
        <reference source="VENDOR" ref_url="http://lists.debian.org/debian-security-announce/2011/msg00137.html" ref_id="DSA-2266-1"/>
        <description>Several vulnerabilities were discovered in PHP, which could lead to denial of service or potentially the execution of arbitrary code. CVE-2010-2531 An information leak was found in the var_export function. CVE-2011-0421 The Zip module could crash. CVE-2011-0708 An integer overflow was discovered in the Exif module. CVE-2011-1466 An integer overflow was discovered in the Calendar module. CVE-2011-1471 The Zip module was prone to denial of service through malformed archives. CVE-2011-2202 Path names in form based file uploads  were incorrectly validated. This update also fixes two bugs, which are not treated as security issues, but fixed nonetheless, see README.Debian.security for details on the scope of security support for PHP .</description>
        <oval_repository>
          <dates>
            <submitted date="2011-09-22T13:04:04-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2011-09-22T12:03:42.070-04:00">DRAFT</status_change>
            <status_change date="2011-10-10T04:00:10.121-04:00">INTERIM</status_change>
            <status_change date="2011-10-31T04:00:18.915-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Release section">
          <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
          <criteria operator="OR" comment="Architecture section">
            <criteria operator="AND" comment="Architecture independent section">
              <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criterion comment="php5 DPKG is earlier than 5.2.6.dfsg.1-1+lenny12" test_ref="oval:org.mitre.oval:tst:43693"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Release section">
          <extend_definition comment="Debian 6.0 is installed" definition_ref="oval:org.mitre.oval:def:12959"/>
          <criteria operator="OR" comment="Architecture section">
            <criteria operator="AND" comment="Architecture independent section">
              <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criterion comment="php5 DPKG is earlier than 5.3.3-7+squeeze3" test_ref="oval:org.mitre.oval:tst:44000"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:12384" version="3" class="patch">
      <metadata>
        <title>DSA-2188-1 webkit -- several</title>
        <affected family="unix">
          <platform>Debian 6.0</platform>
          <product>webkit</product>
        </affected>
        <reference source="VENDOR" ref_url="http://lists.debian.org/debian-security-announce/2011/msg00055.html" ref_id="DSA-2188-1"/>
        <description>Several vulnerabilities have been discovered in webkit, a Web content engine library for Gtk+. The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2010-1783 WebKit does not properly handle dynamic modification of a text node, which allows remote attackers to execute arbitrary code or cause a denial of service  via a crafted HTML document. CVE-2010-2901 The rendering implementation in WebKit allows remote attackers to cause a denial of service  or possibly have unspecified other impact via unknown vectors. CVE-2010-4199 WebKit does not properly perform a cast of an unspecified variable during processing of an SVG use element, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted SVG document. CVE-2010-4040 WebKit does not properly handle animated GIF images, which allows remote attackers to cause a denial of service  or possibly have unspecified other impact via a crafted image. CVE-2010-4492 Use-after-free vulnerability in WebKit allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors involving SVG animations. CVE-2010-4493 Use-after-free vulnerability in Webkit allows remote attackers to cause a denial of service via vectors related to the handling of mouse dragging events CVE-2010-4577 The CSSParser::parseFontFaceSrc function in WebCore/css/CSSParser.cpp in WebKit does not properly parse Cascading Style Sheets  token sequences, which allows remote attackers to cause a denial of service  via a crafted local font, related to &amp;quot;Type Confusion.&amp;quot; CVE-2010-4578 WebKit does not properly perform cursor handling, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors that lead to &amp;quot;stale pointers.&amp;quot; CVE-2011-0482 WebKit does not properly perform a cast of an unspecified variable during handling of anchors, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted HTML document CVE-2011-0778 WebKit does not properly restrict drag and drop operations, which might allow remote attackers to bypass the Same Origin Policy via unspecified vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2011-09-22T21:34:12-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2011-09-22T12:03:22.905-04:00">DRAFT</status_change>
            <status_change date="2011-10-10T04:00:09.842-04:00">INTERIM</status_change>
            <status_change date="2011-10-31T04:00:18.661-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Debian 6.0 is installed" definition_ref="oval:org.mitre.oval:def:12959"/>
        <criteria operator="OR" comment="Architecture section">
          <criteria operator="AND" comment="Architecture independent section">
            <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
            <criterion comment="webkit DPKG is earlier than 1.2.7-0+squeeze1" test_ref="oval:org.mitre.oval:tst:43856"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:12320" version="3" class="patch">
      <metadata>
        <title>DSA-2262-1 moodle -- several</title>
        <affected family="unix">
          <platform>Debian 6.0</platform>
          <product>moodle</product>
        </affected>
        <reference source="VENDOR" ref_url="http://lists.debian.org/debian-security-announce/2011/msg00132.html" ref_id="DSA-2262-1"/>
        <description>Several cross-site scripting and information disclosure issues have been fixed in Moodle, a course management system for online learning: * MSA-11-0002 Cross-site request forgery vulnerability in RSS block * MSA-11-0003 Cross-site scripting vulnerability in tag autocomplete * MSA-11-0008 IMS enterprise enrolment file may disclose sensitive information * MSA-11-0011 Multiple cross-site scripting problems in media filter * MSA-11-0015 Cross Site Scripting through URL encoding * MSA-11-0013 Group/Quiz permissions issue</description>
        <oval_repository>
          <dates>
            <submitted date="2011-09-22T13:59:17-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2011-09-22T12:03:40.889-04:00">DRAFT</status_change>
            <status_change date="2011-10-10T04:00:09.321-04:00">INTERIM</status_change>
            <status_change date="2011-10-31T04:00:17.990-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Debian 6.0 is installed" definition_ref="oval:org.mitre.oval:def:12959"/>
        <criteria operator="OR" comment="Architecture section">
          <criteria operator="AND" comment="Architecture independent section">
            <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
            <criterion comment="moodle DPKG is earlier than 1.9.9.dfsg2-2.1+squeeze1" test_ref="oval:org.mitre.oval:tst:44214"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:12316" version="3" class="patch">
      <metadata>
        <title>DSA-2239-1 libmojolicious-perl -- several</title>
        <affected family="unix">
          <platform>Debian 6.0</platform>
          <product>libmojolicious-perl</product>
        </affected>
        <reference source="VENDOR" ref_url="http://lists.debian.org/debian-security-announce/2011/msg00109.html" ref_id="DSA-2239-1"/>
        <description>Several vulnerabilities have been discovered Mojolicious, a Perl Web Application Framework. The link_to helper was affected by cross-site scripting and implementation errors in the MD5 HMAC and CGI environment handling have been corrected. The oldstable distribution  doesn"t include libmojolicious-perl.</description>
        <oval_repository>
          <dates>
            <submitted date="2011-09-22T20:21:14-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2011-09-22T12:03:34.187-04:00">DRAFT</status_change>
            <status_change date="2011-10-10T04:00:09.067-04:00">INTERIM</status_change>
            <status_change date="2011-10-31T04:00:17.724-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Debian 6.0 is installed" definition_ref="oval:org.mitre.oval:def:12959"/>
        <criteria operator="OR" comment="Architecture section">
          <criteria operator="AND" comment="Architecture independent section">
            <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
            <criterion comment="libmojolicious-perl DPKG is earlier than 0.999926-1+squeeze2" test_ref="oval:org.mitre.oval:tst:43296"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:12253" version="3" class="patch">
      <metadata>
        <title>DSA-2215-1 gitolite -- directory traversal</title>
        <affected family="unix">
          <platform>Debian 6.0</platform>
          <product>gitolite</product>
        </affected>
        <reference source="VENDOR" ref_url="http://lists.debian.org/debian-security-announce/2011/msg00084.html" ref_id="DSA-2215-1"/>
        <description>Dylan Simon discovered that gitolite, a SSH-based gatekeeper for git repositories, is prone to directory traversal attacks when restricting admin defined commands . This allows an attacker to execute arbitrary commands with privileges of the gitolite server via crafted command names. Please note that this only affects installations that have ADC enabled . The oldstable distribution  is not affected by this problem, it does not include gitolite.</description>
        <oval_repository>
          <dates>
            <submitted date="2011-09-22T11:59:20-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2011-09-22T12:03:27.329-04:00">DRAFT</status_change>
            <status_change date="2011-10-10T04:00:08.172-04:00">INTERIM</status_change>
            <status_change date="2011-10-31T04:00:16.336-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Debian 6.0 is installed" definition_ref="oval:org.mitre.oval:def:12959"/>
        <criteria operator="OR" comment="Architecture section">
          <criteria operator="AND" comment="Architecture independent section">
            <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
            <criterion comment="gitolite DPKG is earlier than 1.5.4-2+squeeze1" test_ref="oval:org.mitre.oval:tst:44026"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:12147" version="3" class="patch">
      <metadata>
        <title>DSA-2214-1 ikiwiki -- missing input validation</title>
        <affected family="unix">
          <platform>Debian 6.0</platform>
          <product>ikiwiki</product>
        </affected>
        <reference source="VENDOR" ref_url="http://lists.debian.org/debian-security-announce/2011/msg00083.html" ref_id="DSA-2214-1"/>
        <description>Tango discovered that ikiwiki, a wiki compiler, is not validating if the htmlscrubber plugin is enabled or not on a page when adding alternative stylesheets to pages. This enables an attacker who is able to upload custom stylesheets to add malicious stylesheets as an alternate stylesheet, or replace the default stylesheet, and thus conduct cross-site scripting attacks. The oldstable distribution , this problem has been fixed in version 2.53.6.</description>
        <oval_repository>
          <dates>
            <submitted date="2011-09-22T12:01:37-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2011-09-22T12:03:27.557-04:00">DRAFT</status_change>
            <status_change date="2011-10-10T04:00:06.882-04:00">INTERIM</status_change>
            <status_change date="2011-10-31T04:00:12.686-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Debian 6.0 is installed" definition_ref="oval:org.mitre.oval:def:12959"/>
        <criteria operator="OR" comment="Architecture section">
          <criteria operator="AND" comment="Architecture independent section">
            <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
            <criterion comment="ikiwiki DPKG is earlier than 3.20100815.7" test_ref="oval:org.mitre.oval:tst:43816"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:12110" version="3" class="patch">
      <metadata>
        <title>DSA-2169-1 telepathy-gabble -- insufficient input validation</title>
        <affected family="unix">
          <platform>Debian 5.0</platform>
          <platform>Debian 6.0</platform>
          <product>telepathy-gabble</product>
        </affected>
        <reference source="VENDOR" ref_url="http://lists.debian.org/debian-security-announce/2011/msg00035.html" ref_id="DSA-2169-1"/>
        <description>It was discovered that telepathy-gabble, the Jabber/XMMP connection manager for the Telepathy framework, is processing google:jingleinfo updates without validating their origin. This may allow an attacker to trick telepathy-gabble into relaying streamed media data through a server of his choice and thus intercept audio and video calls.</description>
        <oval_repository>
          <dates>
            <submitted date="2011-09-22T16:54:41-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2011-09-22T12:03:17.431-04:00">DRAFT</status_change>
            <status_change date="2011-10-10T04:00:06.331-04:00">INTERIM</status_change>
            <status_change date="2011-10-31T04:00:11.542-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Release section">
          <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
          <criteria operator="OR" comment="Architecture section">
            <criteria operator="AND" comment="Architecture independent section">
              <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criterion comment="telepathy-gabble DPKG is earlier than 0.7.6-1+lenny1" test_ref="oval:org.mitre.oval:tst:42992"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Release section">
          <extend_definition comment="Debian 6.0 is installed" definition_ref="oval:org.mitre.oval:def:12959"/>
          <criteria operator="OR" comment="Architecture section">
            <criteria operator="AND" comment="Architecture independent section">
              <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criterion comment="telepathy-gabble DPKG is earlier than 0.9.15-1+squeeze1" test_ref="oval:org.mitre.oval:tst:43812"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:12075" version="3" class="patch">
      <metadata>
        <title>DSA-2274-1 wireshark -- several</title>
        <affected family="unix">
          <platform>Debian 5.0</platform>
          <platform>Debian 6.0</platform>
          <product>wireshark</product>
        </affected>
        <reference source="VENDOR" ref_url="http://lists.debian.org/debian-security-announce/2011/msg00146.html" ref_id="DSA-2274-1"/>
        <description>Huzaifa Sidhpurwala, David Maciejak and others discovered several vulnerabilities in the X.509if and DICOM dissectors and in the code to process various capture and dictionary files, which could lead to denial of service or the execution of arbitrary code.</description>
        <oval_repository>
          <dates>
            <submitted date="2011-09-22T15:07:00-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2011-09-22T12:03:44.545-04:00">DRAFT</status_change>
            <status_change date="2011-10-10T04:00:06.011-04:00">INTERIM</status_change>
            <status_change date="2011-10-31T04:00:10.822-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Release section">
          <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
          <criteria operator="OR" comment="Architecture section">
            <criteria operator="AND" comment="Architecture independent section">
              <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criterion comment="wireshark DPKG is earlier than 1.0.2-3+lenny14" test_ref="oval:org.mitre.oval:tst:44147"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Release section">
          <extend_definition comment="Debian 6.0 is installed" definition_ref="oval:org.mitre.oval:def:12959"/>
          <criteria operator="OR" comment="Architecture section">
            <criteria operator="AND" comment="Architecture independent section">
              <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criterion comment="wireshark DPKG is earlier than 1.2.11-6+squeeze2" test_ref="oval:org.mitre.oval:tst:43964"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:12038" version="3" class="patch">
      <metadata>
        <title>DSA-2232-1 exim4 -- format string vulnerability</title>
        <affected family="unix">
          <platform>Debian 6.0</platform>
          <product>exim4</product>
        </affected>
        <reference source="VENDOR" ref_url="http://lists.debian.org/debian-security-announce/2011/msg00101.html" ref_id="DSA-2232-1"/>
        <description>It was discovered that Exim, the default mail transport agent in Debian, uses DKIM data obtain from DNS directly in a format string, potentially allowing malicious mail senders to execute arbitrary code.  The oldstable distribution  is not affected by this problem because it does not contain DKIM support.</description>
        <oval_repository>
          <dates>
            <submitted date="2011-09-22T14:21:32-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2011-09-22T12:03:31.807-04:00">DRAFT</status_change>
            <status_change date="2011-10-10T04:00:05.482-04:00">INTERIM</status_change>
            <status_change date="2011-10-31T04:00:09.837-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Debian 6.0 is installed" definition_ref="oval:org.mitre.oval:def:12959"/>
        <criteria operator="OR" comment="Architecture section">
          <criteria operator="AND" comment="Architecture independent section">
            <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
            <criterion comment="exim4 DPKG is earlier than 4.72-6+squeeze1" test_ref="oval:org.mitre.oval:tst:43985"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:12032" version="3" class="patch">
      <metadata>
        <title>DSA-2216-1 isc-dhcp -- missing input sanitization</title>
        <affected family="unix">
          <platform>Debian 6.0</platform>
          <product>isc-dhcp</product>
        </affected>
        <reference source="VENDOR" ref_url="http://lists.debian.org/debian-security-announce/2011/msg00085.html" ref_id="DSA-2216-1"/>
        <description>Sebastian Krahmer and Marius Tomaschewski discovered that dhclient of isc-dhcp, a DHCP client, is not properly filtering shell meta-characters in certain options in DHCP server responses. These options are reused in an insecure fashion by dhclient scripts. This allows an attacker to execute arbitrary commands with the privileges of such a process by sending crafted DHCP options to a client using a rogue server.</description>
        <oval_repository>
          <dates>
            <submitted date="2011-09-22T12:10:46-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2011-09-22T12:03:28.477-04:00">DRAFT</status_change>
            <status_change date="2011-10-10T04:00:05.246-04:00">INTERIM</status_change>
            <status_change date="2011-10-31T04:00:09.588-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Debian 6.0 is installed" definition_ref="oval:org.mitre.oval:def:12959"/>
        <criteria operator="OR" comment="Architecture section">
          <criteria operator="AND" comment="Architecture independent section">
            <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
            <criterion comment="isc-dhcp DPKG is earlier than 4.1.1-P1-15+squeeze2" test_ref="oval:org.mitre.oval:tst:44097"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11992" version="3" class="patch">
      <metadata>
        <title>DSA-2211-1 vlc -- missing input sanitising</title>
        <affected family="unix">
          <platform>Debian 5.0</platform>
          <platform>Debian 6.0</platform>
          <product>vlc</product>
        </affected>
        <reference source="VENDOR" ref_url="http://lists.debian.org/debian-security-announce/2011/msg00080.html" ref_id="DSA-2211-1"/>
        <description>Ricardo Narvaja discovered that missing input sanitising in VLC, a multimedia player and streamer, could lead to the execution of arbitrary code if a user is tricked into opening a malformed media file. This update also provides updated packages for oldstable  for vulnerabilities, which have already been addressed in Debian stable , either during the freeze or in DSA-2159</description>
        <oval_repository>
          <dates>
            <submitted date="2011-09-22T11:56:54-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2011-09-22T12:03:27.077-04:00">DRAFT</status_change>
            <status_change date="2011-10-10T04:00:04.932-04:00">INTERIM</status_change>
            <status_change date="2011-10-31T04:00:09.271-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Release section">
          <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
          <criteria operator="OR" comment="Architecture section">
            <criteria operator="AND" comment="Architecture independent section">
              <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criterion comment="vlc DPKG is earlier than 0.8.6.h-4+lenny3" test_ref="oval:org.mitre.oval:tst:43806"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Release section">
          <extend_definition comment="Debian 6.0 is installed" definition_ref="oval:org.mitre.oval:def:12959"/>
          <criteria operator="OR" comment="Architecture section">
            <criteria operator="AND" comment="Architecture independent section">
              <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criterion comment="vlc DPKG is earlier than 1.1.3-1squeeze4" test_ref="oval:org.mitre.oval:tst:43982"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6513" version="5" class="inventory">
      <metadata>
        <title>Debian 5.0 is installed</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/o:debian:debian_linux:5.0"/>
        <description>Debian 5.0 is installed</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-04T16:44:51-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-06T20:14:46.813-05:00">DRAFT</status_change>
            <status_change date="2010-01-04T04:01:52.112-05:00">INTERIM</status_change>
            <status_change date="2010-01-25T04:00:22.163-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6513 - Update textfilecontent_test to textfilecontent54_test" date="2011-01-20T13:45:00.069-05:00">
              <contributor organization="SecPod Technologies">Preeti Subramanian</contributor>
            </modified>
            <status_change date="2011-01-20T13:46:58.156-05:00">INTERIM</status_change>
            <status_change date="2011-02-07T04:00:15.513-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:12238 - Pattern match updated &amp; used subexpression in textfilecontent54_state for all states" date="2011-10-21T10:10:00.778-04:00">
              <contributor organization="SecPod Technologies">Chandan S</contributor>
            </modified>
            <status_change date="2011-10-21T10:13:35.218-04:00">INTERIM</status_change>
            <status_change date="2011-11-07T04:01:06.197-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="Debian GNU/Linux 5.0 is installed" test_ref="oval:org.mitre.oval:tst:42061"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:12959" version="4" class="inventory">
      <metadata>
        <title>Debian 6.0 is installed</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 6.0</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/o:debian:debian_linux:6.0"/>
        <description>Debian 6.0 is installed</description>
        <oval_repository>
          <dates>
            <submitted date="2011-09-22T16:40:13">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2011-09-22T12:03:13.885-04:00">DRAFT</status_change>
            <status_change date="2011-10-10T04:00:42.428-04:00">INTERIM</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:15583 - Pattern match updated &amp; used subexpression in textfilecontent54_state for all states" date="2011-10-21T10:10:00.778-04:00">
              <contributor organization="SecPod Technologies">Chandan S</contributor>
            </modified>
            <status_change date="2011-11-07T04:00:46.267-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="Debian 6.0 is installed" test_ref="oval:org.mitre.oval:tst:43618"/>
      </criteria>
    </definition>
  </definitions>
  <tests>
    <dpkginfo_test id="oval:org.mitre.oval:tst:44143" version="1" comment="asterisk DPKG is earlier than 1.6.2.9-2+squeeze3" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:9565"/>
      <state state_ref="oval:org.mitre.oval:ste:12988"/>
    </dpkginfo_test>
    <dpkginfo_test id="oval:org.mitre.oval:tst:44024" version="1" comment="asterisk DPKG is earlier than 1.4.21.2~dfsg-3+lenny3" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:9565"/>
      <state state_ref="oval:org.mitre.oval:ste:12486"/>
    </dpkginfo_test>
    <dpkginfo_test id="oval:org.mitre.oval:tst:44037" version="1" comment="apr DPKG is earlier than 1.2.12-5+lenny4" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15899"/>
      <state state_ref="oval:org.mitre.oval:ste:13030"/>
    </dpkginfo_test>
    <dpkginfo_test id="oval:org.mitre.oval:tst:43152" version="1" comment="apr DPKG is earlier than 1.4.2-6+squeeze2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15899"/>
      <state state_ref="oval:org.mitre.oval:ste:12978"/>
    </dpkginfo_test>
    <dpkginfo_test id="oval:org.mitre.oval:tst:44141" version="1" comment="oprofile DPKG is earlier than 0.9.6-1.1+squeeze1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:16223"/>
      <state state_ref="oval:org.mitre.oval:ste:12660"/>
    </dpkginfo_test>
    <dpkginfo_test id="oval:org.mitre.oval:tst:44007" version="1" comment="oprofile DPKG is earlier than 0.9.3-2+lenny1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:16223"/>
      <state state_ref="oval:org.mitre.oval:ste:12876"/>
    </dpkginfo_test>
    <dpkginfo_test id="oval:org.mitre.oval:tst:44058" version="1" comment="opie DPKG is earlier than 2.32.dfsg.1-0.2+squeeze1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:16027"/>
      <state state_ref="oval:org.mitre.oval:ste:13210"/>
    </dpkginfo_test>
    <dpkginfo_test id="oval:org.mitre.oval:tst:43968" version="1" comment="opie DPKG is earlier than 2.32-10.2+lenny2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:16027"/>
      <state state_ref="oval:org.mitre.oval:ste:13224"/>
    </dpkginfo_test>
    <dpkginfo_test id="oval:org.mitre.oval:tst:43449" version="1" comment="openoffice.org DPKG is earlier than 1:3.2.1-11+squeeze3" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:8253"/>
      <state state_ref="oval:org.mitre.oval:ste:12704"/>
    </dpkginfo_test>
    <dpkginfo_test id="oval:org.mitre.oval:tst:44085" version="1" comment="perl DPKG is earlier than 5.10.0-19lenny4" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11175"/>
      <state state_ref="oval:org.mitre.oval:ste:12705"/>
    </dpkginfo_test>
    <dpkginfo_test id="oval:org.mitre.oval:tst:44040" version="1" comment="perl DPKG is earlier than 5.10.1-17squeeze1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11175"/>
      <state state_ref="oval:org.mitre.oval:ste:13205"/>
    </dpkginfo_test>
    <dpkginfo_test id="oval:org.mitre.oval:tst:43973" version="1" comment="mahara DPKG is earlier than 1.0.4-4+lenny10" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11453"/>
      <state state_ref="oval:org.mitre.oval:ste:13249"/>
    </dpkginfo_test>
    <dpkginfo_test id="oval:org.mitre.oval:tst:43731" version="1" comment="mahara DPKG is earlier than 1.2.6-2+squeeze2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11453"/>
      <state state_ref="oval:org.mitre.oval:ste:12844"/>
    </dpkginfo_test>
    <dpkginfo_test id="oval:org.mitre.oval:tst:44053" version="1" comment="openjdk-6 DPKG is earlier than 6b18-1.8.7-2~lenny1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:16194"/>
      <state state_ref="oval:org.mitre.oval:ste:13138"/>
    </dpkginfo_test>
    <dpkginfo_test id="oval:org.mitre.oval:tst:43745" version="1" comment="openjdk-6 DPKG is earlier than 6b18-1.8.7-2~squeeze1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:16194"/>
      <state state_ref="oval:org.mitre.oval:ste:13212"/>
    </dpkginfo_test>
    <dpkginfo_test id="oval:org.mitre.oval:tst:44188" version="1" comment="libapache2-mod-authnz-external DPKG is earlier than 3.2.4-2+squeeze1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:16240"/>
      <state state_ref="oval:org.mitre.oval:ste:13159"/>
    </dpkginfo_test>
    <dpkginfo_test id="oval:org.mitre.oval:tst:43819" version="1" comment="iceweasel DPKG is earlier than 1.9.0.19-12" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:7910"/>
      <state state_ref="oval:org.mitre.oval:ste:13074"/>
    </dpkginfo_test>
    <dpkginfo_test id="oval:org.mitre.oval:tst:43658" version="1" comment="iceweasel DPKG is earlier than 3.5.16-9" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:7910"/>
      <state state_ref="oval:org.mitre.oval:ste:13198"/>
    </dpkginfo_test>
    <dpkginfo_test id="oval:org.mitre.oval:tst:44229" version="1" comment="perl DPKG is earlier than 5.10.0-19lenny5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11175"/>
      <state state_ref="oval:org.mitre.oval:ste:13143"/>
    </dpkginfo_test>
    <dpkginfo_test id="oval:org.mitre.oval:tst:44087" version="1" comment="perl DPKG is earlier than 5.10.1-17squeeze2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11175"/>
      <state state_ref="oval:org.mitre.oval:ste:12530"/>
    </dpkginfo_test>
    <dpkginfo_test id="oval:org.mitre.oval:tst:44183" version="1" comment="bind9 DPKG is earlier than 1:9.6.ESV.R4+dfsg-0+lenny3" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:8093"/>
      <state state_ref="oval:org.mitre.oval:ste:13189"/>
    </dpkginfo_test>
    <dpkginfo_test id="oval:org.mitre.oval:tst:44080" version="1" comment="bind9 DPKG is earlier than 1:9.7.3.dfsg-1~squeeze3" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:8093"/>
      <state state_ref="oval:org.mitre.oval:ste:13029"/>
    </dpkginfo_test>
    <dpkginfo_test id="oval:org.mitre.oval:tst:44180" version="1" comment="libvirt DPKG is earlier than 0.8.3-5+squeeze2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:16020"/>
      <state state_ref="oval:org.mitre.oval:ste:13234"/>
    </dpkginfo_test>
    <dpkginfo_test id="oval:org.mitre.oval:tst:43931" version="1" comment="libvirt DPKG is earlier than 0.4.6-10+lenny2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:16020"/>
      <state state_ref="oval:org.mitre.oval:ste:12665"/>
    </dpkginfo_test>
    <dpkginfo_test id="oval:org.mitre.oval:tst:44118" version="1" comment="tiff DPKG is earlier than 3.9.4-5+squeeze1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:16301"/>
      <state state_ref="oval:org.mitre.oval:ste:12851"/>
    </dpkginfo_test>
    <dpkginfo_test id="oval:org.mitre.oval:tst:44041" version="1" comment="postfix DPKG is earlier than 2.5.5-1.1+lenny1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:8366"/>
      <state state_ref="oval:org.mitre.oval:ste:13188"/>
    </dpkginfo_test>
    <dpkginfo_test id="oval:org.mitre.oval:tst:43894" version="1" comment="postfix DPKG is earlier than 2.7.1-1+squeeze1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:8366"/>
      <state state_ref="oval:org.mitre.oval:ste:12923"/>
    </dpkginfo_test>
    <dpkginfo_test id="oval:org.mitre.oval:tst:43925" version="1" comment="libmodplug DPKG is earlier than 1:0.8.8.1-1+squeeze1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:16202"/>
      <state state_ref="oval:org.mitre.oval:ste:12948"/>
    </dpkginfo_test>
    <dpkginfo_test id="oval:org.mitre.oval:tst:43864" version="1" comment="libmodplug DPKG is earlier than 0.8.4-1+lenny2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:16202"/>
      <state state_ref="oval:org.mitre.oval:ste:12523"/>
    </dpkginfo_test>
    <dpkginfo_test id="oval:org.mitre.oval:tst:44106" version="1" comment="linux-2.6 DPKG is earlier than 2.6.32-34squeeze1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:16152"/>
      <state state_ref="oval:org.mitre.oval:ste:12807"/>
    </dpkginfo_test>
    <dpkginfo_test id="oval:org.mitre.oval:tst:44079" version="1" comment="libsndfile DPKG is earlier than 1.0.17-4+lenny3" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:16232"/>
      <state state_ref="oval:org.mitre.oval:ste:13097"/>
    </dpkginfo_test>
    <dpkginfo_test id="oval:org.mitre.oval:tst:43537" version="1" comment="libsndfile DPKG is earlier than 1.0.21-3+squeeze1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:16232"/>
      <state state_ref="oval:org.mitre.oval:ste:12740"/>
    </dpkginfo_test>
    <dpkginfo_test id="oval:org.mitre.oval:tst:44089" version="1" comment="iceape DPKG is earlier than 2.0.11-5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:8166"/>
      <state state_ref="oval:org.mitre.oval:ste:13155"/>
    </dpkginfo_test>
    <dpkginfo_test id="oval:org.mitre.oval:tst:43959" version="1" comment="mapserver DPKG is earlier than 5.0.3-3+lenny7" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:16302"/>
      <state state_ref="oval:org.mitre.oval:ste:13134"/>
    </dpkginfo_test>
    <dpkginfo_test id="oval:org.mitre.oval:tst:43855" version="1" comment="mapserver DPKG is earlier than 5.6.5-2+squeeze2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:16302"/>
      <state state_ref="oval:org.mitre.oval:ste:13069"/>
    </dpkginfo_test>
    <dpkginfo_test id="oval:org.mitre.oval:tst:44197" version="1" comment="curl DPKG is earlier than 7.21.0-2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11200"/>
      <state state_ref="oval:org.mitre.oval:ste:13054"/>
    </dpkginfo_test>
    <dpkginfo_test id="oval:org.mitre.oval:tst:44036" version="1" comment="curl DPKG is earlier than 7.18.2-8lenny5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11200"/>
      <state state_ref="oval:org.mitre.oval:ste:12960"/>
    </dpkginfo_test>
    <dpkginfo_test id="oval:org.mitre.oval:tst:43927" version="1" comment="spip DPKG is earlier than 2.1.1-3squeeze1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:16254"/>
      <state state_ref="oval:org.mitre.oval:ste:12697"/>
    </dpkginfo_test>
    <dpkginfo_test id="oval:org.mitre.oval:tst:44166" version="1" comment="chromium-browser DPKG is earlier than 6.0.472.63~r59945-5+squeeze5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15407"/>
      <state state_ref="oval:org.mitre.oval:ste:13228"/>
    </dpkginfo_test>
    <dpkginfo_test id="oval:org.mitre.oval:tst:44055" version="1" comment="tinyproxy DPKG is earlier than 1.8.2-1squeeze1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:16278"/>
      <state state_ref="oval:org.mitre.oval:ste:13007"/>
    </dpkginfo_test>
    <dpkginfo_test id="oval:org.mitre.oval:tst:43809" version="1" comment="vino DPKG is earlier than 2.28.2-2+squeeze1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15873"/>
      <state state_ref="oval:org.mitre.oval:ste:13181"/>
    </dpkginfo_test>
    <dpkginfo_test id="oval:org.mitre.oval:tst:43953" version="1" comment="imp4 DPKG is earlier than 4.3.7+debian0-2.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:10842"/>
      <state state_ref="oval:org.mitre.oval:ste:13075"/>
    </dpkginfo_test>
    <dpkginfo_test id="oval:org.mitre.oval:tst:43083" version="1" comment="imp4 DPKG is earlier than 4.2-4lenny3" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:10842"/>
      <state state_ref="oval:org.mitre.oval:ste:12633"/>
    </dpkginfo_test>
    <dpkginfo_test id="oval:org.mitre.oval:tst:44030" version="1" comment="qemu-kvm DPKG is earlier than 0.12.5+dfsg-5+squeeze1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:16208"/>
      <state state_ref="oval:org.mitre.oval:ste:13070"/>
    </dpkginfo_test>
    <dpkginfo_test id="oval:org.mitre.oval:tst:43883" version="1" comment="icedove DPKG is earlier than 3.0.11-1+squeeze1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:8612"/>
      <state state_ref="oval:org.mitre.oval:ste:12671"/>
    </dpkginfo_test>
    <dpkginfo_test id="oval:org.mitre.oval:tst:43958" version="1" comment="vlc DPKG is earlier than 1.1.3-1squeeze5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:10387"/>
      <state state_ref="oval:org.mitre.oval:ste:13001"/>
    </dpkginfo_test>
    <dpkginfo_test id="oval:org.mitre.oval:tst:44033" version="1" comment="subversion DPKG is earlier than 1.6.12dfsg-5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11585"/>
      <state state_ref="oval:org.mitre.oval:ste:12590"/>
    </dpkginfo_test>
    <dpkginfo_test id="oval:org.mitre.oval:tst:44015" version="1" comment="subversion DPKG is earlier than 1.5.1dfsg1-6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11585"/>
      <state state_ref="oval:org.mitre.oval:ste:13014"/>
    </dpkginfo_test>
    <dpkginfo_test id="oval:org.mitre.oval:tst:44066" version="1" comment="dovecot DPKG is earlier than 1.2.15-7" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15862"/>
      <state state_ref="oval:org.mitre.oval:ste:13044"/>
    </dpkginfo_test>
    <dpkginfo_test id="oval:org.mitre.oval:tst:43717" version="1" comment="pango1.0 DPKG is earlier than 1.28.3-1+squeeze2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15560"/>
      <state state_ref="oval:org.mitre.oval:ste:13065"/>
    </dpkginfo_test>
    <dpkginfo_test id="oval:org.mitre.oval:tst:44236" version="1" comment="tiff DPKG is earlier than 3.8.2-11.5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:16301"/>
      <state state_ref="oval:org.mitre.oval:ste:13194"/>
    </dpkginfo_test>
    <dpkginfo_test id="oval:org.mitre.oval:tst:44113" version="1" comment="tiff DPKG is earlier than 3.9.4-5+squeeze3" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:16301"/>
      <state state_ref="oval:org.mitre.oval:ste:12795"/>
    </dpkginfo_test>
    <dpkginfo_test id="oval:org.mitre.oval:tst:44047" version="1" comment="wordpress DPKG is earlier than 3.0.5+dfsg-0+squeeze1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:10660"/>
      <state state_ref="oval:org.mitre.oval:ste:13102"/>
    </dpkginfo_test>
    <dpkginfo_test id="oval:org.mitre.oval:tst:43880" version="1" comment="isc-dhcp DPKG is earlier than 4.1.1-P1-15+squeeze1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15700"/>
      <state state_ref="oval:org.mitre.oval:ste:12332"/>
    </dpkginfo_test>
    <dpkginfo_test id="oval:org.mitre.oval:tst:44115" version="1" comment="qemu-kvm DPKG is earlier than 0.12.5+dfsg-5+squeeze6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:16208"/>
      <state state_ref="oval:org.mitre.oval:ste:12928"/>
    </dpkginfo_test>
    <dpkginfo_test id="oval:org.mitre.oval:tst:43942" version="1" comment="tex-common DPKG is earlier than 2.08.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15789"/>
      <state state_ref="oval:org.mitre.oval:ste:13048"/>
    </dpkginfo_test>
    <dpkginfo_test id="oval:org.mitre.oval:tst:44029" version="1" comment="apr DPKG is earlier than 1.2.12-5+lenny3" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15899"/>
      <state state_ref="oval:org.mitre.oval:ste:13200"/>
    </dpkginfo_test>
    <dpkginfo_test id="oval:org.mitre.oval:tst:43933" version="1" comment="apr DPKG is earlier than 1.4.2-6+squeeze1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15899"/>
      <state state_ref="oval:org.mitre.oval:ste:12813"/>
    </dpkginfo_test>
    <dpkginfo_test id="oval:org.mitre.oval:tst:44107" version="1" comment="x11-xserver-utils DPKG is earlier than 7.5+3" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:16200"/>
      <state state_ref="oval:org.mitre.oval:ste:12668"/>
    </dpkginfo_test>
    <dpkginfo_test id="oval:org.mitre.oval:tst:44139" version="1" comment="ejabberd DPKG is earlier than 2.0.1-6+lenny3" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11524"/>
      <state state_ref="oval:org.mitre.oval:ste:13147"/>
    </dpkginfo_test>
    <dpkginfo_test id="oval:org.mitre.oval:tst:44131" version="1" comment="ejabberd DPKG is earlier than 2.1.5-3+squeeze1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11524"/>
      <state state_ref="oval:org.mitre.oval:ste:13233"/>
    </dpkginfo_test>
    <dpkginfo_test id="oval:org.mitre.oval:tst:43771" version="1" comment="openssl DPKG is earlier than 0.9.8o-4squeeze1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:7747"/>
      <state state_ref="oval:org.mitre.oval:ste:12747"/>
    </dpkginfo_test>
    <dpkginfo_test id="oval:org.mitre.oval:tst:43696" version="1" comment="bind9 DPKG is earlier than 1:9.7.3.dfsg-1~squeeze1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:8093"/>
      <state state_ref="oval:org.mitre.oval:ste:12718"/>
    </dpkginfo_test>
    <dpkginfo_test id="oval:org.mitre.oval:tst:44018" version="1" comment="asterisk DPKG is earlier than 1:1.6.2.9-2+squeeze2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:9565"/>
      <state state_ref="oval:org.mitre.oval:ste:12176"/>
    </dpkginfo_test>
    <dpkginfo_test id="oval:org.mitre.oval:tst:43839" version="1" comment="asterisk DPKG is earlier than 1:1.4.21.2~dfsg-3+lenny2.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:9565"/>
      <state state_ref="oval:org.mitre.oval:ste:13096"/>
    </dpkginfo_test>
    <dpkginfo_test id="oval:org.mitre.oval:tst:43710" version="1" comment="samba DPKG is earlier than 3.2.5-4lenny14" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:8058"/>
      <state state_ref="oval:org.mitre.oval:ste:13011"/>
    </dpkginfo_test>
    <dpkginfo_test id="oval:org.mitre.oval:tst:43089" version="1" comment="samba DPKG is earlier than 3.5.6~dfsg-3squeeze2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:8058"/>
      <state state_ref="oval:org.mitre.oval:ste:12936"/>
    </dpkginfo_test>
    <dpkginfo_test id="oval:org.mitre.oval:tst:43012" version="1" comment="chromium-browser DPKG is earlier than 6.0.472.63~r59945-5+squeeze2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15407"/>
      <state state_ref="oval:org.mitre.oval:ste:12871"/>
    </dpkginfo_test>
    <dpkginfo_test id="oval:org.mitre.oval:tst:43699" version="1" comment="tomcat6 DPKG is earlier than 6.0.28-9+squeeze1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:16192"/>
      <state state_ref="oval:org.mitre.oval:ste:13095"/>
    </dpkginfo_test>
    <dpkginfo_test id="oval:org.mitre.oval:tst:43384" version="1" comment="rails DPKG is earlier than 2.1.0-7+lenny0.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:8355"/>
      <state state_ref="oval:org.mitre.oval:ste:13058"/>
    </dpkginfo_test>
    <dpkginfo_test id="oval:org.mitre.oval:tst:43242" version="1" comment="rails DPKG is earlier than 2.3.5-1.2+squeeze0.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:8355"/>
      <state state_ref="oval:org.mitre.oval:ste:13022"/>
    </dpkginfo_test>
    <dpkginfo_test id="oval:org.mitre.oval:tst:44247" version="1" comment="opensaml2 DPKG is earlier than 2.3-2+squeeze1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15881"/>
      <state state_ref="oval:org.mitre.oval:ste:12918"/>
    </dpkginfo_test>
    <dpkginfo_test id="oval:org.mitre.oval:tst:44144" version="1" comment="opensaml2 DPKG is earlier than 2.0-2+lenny3" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15881"/>
      <state state_ref="oval:org.mitre.oval:ste:13227"/>
    </dpkginfo_test>
    <dpkginfo_test id="oval:org.mitre.oval:tst:43758" version="1" comment="movabletype-opensource DPKG is earlier than 4.3.5+dfsg-2+squeeze2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:16238"/>
      <state state_ref="oval:org.mitre.oval:ste:13220"/>
    </dpkginfo_test>
    <dpkginfo_test id="oval:org.mitre.oval:tst:43938" version="1" comment="openjdk-6 DPKG is earlier than 6b18-1.8.3-2+squeeze1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:16194"/>
      <state state_ref="oval:org.mitre.oval:ste:12922"/>
    </dpkginfo_test>
    <dpkginfo_test id="oval:org.mitre.oval:tst:44182" version="1" comment="citadel DPKG is earlier than 7.83-2squeeze2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15306"/>
      <state state_ref="oval:org.mitre.oval:ste:12674"/>
    </dpkginfo_test>
    <dpkginfo_test id="oval:org.mitre.oval:tst:43909" version="1" comment="citadel DPKG is earlier than 7.37-8+lenny1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15306"/>
      <state state_ref="oval:org.mitre.oval:ste:12259"/>
    </dpkginfo_test>
    <dpkginfo_test id="oval:org.mitre.oval:tst:43403" version="1" comment="icedove DPKG is earlier than 3.0.11-1+squeeze2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:8612"/>
      <state state_ref="oval:org.mitre.oval:ste:13170"/>
    </dpkginfo_test>
    <dpkginfo_test id="oval:org.mitre.oval:tst:44011" version="1" comment="tgt DPKG is earlier than 1:1.0.4-2squeeze1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15676"/>
      <state state_ref="oval:org.mitre.oval:ste:12548"/>
    </dpkginfo_test>
    <dpkginfo_test id="oval:org.mitre.oval:tst:43490" version="1" comment="nss DPKG is earlier than 3.12.8-1+squeeze1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15604"/>
      <state state_ref="oval:org.mitre.oval:ste:12629"/>
    </dpkginfo_test>
    <dpkginfo_test id="oval:org.mitre.oval:tst:43108" version="1" comment="nss DPKG is earlier than 3.12.3.1-0lenny4" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15604"/>
      <state state_ref="oval:org.mitre.oval:ste:13122"/>
    </dpkginfo_test>
    <dpkginfo_test id="oval:org.mitre.oval:tst:44014" version="1" comment="iceweasel DPKG is earlier than 1.9.0.19-8" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:7910"/>
      <state state_ref="oval:org.mitre.oval:ste:13105"/>
    </dpkginfo_test>
    <dpkginfo_test id="oval:org.mitre.oval:tst:43650" version="1" comment="iceweasel DPKG is earlier than 3.5.16-5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:7910"/>
      <state state_ref="oval:org.mitre.oval:ste:12608"/>
    </dpkginfo_test>
    <dpkginfo_test id="oval:org.mitre.oval:tst:43951" version="1" comment="shadow DPKG is earlier than 1:4.1.4.2+svn3283-2+squeeze1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:16304"/>
      <state state_ref="oval:org.mitre.oval:ste:12802"/>
    </dpkginfo_test>
    <dpkginfo_test id="oval:org.mitre.oval:tst:43638" version="1" comment="logwatch DPKG is earlier than 7.3.6.cvs20080702-2lenny1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15747"/>
      <state state_ref="oval:org.mitre.oval:ste:12773"/>
    </dpkginfo_test>
    <dpkginfo_test id="oval:org.mitre.oval:tst:43381" version="1" comment="logwatch DPKG is earlier than 7.3.6.cvs20090906-1squeeze1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15747"/>
      <state state_ref="oval:org.mitre.oval:ste:13031"/>
    </dpkginfo_test>
    <dpkginfo_test id="oval:org.mitre.oval:tst:43841" version="1" comment="iceape DPKG is earlier than 2.0.11-3" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:8166"/>
      <state state_ref="oval:org.mitre.oval:ste:12553"/>
    </dpkginfo_test>
    <dpkginfo_test id="oval:org.mitre.oval:tst:44102" version="1" comment="oprofile DPKG is earlier than 0.9.3-2+lenny2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:16223"/>
      <state state_ref="oval:org.mitre.oval:ste:13151"/>
    </dpkginfo_test>
    <dpkginfo_test id="oval:org.mitre.oval:tst:43621" version="1" comment="oprofile DPKG is earlier than 0.9.6-1.1+squeeze2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:16223"/>
      <state state_ref="oval:org.mitre.oval:ste:12425"/>
    </dpkginfo_test>
    <dpkginfo_test id="oval:org.mitre.oval:tst:44125" version="1" comment="request-tracker3.6, request-tracker3.8 DPKG is earlier than 3.6.7-5+lenny6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:16259"/>
      <state state_ref="oval:org.mitre.oval:ste:13100"/>
    </dpkginfo_test>
    <dpkginfo_test id="oval:org.mitre.oval:tst:43862" version="1" comment="request-tracker3.6, request-tracker3.8 DPKG is earlier than 3.8.8-7+squeeze1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:16259"/>
      <state state_ref="oval:org.mitre.oval:ste:13161"/>
    </dpkginfo_test>
    <dpkginfo_test id="oval:org.mitre.oval:tst:43792" version="1" comment="krb5-appl DPKG is earlier than 1.0.1-1.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:16215"/>
      <state state_ref="oval:org.mitre.oval:ste:13158"/>
    </dpkginfo_test>
    <dpkginfo_test id="oval:org.mitre.oval:tst:43587" version="1" comment="gdm3 DPKG is earlier than 2.30.5-6squeeze2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:16106"/>
      <state state_ref="oval:org.mitre.oval:ste:12461"/>
    </dpkginfo_test>
    <dpkginfo_test id="oval:org.mitre.oval:tst:43533" version="1" comment="chromium-browser DPKG is earlier than 6.0.472.63~r59945-5+squeeze4" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15407"/>
      <state state_ref="oval:org.mitre.oval:ste:13018"/>
    </dpkginfo_test>
    <dpkginfo_test id="oval:org.mitre.oval:tst:43616" version="1" comment="tiff DPKG is earlier than 3.9.4-5+squeeze2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:16301"/>
      <state state_ref="oval:org.mitre.oval:ste:12827"/>
    </dpkginfo_test>
    <dpkginfo_test id="oval:org.mitre.oval:tst:44172" version="1" comment="horde3 DPKG is earlier than 3.3.8+debian0-2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:7672"/>
      <state state_ref="oval:org.mitre.oval:ste:13077"/>
    </dpkginfo_test>
    <dpkginfo_test id="oval:org.mitre.oval:tst:44069" version="1" comment="horde3 DPKG is earlier than 3.2.2+debian0-2+lenny3" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:7672"/>
      <state state_ref="oval:org.mitre.oval:ste:13243"/>
    </dpkginfo_test>
    <dpkginfo_test id="oval:org.mitre.oval:tst:43929" version="1" comment="proftpd-dfsg DPKG is earlier than 1.3.3a-6squeeze1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:16019"/>
      <state state_ref="oval:org.mitre.oval:ste:12794"/>
    </dpkginfo_test>
    <dpkginfo_test id="oval:org.mitre.oval:tst:43817" version="1" comment="php5 DPKG is earlier than 5.3.3-7+squeeze1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:7704"/>
      <state state_ref="oval:org.mitre.oval:ste:12758"/>
    </dpkginfo_test>
    <dpkginfo_test id="oval:org.mitre.oval:tst:43754" version="1" comment="php5 DPKG is earlier than 5.2.6.dfsg.1-1+lenny10" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:7704"/>
      <state state_ref="oval:org.mitre.oval:ste:12873"/>
    </dpkginfo_test>
    <dpkginfo_test id="oval:org.mitre.oval:tst:43944" version="1" comment="exim4 DPKG is earlier than 4.72-6+squeeze2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:16256"/>
      <state state_ref="oval:org.mitre.oval:ste:12719"/>
    </dpkginfo_test>
    <dpkginfo_test id="oval:org.mitre.oval:tst:43189" version="1" comment="chromium-browser DPKG is earlier than 6.0.472.63~r59945-5+squeeze3" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15407"/>
      <state state_ref="oval:org.mitre.oval:ste:13005"/>
    </dpkginfo_test>
    <dpkginfo_test id="oval:org.mitre.oval:tst:44063" version="1" comment="bind9 DPKG is earlier than 1:9.6.ESV.R4+dfsg-0+lenny2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:8093"/>
      <state state_ref="oval:org.mitre.oval:ste:13156"/>
    </dpkginfo_test>
    <dpkginfo_test id="oval:org.mitre.oval:tst:43217" version="1" comment="bind9 DPKG is earlier than 1:9.7.3.dfsg-1~squeeze2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:8093"/>
      <state state_ref="oval:org.mitre.oval:ste:12855"/>
    </dpkginfo_test>
    <dpkginfo_test id="oval:org.mitre.oval:tst:44039" version="1" comment="iceape DPKG is earlier than 2.0.11-6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:8166"/>
      <state state_ref="oval:org.mitre.oval:ste:12551"/>
    </dpkginfo_test>
    <dpkginfo_test id="oval:org.mitre.oval:tst:43873" version="1" comment="otrs2 DPKG is earlier than 2.4.9+dfsg1-3+squeeze1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:10416"/>
      <state state_ref="oval:org.mitre.oval:ste:13136"/>
    </dpkginfo_test>
    <dpkginfo_test id="oval:org.mitre.oval:tst:43946" version="1" comment="doctrine DPKG is earlier than 1.2.2-2+squeeze1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:16063"/>
      <state state_ref="oval:org.mitre.oval:ste:12696"/>
    </dpkginfo_test>
    <dpkginfo_test id="oval:org.mitre.oval:tst:43979" version="1" comment="openafs DPKG is earlier than 1.4.12.1+dfsg-4" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:16077"/>
      <state state_ref="oval:org.mitre.oval:ste:13067"/>
    </dpkginfo_test>
    <dpkginfo_test id="oval:org.mitre.oval:tst:43681" version="1" comment="openafs DPKG is earlier than 1.4.7.dfsg1-6+lenny4" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:16077"/>
      <state state_ref="oval:org.mitre.oval:ste:13084"/>
    </dpkginfo_test>
    <dpkginfo_test id="oval:org.mitre.oval:tst:43559" version="1" comment="kolab-cyrus-imapd DPKG is earlier than 2.2.13-9.1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11738"/>
      <state state_ref="oval:org.mitre.oval:ste:13225"/>
    </dpkginfo_test>
    <dpkginfo_test id="oval:org.mitre.oval:tst:43429" version="1" comment="kolab-cyrus-imapd DPKG is earlier than 2.2.13-5+lenny3" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11738"/>
      <state state_ref="oval:org.mitre.oval:ste:12561"/>
    </dpkginfo_test>
    <dpkginfo_test id="oval:org.mitre.oval:tst:44135" version="1" comment="xmlsec1 DPKG is earlier than 1.2.14-1+squeeze1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:16205"/>
      <state state_ref="oval:org.mitre.oval:ste:12511"/>
    </dpkginfo_test>
    <dpkginfo_test id="oval:org.mitre.oval:tst:44073" version="1" comment="xmlsec1 DPKG is earlier than 1.2.9-5+lenny1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:16205"/>
      <state state_ref="oval:org.mitre.oval:ste:12469"/>
    </dpkginfo_test>
    <dpkginfo_test id="oval:org.mitre.oval:tst:44198" version="1" comment="phpymadmin DPKG is earlier than 3.3.7-6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15804"/>
      <state state_ref="oval:org.mitre.oval:ste:13216"/>
    </dpkginfo_test>
    <dpkginfo_test id="oval:org.mitre.oval:tst:43924" version="1" comment="fex DPKG is earlier than 20100208+debian1-1+squeeze1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:16116"/>
      <state state_ref="oval:org.mitre.oval:ste:12768"/>
    </dpkginfo_test>
    <dpkginfo_test id="oval:org.mitre.oval:tst:44077" version="1" comment="tmux DPKG is earlier than 1.3-2+squeeze1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15994"/>
      <state state_ref="oval:org.mitre.oval:ste:12959"/>
    </dpkginfo_test>
    <dpkginfo_test id="oval:org.mitre.oval:tst:43954" version="1" comment="vlc DPKG is earlier than 1.1.3-1squeeze3" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:10387"/>
      <state state_ref="oval:org.mitre.oval:ste:12901"/>
    </dpkginfo_test>
    <dpkginfo_test id="oval:org.mitre.oval:tst:44059" version="1" comment="subversion DPKG is earlier than 1.5.1dfsg1-7" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11585"/>
      <state state_ref="oval:org.mitre.oval:ste:12393"/>
    </dpkginfo_test>
    <dpkginfo_test id="oval:org.mitre.oval:tst:44025" version="1" comment="subversion DPKG is earlier than 1.6.12dfsg-6" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11585"/>
      <state state_ref="oval:org.mitre.oval:ste:12964"/>
    </dpkginfo_test>
    <dpkginfo_test id="oval:org.mitre.oval:tst:43872" version="1" comment="libcgroup DPKG is earlier than 0.36.2-3+squeeze1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:16252"/>
      <state state_ref="oval:org.mitre.oval:ste:13124"/>
    </dpkginfo_test>
    <dpkginfo_test id="oval:org.mitre.oval:tst:44072" version="1" comment="iceweasel DPKG is earlier than 3.5.16-7" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:7910"/>
      <state state_ref="oval:org.mitre.oval:ste:13152"/>
    </dpkginfo_test>
    <dpkginfo_test id="oval:org.mitre.oval:tst:43971" version="1" comment="dajaxice DPKG is earlier than 0.1.5-1squeeze1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:16169"/>
      <state state_ref="oval:org.mitre.oval:ste:13062"/>
    </dpkginfo_test>
    <dpkginfo_test id="oval:org.mitre.oval:tst:43139" version="1" comment="libmojolicious-perl DPKG is earlier than 0.999926-1+squeeze1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15491"/>
      <state state_ref="oval:org.mitre.oval:ste:13056"/>
    </dpkginfo_test>
    <dpkginfo_test id="oval:org.mitre.oval:tst:44134" version="1" comment="qemu-kvm DPKG is earlier than 0.12.5+dfsg-5+squeeze2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:16208"/>
      <state state_ref="oval:org.mitre.oval:ste:12976"/>
    </dpkginfo_test>
    <dpkginfo_test id="oval:org.mitre.oval:tst:43826" version="1" comment="pam-pgsql DPKG is earlier than 0.7.1-4+squeeze1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:16146"/>
      <state state_ref="oval:org.mitre.oval:ste:12123"/>
    </dpkginfo_test>
    <dpkginfo_test id="oval:org.mitre.oval:tst:43073" version="1" comment="pam-pgsql DPKG is earlier than 0.6.3-2+lenny1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:16146"/>
      <state state_ref="oval:org.mitre.oval:ste:13106"/>
    </dpkginfo_test>
    <dpkginfo_test id="oval:org.mitre.oval:tst:44109" version="1" comment="jabberd14 DPKG is earlier than 1.6.1.1-5+squeeze1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:16173"/>
      <state state_ref="oval:org.mitre.oval:ste:13217"/>
    </dpkginfo_test>
    <dpkginfo_test id="oval:org.mitre.oval:tst:44230" version="1" comment="libxml2 DPKG is earlier than 2.6.32.dfsg-5+lenny4" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:8060"/>
      <state state_ref="oval:org.mitre.oval:ste:13060"/>
    </dpkginfo_test>
    <dpkginfo_test id="oval:org.mitre.oval:tst:44210" version="1" comment="libxml2 DPKG is earlier than 2.7.8.dfsg-2+squeeze1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:8060"/>
      <state state_ref="oval:org.mitre.oval:ste:13110"/>
    </dpkginfo_test>
    <dpkginfo_test id="oval:org.mitre.oval:tst:43975" version="1" comment="cyrus-imapd-2.2 DPKG is earlier than 2.2.13-14+lenny4" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:8722"/>
      <state state_ref="oval:org.mitre.oval:ste:13008"/>
    </dpkginfo_test>
    <dpkginfo_test id="oval:org.mitre.oval:tst:43881" version="1" comment="cyrus-imapd-2.2 DPKG is earlier than 2.2.13-19+squeeze1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:8722"/>
      <state state_ref="oval:org.mitre.oval:ste:13226"/>
    </dpkginfo_test>
    <dpkginfo_test id="oval:org.mitre.oval:tst:43981" version="1" comment="libvirt DPKG is earlier than 0.8.3-5+squeeze1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:16020"/>
      <state state_ref="oval:org.mitre.oval:ste:12474"/>
    </dpkginfo_test>
    <dpkginfo_test id="oval:org.mitre.oval:tst:43961" version="1" comment="pywebdav DPKG is earlier than 0.9.4-1+squeeze1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15762"/>
      <state state_ref="oval:org.mitre.oval:ste:12842"/>
    </dpkginfo_test>
    <dpkginfo_test id="oval:org.mitre.oval:tst:44187" version="1" comment="libpng DPKG is earlier than 1.2.27-2+lenny5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:16285"/>
      <state state_ref="oval:org.mitre.oval:ste:13114"/>
    </dpkginfo_test>
    <dpkginfo_test id="oval:org.mitre.oval:tst:43887" version="1" comment="libpng DPKG is earlier than 1.2.44-1+squeeze1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:16285"/>
      <state state_ref="oval:org.mitre.oval:ste:13173"/>
    </dpkginfo_test>
    <dpkginfo_test id="oval:org.mitre.oval:tst:43998" version="1" comment="avahi DPKG is earlier than 0.6.27-2+squeeze1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15863"/>
      <state state_ref="oval:org.mitre.oval:ste:12110"/>
    </dpkginfo_test>
    <dpkginfo_test id="oval:org.mitre.oval:tst:43469" version="1" comment="avahi DPKG is earlier than 0.6.23-3lenny3" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15863"/>
      <state state_ref="oval:org.mitre.oval:ste:13109"/>
    </dpkginfo_test>
    <dpkginfo_test id="oval:org.mitre.oval:tst:44132" version="1" comment="mahara DPKG is earlier than 1.2.6-2+squeeze1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11453"/>
      <state state_ref="oval:org.mitre.oval:ste:13193"/>
    </dpkginfo_test>
    <dpkginfo_test id="oval:org.mitre.oval:tst:44114" version="1" comment="mahara DPKG is earlier than 1.0.4-4+lenny8" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11453"/>
      <state state_ref="oval:org.mitre.oval:ste:12750"/>
    </dpkginfo_test>
    <dpkginfo_test id="oval:org.mitre.oval:tst:44211" version="1" comment="xml-security-c DPKG is earlier than 1.4.0-3+lenny3" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15909"/>
      <state state_ref="oval:org.mitre.oval:ste:13166"/>
    </dpkginfo_test>
    <dpkginfo_test id="oval:org.mitre.oval:tst:43273" version="1" comment="xml-security-c DPKG is earlier than 1.5.1-3+squeeze1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15909"/>
      <state state_ref="oval:org.mitre.oval:ste:13172"/>
    </dpkginfo_test>
    <dpkginfo_test id="oval:org.mitre.oval:tst:44061" version="1" comment="quagga DPKG is earlier than 0.99.17-2+squeeze2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11349"/>
      <state state_ref="oval:org.mitre.oval:ste:13082"/>
    </dpkginfo_test>
    <dpkginfo_test id="oval:org.mitre.oval:tst:43815" version="1" comment="quagga DPKG is earlier than 0.99.10-1lenny5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11349"/>
      <state state_ref="oval:org.mitre.oval:ste:13104"/>
    </dpkginfo_test>
    <dpkginfo_test id="oval:org.mitre.oval:tst:43882" version="1" comment="asterisk DPKG is earlier than 1.6.2.9-2+squeeze1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:9565"/>
      <state state_ref="oval:org.mitre.oval:ste:13045"/>
    </dpkginfo_test>
    <dpkginfo_test id="oval:org.mitre.oval:tst:43291" version="1" comment="asterisk DPKG is earlier than 1.4.21.2~dfsg-3+lenny2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:9565"/>
      <state state_ref="oval:org.mitre.oval:ste:13039"/>
    </dpkginfo_test>
    <dpkginfo_test id="oval:org.mitre.oval:tst:44101" version="1" comment="qemu-kvm DPKG is earlier than 0.12.5+dfsg-5+squeeze4" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:16208"/>
      <state state_ref="oval:org.mitre.oval:ste:12733"/>
    </dpkginfo_test>
    <dpkginfo_test id="oval:org.mitre.oval:tst:43453" version="1" comment="python-django DPKG is earlier than 1.2.3-3+squeeze1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:7913"/>
      <state state_ref="oval:org.mitre.oval:ste:13026"/>
    </dpkginfo_test>
    <dpkginfo_test id="oval:org.mitre.oval:tst:43955" version="1" comment="phpmyadmin DPKG is earlier than 4:2.11.8.1-5+lenny8" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:10745"/>
      <state state_ref="oval:org.mitre.oval:ste:12992"/>
    </dpkginfo_test>
    <dpkginfo_test id="oval:org.mitre.oval:tst:42996" version="1" comment="phpmyadmin DPKG is earlier than 4:3.3.7-5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:10745"/>
      <state state_ref="oval:org.mitre.oval:ste:13036"/>
    </dpkginfo_test>
    <dpkginfo_test id="oval:org.mitre.oval:tst:43986" version="1" comment="mailman DPKG is earlier than 1:2.1.13-5" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15894"/>
      <state state_ref="oval:org.mitre.oval:ste:13099"/>
    </dpkginfo_test>
    <dpkginfo_test id="oval:org.mitre.oval:tst:44000" version="1" comment="php5 DPKG is earlier than 5.3.3-7+squeeze3" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:7704"/>
      <state state_ref="oval:org.mitre.oval:ste:13385"/>
    </dpkginfo_test>
    <dpkginfo_test id="oval:org.mitre.oval:tst:43693" version="1" comment="php5 DPKG is earlier than 5.2.6.dfsg.1-1+lenny12" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:7704"/>
      <state state_ref="oval:org.mitre.oval:ste:12431"/>
    </dpkginfo_test>
    <dpkginfo_test id="oval:org.mitre.oval:tst:43856" version="1" comment="webkit DPKG is earlier than 1.2.7-0+squeeze1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:16306"/>
      <state state_ref="oval:org.mitre.oval:ste:12574"/>
    </dpkginfo_test>
    <dpkginfo_test id="oval:org.mitre.oval:tst:44214" version="1" comment="moodle DPKG is earlier than 1.9.9.dfsg2-2.1+squeeze1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:10211"/>
      <state state_ref="oval:org.mitre.oval:ste:13239"/>
    </dpkginfo_test>
    <dpkginfo_test id="oval:org.mitre.oval:tst:43296" version="1" comment="libmojolicious-perl DPKG is earlier than 0.999926-1+squeeze2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15491"/>
      <state state_ref="oval:org.mitre.oval:ste:13126"/>
    </dpkginfo_test>
    <dpkginfo_test id="oval:org.mitre.oval:tst:44026" version="1" comment="gitolite DPKG is earlier than 1.5.4-2+squeeze1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15939"/>
      <state state_ref="oval:org.mitre.oval:ste:12801"/>
    </dpkginfo_test>
    <dpkginfo_test id="oval:org.mitre.oval:tst:43816" version="1" comment="ikiwiki DPKG is earlier than 3.20100815.7" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:10394"/>
      <state state_ref="oval:org.mitre.oval:ste:13013"/>
    </dpkginfo_test>
    <dpkginfo_test id="oval:org.mitre.oval:tst:43812" version="1" comment="telepathy-gabble DPKG is earlier than 0.9.15-1+squeeze1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:16033"/>
      <state state_ref="oval:org.mitre.oval:ste:13101"/>
    </dpkginfo_test>
    <dpkginfo_test id="oval:org.mitre.oval:tst:42992" version="1" comment="telepathy-gabble DPKG is earlier than 0.7.6-1+lenny1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:16033"/>
      <state state_ref="oval:org.mitre.oval:ste:12738"/>
    </dpkginfo_test>
    <dpkginfo_test id="oval:org.mitre.oval:tst:44147" version="1" comment="wireshark DPKG is earlier than 1.0.2-3+lenny14" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:7263"/>
      <state state_ref="oval:org.mitre.oval:ste:13230"/>
    </dpkginfo_test>
    <dpkginfo_test id="oval:org.mitre.oval:tst:43964" version="1" comment="wireshark DPKG is earlier than 1.2.11-6+squeeze2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:7263"/>
      <state state_ref="oval:org.mitre.oval:ste:12662"/>
    </dpkginfo_test>
    <dpkginfo_test id="oval:org.mitre.oval:tst:43985" version="1" comment="exim4 DPKG is earlier than 4.72-6+squeeze1" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:16256"/>
      <state state_ref="oval:org.mitre.oval:ste:12239"/>
    </dpkginfo_test>
    <dpkginfo_test id="oval:org.mitre.oval:tst:44097" version="1" comment="isc-dhcp DPKG is earlier than 4.1.1-P1-15+squeeze2" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:15700"/>
      <state state_ref="oval:org.mitre.oval:ste:13121"/>
    </dpkginfo_test>
    <textfilecontent54_test id="oval:org.mitre.oval:tst:42061" version="2" comment="Debian GNU/Linux 5.0 is installed" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#independent">
      <object object_ref="oval:org.mitre.oval:obj:15583"/>
      <state state_ref="oval:org.mitre.oval:ste:12238"/>
    </textfilecontent54_test>
    <textfilecontent54_test id="oval:org.mitre.oval:tst:43618" version="2" comment="Debian 6.0 is installed" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#independent">
      <object object_ref="oval:org.mitre.oval:obj:15583"/>
      <state state_ref="oval:org.mitre.oval:ste:13042"/>
    </textfilecontent54_test>
    <dpkginfo_test id="oval:org.mitre.oval:tst:43982" version="1" comment="vlc DPKG is earlier than 1.1.3-1squeeze4" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:10387"/>
      <state state_ref="oval:org.mitre.oval:ste:12907"/>
    </dpkginfo_test>
    <dpkginfo_test id="oval:org.mitre.oval:tst:43806" version="1" comment="vlc DPKG is earlier than 0.8.6.h-4+lenny3" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:10387"/>
      <state state_ref="oval:org.mitre.oval:ste:13115"/>
    </dpkginfo_test>
    <uname_test id="oval:org.mitre.oval:tst:10881" version="1" comment="Installed architecture is all" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:2759"/>
    </uname_test>
  </tests>
  <objects>
    <dpkginfo_object id="oval:org.mitre.oval:obj:16027" version="1" comment="opie package information" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>opie</name>
    </dpkginfo_object>
    <dpkginfo_object id="oval:org.mitre.oval:obj:8253" version="1" comment="openoffice.org package information" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>openoffice.org</name>
    </dpkginfo_object>
    <dpkginfo_object id="oval:org.mitre.oval:obj:16240" version="1" comment="libapache2-mod-authnz-external package information" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>libapache2-mod-authnz-external</name>
    </dpkginfo_object>
    <dpkginfo_object id="oval:org.mitre.oval:obj:11175" version="1" comment="perl package information" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>perl</name>
    </dpkginfo_object>
    <dpkginfo_object id="oval:org.mitre.oval:obj:8366" version="1" comment="postfix package information" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>postfix</name>
    </dpkginfo_object>
    <dpkginfo_object id="oval:org.mitre.oval:obj:16202" version="1" comment="libmodplug package information" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>libmodplug</name>
    </dpkginfo_object>
    <dpkginfo_object id="oval:org.mitre.oval:obj:16152" version="1" comment="linux-2.6 package information" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>linux-2.6</name>
    </dpkginfo_object>
    <dpkginfo_object id="oval:org.mitre.oval:obj:16232" version="1" comment="libsndfile package information" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>libsndfile</name>
    </dpkginfo_object>
    <dpkginfo_object id="oval:org.mitre.oval:obj:16302" version="1" comment="mapserver package information" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>mapserver</name>
    </dpkginfo_object>
    <dpkginfo_object id="oval:org.mitre.oval:obj:11200" version="1" comment="curl package information" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>curl</name>
    </dpkginfo_object>
    <dpkginfo_object id="oval:org.mitre.oval:obj:16254" version="1" comment="spip package information" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>spip</name>
    </dpkginfo_object>
    <dpkginfo_object id="oval:org.mitre.oval:obj:16278" version="1" comment="tinyproxy package information" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>tinyproxy</name>
    </dpkginfo_object>
    <dpkginfo_object id="oval:org.mitre.oval:obj:15873" version="1" comment="vino package information" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>vino</name>
    </dpkginfo_object>
    <dpkginfo_object id="oval:org.mitre.oval:obj:10842" version="1" comment="imp4 package information" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>imp4</name>
    </dpkginfo_object>
    <dpkginfo_object id="oval:org.mitre.oval:obj:15862" version="1" comment="dovecot package information" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>dovecot</name>
    </dpkginfo_object>
    <dpkginfo_object id="oval:org.mitre.oval:obj:15560" version="1" comment="pango1.0 package information" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>pango1.0</name>
    </dpkginfo_object>
    <dpkginfo_object id="oval:org.mitre.oval:obj:10660" version="1" comment="wordpress package information" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>wordpress</name>
    </dpkginfo_object>
    <dpkginfo_object id="oval:org.mitre.oval:obj:15789" version="1" comment="tex-common package information" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>tex-common</name>
    </dpkginfo_object>
    <dpkginfo_object id="oval:org.mitre.oval:obj:15899" version="1" comment="apr package information" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>apr</name>
    </dpkginfo_object>
    <dpkginfo_object id="oval:org.mitre.oval:obj:16200" version="1" comment="x11-xserver-utils package information" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>x11-xserver-utils</name>
    </dpkginfo_object>
    <dpkginfo_object id="oval:org.mitre.oval:obj:11524" version="1" comment="ejabberd package information" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>ejabberd</name>
    </dpkginfo_object>
    <dpkginfo_object id="oval:org.mitre.oval:obj:7747" version="1" comment="openssl package information" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>openssl</name>
    </dpkginfo_object>
    <dpkginfo_object id="oval:org.mitre.oval:obj:8058" version="1" comment="samba package information" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>samba</name>
    </dpkginfo_object>
    <dpkginfo_object id="oval:org.mitre.oval:obj:16192" version="1" comment="tomcat6 package information" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>tomcat6</name>
    </dpkginfo_object>
    <dpkginfo_object id="oval:org.mitre.oval:obj:8355" version="1" comment="rails package information" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>rails</name>
    </dpkginfo_object>
    <dpkginfo_object id="oval:org.mitre.oval:obj:15881" version="1" comment="opensaml2 package information" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>opensaml2</name>
    </dpkginfo_object>
    <dpkginfo_object id="oval:org.mitre.oval:obj:16238" version="1" comment="movabletype-opensource package information" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>movabletype-opensource</name>
    </dpkginfo_object>
    <dpkginfo_object id="oval:org.mitre.oval:obj:16194" version="1" comment="openjdk-6 package information" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>openjdk-6</name>
    </dpkginfo_object>
    <dpkginfo_object id="oval:org.mitre.oval:obj:15306" version="1" comment="citadel package information" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>citadel</name>
    </dpkginfo_object>
    <dpkginfo_object id="oval:org.mitre.oval:obj:8612" version="1" comment="icedove package information" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>icedove</name>
    </dpkginfo_object>
    <dpkginfo_object id="oval:org.mitre.oval:obj:15676" version="1" comment="tgt package information" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>tgt</name>
    </dpkginfo_object>
    <dpkginfo_object id="oval:org.mitre.oval:obj:15604" version="1" comment="nss package information" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>nss</name>
    </dpkginfo_object>
    <dpkginfo_object id="oval:org.mitre.oval:obj:16304" version="1" comment="shadow package information" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>shadow</name>
    </dpkginfo_object>
    <dpkginfo_object id="oval:org.mitre.oval:obj:15747" version="1" comment="logwatch package information" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>logwatch</name>
    </dpkginfo_object>
    <dpkginfo_object id="oval:org.mitre.oval:obj:16223" version="1" comment="oprofile package information" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>oprofile</name>
    </dpkginfo_object>
    <dpkginfo_object id="oval:org.mitre.oval:obj:16259" version="1" comment="request-tracker3.6, request-tracker3.8 package information" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>request-tracker3.6, request-tracker3.8</name>
    </dpkginfo_object>
    <dpkginfo_object id="oval:org.mitre.oval:obj:16215" version="1" comment="krb5-appl package information" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>krb5-appl</name>
    </dpkginfo_object>
    <dpkginfo_object id="oval:org.mitre.oval:obj:16106" version="1" comment="gdm3 package information" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>gdm3</name>
    </dpkginfo_object>
    <dpkginfo_object id="oval:org.mitre.oval:obj:16301" version="1" comment="tiff package information" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>tiff</name>
    </dpkginfo_object>
    <dpkginfo_object id="oval:org.mitre.oval:obj:7672" version="1" comment="horde3 package information" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>horde3</name>
    </dpkginfo_object>
    <dpkginfo_object id="oval:org.mitre.oval:obj:16019" version="1" comment="proftpd-dfsg package information" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>proftpd-dfsg</name>
    </dpkginfo_object>
    <dpkginfo_object id="oval:org.mitre.oval:obj:15407" version="1" comment="chromium-browser package information" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>chromium-browser</name>
    </dpkginfo_object>
    <dpkginfo_object id="oval:org.mitre.oval:obj:8093" version="1" comment="bind9 package information" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>bind9</name>
    </dpkginfo_object>
    <dpkginfo_object id="oval:org.mitre.oval:obj:8166" version="1" comment="iceape package information" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>iceape</name>
    </dpkginfo_object>
    <dpkginfo_object id="oval:org.mitre.oval:obj:10416" version="1" comment="otrs2 package information" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>otrs2</name>
    </dpkginfo_object>
    <dpkginfo_object id="oval:org.mitre.oval:obj:16063" version="1" comment="doctrine package information" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>doctrine</name>
    </dpkginfo_object>
    <dpkginfo_object id="oval:org.mitre.oval:obj:16077" version="1" comment="openafs package information" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>openafs</name>
    </dpkginfo_object>
    <dpkginfo_object id="oval:org.mitre.oval:obj:11738" version="1" comment="kolab-cyrus-imapd package information" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>kolab-cyrus-imapd</name>
    </dpkginfo_object>
    <dpkginfo_object id="oval:org.mitre.oval:obj:16205" version="1" comment="xmlsec1 package information" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>xmlsec1</name>
    </dpkginfo_object>
    <dpkginfo_object id="oval:org.mitre.oval:obj:15804" version="1" comment="phpymadmin package information" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>phpymadmin</name>
    </dpkginfo_object>
    <dpkginfo_object id="oval:org.mitre.oval:obj:16116" version="1" comment="fex package information" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>fex</name>
    </dpkginfo_object>
    <dpkginfo_object id="oval:org.mitre.oval:obj:15994" version="1" comment="tmux package information" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>tmux</name>
    </dpkginfo_object>
    <dpkginfo_object id="oval:org.mitre.oval:obj:11585" version="1" comment="subversion package information" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>subversion</name>
    </dpkginfo_object>
    <dpkginfo_object id="oval:org.mitre.oval:obj:16252" version="1" comment="libcgroup package information" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>libcgroup</name>
    </dpkginfo_object>
    <dpkginfo_object id="oval:org.mitre.oval:obj:7910" version="1" comment="iceweasel package information" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>iceweasel</name>
    </dpkginfo_object>
    <dpkginfo_object id="oval:org.mitre.oval:obj:16169" version="1" comment="dajaxice package information" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>dajaxice</name>
    </dpkginfo_object>
    <dpkginfo_object id="oval:org.mitre.oval:obj:16146" version="1" comment="pam-pgsql package information" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>pam-pgsql</name>
    </dpkginfo_object>
    <dpkginfo_object id="oval:org.mitre.oval:obj:16173" version="1" comment="jabberd14 package information" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>jabberd14</name>
    </dpkginfo_object>
    <dpkginfo_object id="oval:org.mitre.oval:obj:8060" version="1" comment="libxml2 package information" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>libxml2</name>
    </dpkginfo_object>
    <dpkginfo_object id="oval:org.mitre.oval:obj:8722" version="1" comment="cyrus-imapd-2.2 package information" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>cyrus-imapd-2.2</name>
    </dpkginfo_object>
    <dpkginfo_object id="oval:org.mitre.oval:obj:16020" version="1" comment="libvirt package information" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>libvirt</name>
    </dpkginfo_object>
    <dpkginfo_object id="oval:org.mitre.oval:obj:15762" version="1" comment="pywebdav package information" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>pywebdav</name>
    </dpkginfo_object>
    <dpkginfo_object id="oval:org.mitre.oval:obj:16285" version="1" comment="libpng package information" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>libpng</name>
    </dpkginfo_object>
    <dpkginfo_object id="oval:org.mitre.oval:obj:15863" version="1" comment="avahi package information" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>avahi</name>
    </dpkginfo_object>
    <dpkginfo_object id="oval:org.mitre.oval:obj:11453" version="1" comment="mahara package information" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>mahara</name>
    </dpkginfo_object>
    <dpkginfo_object id="oval:org.mitre.oval:obj:15909" version="1" comment="xml-security-c package information" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>xml-security-c</name>
    </dpkginfo_object>
    <dpkginfo_object id="oval:org.mitre.oval:obj:11349" version="1" comment="quagga package information" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>quagga</name>
    </dpkginfo_object>
    <dpkginfo_object id="oval:org.mitre.oval:obj:9565" version="1" comment="asterisk package information" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>asterisk</name>
    </dpkginfo_object>
    <dpkginfo_object id="oval:org.mitre.oval:obj:16208" version="1" comment="qemu-kvm package information" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>qemu-kvm</name>
    </dpkginfo_object>
    <dpkginfo_object id="oval:org.mitre.oval:obj:7913" version="1" comment="python-django package information" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>python-django</name>
    </dpkginfo_object>
    <dpkginfo_object id="oval:org.mitre.oval:obj:10745" version="1" comment="phpmyadmin package information" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>phpmyadmin</name>
    </dpkginfo_object>
    <dpkginfo_object id="oval:org.mitre.oval:obj:15894" version="1" comment="mailman package information" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>mailman</name>
    </dpkginfo_object>
    <dpkginfo_object id="oval:org.mitre.oval:obj:7704" version="1" comment="php5 package information" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>php5</name>
    </dpkginfo_object>
    <dpkginfo_object id="oval:org.mitre.oval:obj:16306" version="1" comment="webkit package information" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>webkit</name>
    </dpkginfo_object>
    <dpkginfo_object id="oval:org.mitre.oval:obj:10211" version="1" comment="moodle package information" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>moodle</name>
    </dpkginfo_object>
    <dpkginfo_object id="oval:org.mitre.oval:obj:15491" version="1" comment="libmojolicious-perl package information" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>libmojolicious-perl</name>
    </dpkginfo_object>
    <dpkginfo_object id="oval:org.mitre.oval:obj:15939" version="1" comment="gitolite package information" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>gitolite</name>
    </dpkginfo_object>
    <dpkginfo_object id="oval:org.mitre.oval:obj:10394" version="1" comment="ikiwiki package information" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>ikiwiki</name>
    </dpkginfo_object>
    <dpkginfo_object id="oval:org.mitre.oval:obj:16033" version="1" comment="telepathy-gabble package information" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>telepathy-gabble</name>
    </dpkginfo_object>
    <dpkginfo_object id="oval:org.mitre.oval:obj:7263" version="1" comment="wireshark package information" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>wireshark</name>
    </dpkginfo_object>
    <dpkginfo_object id="oval:org.mitre.oval:obj:16256" version="1" comment="exim4 package information" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>exim4</name>
    </dpkginfo_object>
    <dpkginfo_object id="oval:org.mitre.oval:obj:15700" version="1" comment="isc-dhcp package information" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>isc-dhcp</name>
    </dpkginfo_object>
    <textfilecontent54_object id="oval:org.mitre.oval:obj:15583" version="2" comment="Object holds Debian version" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#independent">
      <path>/etc</path>
      <filename>debian_version</filename>
      <pattern operation="pattern match">^(\d\.\d).*$</pattern>
      <instance datatype="int">1</instance>
    </textfilecontent54_object>
    <dpkginfo_object id="oval:org.mitre.oval:obj:10387" version="1" comment="vlc package information" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>vlc</name>
    </dpkginfo_object>
    <uname_object id="oval:org.mitre.oval:obj:2759" version="1" comment="The single uname object." xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix"/>
  </objects>
  <states>
    <dpkginfo_state id="oval:org.mitre.oval:ste:12988" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:1.6.2.9-2+squeeze3</evr>
    </dpkginfo_state>
    <dpkginfo_state id="oval:org.mitre.oval:ste:12486" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:1.4.21.2~dfsg-3+lenny3</evr>
    </dpkginfo_state>
    <dpkginfo_state id="oval:org.mitre.oval:ste:13030" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:1.2.12-5+lenny4</evr>
    </dpkginfo_state>
    <dpkginfo_state id="oval:org.mitre.oval:ste:12978" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:1.4.2-6+squeeze2</evr>
    </dpkginfo_state>
    <dpkginfo_state id="oval:org.mitre.oval:ste:12660" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:0.9.6-1.1+squeeze1</evr>
    </dpkginfo_state>
    <dpkginfo_state id="oval:org.mitre.oval:ste:12876" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:0.9.3-2+lenny1</evr>
    </dpkginfo_state>
    <dpkginfo_state id="oval:org.mitre.oval:ste:13210" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:2.32.dfsg.1-0.2+squeeze1</evr>
    </dpkginfo_state>
    <dpkginfo_state id="oval:org.mitre.oval:ste:13224" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:2.32-10.2+lenny2</evr>
    </dpkginfo_state>
    <dpkginfo_state id="oval:org.mitre.oval:ste:12704" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:1:3.2.1-11+squeeze3</evr>
    </dpkginfo_state>
    <dpkginfo_state id="oval:org.mitre.oval:ste:12705" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:5.10.0-19lenny4</evr>
    </dpkginfo_state>
    <dpkginfo_state id="oval:org.mitre.oval:ste:13205" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:5.10.1-17squeeze1</evr>
    </dpkginfo_state>
    <dpkginfo_state id="oval:org.mitre.oval:ste:13249" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:1.0.4-4+lenny10</evr>
    </dpkginfo_state>
    <dpkginfo_state id="oval:org.mitre.oval:ste:12844" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:1.2.6-2+squeeze2</evr>
    </dpkginfo_state>
    <dpkginfo_state id="oval:org.mitre.oval:ste:13138" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:6b18-1.8.7-2~lenny1</evr>
    </dpkginfo_state>
    <dpkginfo_state id="oval:org.mitre.oval:ste:13212" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:6b18-1.8.7-2~squeeze1</evr>
    </dpkginfo_state>
    <dpkginfo_state id="oval:org.mitre.oval:ste:13159" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:3.2.4-2+squeeze1</evr>
    </dpkginfo_state>
    <dpkginfo_state id="oval:org.mitre.oval:ste:13074" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:1.9.0.19-12</evr>
    </dpkginfo_state>
    <dpkginfo_state id="oval:org.mitre.oval:ste:13198" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:3.5.16-9</evr>
    </dpkginfo_state>
    <dpkginfo_state id="oval:org.mitre.oval:ste:13143" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:5.10.0-19lenny5</evr>
    </dpkginfo_state>
    <dpkginfo_state id="oval:org.mitre.oval:ste:12530" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:5.10.1-17squeeze2</evr>
    </dpkginfo_state>
    <dpkginfo_state id="oval:org.mitre.oval:ste:13189" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:1:9.6.ESV.R4+dfsg-0+lenny3</evr>
    </dpkginfo_state>
    <dpkginfo_state id="oval:org.mitre.oval:ste:13029" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:1:9.7.3.dfsg-1~squeeze3</evr>
    </dpkginfo_state>
    <dpkginfo_state id="oval:org.mitre.oval:ste:13234" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:0.8.3-5+squeeze2</evr>
    </dpkginfo_state>
    <dpkginfo_state id="oval:org.mitre.oval:ste:12665" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:0.4.6-10+lenny2</evr>
    </dpkginfo_state>
    <dpkginfo_state id="oval:org.mitre.oval:ste:12851" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:3.9.4-5+squeeze1</evr>
    </dpkginfo_state>
    <dpkginfo_state id="oval:org.mitre.oval:ste:13188" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:2.5.5-1.1+lenny1</evr>
    </dpkginfo_state>
    <dpkginfo_state id="oval:org.mitre.oval:ste:12923" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:2.7.1-1+squeeze1</evr>
    </dpkginfo_state>
    <dpkginfo_state id="oval:org.mitre.oval:ste:12948" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:1:0.8.8.1-1+squeeze1</evr>
    </dpkginfo_state>
    <dpkginfo_state id="oval:org.mitre.oval:ste:12523" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:0.8.4-1+lenny2</evr>
    </dpkginfo_state>
    <dpkginfo_state id="oval:org.mitre.oval:ste:12807" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:2.6.32-34squeeze1</evr>
    </dpkginfo_state>
    <dpkginfo_state id="oval:org.mitre.oval:ste:13097" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:1.0.17-4+lenny3</evr>
    </dpkginfo_state>
    <dpkginfo_state id="oval:org.mitre.oval:ste:12740" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:1.0.21-3+squeeze1</evr>
    </dpkginfo_state>
    <dpkginfo_state id="oval:org.mitre.oval:ste:13155" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:2.0.11-5</evr>
    </dpkginfo_state>
    <dpkginfo_state id="oval:org.mitre.oval:ste:13134" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:5.0.3-3+lenny7</evr>
    </dpkginfo_state>
    <dpkginfo_state id="oval:org.mitre.oval:ste:13069" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:5.6.5-2+squeeze2</evr>
    </dpkginfo_state>
    <dpkginfo_state id="oval:org.mitre.oval:ste:13054" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:7.21.0-2</evr>
    </dpkginfo_state>
    <dpkginfo_state id="oval:org.mitre.oval:ste:12960" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:7.18.2-8lenny5</evr>
    </dpkginfo_state>
    <dpkginfo_state id="oval:org.mitre.oval:ste:12697" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:2.1.1-3squeeze1</evr>
    </dpkginfo_state>
    <dpkginfo_state id="oval:org.mitre.oval:ste:13228" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:6.0.472.63~r59945-5+squeeze5</evr>
    </dpkginfo_state>
    <dpkginfo_state id="oval:org.mitre.oval:ste:13007" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:1.8.2-1squeeze1</evr>
    </dpkginfo_state>
    <dpkginfo_state id="oval:org.mitre.oval:ste:13181" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:2.28.2-2+squeeze1</evr>
    </dpkginfo_state>
    <dpkginfo_state id="oval:org.mitre.oval:ste:13075" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:4.3.7+debian0-2.1</evr>
    </dpkginfo_state>
    <dpkginfo_state id="oval:org.mitre.oval:ste:12633" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:4.2-4lenny3</evr>
    </dpkginfo_state>
    <dpkginfo_state id="oval:org.mitre.oval:ste:13070" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:0.12.5+dfsg-5+squeeze1</evr>
    </dpkginfo_state>
    <dpkginfo_state id="oval:org.mitre.oval:ste:12671" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:3.0.11-1+squeeze1</evr>
    </dpkginfo_state>
    <dpkginfo_state id="oval:org.mitre.oval:ste:13001" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:1.1.3-1squeeze5</evr>
    </dpkginfo_state>
    <dpkginfo_state id="oval:org.mitre.oval:ste:12590" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:1.6.12dfsg-5</evr>
    </dpkginfo_state>
    <dpkginfo_state id="oval:org.mitre.oval:ste:13014" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:1.5.1dfsg1-6</evr>
    </dpkginfo_state>
    <dpkginfo_state id="oval:org.mitre.oval:ste:13044" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:1.2.15-7</evr>
    </dpkginfo_state>
    <dpkginfo_state id="oval:org.mitre.oval:ste:13065" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:1.28.3-1+squeeze2</evr>
    </dpkginfo_state>
    <dpkginfo_state id="oval:org.mitre.oval:ste:13194" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:3.8.2-11.5</evr>
    </dpkginfo_state>
    <dpkginfo_state id="oval:org.mitre.oval:ste:12795" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:3.9.4-5+squeeze3</evr>
    </dpkginfo_state>
    <dpkginfo_state id="oval:org.mitre.oval:ste:13102" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:3.0.5+dfsg-0+squeeze1</evr>
    </dpkginfo_state>
    <dpkginfo_state id="oval:org.mitre.oval:ste:12332" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:4.1.1-P1-15+squeeze1</evr>
    </dpkginfo_state>
    <dpkginfo_state id="oval:org.mitre.oval:ste:12928" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:0.12.5+dfsg-5+squeeze6</evr>
    </dpkginfo_state>
    <dpkginfo_state id="oval:org.mitre.oval:ste:13048" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:2.08.1</evr>
    </dpkginfo_state>
    <dpkginfo_state id="oval:org.mitre.oval:ste:13200" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:1.2.12-5+lenny3</evr>
    </dpkginfo_state>
    <dpkginfo_state id="oval:org.mitre.oval:ste:12813" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:1.4.2-6+squeeze1</evr>
    </dpkginfo_state>
    <dpkginfo_state id="oval:org.mitre.oval:ste:12668" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:7.5+3</evr>
    </dpkginfo_state>
    <dpkginfo_state id="oval:org.mitre.oval:ste:13147" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:2.0.1-6+lenny3</evr>
    </dpkginfo_state>
    <dpkginfo_state id="oval:org.mitre.oval:ste:13233" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:2.1.5-3+squeeze1</evr>
    </dpkginfo_state>
    <dpkginfo_state id="oval:org.mitre.oval:ste:12747" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:0.9.8o-4squeeze1</evr>
    </dpkginfo_state>
    <dpkginfo_state id="oval:org.mitre.oval:ste:12718" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:1:9.7.3.dfsg-1~squeeze1</evr>
    </dpkginfo_state>
    <dpkginfo_state id="oval:org.mitre.oval:ste:12176" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:1:1.6.2.9-2+squeeze2</evr>
    </dpkginfo_state>
    <dpkginfo_state id="oval:org.mitre.oval:ste:13096" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:1:1.4.21.2~dfsg-3+lenny2.1</evr>
    </dpkginfo_state>
    <dpkginfo_state id="oval:org.mitre.oval:ste:13011" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:3.2.5-4lenny14</evr>
    </dpkginfo_state>
    <dpkginfo_state id="oval:org.mitre.oval:ste:12936" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:3.5.6~dfsg-3squeeze2</evr>
    </dpkginfo_state>
    <dpkginfo_state id="oval:org.mitre.oval:ste:12871" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:6.0.472.63~r59945-5+squeeze2</evr>
    </dpkginfo_state>
    <dpkginfo_state id="oval:org.mitre.oval:ste:13095" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:6.0.28-9+squeeze1</evr>
    </dpkginfo_state>
    <dpkginfo_state id="oval:org.mitre.oval:ste:13058" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:2.1.0-7+lenny0.1</evr>
    </dpkginfo_state>
    <dpkginfo_state id="oval:org.mitre.oval:ste:13022" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:2.3.5-1.2+squeeze0.1</evr>
    </dpkginfo_state>
    <dpkginfo_state id="oval:org.mitre.oval:ste:12918" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:2.3-2+squeeze1</evr>
    </dpkginfo_state>
    <dpkginfo_state id="oval:org.mitre.oval:ste:13227" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:2.0-2+lenny3</evr>
    </dpkginfo_state>
    <dpkginfo_state id="oval:org.mitre.oval:ste:13220" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:4.3.5+dfsg-2+squeeze2</evr>
    </dpkginfo_state>
    <dpkginfo_state id="oval:org.mitre.oval:ste:12922" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:6b18-1.8.3-2+squeeze1</evr>
    </dpkginfo_state>
    <dpkginfo_state id="oval:org.mitre.oval:ste:12674" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:7.83-2squeeze2</evr>
    </dpkginfo_state>
    <dpkginfo_state id="oval:org.mitre.oval:ste:12259" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:7.37-8+lenny1</evr>
    </dpkginfo_state>
    <dpkginfo_state id="oval:org.mitre.oval:ste:13170" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:3.0.11-1+squeeze2</evr>
    </dpkginfo_state>
    <dpkginfo_state id="oval:org.mitre.oval:ste:12548" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:1:1.0.4-2squeeze1</evr>
    </dpkginfo_state>
    <dpkginfo_state id="oval:org.mitre.oval:ste:12629" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:3.12.8-1+squeeze1</evr>
    </dpkginfo_state>
    <dpkginfo_state id="oval:org.mitre.oval:ste:13122" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:3.12.3.1-0lenny4</evr>
    </dpkginfo_state>
    <dpkginfo_state id="oval:org.mitre.oval:ste:13105" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:1.9.0.19-8</evr>
    </dpkginfo_state>
    <dpkginfo_state id="oval:org.mitre.oval:ste:12608" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:3.5.16-5</evr>
    </dpkginfo_state>
    <dpkginfo_state id="oval:org.mitre.oval:ste:12802" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:1:4.1.4.2+svn3283-2+squeeze1</evr>
    </dpkginfo_state>
    <dpkginfo_state id="oval:org.mitre.oval:ste:12773" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:7.3.6.cvs20080702-2lenny1</evr>
    </dpkginfo_state>
    <dpkginfo_state id="oval:org.mitre.oval:ste:13031" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:7.3.6.cvs20090906-1squeeze1</evr>
    </dpkginfo_state>
    <dpkginfo_state id="oval:org.mitre.oval:ste:12553" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:2.0.11-3</evr>
    </dpkginfo_state>
    <dpkginfo_state id="oval:org.mitre.oval:ste:13151" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:0.9.3-2+lenny2</evr>
    </dpkginfo_state>
    <dpkginfo_state id="oval:org.mitre.oval:ste:12425" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:0.9.6-1.1+squeeze2</evr>
    </dpkginfo_state>
    <dpkginfo_state id="oval:org.mitre.oval:ste:13100" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:3.6.7-5+lenny6</evr>
    </dpkginfo_state>
    <dpkginfo_state id="oval:org.mitre.oval:ste:13161" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:3.8.8-7+squeeze1</evr>
    </dpkginfo_state>
    <dpkginfo_state id="oval:org.mitre.oval:ste:13158" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:1.0.1-1.1</evr>
    </dpkginfo_state>
    <dpkginfo_state id="oval:org.mitre.oval:ste:12461" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:2.30.5-6squeeze2</evr>
    </dpkginfo_state>
    <dpkginfo_state id="oval:org.mitre.oval:ste:13018" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:6.0.472.63~r59945-5+squeeze4</evr>
    </dpkginfo_state>
    <dpkginfo_state id="oval:org.mitre.oval:ste:12827" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:3.9.4-5+squeeze2</evr>
    </dpkginfo_state>
    <dpkginfo_state id="oval:org.mitre.oval:ste:13077" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:3.3.8+debian0-2</evr>
    </dpkginfo_state>
    <dpkginfo_state id="oval:org.mitre.oval:ste:13243" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:3.2.2+debian0-2+lenny3</evr>
    </dpkginfo_state>
    <dpkginfo_state id="oval:org.mitre.oval:ste:12794" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:1.3.3a-6squeeze1</evr>
    </dpkginfo_state>
    <dpkginfo_state id="oval:org.mitre.oval:ste:12758" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:5.3.3-7+squeeze1</evr>
    </dpkginfo_state>
    <dpkginfo_state id="oval:org.mitre.oval:ste:12873" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:5.2.6.dfsg.1-1+lenny10</evr>
    </dpkginfo_state>
    <dpkginfo_state id="oval:org.mitre.oval:ste:12719" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:4.72-6+squeeze2</evr>
    </dpkginfo_state>
    <dpkginfo_state id="oval:org.mitre.oval:ste:13005" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:6.0.472.63~r59945-5+squeeze3</evr>
    </dpkginfo_state>
    <dpkginfo_state id="oval:org.mitre.oval:ste:13156" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:1:9.6.ESV.R4+dfsg-0+lenny2</evr>
    </dpkginfo_state>
    <dpkginfo_state id="oval:org.mitre.oval:ste:12855" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:1:9.7.3.dfsg-1~squeeze2</evr>
    </dpkginfo_state>
    <dpkginfo_state id="oval:org.mitre.oval:ste:12551" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:2.0.11-6</evr>
    </dpkginfo_state>
    <dpkginfo_state id="oval:org.mitre.oval:ste:13136" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:2.4.9+dfsg1-3+squeeze1</evr>
    </dpkginfo_state>
    <dpkginfo_state id="oval:org.mitre.oval:ste:12696" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:1.2.2-2+squeeze1</evr>
    </dpkginfo_state>
    <dpkginfo_state id="oval:org.mitre.oval:ste:13067" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:1.4.12.1+dfsg-4</evr>
    </dpkginfo_state>
    <dpkginfo_state id="oval:org.mitre.oval:ste:13084" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:1.4.7.dfsg1-6+lenny4</evr>
    </dpkginfo_state>
    <dpkginfo_state id="oval:org.mitre.oval:ste:13225" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:2.2.13-9.1</evr>
    </dpkginfo_state>
    <dpkginfo_state id="oval:org.mitre.oval:ste:12561" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:2.2.13-5+lenny3</evr>
    </dpkginfo_state>
    <dpkginfo_state id="oval:org.mitre.oval:ste:12511" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:1.2.14-1+squeeze1</evr>
    </dpkginfo_state>
    <dpkginfo_state id="oval:org.mitre.oval:ste:12469" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:1.2.9-5+lenny1</evr>
    </dpkginfo_state>
    <dpkginfo_state id="oval:org.mitre.oval:ste:13216" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:3.3.7-6</evr>
    </dpkginfo_state>
    <dpkginfo_state id="oval:org.mitre.oval:ste:12768" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:20100208+debian1-1+squeeze1</evr>
    </dpkginfo_state>
    <dpkginfo_state id="oval:org.mitre.oval:ste:12959" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:1.3-2+squeeze1</evr>
    </dpkginfo_state>
    <dpkginfo_state id="oval:org.mitre.oval:ste:12901" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:1.1.3-1squeeze3</evr>
    </dpkginfo_state>
    <dpkginfo_state id="oval:org.mitre.oval:ste:12393" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:1.5.1dfsg1-7</evr>
    </dpkginfo_state>
    <dpkginfo_state id="oval:org.mitre.oval:ste:12964" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:1.6.12dfsg-6</evr>
    </dpkginfo_state>
    <dpkginfo_state id="oval:org.mitre.oval:ste:13124" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:0.36.2-3+squeeze1</evr>
    </dpkginfo_state>
    <dpkginfo_state id="oval:org.mitre.oval:ste:13152" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:3.5.16-7</evr>
    </dpkginfo_state>
    <dpkginfo_state id="oval:org.mitre.oval:ste:13062" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:0.1.5-1squeeze1</evr>
    </dpkginfo_state>
    <dpkginfo_state id="oval:org.mitre.oval:ste:13056" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:0.999926-1+squeeze1</evr>
    </dpkginfo_state>
    <dpkginfo_state id="oval:org.mitre.oval:ste:12976" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:0.12.5+dfsg-5+squeeze2</evr>
    </dpkginfo_state>
    <dpkginfo_state id="oval:org.mitre.oval:ste:12123" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:0.7.1-4+squeeze1</evr>
    </dpkginfo_state>
    <dpkginfo_state id="oval:org.mitre.oval:ste:13106" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:0.6.3-2+lenny1</evr>
    </dpkginfo_state>
    <dpkginfo_state id="oval:org.mitre.oval:ste:13217" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:1.6.1.1-5+squeeze1</evr>
    </dpkginfo_state>
    <dpkginfo_state id="oval:org.mitre.oval:ste:13060" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:2.6.32.dfsg-5+lenny4</evr>
    </dpkginfo_state>
    <dpkginfo_state id="oval:org.mitre.oval:ste:13110" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:2.7.8.dfsg-2+squeeze1</evr>
    </dpkginfo_state>
    <dpkginfo_state id="oval:org.mitre.oval:ste:13008" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:2.2.13-14+lenny4</evr>
    </dpkginfo_state>
    <dpkginfo_state id="oval:org.mitre.oval:ste:13226" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:2.2.13-19+squeeze1</evr>
    </dpkginfo_state>
    <dpkginfo_state id="oval:org.mitre.oval:ste:12474" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:0.8.3-5+squeeze1</evr>
    </dpkginfo_state>
    <dpkginfo_state id="oval:org.mitre.oval:ste:12842" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:0.9.4-1+squeeze1</evr>
    </dpkginfo_state>
    <dpkginfo_state id="oval:org.mitre.oval:ste:13114" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:1.2.27-2+lenny5</evr>
    </dpkginfo_state>
    <dpkginfo_state id="oval:org.mitre.oval:ste:13173" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:1.2.44-1+squeeze1</evr>
    </dpkginfo_state>
    <dpkginfo_state id="oval:org.mitre.oval:ste:12110" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:0.6.27-2+squeeze1</evr>
    </dpkginfo_state>
    <dpkginfo_state id="oval:org.mitre.oval:ste:13109" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:0.6.23-3lenny3</evr>
    </dpkginfo_state>
    <dpkginfo_state id="oval:org.mitre.oval:ste:13193" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:1.2.6-2+squeeze1</evr>
    </dpkginfo_state>
    <dpkginfo_state id="oval:org.mitre.oval:ste:12750" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:1.0.4-4+lenny8</evr>
    </dpkginfo_state>
    <dpkginfo_state id="oval:org.mitre.oval:ste:13166" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:1.4.0-3+lenny3</evr>
    </dpkginfo_state>
    <dpkginfo_state id="oval:org.mitre.oval:ste:13172" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:1.5.1-3+squeeze1</evr>
    </dpkginfo_state>
    <dpkginfo_state id="oval:org.mitre.oval:ste:13082" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:0.99.17-2+squeeze2</evr>
    </dpkginfo_state>
    <dpkginfo_state id="oval:org.mitre.oval:ste:13104" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:0.99.10-1lenny5</evr>
    </dpkginfo_state>
    <dpkginfo_state id="oval:org.mitre.oval:ste:13045" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:1.6.2.9-2+squeeze1</evr>
    </dpkginfo_state>
    <dpkginfo_state id="oval:org.mitre.oval:ste:13039" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:1.4.21.2~dfsg-3+lenny2</evr>
    </dpkginfo_state>
    <dpkginfo_state id="oval:org.mitre.oval:ste:12733" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:0.12.5+dfsg-5+squeeze4</evr>
    </dpkginfo_state>
    <dpkginfo_state id="oval:org.mitre.oval:ste:13026" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:1.2.3-3+squeeze1</evr>
    </dpkginfo_state>
    <dpkginfo_state id="oval:org.mitre.oval:ste:12992" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:4:2.11.8.1-5+lenny8</evr>
    </dpkginfo_state>
    <dpkginfo_state id="oval:org.mitre.oval:ste:13036" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:4:3.3.7-5</evr>
    </dpkginfo_state>
    <dpkginfo_state id="oval:org.mitre.oval:ste:13099" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:1:2.1.13-5</evr>
    </dpkginfo_state>
    <dpkginfo_state id="oval:org.mitre.oval:ste:13385" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:5.3.3-7+squeeze3</evr>
    </dpkginfo_state>
    <dpkginfo_state id="oval:org.mitre.oval:ste:12431" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:5.2.6.dfsg.1-1+lenny12</evr>
    </dpkginfo_state>
    <dpkginfo_state id="oval:org.mitre.oval:ste:12574" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:1.2.7-0+squeeze1</evr>
    </dpkginfo_state>
    <dpkginfo_state id="oval:org.mitre.oval:ste:13239" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:1.9.9.dfsg2-2.1+squeeze1</evr>
    </dpkginfo_state>
    <dpkginfo_state id="oval:org.mitre.oval:ste:13126" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:0.999926-1+squeeze2</evr>
    </dpkginfo_state>
    <dpkginfo_state id="oval:org.mitre.oval:ste:12801" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:1.5.4-2+squeeze1</evr>
    </dpkginfo_state>
    <dpkginfo_state id="oval:org.mitre.oval:ste:13013" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:3.20100815.7</evr>
    </dpkginfo_state>
    <dpkginfo_state id="oval:org.mitre.oval:ste:13101" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:0.9.15-1+squeeze1</evr>
    </dpkginfo_state>
    <dpkginfo_state id="oval:org.mitre.oval:ste:12738" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:0.7.6-1+lenny1</evr>
    </dpkginfo_state>
    <dpkginfo_state id="oval:org.mitre.oval:ste:13230" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:1.0.2-3+lenny14</evr>
    </dpkginfo_state>
    <dpkginfo_state id="oval:org.mitre.oval:ste:12662" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:1.2.11-6+squeeze2</evr>
    </dpkginfo_state>
    <dpkginfo_state id="oval:org.mitre.oval:ste:12239" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:4.72-6+squeeze1</evr>
    </dpkginfo_state>
    <dpkginfo_state id="oval:org.mitre.oval:ste:13121" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:4.1.1-P1-15+squeeze2</evr>
    </dpkginfo_state>
    <textfilecontent54_state id="oval:org.mitre.oval:ste:12238" version="2" comment="State matches if version is 5.0" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#independent">
      <subexpression>5.0</subexpression>
    </textfilecontent54_state>
    <textfilecontent54_state id="oval:org.mitre.oval:ste:13042" version="2" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#independent">
      <subexpression>6.0</subexpression>
    </textfilecontent54_state>
    <dpkginfo_state id="oval:org.mitre.oval:ste:12907" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:1.1.3-1squeeze4</evr>
    </dpkginfo_state>
    <dpkginfo_state id="oval:org.mitre.oval:ste:13115" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:0.8.6.h-4+lenny3</evr>
    </dpkginfo_state>
  </states>
</oval_definitions>
