<?xml version="1.0" encoding="UTF-8"?>
<oval_definitions xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-definitions-5 oval-definitions-schema.xsd http://oval.mitre.org/XMLSchema/oval-definitions-5#linux linux-definitions-schema.xsd http://oval.mitre.org/XMLSchema/oval-definitions-5#independent independent-definitions-schema.xsd http://oval.mitre.org/XMLSchema/oval-common-5 oval-common-schema.xsd http://oval.mitre.org/XMLSchema/oval-definitions-5#unix unix-definitions-schema.xsd" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:oval="http://oval.mitre.org/XMLSchema/oval-common-5" xmlns:oval-def="http://oval.mitre.org/XMLSchema/oval-definitions-5">
  <generator>
    <oval:product_name>The OVAL Repository</oval:product_name>
    <oval:schema_version>5.9</oval:schema_version>
    <oval:timestamp>2012-01-27T05:04:43.827-05:00</oval:timestamp>
  </generator>
  <definitions>
    <definition version="1" id="oval:org.mitre.oval:def:8413" class="patch">
      <metadata>
        <title>DSA-1802 squirrelmail -- several vulnerabilities</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <platform>Debian GNU/Linux 4.0</platform>
          <product>squirrelmail</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2009/dsa-1802" ref_id="DSA-1802"/>
        <description>Several remote vulnerabilities have been discovered in SquirrelMail, a webmail application. The Common Vulnerabilities and Exposures project identifies the following problems: Cross site scripting was possible through a number of pages which allowed an attacker to steal sensitive session data. Code injection was possible when SquirrelMail was configured to use the map_yp_alias function to authenticate users. This is not the default. It was possible to hijack an active user session by planting a specially crafted cookie into the user's browser. Specially crafted HTML emails could use the CSS positioning feature to place email content over the SquirrelMail user interface, allowing for phishing.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:13-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T08:00:44.925-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:05:33.775-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:04:16.520-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Platform section" operator="OR">
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Architecture independent section" operator="AND">
              <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criterion comment="squirrelmail is earlier than 1.4.15-4+lenny2" test_ref="oval:org.mitre.oval:tst:20530"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 4.0 is installed" definition_ref="oval:org.mitre.oval:def:6461"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Architecture independent section" operator="AND">
              <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criterion comment="squirrelmail is earlier than 1.4.9a-5" test_ref="oval:org.mitre.oval:tst:20305"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:8408" class="patch">
      <metadata>
        <title>DSA-1762 icu -- insufficient input sanitising</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <platform>Debian GNU/Linux 4.0</platform>
          <product>icu</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2009/dsa-1762" ref_id="DSA-1762"/>
        <description>It was discovered that icu, the internal components for Unicode, did not properly sanitise invalid encoded data, which could lead to crosssite scripting attacks.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:13-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T08:00:38.275-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:05:33.307-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:04:16.001-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Platform section" operator="OR">
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Architecture independent section" operator="AND">
              <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criterion comment="icu-doc is earlier than 3.8.1-3+lenny1" test_ref="oval:org.mitre.oval:tst:20386"/>
            </criteria>
            <criteria comment="Architecture dependent section" operator="AND">
              <criteria comment="Supported architectures section" operator="OR">
                <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
                <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
                <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
                <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
                <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
                <criterion comment="Installed architecture is armel" test_ref="oval:org.mitre.oval:tst:11101"/>
                <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
                <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
                <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
                <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
                <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
                <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
              </criteria>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="libicu38 DPKG is earlier than 3.8.1-3+lenny1" test_ref="oval:org.mitre.oval:tst:19463"/>
                <criterion comment="libicu38-dbg DPKG is earlier than 3.8.1-3+lenny1" test_ref="oval:org.mitre.oval:tst:20268"/>
                <criterion comment="libicu-dev DPKG is earlier than 3.8.1-3+lenny1" test_ref="oval:org.mitre.oval:tst:20455"/>
              </criteria>
            </criteria>
            <criteria comment="Architecture dependent section" operator="AND">
              <criteria comment="Supported architectures section" operator="OR">
                <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
              </criteria>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="lib32icu38 DPKG is earlier than 3.8.1-3+lenny1" test_ref="oval:org.mitre.oval:tst:20426"/>
                <criterion comment="lib32icu-dev DPKG is earlier than 3.8.1-3+lenny1" test_ref="oval:org.mitre.oval:tst:20422"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 4.0 is installed" definition_ref="oval:org.mitre.oval:def:6461"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Architecture independent section" operator="AND">
              <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criterion comment="icu-doc is earlier than 3.6-2etch2" test_ref="oval:org.mitre.oval:tst:20067"/>
            </criteria>
            <criteria comment="Architecture dependent section" operator="AND">
              <criteria comment="Supported architectures section" operator="OR">
                <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
                <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
                <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
                <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
                <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
                <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
                <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
                <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
                <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
                <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
              </criteria>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="libicu36-dev DPKG is earlier than 3.6-2etch2" test_ref="oval:org.mitre.oval:tst:20050"/>
                <criterion comment="libicu36 DPKG is earlier than 3.6-2etch2" test_ref="oval:org.mitre.oval:tst:19727"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:8390" class="patch">
      <metadata>
        <title>DSA-1892 dovecot -- buffer overflow</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <platform>Debian GNU/Linux 4.0</platform>
          <product>dovecot</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2009/dsa-1892" ref_id="DSA-1892"/>
        <description>It was discovered that the SIEVE component of dovecot, a mail server that supports mbox and maildir mailboxes, is vulnerable to a buffer overflow when processing SIEVE scripts. This can be used to elevate privileges to the dovecot system user. An attacker who is able to install SIEVE scripts executed by the server is therefore able to read and modify arbitrary email messages on the system.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:12-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T08:00:21.275-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:05:32.484-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:04:15.188-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Platform section" operator="OR">
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Architecture dependent section" operator="AND">
              <criteria comment="Supported architectures section" operator="OR">
                <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
                <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
                <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
                <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
                <criterion comment="Installed architecture is armel" test_ref="oval:org.mitre.oval:tst:11101"/>
                <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
                <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
                <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
                <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
                <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
                <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
              </criteria>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="dovecot-pop3d DPKG is earlier than 1.0.15-2.3+lenny1" test_ref="oval:org.mitre.oval:tst:20162"/>
                <criterion comment="dovecot-common DPKG is earlier than 1.0.15-2.3+lenny1" test_ref="oval:org.mitre.oval:tst:19778"/>
                <criterion comment="dovecot-imapd DPKG is earlier than 1.0.15-2.3+lenny1" test_ref="oval:org.mitre.oval:tst:20133"/>
                <criterion comment="dovecot-dev DPKG is earlier than 1.0.15-2.3+lenny1" test_ref="oval:org.mitre.oval:tst:20214"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 4.0 is installed" definition_ref="oval:org.mitre.oval:def:6461"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Architecture dependent section" operator="AND">
              <criteria comment="Supported architectures section" operator="OR">
                <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
                <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
                <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
                <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
                <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
                <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
                <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
                <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
                <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
              </criteria>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="dovecot-pop3d DPKG is earlier than 1.0.rc15-2etch5" test_ref="oval:org.mitre.oval:tst:20136"/>
                <criterion comment="dovecot-common DPKG is earlier than 1.0.rc15-2etch5" test_ref="oval:org.mitre.oval:tst:19805"/>
                <criterion comment="dovecot-imapd DPKG is earlier than 1.0.rc15-2etch5" test_ref="oval:org.mitre.oval:tst:20210"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:8385" class="patch">
      <metadata>
        <title>DSA-1734 opensc -- programming error</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <product>opensc</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2009/dsa-1734" ref_id="DSA-1734"/>
        <description>b.badrignans discovered that OpenSC, a set of smart card utilities, could store private data on a smart card without proper access restrictions. Only blank cards initialised with OpenSC are affected by this problem. This update only improves creating new private data objects, but cards already initialised with such private data objects need to be modified to repair the access control conditions on such cards. Instructions for a variety of situations can be found at the OpenSC web site: http://www.opensc-project.org/security.html  The oldstable distribution (etch) is not affected by this problem.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:11-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T07:59:32.813-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:05:32.248-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:04:14.910-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Release section" operator="AND">
        <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
        <criteria comment="Architecture section" operator="OR">
          <criteria comment="Packages section" operator="OR">
            <criterion comment="libopensc2 DPKG is earlier than 0.11.4-5+lenny1" test_ref="oval:org.mitre.oval:tst:19122"/>
            <criterion comment="libopensc2-dev DPKG is earlier than 0.11.4-5+lenny1" test_ref="oval:org.mitre.oval:tst:19505"/>
            <criterion comment="opensc DPKG is earlier than 0.11.4-5+lenny1" test_ref="oval:org.mitre.oval:tst:19501"/>
            <criterion comment="mozilla-opensc DPKG is earlier than 0.11.4-5+lenny1" test_ref="oval:org.mitre.oval:tst:18934"/>
            <criterion comment="libopensc2-dbg DPKG is earlier than 0.11.4-5+lenny1" test_ref="oval:org.mitre.oval:tst:19635"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:8381" class="patch">
      <metadata>
        <title>DSA-1749 linux-2.6 -- denial of service/privilege escalation/sensitive memory leak</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <product>linux-2.6</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2009/dsa-1749" ref_id="DSA-1749"/>
        <description>Several vulnerabilities have been discovered in the Linux kernel that may lead to a denial of service or privilege escalation. The Common Vulnerabilities and Exposures project identifies the following problems: Christian Borntraeger discovered an issue effecting the alpha, mips, powerpc, s390 and sparc64 architectures that allows local users to cause a denial of service or potentially gain elevated privileges. Vegard Nossum discovered a memory leak in the keyctl subsystem that allows local users to cause a denial of service by consuming all of kernel memory. Wei Yongjun discovered a memory overflow in the SCTP implementation that can be triggered by remote users. Duane Griffin provided a fix for an issue in the eCryptfs subsystem which allows local users to cause a denial of service (fault or memory corruption). Pavel Roskin provided a fix for an issue in the dell_rbu driver that allows a local user to cause a denial of service (oops) by reading 0 bytes from a sysfs entry. Clement LECIGNE discovered a bug in the sock_getsockopt function that may result in leaking sensitive kernel memory. Roel Kluin discovered inverted logic in the skfddi driver that permits local, unprivileged users to reset the driver statistics. Peter Kerwien discovered an issue in the ext4 filesystem that allows local users to cause a denial of service (kernel oops) during a resize operation. Sami Liedes reported an issue in the ext4 filesystem that allows local users to cause a denial of service (kernel oops) when accessing a specially crafted corrupt filesystem. David Maciejak reported an issue in the ext4 filesystem that allows local users to cause a denial of service (kernel oops) when mounting a specially crafted corrupt filesystem. David Maciejak reported an additional issue in the ext4 filesystem that allows local users to cause a denial of service (kernel oops) when mounting a specially crafted corrupt filesystem.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:12-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T07:59:53.235-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:05:31.395-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:04:14.106-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Release section" operator="AND">
        <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
        <criteria comment="Architecture section" operator="OR">
          <criteria comment="Architecture independent section" operator="AND">
            <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
            <criteria comment="Packages section" operator="OR">
              <criterion comment="linux-patch-debian-2.6.26 is earlier than 2.6.26-13lenny2" test_ref="oval:org.mitre.oval:tst:19025"/>
              <criterion comment="linux-support-2.6.26-1 is earlier than 2.6.26-13lenny2" test_ref="oval:org.mitre.oval:tst:19910"/>
              <criterion comment="linux-doc-2.6.26 is earlier than 2.6.26-13lenny2" test_ref="oval:org.mitre.oval:tst:19400"/>
              <criterion comment="linux-tree-2.6.26 is earlier than 2.6.26-13lenny2" test_ref="oval:org.mitre.oval:tst:19875"/>
              <criterion comment="linux-source-2.6.26 is earlier than 2.6.26-13lenny2" test_ref="oval:org.mitre.oval:tst:19907"/>
              <criterion comment="linux-manual-2.6.26 is earlier than 2.6.26-13lenny2" test_ref="oval:org.mitre.oval:tst:19029"/>
            </criteria>
          </criteria>
          <criteria comment="Architecture dependent section" operator="AND">
            <criteria comment="Supported architectures section" operator="OR">
              <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
            </criteria>
            <criteria comment="Packages section" operator="OR">
              <criterion comment="linux-headers-2.6.26-1-all DPKG is earlier than 2.6.26-13lenny2" test_ref="oval:org.mitre.oval:tst:19865"/>
              <criterion comment="linux-image-2.6.26-1-vserver-s390x DPKG is earlier than 2.6.26-13lenny2" test_ref="oval:org.mitre.oval:tst:19422"/>
              <criterion comment="linux-headers-2.6.26-1-common DPKG is earlier than 2.6.26-13lenny2" test_ref="oval:org.mitre.oval:tst:19663"/>
              <criterion comment="linux-image-2.6.26-1-s390 DPKG is earlier than 2.6.26-13lenny2" test_ref="oval:org.mitre.oval:tst:19858"/>
              <criterion comment="linux-headers-2.6.26-1-all-s390 DPKG is earlier than 2.6.26-13lenny2" test_ref="oval:org.mitre.oval:tst:19704"/>
              <criterion comment="linux-headers-2.6.26-1-common-vserver DPKG is earlier than 2.6.26-13lenny2" test_ref="oval:org.mitre.oval:tst:19149"/>
              <criterion comment="linux-headers-2.6.26-1-vserver-s390x DPKG is earlier than 2.6.26-13lenny2" test_ref="oval:org.mitre.oval:tst:19872"/>
              <criterion comment="linux-headers-2.6.26-1-s390x DPKG is earlier than 2.6.26-13lenny2" test_ref="oval:org.mitre.oval:tst:19894"/>
              <criterion comment="linux-libc-dev DPKG is earlier than 2.6.26-13lenny2" test_ref="oval:org.mitre.oval:tst:19667"/>
              <criterion comment="linux-headers-2.6.26-1-s390 DPKG is earlier than 2.6.26-13lenny2" test_ref="oval:org.mitre.oval:tst:19827"/>
              <criterion comment="linux-image-2.6.26-1-s390-tape DPKG is earlier than 2.6.26-13lenny2" test_ref="oval:org.mitre.oval:tst:19688"/>
              <criterion comment="linux-image-2.6.26-1-s390x DPKG is earlier than 2.6.26-13lenny2" test_ref="oval:org.mitre.oval:tst:19851"/>
            </criteria>
          </criteria>
          <criteria comment="Architecture dependent section" operator="AND">
            <criteria comment="Supported architectures section" operator="OR">
              <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
            </criteria>
            <criteria comment="Packages section" operator="OR">
              <criterion comment="linux-headers-2.6.26-1-vserver-amd64 DPKG is earlier than 2.6.26-13lenny2" test_ref="oval:org.mitre.oval:tst:19916"/>
              <criterion comment="linux-headers-2.6.26-1-all DPKG is earlier than 2.6.26-13lenny2" test_ref="oval:org.mitre.oval:tst:19734"/>
              <criterion comment="linux-headers-2.6.26-1-all-amd64 DPKG is earlier than 2.6.26-13lenny2" test_ref="oval:org.mitre.oval:tst:19763"/>
              <criterion comment="linux-image-2.6.26-1-vserver-amd64 DPKG is earlier than 2.6.26-13lenny2" test_ref="oval:org.mitre.oval:tst:19861"/>
              <criterion comment="linux-headers-2.6.26-1-common DPKG is earlier than 2.6.26-13lenny2" test_ref="oval:org.mitre.oval:tst:18980"/>
              <criterion comment="linux-image-2.6.26-1-openvz-amd64 DPKG is earlier than 2.6.26-13lenny2" test_ref="oval:org.mitre.oval:tst:19936"/>
              <criterion comment="linux-headers-2.6.26-1-amd64 DPKG is earlier than 2.6.26-13lenny2" test_ref="oval:org.mitre.oval:tst:19911"/>
              <criterion comment="linux-headers-2.6.26-1-openvz-amd64 DPKG is earlier than 2.6.26-13lenny2" test_ref="oval:org.mitre.oval:tst:19745"/>
              <criterion comment="linux-modules-2.6.26-1-xen-amd64 DPKG is earlier than 2.6.26-13lenny2" test_ref="oval:org.mitre.oval:tst:19389"/>
              <criterion comment="linux-headers-2.6.26-1-common-vserver DPKG is earlier than 2.6.26-13lenny2" test_ref="oval:org.mitre.oval:tst:19442"/>
              <criterion comment="linux-headers-2.6.26-1-xen-amd64 DPKG is earlier than 2.6.26-13lenny2" test_ref="oval:org.mitre.oval:tst:19585"/>
              <criterion comment="linux-image-2.6.26-1-amd64 DPKG is earlier than 2.6.26-13lenny2" test_ref="oval:org.mitre.oval:tst:19809"/>
              <criterion comment="linux-headers-2.6.26-1-common-openvz DPKG is earlier than 2.6.26-13lenny2" test_ref="oval:org.mitre.oval:tst:19807"/>
              <criterion comment="linux-libc-dev DPKG is earlier than 2.6.26-13lenny2" test_ref="oval:org.mitre.oval:tst:19515"/>
              <criterion comment="linux-image-2.6.26-1-xen-amd64 DPKG is earlier than 2.6.26-13lenny2" test_ref="oval:org.mitre.oval:tst:19794"/>
              <criterion comment="linux-headers-2.6.26-1-common-xen DPKG is earlier than 2.6.26-13lenny2" test_ref="oval:org.mitre.oval:tst:19157"/>
              <criterion comment="xen-linux-system-2.6.26-1-xen-amd64 DPKG is earlier than 2.6.26-13lenny2" test_ref="oval:org.mitre.oval:tst:19882"/>
            </criteria>
          </criteria>
          <criteria comment="Architecture depended section" operator="AND">
            <criteria comment="Supported platform section" operator="AND">
              <criterion comment="hppa architecture" test_ref="oval:org.mitre.oval:tst:11164"/>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="linux-headers-2.6.26-1-parisc64 DPKG is earlier than 2.6.26-13lenny2" test_ref="oval:org.mitre.oval:tst:19857"/>
                <criterion comment="linux-headers-2.6.26-1-all-hppa DPKG is earlier than 2.6.26-13lenny2" test_ref="oval:org.mitre.oval:tst:19978"/>
                <criterion comment="linux-headers-2.6.26-1-common DPKG is earlier than 2.6.26-13lenny2" test_ref="oval:org.mitre.oval:tst:20086"/>
                <criterion comment="linux-image-2.6.26-1-parisc DPKG is earlier than 2.6.26-13lenny2" test_ref="oval:org.mitre.oval:tst:19707"/>
                <criterion comment="linux-headers-2.6.26-1-all DPKG is earlier than 2.6.26-13lenny2" test_ref="oval:org.mitre.oval:tst:19849"/>
                <criterion comment="linux-image-2.6.26-1-parisc64-smp DPKG is earlier than 2.6.26-13lenny2" test_ref="oval:org.mitre.oval:tst:19888"/>
                <criterion comment="linux-image-2.6.26-1-parisc64 DPKG is earlier than 2.6.26-13lenny2" test_ref="oval:org.mitre.oval:tst:19969"/>
                <criterion comment="linux-image-2.6.26-1-parisc-smp DPKG is earlier than 2.6.26-13lenny2" test_ref="oval:org.mitre.oval:tst:19931"/>
                <criterion comment="linux-libc-dev DPKG is earlier than 2.6.26-13lenny2" test_ref="oval:org.mitre.oval:tst:19886"/>
                <criterion comment="linux-headers-2.6.26-1-parisc DPKG is earlier than 2.6.26-13lenny2" test_ref="oval:org.mitre.oval:tst:20081"/>
                <criterion comment="linux-headers-2.6.26-1-parisc64-smp DPKG is earlier than 2.6.26-13lenny2" test_ref="oval:org.mitre.oval:tst:19964"/>
                <criterion comment="linux-headers-2.6.26-1-parisc-smp DPKG is earlier than 2.6.26-13lenny2" test_ref="oval:org.mitre.oval:tst:19760"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:8375" class="patch">
      <metadata>
        <title>DSA-1736 mahara -- insufficient input sanitising</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <product>mahara</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2009/dsa-1736" ref_id="DSA-1736"/>
        <description>It was discovered that mahara, an electronic portfolio, weblog, and resume builder, is prone to cross-site scripting attacks, which allows the injection of arbitrary Java or HTML code. The oldstable distribution (etch) does not contain mahara.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:11-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T07:59:37.394-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:05:31.178-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:04:13.210-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Release section" operator="AND">
        <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
        <criteria comment="Architecture section" operator="OR">
          <criteria comment="Architecture independent section" operator="AND">
            <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
            <criteria comment="Packages section" operator="OR">
              <criterion comment="mahara-apache2 is earlier than 1.0.4-4+lenny1" test_ref="oval:org.mitre.oval:tst:18975"/>
              <criterion comment="mahara is earlier than 1.0.4-4+lenny1" test_ref="oval:org.mitre.oval:tst:19440"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:8370" class="patch">
      <metadata>
        <title>DSA-1737 wesnoth -- several vulnerabilities</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <platform>Debian GNU/Linux 4.0</platform>
          <product>wesnoth</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2009/dsa-1737" ref_id="DSA-1737"/>
        <description>Several security issues have been discovered in wesnoth, a fantasy turn-based strategy game. The Common Vulnerabilities and Exposures project identifies the following problems: Daniel Franke discovered that the wesnoth server is prone to a denial of service attack when receiving special crafted compressed data. Daniel Franke discovered that the sandbox implementation for the python AIs can be used to execute arbitrary python code on wesnoth clients. In order to prevent this issue, the python support has been disabled. A compatibility patch was included, so that the affected campagne is still working properly.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:11-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T07:59:36.478-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:05:30.268-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:04:12.386-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Platform section" operator="OR">
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Architecture independent section" operator="AND">
              <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="wesnoth-sotbe is earlier than 1.4.4-2+lenny1" test_ref="oval:org.mitre.oval:tst:19644"/>
                <criterion comment="wesnoth-aoi is earlier than 1.4.4-2+lenny1" test_ref="oval:org.mitre.oval:tst:19599"/>
                <criterion comment="wesnoth-tsg is earlier than 1.4.4-2+lenny1" test_ref="oval:org.mitre.oval:tst:19642"/>
                <criterion comment="wesnoth-nr is earlier than 1.4.4-2+lenny1" test_ref="oval:org.mitre.oval:tst:19252"/>
                <criterion comment="wesnoth-l is earlier than 1.4.4-2+lenny1" test_ref="oval:org.mitre.oval:tst:19621"/>
                <criterion comment="wesnoth-music is earlier than 1.4.4-2+lenny1" test_ref="oval:org.mitre.oval:tst:19102"/>
                <criterion comment="wesnoth-thot is earlier than 1.4.4-2+lenny1" test_ref="oval:org.mitre.oval:tst:18684"/>
                <criterion comment="wesnoth-httt is earlier than 1.4.4-2+lenny1" test_ref="oval:org.mitre.oval:tst:19623"/>
                <criterion comment="wesnoth-tools is earlier than 1.4.4-2+lenny1" test_ref="oval:org.mitre.oval:tst:19254"/>
                <criterion comment="wesnoth-sof is earlier than 1.4.4-2+lenny1" test_ref="oval:org.mitre.oval:tst:19647"/>
                <criterion comment="wesnoth-data is earlier than 1.4.4-2+lenny1" test_ref="oval:org.mitre.oval:tst:19180"/>
                <criterion comment="wesnoth-ttb is earlier than 1.4.4-2+lenny1" test_ref="oval:org.mitre.oval:tst:18852"/>
                <criterion comment="wesnoth-trow is earlier than 1.4.4-2+lenny1" test_ref="oval:org.mitre.oval:tst:19580"/>
                <criterion comment="wesnoth-did is earlier than 1.4.4-2+lenny1" test_ref="oval:org.mitre.oval:tst:19593"/>
                <criterion comment="wesnoth-ei is earlier than 1.4.4-2+lenny1" test_ref="oval:org.mitre.oval:tst:18711"/>
                <criterion comment="wesnoth-utbs is earlier than 1.4.4-2+lenny1" test_ref="oval:org.mitre.oval:tst:19691"/>
                <criterion comment="wesnoth-all is earlier than 1.4.4-2+lenny1" test_ref="oval:org.mitre.oval:tst:19658"/>
              </criteria>
            </criteria>
            <criteria comment="Architecture dependent section" operator="AND">
              <criteria comment="Supported architectures section" operator="OR">
                <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
                <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
                <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
                <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
                <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
                <criterion comment="Installed architecture is armel" test_ref="oval:org.mitre.oval:tst:11101"/>
                <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
                <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
                <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
                <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
                <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
                <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
              </criteria>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="wesnoth-server DPKG is earlier than 1.4.4-2+lenny1" test_ref="oval:org.mitre.oval:tst:19684"/>
                <criterion comment="wesnoth DPKG is earlier than 1.4.4-2+lenny1" test_ref="oval:org.mitre.oval:tst:19693"/>
                <criterion comment="wesnoth-editor DPKG is earlier than 1.4.4-2+lenny1" test_ref="oval:org.mitre.oval:tst:19589"/>
                <criterion comment="wesnoth-dbg DPKG is earlier than 1.4.4-2+lenny1" test_ref="oval:org.mitre.oval:tst:19609"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 4.0 is installed" definition_ref="oval:org.mitre.oval:def:6461"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Architecture independent section" operator="AND">
              <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="wesnoth-data is earlier than 1.2-5" test_ref="oval:org.mitre.oval:tst:19639"/>
                <criterion comment="wesnoth-tsg is earlier than 1.2-5" test_ref="oval:org.mitre.oval:tst:18938"/>
                <criterion comment="wesnoth-music is earlier than 1.2-5" test_ref="oval:org.mitre.oval:tst:19552"/>
                <criterion comment="wesnoth-httt is earlier than 1.2-5" test_ref="oval:org.mitre.oval:tst:19496"/>
                <criterion comment="wesnoth-ttb is earlier than 1.2-5" test_ref="oval:org.mitre.oval:tst:18990"/>
                <criterion comment="wesnoth-trow is earlier than 1.2-5" test_ref="oval:org.mitre.oval:tst:19610"/>
                <criterion comment="wesnoth-ei is earlier than 1.2-5" test_ref="oval:org.mitre.oval:tst:19105"/>
                <criterion comment="wesnoth-utbs is earlier than 1.2-5" test_ref="oval:org.mitre.oval:tst:19280"/>
              </criteria>
            </criteria>
            <criteria comment="Architecture dependent section" operator="AND">
              <criteria comment="Supported architectures section" operator="OR">
                <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
                <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
                <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
                <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
                <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
                <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
                <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
                <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
                <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
                <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
              </criteria>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="wesnoth-server DPKG is earlier than 1.2-5" test_ref="oval:org.mitre.oval:tst:19262"/>
                <criterion comment="wesnoth DPKG is earlier than 1.2-5" test_ref="oval:org.mitre.oval:tst:19011"/>
                <criterion comment="wesnoth-editor DPKG is earlier than 1.2-5" test_ref="oval:org.mitre.oval:tst:19710"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:8369" class="patch">
      <metadata>
        <title>DSA-1898 openswan -- denial of service</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <platform>Debian GNU/Linux 4.0</platform>
          <product>openswan</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2009/dsa-1898" ref_id="DSA-1898"/>
        <description>It was discovered that the pluto daemon in openswan, an implementation of IPSEC and IKE, could crash when processing a crafted X.509 certificate.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:12-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T08:00:02.425-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:05:29.775-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:04:11.891-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Platform section" operator="OR">
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Architecture independent section" operator="AND">
              <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="linux-patch-openswan is earlier than 2.4.12+dfsg-1.3+lenny2" test_ref="oval:org.mitre.oval:tst:19959"/>
                <criterion comment="openswan-modules-source is earlier than 2.4.12+dfsg-1.3+lenny2" test_ref="oval:org.mitre.oval:tst:19789"/>
              </criteria>
            </criteria>
            <criteria comment="Architecture dependent section" operator="AND">
              <criteria comment="Supported architectures section" operator="OR">
                <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
                <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
                <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
                <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
                <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
                <criterion comment="Installed architecture is armel" test_ref="oval:org.mitre.oval:tst:11101"/>
                <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
                <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
                <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
                <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
                <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
                <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
              </criteria>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="openswan DPKG is earlier than 2.4.12+dfsg-1.3+lenny2" test_ref="oval:org.mitre.oval:tst:19979"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 4.0 is installed" definition_ref="oval:org.mitre.oval:def:6461"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Architecture independent section" operator="AND">
              <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="linux-patch-openswan is earlier than 2.4.6+dfsg.2-1.1+etch2" test_ref="oval:org.mitre.oval:tst:19963"/>
                <criterion comment="openswan-modules-source is earlier than 2.4.6+dfsg.2-1.1+etch2" test_ref="oval:org.mitre.oval:tst:19531"/>
              </criteria>
            </criteria>
            <criteria comment="Packages section" operator="OR">
              <criterion comment="openswan DPKG is earlier than 2.4.6+dfsg.2-1.1+etch2" test_ref="oval:org.mitre.oval:tst:19100"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:8365" class="patch">
      <metadata>
        <title>DSA-1895 xmltooling -- several vulnerabilities</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <product>xmltooling</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2009/dsa-1895" ref_id="DSA-1895"/>
        <description>Several vulnerabilities have been discovered in the xmltooling packages, as used by Shibboleth: Chris Ries discovered that decoding a crafted URL leads to a crash (and potentially, arbitrary code execution). Ian Young discovered that embedded NUL characters in certificate names were not correctly handled, exposing configurations using PKIX trust validation to impersonation attacks. Incorrect processing of SAML metadata ignores key usage constraints. This minor issue also needs a correction in the opensaml2 packages, which will be provided in an upcoming stable point release (and, before that, via stable-proposed-updates).</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:12-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T08:00:05.686-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:05:29.390-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:04:11.499-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Release section" operator="AND">
        <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
        <criteria comment="Architecture section" operator="OR">
          <criteria comment="Architecture independent section" operator="AND">
            <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
            <criteria comment="Packages section" operator="OR">
              <criterion comment="xmltooling-schemas is earlier than 1.0-2+lenny1" test_ref="oval:org.mitre.oval:tst:19568"/>
              <criterion comment="libxmltooling-doc is earlier than 1.0-2+lenny1" test_ref="oval:org.mitre.oval:tst:20173"/>
            </criteria>
          </criteria>
          <criteria comment="Architecture dependent section" operator="AND">
            <criteria comment="Supported architectures section" operator="OR">
              <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
              <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
              <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
              <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
              <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
              <criterion comment="Installed architecture is armel" test_ref="oval:org.mitre.oval:tst:11101"/>
              <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
              <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
              <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
              <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
              <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
              <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
            </criteria>
            <criteria comment="Packages section" operator="OR">
              <criterion comment="libxmltooling-dev DPKG is earlier than 1.0-2+lenny1" test_ref="oval:org.mitre.oval:tst:20154"/>
              <criterion comment="libxmltooling1 DPKG is earlier than 1.0-2+lenny1" test_ref="oval:org.mitre.oval:tst:19846"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:8362" class="patch">
      <metadata>
        <title>DSA-1743 libtk-img -- buffer overflows</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <platform>Debian GNU/Linux 4.0</platform>
          <product>libtk-img</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2009/dsa-1743" ref_id="DSA-1743"/>
        <description>Two buffer overflows have been found in the GIF image parsing code of Tk, a cross-platform graphical toolkit, which could lead to the execution of arbitrary code. The Common Vulnerabilities and Exposures project identifies the following problems: It was discovered that libtk-img is prone to a buffer overflow via specially crafted multi-frame interlaced GIF files. It was discovered that libtk-img is prone to a buffer overflow via specially crafted GIF files with certain subimage sizes.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:12-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T08:00:01.602-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:05:28.646-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:04:10.743-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Platform section" operator="OR">
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Architecture independent section" operator="AND">
              <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criterion comment="libtk-img-doc is earlier than 1.3-release-7+lenny1" test_ref="oval:org.mitre.oval:tst:19876"/>
            </criteria>
            <criteria comment="Packages section" operator="OR">
              <criterion comment="libtk-img DPKG is earlier than 1.3-release-7+lenny1" test_ref="oval:org.mitre.oval:tst:20000"/>
              <criterion comment="libtk-img-dev DPKG is earlier than 1.3-release-7+lenny1" test_ref="oval:org.mitre.oval:tst:19985"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 4.0 is installed" definition_ref="oval:org.mitre.oval:def:6461"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Architecture dependent section" operator="AND">
              <criteria comment="Supported architectures section" operator="OR">
                <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
                <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
                <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
                <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
                <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
                <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
                <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
                <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
                <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
                <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
              </criteria>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="libtk-img DPKG is earlier than 1.3-15etch3" test_ref="oval:org.mitre.oval:tst:19877"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:8333" class="patch">
      <metadata>
        <title>DSA-1807 cyrus-sasl2, cyrus-sasl2-heimdal -- buffer overflow</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <product>cyrus-sasl2</product>
          <product>cyrus-sasl2-heimdal</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2009/dsa-1807" ref_id="DSA-1807"/>
        <description>James Ralston discovered that the sasl_encode64() function of cyrus-sasl2, a free library implementing the Simple Authentication and Security Layer, suffers from a missing null termination in certain situations. This causes several buffer overflows in situations where cyrus-sasl2 itself requires the string to be null terminated which can lead to denial of service or arbitrary code execution. Important notice (Quoting from US-CERT): While this patch will fix currently vulnerable code, it can cause non-vulnerable existing code to break. Here's a function prototype from include/saslutil.h to clarify my explanation: Assume a scenario where calling code has been written in such a way that it calculates the exact size required for base64 encoding in advance, then allocates a buffer of that exact size, passing a pointer to the buffer into sasl_encode64() as *out. As long as this code does not anticipate that the buffer is NUL-terminated (does not call any string-handling functions like strlen(), for example) the code will work and it will not be vulnerable. Once this patch is applied, that same code will break because sasl_encode64() will begin to return SASL_BUFOVER.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:13-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T08:00:40.952-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:05:27.372-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:04:09.429-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Release section" operator="AND">
        <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
        <criteria comment="Architecture section" operator="OR">
          <criteria comment="Architecture independent section" operator="AND">
            <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
            <criterion comment="cyrus-sasl2-doc is earlier than 2.1.22.dfsg1-23+lenny1" test_ref="oval:org.mitre.oval:tst:20447"/>
          </criteria>
          <criteria comment="Architecture dependent section" operator="AND">
            <criteria comment="Supported architectures section" operator="OR">
              <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
              <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
              <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
              <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
              <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
              <criterion comment="Installed architecture is armel" test_ref="oval:org.mitre.oval:tst:11101"/>
              <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
              <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
              <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
              <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
              <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
              <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
            </criteria>
            <criteria comment="Packages section" operator="OR">
              <criterion comment="libsasl2-2 DPKG is earlier than 2.1.22.dfsg1-23+lenny1" test_ref="oval:org.mitre.oval:tst:20234"/>
              <criterion comment="libsasl2-modules-gssapi-heimdal DPKG is earlier than 2.1.22.dfsg1-23+lenny1" test_ref="oval:org.mitre.oval:tst:20148"/>
              <criterion comment="cyrus-sasl2-heimdal-dbg DPKG is earlier than 2.1.22.dfsg1-23+lenny1" test_ref="oval:org.mitre.oval:tst:20365"/>
              <criterion comment="sasl2-bin DPKG is earlier than 2.1.22.dfsg1-23+lenny1" test_ref="oval:org.mitre.oval:tst:20378"/>
              <criterion comment="cyrus-sasl2-dbg DPKG is earlier than 2.1.22.dfsg1-23+lenny1" test_ref="oval:org.mitre.oval:tst:19990"/>
              <criterion comment="libsasl2-modules-gssapi-mit DPKG is earlier than 2.1.22.dfsg1-23+lenny1" test_ref="oval:org.mitre.oval:tst:20409"/>
              <criterion comment="libsasl2-dev DPKG is earlier than 2.1.22.dfsg1-23+lenny1" test_ref="oval:org.mitre.oval:tst:20331"/>
              <criterion comment="libsasl2-modules-sql DPKG is earlier than 2.1.22.dfsg1-23+lenny1" test_ref="oval:org.mitre.oval:tst:19896"/>
              <criterion comment="libsasl2-modules DPKG is earlier than 2.1.22.dfsg1-23+lenny1" test_ref="oval:org.mitre.oval:tst:20458"/>
              <criterion comment="libsasl2-modules-ldap DPKG is earlier than 2.1.22.dfsg1-23+lenny1" test_ref="oval:org.mitre.oval:tst:20215"/>
              <criterion comment="libsasl2-modules-otp DPKG is earlier than 2.1.22.dfsg1-23+lenny1" test_ref="oval:org.mitre.oval:tst:20402"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:8328" class="patch">
      <metadata>
        <title>DSA-1805 pidgin -- several vulnerabilities</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <product>pidgin</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2009/dsa-1805" ref_id="DSA-1805"/>
        <description>Several vulnerabilities have been discovered in Pidgin, a graphical multi-protocol instant messaging client. The Common Vulnerabilities and Exposures project identifies the following problems: A buffer overflow in the Jabber file transfer code may lead to denial of service or the execution of arbitrary code. Memory corruption in an internal library may lead to denial of service. The patch provided for the security issue tracked as CVE-2008-2927 - integer overflows in the MSN protocol handler - was found to be incomplete. The old stable distribution (etch) is affected under the source package name gaim. However, due to build problems the updated packages couldn't be released along with the stable version. It will be released once the build problem is resolved.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:13-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T08:00:42.555-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:05:26.542-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:04:08.553-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Release section" operator="AND">
        <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
        <criteria comment="Architecture section" operator="OR">
          <criteria comment="Architecture independent section" operator="AND">
            <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
            <criteria comment="Packages section" operator="OR">
              <criterion comment="libpurple-dev is earlier than 2.4.3-4lenny2" test_ref="oval:org.mitre.oval:tst:20333"/>
              <criterion comment="finch-dev is earlier than 2.4.3-4lenny2" test_ref="oval:org.mitre.oval:tst:20175"/>
              <criterion comment="pidgin-dev is earlier than 2.4.3-4lenny2" test_ref="oval:org.mitre.oval:tst:20002"/>
              <criterion comment="libpurple-bin is earlier than 2.4.3-4lenny2" test_ref="oval:org.mitre.oval:tst:20245"/>
              <criterion comment="pidgin-data is earlier than 2.4.3-4lenny2" test_ref="oval:org.mitre.oval:tst:20394"/>
            </criteria>
          </criteria>
          <criteria comment="Architecture dependent section" operator="AND">
            <criteria comment="Supported architectures section" operator="OR">
              <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
              <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
              <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
              <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
              <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
              <criterion comment="Installed architecture is armel" test_ref="oval:org.mitre.oval:tst:11101"/>
              <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
              <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
              <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
              <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
              <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
              <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
            </criteria>
            <criteria comment="Packages section" operator="OR">
              <criterion comment="finch DPKG is earlier than 2.4.3-4lenny2" test_ref="oval:org.mitre.oval:tst:19558"/>
              <criterion comment="pidgin-dbg DPKG is earlier than 2.4.3-4lenny2" test_ref="oval:org.mitre.oval:tst:20510"/>
              <criterion comment="pidgin DPKG is earlier than 2.4.3-4lenny2" test_ref="oval:org.mitre.oval:tst:19582"/>
              <criterion comment="libpurple0 DPKG is earlier than 2.4.3-4lenny2" test_ref="oval:org.mitre.oval:tst:19613"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:8306" class="patch">
      <metadata>
        <title>DSA-1850 libmodplug -- several vulnerabilities</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <platform>Debian GNU/Linux 4.0</platform>
          <product>libmodplug</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2009/dsa-1850" ref_id="DSA-1850"/>
        <description>Several vulnerabilities have been discovered in libmodplug, the shared libraries for mod music based on ModPlug. The Common Vulnerabilities and Exposures project identifies the following problems: It was discovered that libmodplug is prone to an integer overflow when processing a MED file with a crafted song comment or song name. It was discovered that libmodplug is prone to a buffer overflow in the PATinst function, when processing a long instrument name.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:10-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T07:58:48.501-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:05:24.245-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:04:05.717-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Platform section" operator="OR">
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Architecture independent section" operator="AND">
              <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criterion comment="libmodplug-dev is earlier than 0.8.4-1+lenny1" test_ref="oval:org.mitre.oval:tst:18977"/>
            </criteria>
            <criteria comment="Architecture dependent section" operator="AND">
              <criteria comment="Supported architectures section" operator="OR">
                <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
                <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
                <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
                <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
                <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
                <criterion comment="Installed architecture is armel" test_ref="oval:org.mitre.oval:tst:11101"/>
                <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
                <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
                <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
                <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
                <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
              </criteria>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="libmodplug0c2 DPKG is earlier than 0.8.4-1+lenny1" test_ref="oval:org.mitre.oval:tst:19028"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 4.0 is installed" definition_ref="oval:org.mitre.oval:def:6461"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Architecture independent section" operator="AND">
              <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criterion comment="libmodplug-dev is earlier than 0.7-5.2+etch1" test_ref="oval:org.mitre.oval:tst:19258"/>
            </criteria>
            <criteria comment="Packages section" operator="OR">
              <criterion comment="libmodplug0c2 DPKG is earlier than 0.7-5.2+etch1" test_ref="oval:org.mitre.oval:tst:18805"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:8300" class="patch">
      <metadata>
        <title>DSA-1800 linux-2.6 -- denial of service/privilege escalation/sensitive memory leak</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <product>linux-2.6</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2009/dsa-1800" ref_id="DSA-1800"/>
        <description>Several vulnerabilities have been discovered in the Linux kernel that may lead to a denial of service, privilege escalation or a sensitive memory leak. The Common Vulnerabilities and Exposures project identifies the following problems: Chris Evans discovered a situation in which a child process can send an arbitrary signal to its parent. Roland McGrath discovered an issue on amd64 kernels that allows local users to circumvent system call audit configurations which filter based on the syscall numbers or argument details. Roland McGrath discovered an issue on amd64 kernels with CONFIG_SECCOMP enabled. By making a specially crafted syscall, local users can bypass access restrictions. Jiri Olsa discovered that a local user can cause a denial of service (system hang) using a SHM_INFO shmctl call on kernels compiled with CONFIG_SHMEM disabled. This issue does not affect prebuilt Debian kernels. Mikulas Patocka reported an issue in the console subsystem that allows a local user to cause memory corruption by selecting a small number of 3-byte UTF-8 characters. Igor Zhbanov reported that nfsd was not properly dropping CAP_MKNOD, allowing users to create device nodes on file systems exported with root_squash. Dan Carpenter reported a coding issue in the selinux subsystem that allows local users to bypass certain networking checks when running with compat_net=1. Shaohua Li reported an issue in the AGP subsystem they may allow local users to read sensitive kernel memory due to a leak of uninitialized memory. Benjamin Gilbert reported a local denial of service vulnerability in the KVM VMX implementation that allows local users to trigger an oops. Thomas Pollet reported an overflow in the af_rose implementation that allows remote attackers to retrieve uninitialized kernel memory that may contain sensitive data. Oleg Nesterov discovered an issue in the exit_notify function that allows local users to send an arbitrary signal to a process by running a program that modifies the exit_signal field and then uses an exec system call to launch a setuid application. Daniel Hokka Zakrisson discovered that a kill(-1) is permitted to reach processes outside of the current process namespace. Pavan Naregundi reported an issue in the CIFS filesystem code that allows remote users to overwrite memory via a long nativeFileSystem field in a Tree Connect response during mount.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:13-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T08:00:50.655-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:05:23.360-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:04:04.847-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Release section" operator="AND">
        <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
        <criteria comment="Architecture section" operator="OR">
          <criteria comment="Architecture independent section" operator="AND">
            <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
            <criteria comment="Packages section" operator="OR">
              <criterion comment="linux-patch-debian-2.6.26 is earlier than 2.6.26-15lenny2" test_ref="oval:org.mitre.oval:tst:20152"/>
              <criterion comment="linux-support-2.6.26-2 is earlier than 2.6.26-15lenny2" test_ref="oval:org.mitre.oval:tst:20463"/>
              <criterion comment="linux-doc-2.6.26 is earlier than 2.6.26-15lenny2" test_ref="oval:org.mitre.oval:tst:20581"/>
              <criterion comment="linux-tree-2.6.26 is earlier than 2.6.26-15lenny2" test_ref="oval:org.mitre.oval:tst:20515"/>
              <criterion comment="linux-source-2.6.26 is earlier than 2.6.26-15lenny2" test_ref="oval:org.mitre.oval:tst:20509"/>
              <criterion comment="linux-manual-2.6.26 is earlier than 2.6.26-15lenny2" test_ref="oval:org.mitre.oval:tst:20586"/>
            </criteria>
          </criteria>
          <criteria comment="Architecture dependent section" operator="AND">
            <criteria comment="Supported architectures section" operator="OR">
              <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
            </criteria>
            <criteria comment="Packages section" operator="OR">
              <criterion comment="linux-headers-2.6.26-2-all DPKG is earlier than 2.6.26-15lenny2" test_ref="oval:org.mitre.oval:tst:20602"/>
              <criterion comment="linux-image-2.6.26-2-vserver-s390x DPKG is earlier than 2.6.26-15lenny2" test_ref="oval:org.mitre.oval:tst:20358"/>
              <criterion comment="linux-image-2.6.26-2-s390 DPKG is earlier than 2.6.26-15lenny2" test_ref="oval:org.mitre.oval:tst:20499"/>
              <criterion comment="linux-headers-2.6.26-2-s390 DPKG is earlier than 2.6.26-15lenny2" test_ref="oval:org.mitre.oval:tst:20375"/>
              <criterion comment="linux-image-2.6.26-2-s390-tape DPKG is earlier than 2.6.26-15lenny2" test_ref="oval:org.mitre.oval:tst:20404"/>
              <criterion comment="linux-headers-2.6.26-2-all-s390 DPKG is earlier than 2.6.26-15lenny2" test_ref="oval:org.mitre.oval:tst:20335"/>
              <criterion comment="linux-headers-2.6.26-2-vserver-s390x DPKG is earlier than 2.6.26-15lenny2" test_ref="oval:org.mitre.oval:tst:20539"/>
              <criterion comment="linux-headers-2.6.26-2-common-vserver DPKG is earlier than 2.6.26-15lenny2" test_ref="oval:org.mitre.oval:tst:20373"/>
              <criterion comment="linux-libc-dev DPKG is earlier than 2.6.26-15lenny2" test_ref="oval:org.mitre.oval:tst:20461"/>
              <criterion comment="linux-image-2.6.26-2-s390x DPKG is earlier than 2.6.26-15lenny2" test_ref="oval:org.mitre.oval:tst:20117"/>
              <criterion comment="linux-headers-2.6.26-2-common DPKG is earlier than 2.6.26-15lenny2" test_ref="oval:org.mitre.oval:tst:19880"/>
              <criterion comment="linux-headers-2.6.26-2-s390x DPKG is earlier than 2.6.26-15lenny2" test_ref="oval:org.mitre.oval:tst:20354"/>
            </criteria>
          </criteria>
          <criteria comment="Architecture dependent section" operator="AND">
            <criteria comment="Supported architectures section" operator="OR">
              <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
            </criteria>
            <criteria comment="Packages section" operator="OR">
              <criterion comment="xen-linux-system-2.6.26-2-xen-amd64 DPKG is earlier than 2.6.26-15lenny2" test_ref="oval:org.mitre.oval:tst:20537"/>
              <criterion comment="linux-headers-2.6.26-2-all DPKG is earlier than 2.6.26-15lenny2" test_ref="oval:org.mitre.oval:tst:20576"/>
              <criterion comment="linux-modules-2.6.26-2-xen-amd64 DPKG is earlier than 2.6.26-15lenny2" test_ref="oval:org.mitre.oval:tst:20523"/>
              <criterion comment="linux-headers-2.6.26-2-openvz-amd64 DPKG is earlier than 2.6.26-15lenny2" test_ref="oval:org.mitre.oval:tst:20434"/>
              <criterion comment="linux-headers-2.6.26-2-common-vserver DPKG is earlier than 2.6.26-15lenny2" test_ref="oval:org.mitre.oval:tst:20555"/>
              <criterion comment="linux-image-2.6.26-2-openvz-amd64 DPKG is earlier than 2.6.26-15lenny2" test_ref="oval:org.mitre.oval:tst:20549"/>
              <criterion comment="linux-image-2.6.26-2-amd64 DPKG is earlier than 2.6.26-15lenny2" test_ref="oval:org.mitre.oval:tst:20460"/>
              <criterion comment="user-mode-linux DPKG is earlier than 2.6.26-1um-2+15lenny2" test_ref="oval:org.mitre.oval:tst:20584"/>
              <criterion comment="linux-headers-2.6.26-2-common-openvz DPKG is earlier than 2.6.26-15lenny2" test_ref="oval:org.mitre.oval:tst:20446"/>
              <criterion comment="linux-image-2.6.26-2-vserver-amd64 DPKG is earlier than 2.6.26-15lenny2" test_ref="oval:org.mitre.oval:tst:20437"/>
              <criterion comment="linux-headers-2.6.26-2-all-amd64 DPKG is earlier than 2.6.26-15lenny2" test_ref="oval:org.mitre.oval:tst:20527"/>
              <criterion comment="linux-image-2.6.26-2-xen-amd64 DPKG is earlier than 2.6.26-15lenny2" test_ref="oval:org.mitre.oval:tst:20167"/>
              <criterion comment="linux-headers-2.6.26-2-common-xen DPKG is earlier than 2.6.26-15lenny2" test_ref="oval:org.mitre.oval:tst:19738"/>
              <criterion comment="linux-libc-dev DPKG is earlier than 2.6.26-15lenny2" test_ref="oval:org.mitre.oval:tst:20546"/>
              <criterion comment="linux-headers-2.6.26-2-xen-amd64 DPKG is earlier than 2.6.26-15lenny2" test_ref="oval:org.mitre.oval:tst:20494"/>
              <criterion comment="linux-headers-2.6.26-2-amd64 DPKG is earlier than 2.6.26-15lenny2" test_ref="oval:org.mitre.oval:tst:20540"/>
              <criterion comment="linux-headers-2.6.26-2-common DPKG is earlier than 2.6.26-15lenny2" test_ref="oval:org.mitre.oval:tst:19838"/>
              <criterion comment="linux-headers-2.6.26-2-vserver-amd64 DPKG is earlier than 2.6.26-15lenny2" test_ref="oval:org.mitre.oval:tst:20414"/>
            </criteria>
          </criteria>
          <criteria comment="Architecture depended section" operator="AND">
            <criteria comment="Supported platform section" operator="AND">
              <criterion comment="hppa architecture" test_ref="oval:org.mitre.oval:tst:11164"/>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="linux-headers-2.6.26-2-all DPKG is earlier than 2.6.26-15lenny2" test_ref="oval:org.mitre.oval:tst:20741"/>
                <criterion comment="linux-headers-2.6.26-2-parisc DPKG is earlier than 2.6.26-15lenny2" test_ref="oval:org.mitre.oval:tst:20442"/>
                <criterion comment="linux-image-2.6.26-2-parisc64 DPKG is earlier than 2.6.26-15lenny2" test_ref="oval:org.mitre.oval:tst:20610"/>
                <criterion comment="linux-image-2.6.26-2-parisc DPKG is earlier than 2.6.26-15lenny2" test_ref="oval:org.mitre.oval:tst:19821"/>
                <criterion comment="linux-headers-2.6.26-2-parisc-smp DPKG is earlier than 2.6.26-15lenny2" test_ref="oval:org.mitre.oval:tst:20553"/>
                <criterion comment="linux-headers-2.6.26-2-all-hppa DPKG is earlier than 2.6.26-15lenny2" test_ref="oval:org.mitre.oval:tst:20652"/>
                <criterion comment="linux-headers-2.6.26-2-parisc64 DPKG is earlier than 2.6.26-15lenny2" test_ref="oval:org.mitre.oval:tst:20604"/>
                <criterion comment="linux-headers-2.6.26-2-parisc64-smp DPKG is earlier than 2.6.26-15lenny2" test_ref="oval:org.mitre.oval:tst:20740"/>
                <criterion comment="linux-libc-dev DPKG is earlier than 2.6.26-15lenny2" test_ref="oval:org.mitre.oval:tst:20501"/>
                <criterion comment="linux-image-2.6.26-2-parisc64-smp DPKG is earlier than 2.6.26-15lenny2" test_ref="oval:org.mitre.oval:tst:20179"/>
                <criterion comment="linux-headers-2.6.26-2-common DPKG is earlier than 2.6.26-15lenny2" test_ref="oval:org.mitre.oval:tst:20281"/>
                <criterion comment="linux-image-2.6.26-2-parisc-smp DPKG is earlier than 2.6.26-15lenny2" test_ref="oval:org.mitre.oval:tst:20082"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:8299" class="patch">
      <metadata>
        <title>DSA-1852 fetchmail -- insufficient input validation</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <platform>Debian GNU/Linux 4.0</platform>
          <product>fetchmail</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2009/dsa-1852" ref_id="DSA-1852"/>
        <description>It was discovered that fetchmail, a full-featured remote mail retrieval and forwarding utility, is vulnerable to the "Null Prefix Attacks Against SSL/TLS Certificates" recently published at the Blackhat conference. This allows an attacker to perform undetected man-in-the-middle attacks via a crafted ITU-T X.509 certificate with an injected null byte in the subjectAltName or Common Name fields. Note, as a fetchmail user you should always use strict certificate validation through either these option combinations: sslcertck ssl sslproto ssl3 (for service on SSL-wrapped ports) or sslcertck sslproto tls1 (for STARTTLS-based services)</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:11-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T07:58:50.207-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:05:22.899-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:04:04.408-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Platform section" operator="OR">
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Architecture independent section" operator="AND">
              <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criterion comment="fetchmailconf is earlier than 6.3.9~rc2-4+lenny1" test_ref="oval:org.mitre.oval:tst:18983"/>
            </criteria>
            <criteria comment="Architecture dependent section" operator="AND">
              <criteria comment="Supported architectures section" operator="OR">
                <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
                <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
                <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
                <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
                <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
                <criterion comment="Installed architecture is armel" test_ref="oval:org.mitre.oval:tst:11101"/>
                <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
                <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
                <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
                <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
                <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
                <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
              </criteria>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="fetchmail DPKG is earlier than 6.3.9~rc2-4+lenny1" test_ref="oval:org.mitre.oval:tst:19217"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 4.0 is installed" definition_ref="oval:org.mitre.oval:def:6461"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Architecture independent section" operator="AND">
              <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criterion comment="fetchmailconf is earlier than 6.3.6-1etch2" test_ref="oval:org.mitre.oval:tst:18503"/>
            </criteria>
            <criteria comment="Architecture dependent section" operator="AND">
              <criteria comment="Supported architectures section" operator="OR">
                <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
                <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
                <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
                <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
                <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
                <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
                <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
                <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
                <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
              </criteria>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="fetchmail DPKG is earlier than 6.3.6-1etch2" test_ref="oval:org.mitre.oval:tst:19174"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:8294" class="patch">
      <metadata>
        <title>DSA-1803 nsd, nsd3 -- buffer overflow</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <platform>Debian GNU/Linux 4.0</platform>
          <product>nsd</product>
          <product>nsd3</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2009/dsa-1803" ref_id="DSA-1803"/>
        <description>Ilja van Sprundel discovered that a buffer overflow in NSD, an authoritative name service daemon, allowed to crash the server by sending a crafted packet, creating a denial of service.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:13-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T08:00:44.212-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:05:22.502-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:04:03.960-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Platform section" operator="OR">
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Architecture dependent section" operator="AND">
              <criteria comment="Supported architectures section" operator="OR">
                <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
                <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
                <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
                <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
                <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
                <criterion comment="Installed architecture is armel" test_ref="oval:org.mitre.oval:tst:11101"/>
                <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
                <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
                <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
                <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
                <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
                <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
              </criteria>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="nsd3 DPKG is earlier than 3.0.7-3.lenny2" test_ref="oval:org.mitre.oval:tst:19874"/>
                <criterion comment="nsd DPKG is earlier than 2.3.7-1.1+lenny1" test_ref="oval:org.mitre.oval:tst:20552"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 4.0 is installed" definition_ref="oval:org.mitre.oval:def:6461"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Packages section" operator="OR">
              <criterion comment="nsd DPKG is earlier than 2.3.6-1+etch1" test_ref="oval:org.mitre.oval:tst:20410"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:8289" class="patch">
      <metadata>
        <title>DSA-1935 gnutls13 gnutls26 -- several vulnerabilities</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <platform>Debian GNU/Linux 4.0</platform>
          <product>gnutls13</product>
          <product>gnutls26</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2009/dsa-1935" ref_id="DSA-1935"/>
        <description>Dan Kaminsky and Moxie Marlinspike discovered that gnutls, an implementation of the TLS/SSL protocol, does not properly handle a "\0" character in a domain name in the subject's Common Name or Subject Alternative Name (SAN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority. (CVE-2009-2730) In addition, with this update, certificates with MD2 hash signatures are no longer accepted since they're no longer considered cryptograhically secure. It only affects the oldstable distribution (etch).(CVE-2009-2409)</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:11-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T07:59:14.513-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:05:21.730-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:04:02.964-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Platform section" operator="OR">
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Architecture independent section" operator="AND">
              <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criterion comment="gnutls-doc is earlier than 2.4.2-6+lenny2" test_ref="oval:org.mitre.oval:tst:19120"/>
            </criteria>
            <criteria comment="Architecture dependent section" operator="AND">
              <criteria comment="Supported architectures section" operator="OR">
                <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
                <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
                <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
                <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
                <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
                <criterion comment="Installed architecture is armel" test_ref="oval:org.mitre.oval:tst:11101"/>
                <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
                <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
                <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
                <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
                <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
              </criteria>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="libgnutls-dev DPKG is earlier than 2.4.2-6+lenny2" test_ref="oval:org.mitre.oval:tst:19418"/>
                <criterion comment="libgnutls26-dbg DPKG is earlier than 2.4.2-6+lenny2" test_ref="oval:org.mitre.oval:tst:19207"/>
                <criterion comment="libgnutls26 DPKG is earlier than 2.4.2-6+lenny2" test_ref="oval:org.mitre.oval:tst:18509"/>
                <criterion comment="gnutls-bin DPKG is earlier than 2.4.2-6+lenny2" test_ref="oval:org.mitre.oval:tst:19103"/>
              </criteria>
            </criteria>
            <criteria comment="Packages section" operator="OR">
              <criterion comment="guile-gnutls DPKG is earlier than 2.4.2-6+lenny2" test_ref="oval:org.mitre.oval:tst:18710"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 4.0 is installed" definition_ref="oval:org.mitre.oval:def:6461"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Architecture independent section" operator="AND">
              <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criterion comment="gnutls-doc is earlier than 1.4.4-3+etch5" test_ref="oval:org.mitre.oval:tst:19426"/>
            </criteria>
            <criteria comment="Packages section" operator="OR">
              <criterion comment="libgnutls13 DPKG is earlier than 1.4.4-3+etch5" test_ref="oval:org.mitre.oval:tst:19199"/>
              <criterion comment="gnutls-bin DPKG is earlier than 1.4.4-3+etch5" test_ref="oval:org.mitre.oval:tst:19427"/>
              <criterion comment="libgnutls-dev DPKG is earlier than 1.4.4-3+etch5" test_ref="oval:org.mitre.oval:tst:19377"/>
              <criterion comment="libgnutls13-dbg DPKG is earlier than 1.4.4-3+etch5" test_ref="oval:org.mitre.oval:tst:19467"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:8285" class="patch">
      <metadata>
        <title>DSA-1894 newt -- buffer overflow</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <platform>Debian GNU/Linux 4.0</platform>
          <product>newt</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2009/dsa-1894" ref_id="DSA-1894"/>
        <description>Miroslav Lichvar discovered that newt, a windowing toolkit, is prone to a buffer overflow in the content processing code, which can lead to the execution of arbitrary code.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:12-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T08:00:04.752-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:05:20.989-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:04:02.242-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Platform section" operator="OR">
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Architecture dependent section" operator="AND">
              <criteria comment="Supported architectures section" operator="OR">
                <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
                <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
                <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
                <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
                <criterion comment="Installed architecture is armel" test_ref="oval:org.mitre.oval:tst:11101"/>
                <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
                <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
                <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
                <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
                <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
                <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
              </criteria>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="libnewt-dev DPKG is earlier than 0.52.2-11.3+lenny1" test_ref="oval:org.mitre.oval:tst:19799"/>
                <criterion comment="libnewt-pic DPKG is earlier than 0.52.2-11.3+lenny1" test_ref="oval:org.mitre.oval:tst:19994"/>
                <criterion comment="whiptail DPKG is earlier than 0.52.2-11.3+lenny1" test_ref="oval:org.mitre.oval:tst:20041"/>
                <criterion comment="libnewt0.52 DPKG is earlier than 0.52.2-11.3+lenny1" test_ref="oval:org.mitre.oval:tst:19853"/>
                <criterion comment="newt-tcl DPKG is earlier than 0.52.2-11.3+lenny1" test_ref="oval:org.mitre.oval:tst:20033"/>
                <criterion comment="python-newt DPKG is earlier than 0.52.2-11.3+lenny1" test_ref="oval:org.mitre.oval:tst:19786"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 4.0 is installed" definition_ref="oval:org.mitre.oval:def:6461"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Architecture dependent section" operator="AND">
              <criteria comment="Supported architectures section" operator="OR">
                <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
                <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
                <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
                <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
                <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
                <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
                <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
                <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
                <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
                <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
              </criteria>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="libnewt-dev DPKG is earlier than 0.52.2-10+etch1" test_ref="oval:org.mitre.oval:tst:19278"/>
                <criterion comment="libnewt-pic DPKG is earlier than 0.52.2-10+etch1" test_ref="oval:org.mitre.oval:tst:19908"/>
                <criterion comment="whiptail DPKG is earlier than 0.52.2-10+etch1" test_ref="oval:org.mitre.oval:tst:19370"/>
                <criterion comment="libnewt0.52 DPKG is earlier than 0.52.2-10+etch1" test_ref="oval:org.mitre.oval:tst:20156"/>
                <criterion comment="newt-tcl DPKG is earlier than 0.52.2-10+etch1" test_ref="oval:org.mitre.oval:tst:20138"/>
                <criterion comment="python-newt DPKG is earlier than 0.52.2-10+etch1" test_ref="oval:org.mitre.oval:tst:20132"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:8284" class="patch">
      <metadata>
        <title>DSA-1890 wxwindows2.4 wxwidgets2.6 wxwidgets2.8 -- integer overflow</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <platform>Debian GNU/Linux 4.0</platform>
          <product>wxwindows2.4</product>
          <product>wxwidgets2.6</product>
          <product>wxwidgets2.8</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2009/dsa-1890" ref_id="DSA-1890"/>
        <description>Tielei Wang has discovered an integer overflow in wxWidgets, the wxWidgets Cross-platform C++ GUI toolkit, which allows the execution of arbitrary code via a crafted JPEG file.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:12-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T08:00:18.597-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:05:19.302-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:04:00.597-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Platform section" operator="OR">
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Architecture independent section" operator="AND">
              <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="wx2.6-doc is earlier than 2.6.3.2.2-3+lenny1" test_ref="oval:org.mitre.oval:tst:19944"/>
                <criterion comment="python-wxversion is earlier than 2.6.3.2.2-3+lenny1" test_ref="oval:org.mitre.oval:tst:20087"/>
                <criterion comment="wx2.8-examples is earlier than 2.8.7.1-1.1+lenny1" test_ref="oval:org.mitre.oval:tst:19226"/>
                <criterion comment="wx2.6-i18n is earlier than 2.6.3.2.2-3+lenny1" test_ref="oval:org.mitre.oval:tst:19678"/>
                <criterion comment="wx2.6-examples is earlier than 2.6.3.2.2-3+lenny1" test_ref="oval:org.mitre.oval:tst:19904"/>
                <criterion comment="wx2.8-doc is earlier than 2.8.7.1-1.1+lenny1" test_ref="oval:org.mitre.oval:tst:19822"/>
                <criterion comment="python-wxtools is earlier than 2.6.3.2.2-3+lenny1" test_ref="oval:org.mitre.oval:tst:20019"/>
                <criterion comment="wx2.8-i18n is earlier than 2.8.7.1-1.1+lenny1" test_ref="oval:org.mitre.oval:tst:19532"/>
              </criteria>
            </criteria>
            <criteria comment="Architecture dependent section" operator="AND">
              <criteria comment="Supported architectures section" operator="OR">
                <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
                <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
                <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
                <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
                <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
                <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
              </criteria>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="python-wxgtk2.8 DPKG is earlier than 2.8.7.1-1.1+lenny1" test_ref="oval:org.mitre.oval:tst:19329"/>
                <criterion comment="python-wxgtk2.6-dbg DPKG is earlier than 2.6.3.2.2-3+lenny1" test_ref="oval:org.mitre.oval:tst:19982"/>
                <criterion comment="libwxbase2.8-dev DPKG is earlier than 2.8.7.1-1.1+lenny1" test_ref="oval:org.mitre.oval:tst:19968"/>
                <criterion comment="libwxbase2.6-dev DPKG is earlier than 2.6.3.2.2-3+lenny1" test_ref="oval:org.mitre.oval:tst:19581"/>
                <criterion comment="python-wxgtk2.8-dbg DPKG is earlier than 2.8.7.1-1.1+lenny1" test_ref="oval:org.mitre.oval:tst:19265"/>
                <criterion comment="libwxbase2.8-dbg DPKG is earlier than 2.8.7.1-1.1+lenny1" test_ref="oval:org.mitre.oval:tst:20125"/>
                <criterion comment="wx-common DPKG is earlier than 2.6.3.2.2-3+lenny1" test_ref="oval:org.mitre.oval:tst:20064"/>
                <criterion comment="libwxgtk2.8-dbg DPKG is earlier than 2.8.7.1-1.1+lenny1" test_ref="oval:org.mitre.oval:tst:20126"/>
                <criterion comment="python-wxgtk2.6 DPKG is earlier than 2.6.3.2.2-3+lenny1" test_ref="oval:org.mitre.oval:tst:19820"/>
                <criterion comment="libwxgtk2.6-0 DPKG is earlier than 2.6.3.2.2-3+lenny1" test_ref="oval:org.mitre.oval:tst:20031"/>
                <criterion comment="libwxgtk2.8-0 DPKG is earlier than 2.8.7.1-1.1+lenny1" test_ref="oval:org.mitre.oval:tst:19700"/>
                <criterion comment="libwxgtk2.6-dev DPKG is earlier than 2.6.3.2.2-3+lenny1" test_ref="oval:org.mitre.oval:tst:19864"/>
                <criterion comment="libwxgtk2.6-dbg DPKG is earlier than 2.6.3.2.2-3+lenny1" test_ref="oval:org.mitre.oval:tst:19652"/>
                <criterion comment="libwxbase2.6-0 DPKG is earlier than 2.6.3.2.2-3+lenny1" test_ref="oval:org.mitre.oval:tst:20043"/>
                <criterion comment="wx2.6-headers DPKG is earlier than 2.6.3.2.2-3+lenny1" test_ref="oval:org.mitre.oval:tst:19591"/>
                <criterion comment="wx2.8-headers DPKG is earlier than 2.8.7.1-1.1+lenny1" test_ref="oval:org.mitre.oval:tst:19454"/>
                <criterion comment="libwxbase2.8-0 DPKG is earlier than 2.8.7.1-1.1+lenny1" test_ref="oval:org.mitre.oval:tst:20070"/>
                <criterion comment="libwxgtk2.8-dev DPKG is earlier than 2.8.7.1-1.1+lenny1" test_ref="oval:org.mitre.oval:tst:19991"/>
                <criterion comment="libwxbase2.6-dbg DPKG is earlier than 2.6.3.2.2-3+lenny1" test_ref="oval:org.mitre.oval:tst:20071"/>
              </criteria>
            </criteria>
            <criteria comment="Architecture dependent section" operator="AND">
              <criteria comment="Supported architectures section" operator="OR">
                <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
              </criteria>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="libwxgtk2.6-dev DPKG is earlier than 2.6.3.2.2-3+lenny1" test_ref="oval:org.mitre.oval:tst:19245"/>
                <criterion comment="libwxbase2.6-dev DPKG is earlier than 2.6.3.2.2-3+lenny1" test_ref="oval:org.mitre.oval:tst:20143"/>
                <criterion comment="wx-common DPKG is earlier than 2.6.3.2.2-3+lenny1" test_ref="oval:org.mitre.oval:tst:19508"/>
                <criterion comment="python-wxgtk2.6 DPKG is earlier than 2.6.3.2.2-3+lenny1" test_ref="oval:org.mitre.oval:tst:20112"/>
                <criterion comment="libwxgtk2.6-0 DPKG is earlier than 2.6.3.2.2-3+lenny1" test_ref="oval:org.mitre.oval:tst:20177"/>
                <criterion comment="libwxgtk2.6-dbg DPKG is earlier than 2.6.3.2.2-3+lenny1" test_ref="oval:org.mitre.oval:tst:19837"/>
                <criterion comment="python-wxgtk2.6-dbg DPKG is earlier than 2.6.3.2.2-3+lenny1" test_ref="oval:org.mitre.oval:tst:20119"/>
                <criterion comment="libwxbase2.6-0 DPKG is earlier than 2.6.3.2.2-3+lenny1" test_ref="oval:org.mitre.oval:tst:20091"/>
                <criterion comment="wx2.6-headers DPKG is earlier than 2.6.3.2.2-3+lenny1" test_ref="oval:org.mitre.oval:tst:20078"/>
                <criterion comment="libwxbase2.6-dbg DPKG is earlier than 2.6.3.2.2-3+lenny1" test_ref="oval:org.mitre.oval:tst:19955"/>
              </criteria>
            </criteria>
            <criteria comment="Architecture depended section" operator="AND">
              <criteria comment="Supported platform section" operator="AND">
                <criterion comment="armel architecture" test_ref="oval:org.mitre.oval:tst:11101"/>
                <criteria comment="Packages section" operator="OR">
                  <criterion comment="libwxgtk2.8-dbg DPKG is earlier than 2.8.7.1-1.1+lenny1" test_ref="oval:org.mitre.oval:tst:19692"/>
                  <criterion comment="libwxbase2.8-dev DPKG is earlier than 2.8.7.1-1.1+lenny1" test_ref="oval:org.mitre.oval:tst:20191"/>
                  <criterion comment="python-wxgtk2.8 DPKG is earlier than 2.8.7.1-1.1+lenny1" test_ref="oval:org.mitre.oval:tst:20165"/>
                  <criterion comment="libwxbase2.8-dbg DPKG is earlier than 2.8.7.1-1.1+lenny1" test_ref="oval:org.mitre.oval:tst:20128"/>
                  <criterion comment="libwxgtk2.8-0 DPKG is earlier than 2.8.7.1-1.1+lenny1" test_ref="oval:org.mitre.oval:tst:20212"/>
                  <criterion comment="libwxgtk2.8-dev DPKG is earlier than 2.8.7.1-1.1+lenny1" test_ref="oval:org.mitre.oval:tst:20211"/>
                  <criterion comment="libwxbase2.8-0 DPKG is earlier than 2.8.7.1-1.1+lenny1" test_ref="oval:org.mitre.oval:tst:19898"/>
                  <criterion comment="python-wxgtk2.8-dbg DPKG is earlier than 2.8.7.1-1.1+lenny1" test_ref="oval:org.mitre.oval:tst:20109"/>
                  <criterion comment="wx2.8-headers DPKG is earlier than 2.8.7.1-1.1+lenny1" test_ref="oval:org.mitre.oval:tst:19683"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 4.0 is installed" definition_ref="oval:org.mitre.oval:def:6461"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Architecture independent section" operator="AND">
              <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="wx2.6-doc is earlier than 2.6.3.2.1.5+etch1" test_ref="oval:org.mitre.oval:tst:19859"/>
                <criterion comment="python-wxversion is earlier than 2.6.3.2.1.5+etch1" test_ref="oval:org.mitre.oval:tst:20140"/>
                <criterion comment="wx2.4-examples is earlier than 2.4.5.1.1+etch1" test_ref="oval:org.mitre.oval:tst:20149"/>
                <criterion comment="wx2.6-i18n is earlier than 2.6.3.2.1.5+etch1" test_ref="oval:org.mitre.oval:tst:19930"/>
                <criterion comment="wx2.6-examples is earlier than 2.6.3.2.1.5+etch1" test_ref="oval:org.mitre.oval:tst:19953"/>
                <criterion comment="python-wxtools is earlier than 2.6.3.2.1.5+etch1" test_ref="oval:org.mitre.oval:tst:19852"/>
                <criterion comment="wx2.4-doc is earlier than 2.4.5.1.1+etch1" test_ref="oval:org.mitre.oval:tst:20198"/>
                <criterion comment="wx2.4-i18n is earlier than 2.4.5.1.1+etch1" test_ref="oval:org.mitre.oval:tst:19998"/>
              </criteria>
            </criteria>
            <criteria comment="Architecture dependent section" operator="AND">
              <criteria comment="Supported architectures section" operator="OR">
                <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
                <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
                <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
                <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
                <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
                <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
                <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
              </criteria>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="libwxgtk2.6-dev DPKG is earlier than 2.6.3.2.1.5+etch1" test_ref="oval:org.mitre.oval:tst:20174"/>
                <criterion comment="libwxbase2.6-dbg DPKG is earlier than 2.6.3.2.1.5+etch1" test_ref="oval:org.mitre.oval:tst:20194"/>
                <criterion comment="libwxgtk2.4-1-contrib DPKG is earlier than 2.4.5.1.1+etch1" test_ref="oval:org.mitre.oval:tst:20027"/>
                <criterion comment="wx-common DPKG is earlier than 2.6.3.2.1.5+etch1" test_ref="oval:org.mitre.oval:tst:19780"/>
                <criterion comment="python-wxgtk2.4 DPKG is earlier than 2.4.5.1.1+etch1" test_ref="oval:org.mitre.oval:tst:20046"/>
                <criterion comment="libwxbase2.4-dev DPKG is earlier than 2.4.5.1.1+etch1" test_ref="oval:org.mitre.oval:tst:20006"/>
                <criterion comment="libwxgtk2.6-0 DPKG is earlier than 2.6.3.2.1.5+etch1" test_ref="oval:org.mitre.oval:tst:20055"/>
                <criterion comment="python-wxgtk2.6 DPKG is earlier than 2.6.3.2.1.5+etch1" test_ref="oval:org.mitre.oval:tst:20053"/>
                <criterion comment="libwxgtk2.4-contrib-dev DPKG is earlier than 2.4.5.1.1+etch1" test_ref="oval:org.mitre.oval:tst:20172"/>
                <criterion comment="libwxgtk2.6-dbg DPKG is earlier than 2.6.3.2.1.5+etch1" test_ref="oval:org.mitre.oval:tst:19856"/>
                <criterion comment="libwxgtk2.4-1 DPKG is earlier than 2.4.5.1.1+etch1" test_ref="oval:org.mitre.oval:tst:19699"/>
                <criterion comment="libwxgtk2.4-dev DPKG is earlier than 2.4.5.1.1+etch1" test_ref="oval:org.mitre.oval:tst:20205"/>
                <criterion comment="libwxbase2.6-0 DPKG is earlier than 2.6.3.2.1.5+etch1" test_ref="oval:org.mitre.oval:tst:19674"/>
                <criterion comment="wx2.6-headers DPKG is earlier than 2.6.3.2.1.5+etch1" test_ref="oval:org.mitre.oval:tst:20184"/>
                <criterion comment="libwxbase2.4-1 DPKG is earlier than 2.4.5.1.1+etch1" test_ref="oval:org.mitre.oval:tst:20093"/>
                <criterion comment="libwxbase2.4-dbg DPKG is earlier than 2.4.5.1.1+etch1" test_ref="oval:org.mitre.oval:tst:20028"/>
                <criterion comment="wx2.4-headers DPKG is earlier than 2.4.5.1.1+etch1" test_ref="oval:org.mitre.oval:tst:20106"/>
                <criterion comment="libwxgtk2.4-dbg DPKG is earlier than 2.4.5.1.1+etch1" test_ref="oval:org.mitre.oval:tst:19730"/>
                <criterion comment="libwxbase2.6-dev DPKG is earlier than 2.6.3.2.1.5+etch1" test_ref="oval:org.mitre.oval:tst:19486"/>
              </criteria>
            </criteria>
            <criteria comment="Architecture dependent section" operator="AND">
              <criteria comment="Supported architectures section" operator="OR">
                <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
              </criteria>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="libwxgtk2.6-dev DPKG is earlier than 2.6.3.2.1.5+etch1" test_ref="oval:org.mitre.oval:tst:19860"/>
                <criterion comment="libwxbase2.6-dbg DPKG is earlier than 2.6.3.2.1.5+etch1" test_ref="oval:org.mitre.oval:tst:20242"/>
                <criterion comment="wx-common DPKG is earlier than 2.6.3.2.1.5+etch1" test_ref="oval:org.mitre.oval:tst:20202"/>
                <criterion comment="python-wxgtk2.6 DPKG is earlier than 2.6.3.2.1.5+etch1" test_ref="oval:org.mitre.oval:tst:19731"/>
                <criterion comment="libwxgtk2.6-0 DPKG is earlier than 2.6.3.2.1.5+etch1" test_ref="oval:org.mitre.oval:tst:20213"/>
                <criterion comment="libwxgtk2.6-dbg DPKG is earlier than 2.6.3.2.1.5+etch1" test_ref="oval:org.mitre.oval:tst:19346"/>
                <criterion comment="libwxbase2.6-0 DPKG is earlier than 2.6.3.2.1.5+etch1" test_ref="oval:org.mitre.oval:tst:19899"/>
                <criterion comment="wx2.6-headers DPKG is earlier than 2.6.3.2.1.5+etch1" test_ref="oval:org.mitre.oval:tst:19753"/>
                <criterion comment="libwxbase2.6-dev DPKG is earlier than 2.6.3.2.1.5+etch1" test_ref="oval:org.mitre.oval:tst:19810"/>
              </criteria>
            </criteria>
            <criteria comment="Architecture depended section" operator="AND">
              <criteria comment="Supported platform section" operator="AND">
                <criterion comment="hppa architecture" test_ref="oval:org.mitre.oval:tst:11164"/>
                <criteria comment="Packages section" operator="OR">
                  <criterion comment="libwxgtk2.4-contrib-dev DPKG is earlier than 2.4.5.1.1+etch1" test_ref="oval:org.mitre.oval:tst:20235"/>
                  <criterion comment="libwxgtk2.4-1-contrib DPKG is earlier than 2.4.5.1.1+etch1" test_ref="oval:org.mitre.oval:tst:20186"/>
                  <criterion comment="libwxbase2.4-dev DPKG is earlier than 2.4.5.1.1+etch1" test_ref="oval:org.mitre.oval:tst:20222"/>
                  <criterion comment="python-wxgtk2.4 DPKG is earlier than 2.4.5.1.1+etch1" test_ref="oval:org.mitre.oval:tst:19892"/>
                  <criterion comment="libwxgtk2.4-1 DPKG is earlier than 2.4.5.1.1+etch1" test_ref="oval:org.mitre.oval:tst:20199"/>
                  <criterion comment="wx2.4-headers DPKG is earlier than 2.4.5.1.1+etch1" test_ref="oval:org.mitre.oval:tst:19909"/>
                  <criterion comment="libwxgtk2.4-dev DPKG is earlier than 2.4.5.1.1+etch1" test_ref="oval:org.mitre.oval:tst:19430"/>
                  <criterion comment="libwxbase2.4-1 DPKG is earlier than 2.4.5.1.1+etch1" test_ref="oval:org.mitre.oval:tst:20230"/>
                  <criterion comment="libwxbase2.4-dbg DPKG is earlier than 2.4.5.1.1+etch1" test_ref="oval:org.mitre.oval:tst:20226"/>
                  <criterion comment="libwxgtk2.4-dbg DPKG is earlier than 2.4.5.1.1+etch1" test_ref="oval:org.mitre.oval:tst:20139"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:8279" class="patch">
      <metadata>
        <title>DSA-1851 gst-plugins-bad0.10 -- integer overflow</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <platform>Debian GNU/Linux 4.0</platform>
          <product>gst-plugins-bad0.10</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2009/dsa-1851" ref_id="DSA-1851"/>
        <description>It was discovered that gst-plugins-bad0.10, the GStreamer plugins from the "bad" set, is prone to an integer overflow when processing a MED file with a crafted song comment or song name.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:11-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T07:58:49.407-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:05:18.815-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:04:00.139-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Platform section" operator="OR">
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Architecture independent section" operator="AND">
              <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criterion comment="gstreamer0.10-plugins-bad-doc is earlier than 0.10.7-2+lenny2" test_ref="oval:org.mitre.oval:tst:19107"/>
            </criteria>
            <criteria comment="Architecture dependent section" operator="AND">
              <criteria comment="Supported architectures section" operator="OR">
                <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
                <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
                <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
                <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
                <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
                <criterion comment="Installed architecture is armel" test_ref="oval:org.mitre.oval:tst:11101"/>
                <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
                <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
                <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
                <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
                <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
                <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
              </criteria>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="gstreamer0.10-plugins-bad-dbg DPKG is earlier than 0.10.7-2+lenny2" test_ref="oval:org.mitre.oval:tst:18287"/>
                <criterion comment="gstreamer0.10-sdl DPKG is earlier than 0.10.7-2+lenny2" test_ref="oval:org.mitre.oval:tst:19111"/>
                <criterion comment="gstreamer0.10-plugins-bad DPKG is earlier than 0.10.7-2+lenny2" test_ref="oval:org.mitre.oval:tst:19266"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 4.0 is installed" definition_ref="oval:org.mitre.oval:def:6461"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Packages section" operator="OR">
              <criterion comment="gstreamer0.10-plugins-bad DPKG is earlier than 0.10.3-3.1+etch3" test_ref="oval:org.mitre.oval:tst:18889"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:8263" class="patch">
      <metadata>
        <title>DSA-1779 apt -- several vulnerabilities</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <platform>Debian GNU/Linux 4.0</platform>
          <product>apt</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2009/dsa-1779" ref_id="DSA-1779"/>
        <description>Two vulnerabilities have been discovered in APT, the well-known dpkg frontend. The Common Vulnerabilities and Exposures project identifies the following problems: In time zones where daylight savings time occurs at midnight, the apt cron.daily script fails, stopping new security updates from being applied automatically. A repository that has been signed with an expired or revoked OpenPGP key would still be considered valid by APT.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:10-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T07:58:26.283-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:05:17.716-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:03:58.945-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Platform section" operator="OR">
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Architecture independent section" operator="AND">
              <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="libapt-pkg-doc is earlier than 0.7.20.2+lenny1" test_ref="oval:org.mitre.oval:tst:18385"/>
                <criterion comment="apt-doc is earlier than 0.7.20.2+lenny1" test_ref="oval:org.mitre.oval:tst:18082"/>
              </criteria>
            </criteria>
            <criteria comment="Architecture dependent section" operator="AND">
              <criteria comment="Supported architectures section" operator="OR">
                <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
                <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
                <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
                <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
                <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
                <criterion comment="Installed architecture is armel" test_ref="oval:org.mitre.oval:tst:11101"/>
                <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
                <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
                <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
                <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
                <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
              </criteria>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="apt-utils DPKG is earlier than 0.7.20.2+lenny1" test_ref="oval:org.mitre.oval:tst:18142"/>
                <criterion comment="apt-transport-https DPKG is earlier than 0.7.20.2+lenny1" test_ref="oval:org.mitre.oval:tst:18992"/>
                <criterion comment="libapt-pkg-dev DPKG is earlier than 0.7.20.2+lenny1" test_ref="oval:org.mitre.oval:tst:18930"/>
                <criterion comment="apt DPKG is earlier than 0.7.20.2+lenny1" test_ref="oval:org.mitre.oval:tst:18712"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 4.0 is installed" definition_ref="oval:org.mitre.oval:def:6461"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Architecture independent section" operator="AND">
              <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="libapt-pkg-doc is earlier than 0.6.46.4-0.1+etch1" test_ref="oval:org.mitre.oval:tst:19094"/>
                <criterion comment="apt-doc is earlier than 0.6.46.4-0.1+etch1" test_ref="oval:org.mitre.oval:tst:18921"/>
              </criteria>
            </criteria>
            <criteria comment="Architecture dependent section" operator="AND">
              <criteria comment="Supported architectures section" operator="OR">
                <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
                <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
                <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
                <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
                <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
                <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
                <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
                <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
                <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
                <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
              </criteria>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="apt-utils DPKG is earlier than 0.6.46.4-0.1+etch1" test_ref="oval:org.mitre.oval:tst:18849"/>
                <criterion comment="libapt-pkg-dev DPKG is earlier than 0.6.46.4-0.1+etch1" test_ref="oval:org.mitre.oval:tst:19098"/>
                <criterion comment="apt DPKG is earlier than 0.6.46.4-0.1+etch1" test_ref="oval:org.mitre.oval:tst:19085"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:8262" class="patch">
      <metadata>
        <title>DSA-1741 psi -- integer overflow</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <product>psi</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2009/dsa-1741" ref_id="DSA-1741"/>
        <description>Jesus Olmos Gonzalez discovered that an integer overflow in the PSI Jabber client may lead to remote denial of service. The old stable distribution (etch) is not affected.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:12-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T08:00:00.082-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:05:17.377-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:03:58.594-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Release section" operator="AND">
        <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
        <criteria comment="Architecture section" operator="OR">
          <criteria comment="Architecture dependent section" operator="AND">
            <criteria comment="Supported architectures section" operator="OR">
              <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
              <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
              <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
              <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
              <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
              <criterion comment="Installed architecture is armel" test_ref="oval:org.mitre.oval:tst:11101"/>
              <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
              <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
              <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
              <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
              <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
              <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
            </criteria>
            <criteria comment="Packages section" operator="OR">
              <criterion comment="psi DPKG is earlier than 0.11-9" test_ref="oval:org.mitre.oval:tst:20057"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:8260" class="patch">
      <metadata>
        <title>DSA-1817 ctorrent -- stack-based buffer overflow</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <product>ctorrent</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2009/dsa-1817" ref_id="DSA-1817"/>
        <description>Michael Brooks discovered that ctorrent, a text-mode bittorrent client, does not verify the length of file paths in torrent files. An attacker can exploit this via a crafted torrent that contains a long file path to execute arbitrary code with the rights of the user opening the file. The oldstable distribution (etch) does not contain ctorrent.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:09-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T07:57:35.588-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:05:16.982-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:03:58.252-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Release section" operator="AND">
        <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
        <criteria comment="Architecture section" operator="OR">
          <criteria comment="Architecture dependent section" operator="AND">
            <criteria comment="Supported architectures section" operator="OR">
              <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
              <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
              <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
              <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
              <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
              <criterion comment="Installed architecture is armel" test_ref="oval:org.mitre.oval:tst:11101"/>
              <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
              <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
              <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
              <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
              <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
              <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
            </criteria>
            <criteria comment="Packages section" operator="OR">
              <criterion comment="ctorrent DPKG is earlier than 1.3.4-dnh3.2-1+lenny1" test_ref="oval:org.mitre.oval:tst:18425"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:8258" class="patch">
      <metadata>
        <title>DSA-1891 changetrack -- shell command execution</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <platform>Debian GNU/Linux 4.0</platform>
          <product>changetrack</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2009/dsa-1891" ref_id="DSA-1891"/>
        <description>Marek Grzybowski discovered that changetrack, a program to monitor changes to (configuration) files, is prone to shell command injection via metacharacters in filenames. The behaviour of the program has been adjusted to reject all filenames with metacharacters.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:12-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T08:00:20.353-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:05:16.749-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:03:57.963-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Platform section" operator="OR">
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Architecture independent section" operator="AND">
              <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criterion comment="changetrack is earlier than 4.3-3+lenny1" test_ref="oval:org.mitre.oval:tst:19869"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 4.0 is installed" definition_ref="oval:org.mitre.oval:def:6461"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Architecture independent section" operator="AND">
              <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criterion comment="changetrack is earlier than 4.3-3+etch1" test_ref="oval:org.mitre.oval:tst:19507"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:8256" class="patch">
      <metadata>
        <title>DSA-1771 clamav -- several vulnerabilities</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <platform>Debian GNU/Linux 4.0</platform>
          <product>clamav</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2009/dsa-1771" ref_id="DSA-1771"/>
        <description>Several vulnerabilities have been discovered in the ClamAV anti-virus toolkit: Attackers can cayse a denial of service (crash) via a crafted EXE file that triggers a divide-by-zero error. Attackers can cause a denial of service (infinite loop) via a crafted tar file that causes (1) clamd and (2) clamscan to hang. (no CVE Id yet) Attackers can cause a denial of service (crash) via a crafted EXE file that crashes the UPack unpacker.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:10-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T07:58:20.654-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:05:16.152-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:03:57.229-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Platform section" operator="OR">
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Architecture independent section" operator="AND">
              <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="clamav-docs is earlier than 0.94.dfsg.2-1lenny2" test_ref="oval:org.mitre.oval:tst:18614"/>
                <criterion comment="clamav-testfiles is earlier than 0.94.dfsg.2-1lenny2" test_ref="oval:org.mitre.oval:tst:18644"/>
                <criterion comment="clamav-base is earlier than 0.94.dfsg.2-1lenny2" test_ref="oval:org.mitre.oval:tst:18931"/>
              </criteria>
            </criteria>
            <criteria comment="Architecture dependent section" operator="AND">
              <criteria comment="Supported architectures section" operator="OR">
                <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
                <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
                <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
                <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
                <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
                <criterion comment="Installed architecture is armel" test_ref="oval:org.mitre.oval:tst:11101"/>
                <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
                <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
                <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
                <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
                <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
              </criteria>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="libclamav-dev DPKG is earlier than 0.94.dfsg.2-1lenny2" test_ref="oval:org.mitre.oval:tst:18964"/>
                <criterion comment="clamav DPKG is earlier than 0.94.dfsg.2-1lenny2" test_ref="oval:org.mitre.oval:tst:18946"/>
                <criterion comment="libclamav5 DPKG is earlier than 0.94.dfsg.2-1lenny2" test_ref="oval:org.mitre.oval:tst:18967"/>
                <criterion comment="clamav-dbg DPKG is earlier than 0.94.dfsg.2-1lenny2" test_ref="oval:org.mitre.oval:tst:18859"/>
                <criterion comment="clamav-daemon DPKG is earlier than 0.94.dfsg.2-1lenny2" test_ref="oval:org.mitre.oval:tst:18880"/>
                <criterion comment="clamav-milter DPKG is earlier than 0.94.dfsg.2-1lenny2" test_ref="oval:org.mitre.oval:tst:18391"/>
                <criterion comment="clamav-freshclam DPKG is earlier than 0.94.dfsg.2-1lenny2" test_ref="oval:org.mitre.oval:tst:18790"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 4.0 is installed" definition_ref="oval:org.mitre.oval:def:6461"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Architecture independent section" operator="AND">
              <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="clamav-docs is earlier than 0.90.1dfsg-4etch19" test_ref="oval:org.mitre.oval:tst:18191"/>
                <criterion comment="clamav-testfiles is earlier than 0.90.1dfsg-4etch19" test_ref="oval:org.mitre.oval:tst:18877"/>
                <criterion comment="clamav-base is earlier than 0.90.1dfsg-4etch19" test_ref="oval:org.mitre.oval:tst:18896"/>
              </criteria>
            </criteria>
            <criteria comment="Architecture dependent section" operator="AND">
              <criteria comment="Supported architectures section" operator="OR">
                <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
                <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
                <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
                <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
                <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
                <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
                <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
                <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
                <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
                <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
              </criteria>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="libclamav-dev DPKG is earlier than 0.90.1dfsg-4etch19" test_ref="oval:org.mitre.oval:tst:19054"/>
                <criterion comment="clamav DPKG is earlier than 0.90.1dfsg-4etch19" test_ref="oval:org.mitre.oval:tst:18476"/>
                <criterion comment="clamav-dbg DPKG is earlier than 0.90.1dfsg-4etch19" test_ref="oval:org.mitre.oval:tst:18968"/>
                <criterion comment="libclamav2 DPKG is earlier than 0.90.1dfsg-4etch19" test_ref="oval:org.mitre.oval:tst:19045"/>
                <criterion comment="clamav-daemon DPKG is earlier than 0.90.1dfsg-4etch19" test_ref="oval:org.mitre.oval:tst:18835"/>
                <criterion comment="clamav-milter DPKG is earlier than 0.90.1dfsg-4etch19" test_ref="oval:org.mitre.oval:tst:18544"/>
                <criterion comment="clamav-freshclam DPKG is earlier than 0.90.1dfsg-4etch19" test_ref="oval:org.mitre.oval:tst:18754"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:8245" class="patch">
      <metadata>
        <title>DSA-1806 cscope -- buffer overflows</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <product>cscope</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2009/dsa-1806" ref_id="DSA-1806"/>
        <description>Matt Murphy discovered that cscope, a source code browsing tool, does not verify the length of file names sourced in include statements, which may potentially lead to the execution of arbitrary code through specially crafted source code files.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:13-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T08:00:41.564-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:05:14.121-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:03:55.500-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Release section" operator="AND">
        <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
        <criteria comment="Architecture section" operator="OR">
          <criteria comment="Architecture dependent section" operator="AND">
            <criteria comment="Supported architectures section" operator="OR">
              <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
              <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
              <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
              <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
              <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
              <criterion comment="Installed architecture is armel" test_ref="oval:org.mitre.oval:tst:11101"/>
              <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
              <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
              <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
              <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
              <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
              <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
            </criteria>
            <criteria comment="Packages section" operator="OR">
              <criterion comment="cscope DPKG is earlier than 15.6-6+lenny1" test_ref="oval:org.mitre.oval:tst:20472"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:8233" class="patch">
      <metadata>
        <title>DSA-1725 websvn -- programming error</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <product>websvn</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2009/dsa-1725" ref_id="DSA-1725"/>
        <description>Bas van Schaik discovered that WebSVN, a tool to view Subversion repositories over the web, did not properly restrict access to private repositories, allowing a remote attacker to read significant parts of their content. The old stable distribution (etch) is not affected by this problem.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:08-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T07:56:31.123-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:05:10.077-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:03:53.162-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Release section" operator="AND">
        <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
        <criteria comment="Architecture section" operator="OR">
          <criteria comment="Architecture independent section" operator="AND">
            <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
            <criterion comment="websvn is earlier than 2.0-4+lenny1" test_ref="oval:org.mitre.oval:tst:17582"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:8230" class="patch">
      <metadata>
        <title>DSA-1933 cups -- missing input sanitising</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <platform>Debian GNU/Linux 4.0</platform>
          <product>cups</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2009/dsa-1933" ref_id="DSA-1933"/>
        <description>Aaron Siegel discovered that the web interface of cups, the Common UNIX Printing System, is prone to cross-site scripting attacks.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:11-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T07:59:06.967-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:05:08.584-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:03:51.819-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Platform section" operator="OR">
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Architecture independent section" operator="AND">
              <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="cupsys-bsd is earlier than 1.3.8-1+lenny7" test_ref="oval:org.mitre.oval:tst:19285"/>
                <criterion comment="cupsys-client is earlier than 1.3.8-1+lenny7" test_ref="oval:org.mitre.oval:tst:19331"/>
                <criterion comment="libcupsys2-dev is earlier than 1.3.8-1+lenny7" test_ref="oval:org.mitre.oval:tst:19275"/>
                <criterion comment="cupsys-common is earlier than 1.3.8-1+lenny7" test_ref="oval:org.mitre.oval:tst:18394"/>
                <criterion comment="cups-common is earlier than 1.3.8-1+lenny7" test_ref="oval:org.mitre.oval:tst:19068"/>
                <criterion comment="cupsys-dbg is earlier than 1.3.8-1+lenny7" test_ref="oval:org.mitre.oval:tst:19155"/>
                <criterion comment="cupsys is earlier than 1.3.8-1+lenny7" test_ref="oval:org.mitre.oval:tst:18634"/>
                <criterion comment="libcupsys2 is earlier than 1.3.8-1+lenny7" test_ref="oval:org.mitre.oval:tst:19225"/>
              </criteria>
            </criteria>
            <criteria comment="Architecture dependent section" operator="AND">
              <criteria comment="Supported architectures section" operator="OR">
                <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
                <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
                <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
                <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
                <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
                <criterion comment="Installed architecture is armel" test_ref="oval:org.mitre.oval:tst:11101"/>
                <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
                <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
                <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
                <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
                <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
                <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
              </criteria>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="libcups2-dev DPKG is earlier than 1.3.8-1+lenny7" test_ref="oval:org.mitre.oval:tst:19271"/>
                <criterion comment="cups-bsd DPKG is earlier than 1.3.8-1+lenny7" test_ref="oval:org.mitre.oval:tst:18902"/>
                <criterion comment="libcupsimage2-dev DPKG is earlier than 1.3.8-1+lenny7" test_ref="oval:org.mitre.oval:tst:19311"/>
                <criterion comment="libcupsimage2 DPKG is earlier than 1.3.8-1+lenny7" test_ref="oval:org.mitre.oval:tst:19104"/>
                <criterion comment="cups-client DPKG is earlier than 1.3.8-1+lenny7" test_ref="oval:org.mitre.oval:tst:18803"/>
                <criterion comment="libcups2 DPKG is earlier than 1.3.8-1+lenny7" test_ref="oval:org.mitre.oval:tst:18969"/>
                <criterion comment="cups-dbg DPKG is earlier than 1.3.8-1+lenny7" test_ref="oval:org.mitre.oval:tst:18490"/>
                <criterion comment="cups DPKG is earlier than 1.3.8-1+lenny7" test_ref="oval:org.mitre.oval:tst:19288"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 4.0 is installed" definition_ref="oval:org.mitre.oval:def:6461"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Architecture independent section" operator="AND">
              <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="libcupsys2-gnutls10 is earlier than 1.2.7-4+etch9" test_ref="oval:org.mitre.oval:tst:19318"/>
                <criterion comment="cupsys-common is earlier than 1.2.7-4+etch9" test_ref="oval:org.mitre.oval:tst:19277"/>
              </criteria>
            </criteria>
            <criteria comment="Packages section" operator="OR">
              <criterion comment="cupsys-bsd DPKG is earlier than 1.2.7-4+etch9" test_ref="oval:org.mitre.oval:tst:18483"/>
              <criterion comment="cupsys-client DPKG is earlier than 1.2.7-4+etch9" test_ref="oval:org.mitre.oval:tst:19310"/>
              <criterion comment="libcupsys2-dev DPKG is earlier than 1.2.7-4+etch9" test_ref="oval:org.mitre.oval:tst:18521"/>
              <criterion comment="libcupsimage2-dev DPKG is earlier than 1.2.7-4+etch9" test_ref="oval:org.mitre.oval:tst:18729"/>
              <criterion comment="libcupsimage2 DPKG is earlier than 1.2.7-4+etch9" test_ref="oval:org.mitre.oval:tst:19125"/>
              <criterion comment="cupsys-dbg DPKG is earlier than 1.2.7-4+etch9" test_ref="oval:org.mitre.oval:tst:18534"/>
              <criterion comment="cupsys DPKG is earlier than 1.2.7-4+etch9" test_ref="oval:org.mitre.oval:tst:19342"/>
              <criterion comment="libcupsys2 DPKG is earlier than 1.2.7-4+etch9" test_ref="oval:org.mitre.oval:tst:18575"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:8225" class="patch">
      <metadata>
        <title>DSA-1936 libgd2 -- several vulnerabilities</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <platform>Debian GNU/Linux 4.0</platform>
          <product>libgd2</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2009/dsa-1936" ref_id="DSA-1936"/>
        <description>Several vulnerabilities have been discovered in libgd2, a library for programmatic graphics creation and manipulation. The Common Vulnerabilities and Exposures project identifies the following problems: Kees Cook discovered a buffer overflow in libgd2"s font renderer. An attacker could cause denial of service (application crash) and possibly execute arbitrary code via a crafted string with a JIS encoded font. This issue only affects the oldstable distribution (etch). Tomas Hoger discovered a boundary error in the "_gdGetColors()" function. An attacker could conduct a buffer overflow or buffer over-read attacks via a crafted GD file.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:11-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T07:59:12.922-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:05:07.316-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:03:50.770-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Platform section" operator="OR">
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Architecture dependent section" operator="AND">
              <criteria comment="Supported architectures section" operator="OR">
                <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
                <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
                <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
                <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
                <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
                <criterion comment="Installed architecture is armel" test_ref="oval:org.mitre.oval:tst:11101"/>
                <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
                <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
                <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
                <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
                <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
                <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
              </criteria>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="libgd2-xpm DPKG is earlier than 2.0.36~rc1~dfsg-3+lenny1" test_ref="oval:org.mitre.oval:tst:19475"/>
                <criterion comment="libgd2-noxpm DPKG is earlier than 2.0.36~rc1~dfsg-3+lenny1" test_ref="oval:org.mitre.oval:tst:19448"/>
                <criterion comment="libgd2-xpm-dev DPKG is earlier than 2.0.36~rc1~dfsg-3+lenny1" test_ref="oval:org.mitre.oval:tst:19143"/>
                <criterion comment="libgd2-noxpm-dev DPKG is earlier than 2.0.36~rc1~dfsg-3+lenny1" test_ref="oval:org.mitre.oval:tst:19013"/>
                <criterion comment="libgd-tools DPKG is earlier than 2.0.36~rc1~dfsg-3+lenny1" test_ref="oval:org.mitre.oval:tst:19135"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 4.0 is installed" definition_ref="oval:org.mitre.oval:def:6461"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Packages section" operator="OR">
              <criterion comment="libgd2-xpm DPKG is earlier than 2.0.33-5.2etch2" test_ref="oval:org.mitre.oval:tst:19482"/>
              <criterion comment="libgd2-noxpm DPKG is earlier than 2.0.33-5.2etch2" test_ref="oval:org.mitre.oval:tst:19026"/>
              <criterion comment="libgd2-xpm-dev DPKG is earlier than 2.0.33-5.2etch2" test_ref="oval:org.mitre.oval:tst:19223"/>
              <criterion comment="libgd-tools DPKG is earlier than 2.0.33-5.2etch2" test_ref="oval:org.mitre.oval:tst:19188"/>
              <criterion comment="libgd2-noxpm-dev DPKG is earlier than 2.0.33-5.2etch2" test_ref="oval:org.mitre.oval:tst:18844"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:8224" class="patch">
      <metadata>
        <title>DSA-1784 freetype -- integer overflows</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <platform>Debian GNU/Linux 4.0</platform>
          <product>freetype</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2009/dsa-1784" ref_id="DSA-1784"/>
        <description>Tavis Ormandy discovered several integer overflows in FreeType, a library to process and access font files, resulting in heap- or stack-based buffer overflows leading to application crashes or the execution of arbitrary code via a crafted font file.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:10-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T07:58:09.079-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:05:06.748-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:03:50.341-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Platform section" operator="OR">
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Architecture dependent section" operator="AND">
              <criteria comment="Supported architectures section" operator="OR">
                <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
                <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
                <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
                <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
                <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
                <criterion comment="Installed architecture is armel" test_ref="oval:org.mitre.oval:tst:11101"/>
                <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
                <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
                <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
                <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
                <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
              </criteria>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="libfreetype6-dev DPKG is earlier than 2.3.7-2+lenny1" test_ref="oval:org.mitre.oval:tst:18520"/>
                <criterion comment="freetype2-demos DPKG is earlier than 2.3.7-2+lenny1" test_ref="oval:org.mitre.oval:tst:18738"/>
                <criterion comment="libfreetype6 DPKG is earlier than 2.3.7-2+lenny1" test_ref="oval:org.mitre.oval:tst:18761"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 4.0 is installed" definition_ref="oval:org.mitre.oval:def:6461"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Packages section" operator="OR">
              <criterion comment="libfreetype6-dev DPKG is earlier than 2.2.1-5+etch4" test_ref="oval:org.mitre.oval:tst:18524"/>
              <criterion comment="freetype2-demos DPKG is earlier than 2.2.1-5+etch4" test_ref="oval:org.mitre.oval:tst:18549"/>
              <criterion comment="libfreetype6 DPKG is earlier than 2.2.1-5+etch4" test_ref="oval:org.mitre.oval:tst:18342"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:8221" class="patch">
      <metadata>
        <title>DSA-1932 pidgin -- programming error</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <product>pidgin</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2009/dsa-1932" ref_id="DSA-1932"/>
        <description>It was discovered that incorrect pointer handling in the purple library, an internal component of the multi-protocol instant messaging client Pidgin, could lead to denial of service or the execution of arbitrary code through malformed contact requests.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:11-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T07:59:08.308-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:05:06.071-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:03:49.794-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Release section" operator="AND">
        <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
        <criteria comment="Architecture section" operator="OR">
          <criteria comment="Architecture independent section" operator="AND">
            <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
            <criteria comment="Packages section" operator="OR">
              <criterion comment="libpurple-dev is earlier than 2.4.3-4lenny5" test_ref="oval:org.mitre.oval:tst:18722"/>
              <criterion comment="finch-dev is earlier than 2.4.3-4lenny5" test_ref="oval:org.mitre.oval:tst:18904"/>
              <criterion comment="pidgin-dev is earlier than 2.4.3-4lenny5" test_ref="oval:org.mitre.oval:tst:18847"/>
              <criterion comment="libpurple-bin is earlier than 2.4.3-4lenny5" test_ref="oval:org.mitre.oval:tst:19352"/>
              <criterion comment="pidgin-data is earlier than 2.4.3-4lenny5" test_ref="oval:org.mitre.oval:tst:19451"/>
            </criteria>
          </criteria>
          <criteria comment="Packages section" operator="OR">
            <criterion comment="libpurple0 DPKG is earlier than 2.4.3-4lenny5" test_ref="oval:org.mitre.oval:tst:18808"/>
            <criterion comment="pidgin-dbg DPKG is earlier than 2.4.3-4lenny5" test_ref="oval:org.mitre.oval:tst:19383"/>
            <criterion comment="pidgin DPKG is earlier than 2.4.3-4lenny5" test_ref="oval:org.mitre.oval:tst:18867"/>
            <criterion comment="finch DPKG is earlier than 2.4.3-4lenny5" test_ref="oval:org.mitre.oval:tst:19231"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:8217" class="patch">
      <metadata>
        <title>DSA-1772 udev -- several vulnerabilities</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <platform>Debian GNU/Linux 4.0</platform>
          <product>udev</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2009/dsa-1772" ref_id="DSA-1772"/>
        <description>Sebastian Kramer discovered two vulnerabilities in udev, the /dev and hotplug management daemon. udev does not check the origin of NETLINK messages, allowing local users to gain root privileges. udev suffers from a buffer overflow condition in path encoding, potentially allowing arbitrary code execution.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:10-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T07:58:24.856-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:05:05.000-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:03:48.925-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Platform section" operator="OR">
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Architecture dependent section" operator="AND">
              <criteria comment="Supported architectures section" operator="OR">
                <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
                <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
                <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
                <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
                <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
                <criterion comment="Installed architecture is armel" test_ref="oval:org.mitre.oval:tst:11101"/>
                <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
                <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
                <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
                <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
                <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
                <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
              </criteria>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="libvolume-id-dev DPKG is earlier than 0.125-7+lenny1" test_ref="oval:org.mitre.oval:tst:18836"/>
                <criterion comment="libvolume-id0 DPKG is earlier than 0.125-7+lenny1" test_ref="oval:org.mitre.oval:tst:18915"/>
                <criterion comment="udev DPKG is earlier than 0.125-7+lenny1" test_ref="oval:org.mitre.oval:tst:18875"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 4.0 is installed" definition_ref="oval:org.mitre.oval:def:6461"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Packages section" operator="OR">
              <criterion comment="libvolume-id-dev DPKG is earlier than 0.105-4etch1" test_ref="oval:org.mitre.oval:tst:18811"/>
              <criterion comment="libvolume-id0 DPKG is earlier than 0.105-4etch1" test_ref="oval:org.mitre.oval:tst:19015"/>
              <criterion comment="udev DPKG is earlier than 0.105-4etch1" test_ref="oval:org.mitre.oval:tst:18997"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:8213" class="patch">
      <metadata>
        <title>DSA-1938 php-mail -- programming error</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <platform>Debian GNU/Linux 4.0</platform>
          <product>php-mail</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2009/dsa-1938" ref_id="DSA-1938"/>
        <description>It was discovered that php-mail, a PHP PEAR module for sending email, has insufficient input sanitising, which might be used to obtain sensitive data from the system that uses php-mail.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:11-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T07:59:19.109-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:05:04.464-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:03:48.470-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Platform section" operator="OR">
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Architecture independent section" operator="AND">
              <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criterion comment="php-mail is earlier than 1.1.14-1+lenny1" test_ref="oval:org.mitre.oval:tst:18641"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 4.0 is installed" definition_ref="oval:org.mitre.oval:def:6461"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Architecture independent section" operator="AND">
              <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criterion comment="php-mail is earlier than 1.1.6-2+etch1" test_ref="oval:org.mitre.oval:tst:19439"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:8210" class="patch">
      <metadata>
        <title>DSA-1740 yaws -- denial of service</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <platform>Debian GNU/Linux 4.0</platform>
          <product>yaws</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2009/dsa-1740" ref_id="DSA-1740"/>
        <description>It was discovered that yaws, a high performance HTTP 1.1 webserver, is prone to a denial of service attack via a request with a large HTTP header.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:12-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T07:59:59.561-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:05:03.878-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:03:47.993-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Platform section" operator="OR">
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Architecture independent section" operator="AND">
              <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="yaws-wiki is earlier than 1.77-3+lenny1" test_ref="oval:org.mitre.oval:tst:20039"/>
                <criterion comment="yaws-mail is earlier than 1.77-3+lenny1" test_ref="oval:org.mitre.oval:tst:20038"/>
                <criterion comment="yaws-chat is earlier than 1.77-3+lenny1" test_ref="oval:org.mitre.oval:tst:19750"/>
                <criterion comment="yaws-yapp is earlier than 1.77-3+lenny1" test_ref="oval:org.mitre.oval:tst:20045"/>
              </criteria>
            </criteria>
            <criteria comment="Architecture dependent section" operator="AND">
              <criteria comment="Supported architectures section" operator="OR">
                <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
                <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
                <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
                <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
                <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
                <criterion comment="Installed architecture is armel" test_ref="oval:org.mitre.oval:tst:11101"/>
                <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
                <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
                <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
                <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
                <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
                <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
              </criteria>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="yaws DPKG is earlier than 1.77-3+lenny1" test_ref="oval:org.mitre.oval:tst:20001"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 4.0 is installed" definition_ref="oval:org.mitre.oval:def:6461"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Architecture dependent section" operator="AND">
              <criteria comment="Supported architectures section" operator="OR">
                <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
                <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
                <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
                <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
                <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
                <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
                <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
                <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
                <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
                <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
              </criteria>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="yaws DPKG is earlier than 1.65-4etch1" test_ref="oval:org.mitre.oval:tst:19697"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:8206" class="patch">
      <metadata>
        <title>DSA-1858 imagemagick -- multiple vulnerabilities</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <platform>Debian GNU/Linux 4.0</platform>
          <product>imagemagick</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2009/dsa-1858" ref_id="DSA-1858"/>
        <description>Several vulnerabilities have been discovered in the imagemagick image manipulation programs which can lead to the execution of arbitrary code, exposure of sensitive information or cause DoS. The Common Vulnerabilities and Exposures project identifies the following problems: Multiple integer overflows in XInitImage function in xwd.c for ImageMagick, allow user-assisted remote attackers to cause a denial of service (crash) or obtain sensitive information via crafted images with large or negative values that trigger a buffer overflow. It only affects the oldstable distribution (etch). Multiple integer overflows allow remote attackers to execute arbitrary code via a crafted DCM image, or the colors or comments field in a crafted XWD image. It only affects the oldstable distribution (etch). A crafted image file can trigger an infinite loop in the ReadDCMImage function or in the ReadXCFImage function. It only affects the oldstable distribution (etch). Multiple integer overflows allow context-dependent attackers to execute arbitrary code via a crafted .dcm, .dib, .xbm, .xcf, or .xwd image file, which triggers a heap-based buffer overflow. It only affects the oldstable distribution (etch). Off-by-one error allows context-dependent attackers to execute arbitrary code via a crafted image file, which triggers the writing of a "\0" character to an out-of-bounds address. It affects only the oldstable distribution (etch). A sign extension error allows context-dependent attackers to execute arbitrary code via a crafted width value in an image file, which triggers an integer overflow and a heap-based buffer overflow. It affects only the oldstable distribution (etch). The load_tile function in the XCF coder allows user-assisted remote attackers to cause a denial of service or possibly execute arbitrary code via a crafted .xcf file that triggers an out-of-bounds heap write. It affects only to oldstable (etch). Heap-based buffer overflow in the PCX coder allows user-assisted remote attackers to cause a denial of service or possibly execute arbitrary code via a crafted .pcx file that triggers incorrect memory allocation for the scanline array, leading to memory corruption. It affects only to oldstable (etch). Integer overflow allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted TIFF file, which triggers a buffer overflow.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:10-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T07:58:45.975-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:05:02.923-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:03:47.155-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Platform section" operator="OR">
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Architecture dependent section" operator="AND">
              <criteria comment="Supported architectures section" operator="OR">
                <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
                <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
                <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
                <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
                <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
                <criterion comment="Installed architecture is armel" test_ref="oval:org.mitre.oval:tst:11101"/>
                <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
                <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
                <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
                <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
                <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
              </criteria>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="imagemagick DPKG is earlier than 6.3.7.9.dfsg2-1~lenny3" test_ref="oval:org.mitre.oval:tst:19229"/>
                <criterion comment="libmagick9-dev DPKG is earlier than 6.3.7.9.dfsg2-1~lenny3" test_ref="oval:org.mitre.oval:tst:18985"/>
                <criterion comment="perlmagick DPKG is earlier than 6.3.7.9.dfsg2-1~lenny3" test_ref="oval:org.mitre.oval:tst:18813"/>
                <criterion comment="libmagick++9-dev DPKG is earlier than 6.3.7.9.dfsg2-1~lenny3" test_ref="oval:org.mitre.oval:tst:19014"/>
                <criterion comment="libmagick++10 DPKG is earlier than 6.3.7.9.dfsg2-1~lenny3" test_ref="oval:org.mitre.oval:tst:19162"/>
                <criterion comment="libmagick10 DPKG is earlier than 6.3.7.9.dfsg2-1~lenny3" test_ref="oval:org.mitre.oval:tst:19187"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 4.0 is installed" definition_ref="oval:org.mitre.oval:def:6461"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Architecture dependent section" operator="AND">
              <criteria comment="Supported architectures section" operator="OR">
                <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
                <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
                <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
                <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
                <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
                <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
                <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
                <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
                <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
                <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
              </criteria>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="libmagick9 DPKG is earlier than 6.2.4.5.dfsg1-0.15+etch1" test_ref="oval:org.mitre.oval:tst:18989"/>
                <criterion comment="imagemagick DPKG is earlier than 6.2.4.5.dfsg1-0.15+etch1" test_ref="oval:org.mitre.oval:tst:18670"/>
                <criterion comment="libmagick9-dev DPKG is earlier than 6.2.4.5.dfsg1-0.15+etch1" test_ref="oval:org.mitre.oval:tst:18832"/>
                <criterion comment="libmagick++9c2a DPKG is earlier than 6.2.4.5.dfsg1-0.15+etch1" test_ref="oval:org.mitre.oval:tst:19185"/>
                <criterion comment="perlmagick DPKG is earlier than 6.2.4.5.dfsg1-0.15+etch1" test_ref="oval:org.mitre.oval:tst:19173"/>
                <criterion comment="libmagick++9-dev DPKG is earlier than 6.2.4.5.dfsg1-0.15+etch1" test_ref="oval:org.mitre.oval:tst:18932"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:8205" class="patch">
      <metadata>
        <title>DSA-1739 mldonkey -- path traversal</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <product>mldonkey</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2009/dsa-1739" ref_id="DSA-1739"/>
        <description>It has been discovered that mldonkey, a client for several P2P networks, allows attackers to download arbitrary files using crafted requests to the HTTP console. The old stable distribution (etch) is not affected by this problem.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:11-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T07:59:19.528-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:05:02.530-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:03:46.742-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Release section" operator="AND">
        <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
        <criteria comment="Architecture section" operator="OR">
          <criteria comment="Architecture dependent section" operator="AND">
            <criteria comment="Supported architectures section" operator="OR">
              <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
              <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
              <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
              <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
              <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
              <criterion comment="Installed architecture is armel" test_ref="oval:org.mitre.oval:tst:11101"/>
              <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
              <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
              <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
              <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
              <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
              <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
            </criteria>
            <criteria comment="Packages section" operator="OR">
              <criterion comment="mldonkey-gui DPKG is earlier than 2.9.5-2+lenny1" test_ref="oval:org.mitre.oval:tst:19392"/>
              <criterion comment="mldonkey-server DPKG is earlier than 2.9.5-2+lenny1" test_ref="oval:org.mitre.oval:tst:19453"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:8201" class="patch">
      <metadata>
        <title>DSA-1934 apache2 -- multiple issues</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <platform>Debian GNU/Linux 4.0</platform>
          <product>apache2</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2009/dsa-1934" ref_id="DSA-1934"/>
        <description>A design flaw has been found in the TLS and SSL protocol that allows an attacker to inject arbitrary content at the beginning of a TLS/SSL connection. The attack is related to the way how TLS and SSL handle session renegotiations. CVE-2009-3555 has been assigned to this vulnerability. As a partial mitigation against this attack, this apache2 update disables client-initiated renegotiations. This should fix the vulnerability for the majority of Apache configurations in use. NOTE: This is not a complete fix for the problem. The attack is still possible in configurations where the server initiates the renegotiation. This is the case for the following configurations (the information in the changelog of the updated packages is slightly inaccurate): As a workaround, you may rearrange your configuration in a way that SSLVerifyClient and SSLCipherSuite are only used on the server or virtual host level. A complete fix for the problem will require a protocol change. Further information will be included in a separate announcement about this issue. In addition, this update fixes the following issues in Apache's mod_proxy_ftp: Insufficient input validation in the mod_proxy_ftp module allowed remote FTP servers to cause a denial of service (NULL pointer dereference and child process crash) via a malformed reply to an EPSV command. Insufficient input validation in the mod_proxy_ftp module allowed remote authenticated attackers to bypass intended access restrictions and send arbitrary FTP commands to an FTP server. The oldstable distribution (etch), these problems have been fixed in version 2.2.3-4+etch11.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:11-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T07:59:17.199-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:05:00.808-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:03:45.542-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Platform section" operator="OR">
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Architecture independent section" operator="AND">
              <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="apache2-doc is earlier than 2.2.9-10+lenny6" test_ref="oval:org.mitre.oval:tst:18971"/>
                <criterion comment="apache2-src is earlier than 2.2.9-10+lenny6" test_ref="oval:org.mitre.oval:tst:19402"/>
                <criterion comment="apache2 is earlier than 2.2.9-10+lenny6" test_ref="oval:org.mitre.oval:tst:19459"/>
              </criteria>
            </criteria>
            <criteria comment="Architecture dependent section" operator="AND">
              <criteria comment="Supported architectures section" operator="OR">
                <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
                <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
                <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
                <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
                <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
                <criterion comment="Installed architecture is armel" test_ref="oval:org.mitre.oval:tst:11101"/>
                <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
                <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
                <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
                <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
                <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
                <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
              </criteria>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="apache2-utils DPKG is earlier than 2.2.9-10+lenny6" test_ref="oval:org.mitre.oval:tst:19247"/>
                <criterion comment="apache2-mpm-worker DPKG is earlier than 2.2.9-10+lenny6" test_ref="oval:org.mitre.oval:tst:19133"/>
                <criterion comment="apache2.2-common DPKG is earlier than 2.2.9-10+lenny6" test_ref="oval:org.mitre.oval:tst:19089"/>
                <criterion comment="apache2-suexec-custom DPKG is earlier than 2.2.9-10+lenny6" test_ref="oval:org.mitre.oval:tst:19323"/>
                <criterion comment="apache2-suexec DPKG is earlier than 2.2.9-10+lenny6" test_ref="oval:org.mitre.oval:tst:19222"/>
                <criterion comment="apache2-threaded-dev DPKG is earlier than 2.2.9-10+lenny6" test_ref="oval:org.mitre.oval:tst:18986"/>
                <criterion comment="apache2-dbg DPKG is earlier than 2.2.9-10+lenny6" test_ref="oval:org.mitre.oval:tst:19347"/>
                <criterion comment="apache2-mpm-event DPKG is earlier than 2.2.9-10+lenny6" test_ref="oval:org.mitre.oval:tst:19299"/>
                <criterion comment="apache2-mpm-prefork DPKG is earlier than 2.2.9-10+lenny6" test_ref="oval:org.mitre.oval:tst:19473"/>
                <criterion comment="apache2-prefork-dev DPKG is earlier than 2.2.9-10+lenny6" test_ref="oval:org.mitre.oval:tst:18822"/>
              </criteria>
            </criteria>
            <criteria comment="Architecture dependent section" operator="AND">
              <criteria comment="Supported architectures section" operator="OR">
                <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
                <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
                <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
                <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
                <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
                <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
                <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
                <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
                <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
                <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
                <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
              </criteria>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="apache2-mpm-itk DPKG is earlier than 2.2.6-02-1+lenny2+b2" test_ref="oval:org.mitre.oval:tst:19074"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 4.0 is installed" definition_ref="oval:org.mitre.oval:def:6461"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Architecture independent section" operator="AND">
              <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="apache2-mpm-perchild is earlier than 2.2.3-4+etch11" test_ref="oval:org.mitre.oval:tst:19447"/>
                <criterion comment="apache2-doc is earlier than 2.2.3-4+etch11" test_ref="oval:org.mitre.oval:tst:19425"/>
                <criterion comment="apache2-src is earlier than 2.2.3-4+etch11" test_ref="oval:org.mitre.oval:tst:19160"/>
                <criterion comment="apache2 is earlier than 2.2.3-4+etch11" test_ref="oval:org.mitre.oval:tst:18828"/>
              </criteria>
            </criteria>
            <criteria comment="Packages section" operator="OR">
              <criterion comment="apache2-utils DPKG is earlier than 2.2.3-4+etch11" test_ref="oval:org.mitre.oval:tst:19385"/>
              <criterion comment="apache2-mpm-worker DPKG is earlier than 2.2.3-4+etch11" test_ref="oval:org.mitre.oval:tst:19234"/>
              <criterion comment="apache2.2-common DPKG is earlier than 2.2.3-4+etch11" test_ref="oval:org.mitre.oval:tst:19409"/>
              <criterion comment="apache2-mpm-prefork DPKG is earlier than 2.2.3-4+etch11" test_ref="oval:org.mitre.oval:tst:18829"/>
              <criterion comment="apache2-threaded-dev DPKG is earlier than 2.2.3-4+etch11" test_ref="oval:org.mitre.oval:tst:18734"/>
              <criterion comment="apache2-mpm-event DPKG is earlier than 2.2.3-4+etch11" test_ref="oval:org.mitre.oval:tst:19469"/>
              <criterion comment="apache2-mpm-itk DPKG is earlier than 2.2.3-01-2+etch4+b1" test_ref="oval:org.mitre.oval:tst:18893"/>
              <criterion comment="apache2-prefork-dev DPKG is earlier than 2.2.3-4+etch11" test_ref="oval:org.mitre.oval:tst:19038"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:8200" class="patch">
      <metadata>
        <title>DSA-1825 nagios2, nagios3 -- insufficient input validation</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <platform>Debian GNU/Linux 4.0</platform>
          <product>nagios2</product>
          <product>nagios3</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2009/dsa-1825" ref_id="DSA-1825"/>
        <description>It was discovered that the statuswml.cgi script of nagios, a monitoring and management system for hosts, services and networks, is prone to a command injection vulnerability. Input to the ping and traceroute parameters of the script is not properly validated which allows an attacker to execute arbitrary shell commands by passing a crafted value to these parameters.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:08-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T07:55:54.077-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:04:59.950-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:03:44.997-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Platform section" operator="OR">
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Architecture independent section" operator="AND">
              <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="nagios3-doc is earlier than 3.0.6-4~lenny2" test_ref="oval:org.mitre.oval:tst:16887"/>
                <criterion comment="nagios3-common is earlier than 3.0.6-4~lenny2" test_ref="oval:org.mitre.oval:tst:17329"/>
              </criteria>
            </criteria>
            <criteria comment="Architecture dependent section" operator="AND">
              <criteria comment="Supported architectures section" operator="OR">
                <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
                <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
                <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
                <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
                <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
                <criterion comment="Installed architecture is armel" test_ref="oval:org.mitre.oval:tst:11101"/>
                <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
                <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
                <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
                <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
                <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
                <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
              </criteria>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="nagios3-dbg DPKG is earlier than 3.0.6-4~lenny2" test_ref="oval:org.mitre.oval:tst:17221"/>
                <criterion comment="nagios3 DPKG is earlier than 3.0.6-4~lenny2" test_ref="oval:org.mitre.oval:tst:16380"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 4.0 is installed" definition_ref="oval:org.mitre.oval:def:6461"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Architecture independent section" operator="AND">
              <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="nagios2-common is earlier than 2.6-2+etch3" test_ref="oval:org.mitre.oval:tst:17108"/>
                <criterion comment="nagios2-doc is earlier than 2.6-2+etch3" test_ref="oval:org.mitre.oval:tst:17015"/>
              </criteria>
            </criteria>
            <criteria comment="Packages section" operator="OR">
              <criterion comment="nagios2-dbg DPKG is earlier than 2.6-2+etch3" test_ref="oval:org.mitre.oval:tst:17299"/>
              <criterion comment="nagios2 DPKG is earlier than 2.6-2+etch3" test_ref="oval:org.mitre.oval:tst:17275"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:8194" class="patch">
      <metadata>
        <title>DSA-1812 apr-util -- denial of service</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <platform>Debian GNU/Linux 4.0</platform>
          <product>apr-util</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2009/dsa-1812" ref_id="DSA-1812"/>
        <description>Apr-util, the Apache Portable Runtime Utility library, is used by Apache 2.x, Subversion, and other applications. Two denial of service vulnerabilities have been found in apr-util: "kcope" discovered a flaw in the handling of internal XML entities in the apr_xml_* interface that can be exploited to use all available memory. This denial of service can be triggered remotely in the Apache mod_dav and mod_dav_svn modules. (No CVE id yet) Matthew Palmer discovered an underflow flaw in the apr_strmatch_precompile function that can be exploited to cause a daemon crash. The vulnerability can be triggered (1) remotely in mod_dav_svn for Apache if the "SVNMasterURI" directive is in use, (2) remotely in mod_apreq2 for Apache or other applications using libapreq2, or (3) locally in Apache by a crafted ".htaccess" file. Other exploit paths in other applications using apr-util may exist. If you use Apache, or if you use svnserve in standalone mode, you need to restart the services after you upgraded the libaprutil1 package. The oldstable distribution (etch), these problems have been fixed in version 1.2.7+dfsg-2+etch2.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:09-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T07:57:40.544-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:04:56.953-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:03:42.469-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Platform section" operator="OR">
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Architecture dependent section" operator="AND">
              <criteria comment="Supported architectures section" operator="OR">
                <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
                <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
                <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
                <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
                <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
                <criterion comment="Installed architecture is armel" test_ref="oval:org.mitre.oval:tst:11101"/>
                <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
                <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
                <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
                <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
                <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
                <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
              </criteria>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="libaprutil1-dbg DPKG is earlier than 1.2.12+dfsg-8+lenny2" test_ref="oval:org.mitre.oval:tst:18469"/>
                <criterion comment="libaprutil1 DPKG is earlier than 1.2.12+dfsg-8+lenny2" test_ref="oval:org.mitre.oval:tst:18330"/>
                <criterion comment="libaprutil1-dev DPKG is earlier than 1.2.12+dfsg-8+lenny2" test_ref="oval:org.mitre.oval:tst:18582"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 4.0 is installed" definition_ref="oval:org.mitre.oval:def:6461"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Packages section" operator="OR">
              <criterion comment="libaprutil1-dbg DPKG is earlier than 1.2.7+dfsg-2+etch2" test_ref="oval:org.mitre.oval:tst:18566"/>
              <criterion comment="libaprutil1 DPKG is earlier than 1.2.7+dfsg-2+etch2" test_ref="oval:org.mitre.oval:tst:17861"/>
              <criterion comment="libaprutil1-dev DPKG is earlier than 1.2.7+dfsg-2+etch2" test_ref="oval:org.mitre.oval:tst:18562"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:8189" class="patch">
      <metadata>
        <title>DSA-1767 multipath-tools -- insecure file permissions</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <platform>Debian GNU/Linux 4.0</platform>
          <product>multipath-tools</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2009/dsa-1767" ref_id="DSA-1767"/>
        <description>It was discovered that multipathd of multipath-tools, a tool-chain to manage disk multipath device maps, uses insecure permissions on its unix domain control socket which enables local attackers to issue commands to multipathd prevent access to storage devices or corrupt file system data.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:07-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T07:54:59.553-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:04:55.974-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:03:41.611-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Platform section" operator="OR">
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Architecture independent section" operator="AND">
              <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criterion comment="multipath-tools-boot is earlier than 0.4.8-14+lenny1" test_ref="oval:org.mitre.oval:tst:16216"/>
            </criteria>
            <criteria comment="Architecture dependent section" operator="AND">
              <criteria comment="Supported architectures section" operator="OR">
                <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
                <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
                <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
                <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
                <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
                <criterion comment="Installed architecture is armel" test_ref="oval:org.mitre.oval:tst:11101"/>
                <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
                <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
                <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
                <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
                <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
                <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
              </criteria>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="kpartx DPKG is earlier than 0.4.8-14+lenny1" test_ref="oval:org.mitre.oval:tst:16625"/>
                <criterion comment="multipath-tools DPKG is earlier than 0.4.8-14+lenny1" test_ref="oval:org.mitre.oval:tst:16626"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 4.0 is installed" definition_ref="oval:org.mitre.oval:def:6461"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Architecture dependent section" operator="AND">
              <criteria comment="Supported architectures section" operator="OR">
                <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
                <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
                <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
                <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
                <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
                <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
                <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
                <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
                <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
              </criteria>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="multipath-tools DPKG is earlier than 0.4.7-1.1etch2" test_ref="oval:org.mitre.oval:tst:16582"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:8185" class="patch">
      <metadata>
        <title>DSA-1764 tunapie -- several vulnerabilities</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <product>tunapie</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2009/dsa-1764" ref_id="DSA-1764"/>
        <description>Several vulnerabilities have been discovered in Tunapie, a GUI frontend to video and radio streams. The Common Vulnerabilities and Exposures project identifies the following problems: Kees Cook discovered that insecure handling of temporary files may lead to local denial of service through symlink attacks. Mike Coleman discovered that insufficient escaping of stream URLs may lead to the execution of arbitrary commands if a user is tricked into opening a malformed stream URL.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:07-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T07:55:00.076-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:04:54.638-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:03:40.965-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Release section" operator="AND">
        <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
        <criteria comment="Architecture section" operator="OR">
          <criteria comment="Architecture independent section" operator="AND">
            <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
            <criterion comment="tunapie is earlier than 2.1.8-2" test_ref="oval:org.mitre.oval:tst:16706"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:8184" class="patch">
      <metadata>
        <title>DSA-1774 ejabberd -- insufficient input sanitising</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <product>ejabberd</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2009/dsa-1774" ref_id="DSA-1774"/>
        <description>It was discovered that ejabberd, a distributed, fault-tolerant Jabber/XMPP server, does not sufficiently sanitise MUC logs, allowing remote attackers to perform cross-site scripting (XSS) attacks. The oldstable distribution (etch) is not affected by this issue.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:10-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T07:58:14.591-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:04:54.148-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:03:40.636-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Release section" operator="AND">
        <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
        <criteria comment="Architecture section" operator="OR">
          <criteria comment="Architecture dependent section" operator="AND">
            <criteria comment="Supported architectures section" operator="OR">
              <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
              <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
              <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
              <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
              <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
              <criterion comment="Installed architecture is armel" test_ref="oval:org.mitre.oval:tst:11101"/>
              <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
              <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
              <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
              <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
              <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
            </criteria>
            <criteria comment="Packages section" operator="OR">
              <criterion comment="ejabberd DPKG is earlier than 2.0.1-6+lenny1" test_ref="oval:org.mitre.oval:tst:18688"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:8182" class="patch">
      <metadata>
        <title>DSA-1924 mahara -- several vulnerabilities</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <product>mahara</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2009/dsa-1924" ref_id="DSA-1924"/>
        <description>Two vulnerabilities have been discovered in mahara, an electronic portfolio, weblog, and resume builder. The Common Vulnerabilities and Exposures project identifies the following problems: Ruslan Kabalin discovered a issue with resetting passwords, which could lead to a privilege escalation of an institutional administrator account. Sven Vetsch discovered a cross-site scripting vulnerability via the resume fields.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:08-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T07:56:03.911-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:04:52.727-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:03:39.551-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Release section" operator="AND">
        <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
        <criteria comment="Architecture section" operator="OR">
          <criteria comment="Architecture independent section" operator="AND">
            <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
            <criteria comment="Packages section" operator="OR">
              <criterion comment="mahara-apache2 is earlier than 1.0.4-4+lenny4" test_ref="oval:org.mitre.oval:tst:16733"/>
              <criterion comment="mahara is earlier than 1.0.4-4+lenny4" test_ref="oval:org.mitre.oval:tst:17305"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:8181" class="patch">
      <metadata>
        <title>DSA-1766 krb5 -- several vulnerabilities</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <platform>Debian GNU/Linux 4.0</platform>
          <product>krb5</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2009/dsa-1766" ref_id="DSA-1766"/>
        <description>Several vulnerabilities have been found in the MIT reference implementation of Kerberos V5, a system for authenticating users and services on a network. The Common Vulnerabilities and Exposures project identified the following problems: The Apple Product Security team discovered that the SPNEGO GSS-API mechanism suffers of a missing bounds check when reading a network input buffer which results in an invalid read crashing the application or possibly leaking information. Under certain conditions the SPNEGO GSS-API mechanism references a null pointer which crashes the application using the library. An incorrect length check inside the ASN.1 decoder of the MIT krb5 implementation allows an unauthenticated remote attacker to crash of the kinit or KDC program. Under certain conditions the the ASN.1 decoder of the MIT krb5 implementation frees an uninitialized pointer which could lead to denial of service and possibly arbitrary code execution.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:07-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T07:54:58.295-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:04:51.621-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:03:38.825-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Platform section" operator="OR">
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Architecture independent section" operator="AND">
              <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criterion comment="krb5-doc is earlier than 1.6.dfsg.4~beta1-5lenny1" test_ref="oval:org.mitre.oval:tst:16278"/>
            </criteria>
            <criteria comment="Architecture dependent section" operator="AND">
              <criteria comment="Supported architectures section" operator="OR">
                <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
                <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
                <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
                <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
                <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
                <criterion comment="Installed architecture is armel" test_ref="oval:org.mitre.oval:tst:11101"/>
                <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
                <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
                <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
                <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
                <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
              </criteria>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="krb5-rsh-server DPKG is earlier than 1.6.dfsg.4~beta1-5lenny1" test_ref="oval:org.mitre.oval:tst:16590"/>
                <criterion comment="krb5-kdc-ldap DPKG is earlier than 1.6.dfsg.4~beta1-5lenny1" test_ref="oval:org.mitre.oval:tst:16660"/>
                <criterion comment="krb5-telnetd DPKG is earlier than 1.6.dfsg.4~beta1-5lenny1" test_ref="oval:org.mitre.oval:tst:16148"/>
                <criterion comment="libkrb5-dev DPKG is earlier than 1.6.dfsg.4~beta1-5lenny1" test_ref="oval:org.mitre.oval:tst:16839"/>
                <criterion comment="libkrb53 DPKG is earlier than 1.6.dfsg.4~beta1-5lenny1" test_ref="oval:org.mitre.oval:tst:16583"/>
                <criterion comment="krb5-ftpd DPKG is earlier than 1.6.dfsg.4~beta1-5lenny1" test_ref="oval:org.mitre.oval:tst:16462"/>
                <criterion comment="krb5-pkinit DPKG is earlier than 1.6.dfsg.4~beta1-5lenny1" test_ref="oval:org.mitre.oval:tst:16027"/>
                <criterion comment="libkadm55 DPKG is earlier than 1.6.dfsg.4~beta1-5lenny1" test_ref="oval:org.mitre.oval:tst:16050"/>
                <criterion comment="libkrb5-dbg DPKG is earlier than 1.6.dfsg.4~beta1-5lenny1" test_ref="oval:org.mitre.oval:tst:16266"/>
                <criterion comment="krb5-user DPKG is earlier than 1.6.dfsg.4~beta1-5lenny1" test_ref="oval:org.mitre.oval:tst:16819"/>
                <criterion comment="krb5-kdc DPKG is earlier than 1.6.dfsg.4~beta1-5lenny1" test_ref="oval:org.mitre.oval:tst:15852"/>
                <criterion comment="krb5-clients DPKG is earlier than 1.6.dfsg.4~beta1-5lenny1" test_ref="oval:org.mitre.oval:tst:16836"/>
                <criterion comment="krb5-admin-server DPKG is earlier than 1.6.dfsg.4~beta1-5lenny1" test_ref="oval:org.mitre.oval:tst:16407"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 4.0 is installed" definition_ref="oval:org.mitre.oval:def:6461"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Architecture independent section" operator="AND">
              <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criterion comment="krb5-doc is earlier than 1.4.4-7etch7" test_ref="oval:org.mitre.oval:tst:15857"/>
            </criteria>
            <criteria comment="Packages section" operator="OR">
              <criterion comment="krb5-rsh-server DPKG is earlier than 1.4.4-7etch7" test_ref="oval:org.mitre.oval:tst:16837"/>
              <criterion comment="krb5-telnetd DPKG is earlier than 1.4.4-7etch7" test_ref="oval:org.mitre.oval:tst:15941"/>
              <criterion comment="libkrb5-dev DPKG is earlier than 1.4.4-7etch7" test_ref="oval:org.mitre.oval:tst:16754"/>
              <criterion comment="libkrb53 DPKG is earlier than 1.4.4-7etch7" test_ref="oval:org.mitre.oval:tst:16814"/>
              <criterion comment="krb5-ftpd DPKG is earlier than 1.4.4-7etch7" test_ref="oval:org.mitre.oval:tst:16694"/>
              <criterion comment="krb5-admin-server DPKG is earlier than 1.4.4-7etch7" test_ref="oval:org.mitre.oval:tst:16636"/>
              <criterion comment="libkadm55 DPKG is earlier than 1.4.4-7etch7" test_ref="oval:org.mitre.oval:tst:16477"/>
              <criterion comment="libkrb5-dbg DPKG is earlier than 1.4.4-7etch7" test_ref="oval:org.mitre.oval:tst:16798"/>
              <criterion comment="krb5-user DPKG is earlier than 1.4.4-7etch7" test_ref="oval:org.mitre.oval:tst:16842"/>
              <criterion comment="krb5-clients DPKG is earlier than 1.4.4-7etch7" test_ref="oval:org.mitre.oval:tst:16768"/>
              <criterion comment="krb5-kdc DPKG is earlier than 1.4.4-7etch7" test_ref="oval:org.mitre.oval:tst:16170"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:8174" class="patch">
      <metadata>
        <title>DSA-1828 ocsinventory-agent -- insecure module search path</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <product>ocsinventory-agent</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2009/dsa-1828" ref_id="DSA-1828"/>
        <description>It was discovered that the ocsinventory-agent which is part of the ocsinventory suite, a hardware and software configuration indexing service, is prone to an insecure perl module search path. As the agent is started via cron and the current directory (/ in this case) is included in the default perl module path the agent scans every directory on the system for its perl modules. This enables an attacker to execute arbitrary code via a crafted ocsinventory-agent perl module placed on the system. The oldstable distribution (etch) does not contain ocsinventory-agent.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:08-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T07:55:53.191-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:04:48.957-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:03:37.118-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Release section" operator="AND">
        <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
        <criteria comment="Architecture section" operator="OR">
          <criteria comment="Architecture independent section" operator="AND">
            <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
            <criterion comment="ocsinventory-agent is earlier than 0.0.9.2repack1-4lenny1" test_ref="oval:org.mitre.oval:tst:17225"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:8171" class="patch">
      <metadata>
        <title>DSA-1931 nspr -- several vulnerabilities</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <product>nspr</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2009/dsa-1931" ref_id="DSA-1931"/>
        <description>Several vulnerabilities have been discovered in the NetScape Portable Runtime Library, which may lead to the execution of arbitrary code. The Common Vulnerabilities and Exposures project identifies the following problems: A programming error in the string handling code may lead to the execution of arbitrary code. An integer overflow in the Base64 decoding functions may lead to the execution of arbitrary code. The old stable distribution (etch) doesn't contain nspr.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:11-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T07:59:08.789-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:04:47.959-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:03:36.196-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Release section" operator="AND">
        <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
        <criteria comment="Architecture section" operator="OR">
          <criteria comment="Architecture dependent section" operator="AND">
            <criteria comment="Supported architectures section" operator="OR">
              <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
              <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
              <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
              <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
              <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
              <criterion comment="Installed architecture is armel" test_ref="oval:org.mitre.oval:tst:11101"/>
              <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
              <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
              <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
              <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
              <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
              <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
            </criteria>
            <criteria comment="Packages section" operator="OR">
              <criterion comment="libnspr4-dev DPKG is earlier than 4.7.1-5" test_ref="oval:org.mitre.oval:tst:19338"/>
              <criterion comment="libnspr4-0d-dbg DPKG is earlier than 4.7.1-5" test_ref="oval:org.mitre.oval:tst:19456"/>
              <criterion comment="libnspr4-0d DPKG is earlier than 4.7.1-5" test_ref="oval:org.mitre.oval:tst:19452"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:8167" class="patch">
      <metadata>
        <title>DSA-1827 ipplan -- insufficient input sanitising</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <product>ipplan</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2009/dsa-1827" ref_id="DSA-1827"/>
        <description>It was discovered that ipplan, a web-based IP address manager and tracker, does not sufficiently escape certain input parameters, which allows remote attackers to conduct cross-site scripting attacks. The oldstable distribution (etch) does not contain ipplan.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:08-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T07:55:54.950-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:04:46.171-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:03:34.638-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Release section" operator="AND">
        <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
        <criteria comment="Architecture section" operator="OR">
          <criteria comment="Architecture independent section" operator="AND">
            <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
            <criterion comment="ipplan is earlier than 4.86a-7+lenny1" test_ref="oval:org.mitre.oval:tst:17358"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:8166" class="patch">
      <metadata>
        <title>DSA-1853 memcached -- heap-based buffer overflow</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <platform>Debian GNU/Linux 4.0</platform>
          <product>memcached</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2009/dsa-1853" ref_id="DSA-1853"/>
        <description>Ronald Volgers discovered that memcached, a high-performance memory object caching system, is vulnerable to several heap-based buffer overflows due to integer conversions when parsing certain length attributes. An attacker can use this to execute arbitrary code on the system running memcached (on etch with root privileges).</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:11-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T07:58:50.782-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:04:45.645-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:03:34.256-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Platform section" operator="OR">
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Architecture dependent section" operator="AND">
              <criteria comment="Supported architectures section" operator="OR">
                <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
                <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
                <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
                <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
                <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
                <criterion comment="Installed architecture is armel" test_ref="oval:org.mitre.oval:tst:11101"/>
                <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
                <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
                <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
                <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
                <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
                <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
              </criteria>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="memcached DPKG is earlier than 1.2.2-1+lenny1" test_ref="oval:org.mitre.oval:tst:18974"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 4.0 is installed" definition_ref="oval:org.mitre.oval:def:6461"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Packages section" operator="OR">
              <criterion comment="memcached DPKG is earlier than 1.1.12-1+etch1" test_ref="oval:org.mitre.oval:tst:19151"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:8164" class="patch">
      <metadata>
        <title>DSA-1789 php5 -- several vulnerabilities</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <platform>Debian GNU/Linux 4.0</platform>
          <product>php5</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2009/dsa-1789" ref_id="DSA-1789"/>
        <description>Several remote vulnerabilities have been discovered in the PHP5 hypertext preprocessor. The Common Vulnerabilities and Exposures project identifies the following problems. The following four vulnerabilities have already been fixed in the stable (lenny) version of php5 prior to the release of lenny. This update now addresses them for etch (oldstable) as well: The GENERATE_SEED macro has several problems that make predicting generated random numbers easier, facilitating attacks against measures that use rand() or mt_rand() as part of a protection. A buffer overflow in the mbstring extension allows attackers to execute arbitrary code via a crafted string containing an HTML entity. The page_uid and page_gid variables are not correctly set, allowing use of some functionality intended to be restricted to root. Directory traversal vulnerability in the ZipArchive::extractTo function allows attackers to write arbitrary files via a ZIP file with a file whose name contains .. (dot dot) sequences. This update also addresses the following three vulnerabilities for both oldstable (etch) and stable (lenny): Cross-site scripting (XSS) vulnerability, when display_errors is enabled, allows remote attackers to inject arbitrary web script or HTML. When running on Apache, PHP allows local users to modify behavior of other sites hosted on the same web server by modifying the mbstring.func_overload setting within .htaccess, which causes this setting to be applied to other virtual hosts on the same server. The JSON_parser function allows a denial of service (segmentation fault) via a malformed string to the json_decode API function. Furthermore, two updates originally scheduled for the next point update for oldstable are included in the etch package: Let PHP use the system timezone database instead of the embedded timezone database which is out of date. From the source tarball, the unused "dbase" module has been removed which contained licensing problems.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:10-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T07:58:01.765-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:04:43.998-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:03:32.939-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Platform section" operator="OR">
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Architecture independent section" operator="AND">
              <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="php5 is earlier than 5.2.6.dfsg.1-1+lenny3" test_ref="oval:org.mitre.oval:tst:18001"/>
                <criterion comment="php-pear is earlier than 5.2.6.dfsg.1-1+lenny3" test_ref="oval:org.mitre.oval:tst:18225"/>
              </criteria>
            </criteria>
            <criteria comment="Architecture dependent section" operator="AND">
              <criteria comment="Supported architectures section" operator="OR">
                <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
                <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
                <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
                <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
                <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
                <criterion comment="Installed architecture is armel" test_ref="oval:org.mitre.oval:tst:11101"/>
                <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
                <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
                <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
                <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
                <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
                <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
              </criteria>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="php5-recode DPKG is earlier than 5.2.6.dfsg.1-1+lenny3" test_ref="oval:org.mitre.oval:tst:18659"/>
                <criterion comment="php5-cgi DPKG is earlier than 5.2.6.dfsg.1-1+lenny3" test_ref="oval:org.mitre.oval:tst:18192"/>
                <criterion comment="php5-curl DPKG is earlier than 5.2.6.dfsg.1-1+lenny3" test_ref="oval:org.mitre.oval:tst:18630"/>
                <criterion comment="php5-snmp DPKG is earlier than 5.2.6.dfsg.1-1+lenny3" test_ref="oval:org.mitre.oval:tst:18567"/>
                <criterion comment="php5-mysql DPKG is earlier than 5.2.6.dfsg.1-1+lenny3" test_ref="oval:org.mitre.oval:tst:18718"/>
                <criterion comment="php5-odbc DPKG is earlier than 5.2.6.dfsg.1-1+lenny3" test_ref="oval:org.mitre.oval:tst:18657"/>
                <criterion comment="php5-xsl DPKG is earlier than 5.2.6.dfsg.1-1+lenny3" test_ref="oval:org.mitre.oval:tst:18372"/>
                <criterion comment="php5-gd DPKG is earlier than 5.2.6.dfsg.1-1+lenny3" test_ref="oval:org.mitre.oval:tst:18163"/>
                <criterion comment="libapache2-mod-php5 DPKG is earlier than 5.2.6.dfsg.1-1+lenny3" test_ref="oval:org.mitre.oval:tst:17817"/>
                <criterion comment="php5-mhash DPKG is earlier than 5.2.6.dfsg.1-1+lenny3" test_ref="oval:org.mitre.oval:tst:18642"/>
                <criterion comment="php5-tidy DPKG is earlier than 5.2.6.dfsg.1-1+lenny3" test_ref="oval:org.mitre.oval:tst:18774"/>
                <criterion comment="php5-mcrypt DPKG is earlier than 5.2.6.dfsg.1-1+lenny3" test_ref="oval:org.mitre.oval:tst:18728"/>
                <criterion comment="php5-dev DPKG is earlier than 5.2.6.dfsg.1-1+lenny3" test_ref="oval:org.mitre.oval:tst:18611"/>
                <criterion comment="php5-pgsql DPKG is earlier than 5.2.6.dfsg.1-1+lenny3" test_ref="oval:org.mitre.oval:tst:18785"/>
                <criterion comment="php5-gmp DPKG is earlier than 5.2.6.dfsg.1-1+lenny3" test_ref="oval:org.mitre.oval:tst:18560"/>
                <criterion comment="php5-xmlrpc DPKG is earlier than 5.2.6.dfsg.1-1+lenny3" test_ref="oval:org.mitre.oval:tst:18766"/>
                <criterion comment="php5-imap DPKG is earlier than 5.2.6.dfsg.1-1+lenny3" test_ref="oval:org.mitre.oval:tst:18537"/>
                <criterion comment="php5-sqlite DPKG is earlier than 5.2.6.dfsg.1-1+lenny3" test_ref="oval:org.mitre.oval:tst:17824"/>
                <criterion comment="php5-ldap DPKG is earlier than 5.2.6.dfsg.1-1+lenny3" test_ref="oval:org.mitre.oval:tst:18059"/>
                <criterion comment="php5-cli DPKG is earlier than 5.2.6.dfsg.1-1+lenny3" test_ref="oval:org.mitre.oval:tst:18553"/>
                <criterion comment="php5-sybase DPKG is earlier than 5.2.6.dfsg.1-1+lenny3" test_ref="oval:org.mitre.oval:tst:18375"/>
                <criterion comment="php5-pspell DPKG is earlier than 5.2.6.dfsg.1-1+lenny3" test_ref="oval:org.mitre.oval:tst:18590"/>
                <criterion comment="libapache2-mod-php5filter DPKG is earlier than 5.2.6.dfsg.1-1+lenny3" test_ref="oval:org.mitre.oval:tst:18825"/>
                <criterion comment="php5-common DPKG is earlier than 5.2.6.dfsg.1-1+lenny3" test_ref="oval:org.mitre.oval:tst:18473"/>
                <criterion comment="php5-dbg DPKG is earlier than 5.2.6.dfsg.1-1+lenny3" test_ref="oval:org.mitre.oval:tst:18498"/>
              </criteria>
            </criteria>
            <criteria comment="Architecture dependent section" operator="AND">
              <criteria comment="Supported architectures section" operator="OR">
                <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
                <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
                <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
                <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
              </criteria>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="php5-interbase DPKG is earlier than 5.2.6.dfsg.1-1+lenny3" test_ref="oval:org.mitre.oval:tst:18293"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 4.0 is installed" definition_ref="oval:org.mitre.oval:def:6461"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Architecture independent section" operator="AND">
              <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="php5 is earlier than 5.2.0+dfsg-8+etch15" test_ref="oval:org.mitre.oval:tst:18666"/>
                <criterion comment="php-pear is earlier than 5.2.0+dfsg-8+etch15" test_ref="oval:org.mitre.oval:tst:18784"/>
              </criteria>
            </criteria>
            <criteria comment="Packages section" operator="OR">
              <criterion comment="libapache-mod-php5 DPKG is earlier than 5.2.0+dfsg-8+etch15" test_ref="oval:org.mitre.oval:tst:18781"/>
              <criterion comment="php5-recode DPKG is earlier than 5.2.0+dfsg-8+etch15" test_ref="oval:org.mitre.oval:tst:18782"/>
              <criterion comment="php5-xmlrpc DPKG is earlier than 5.2.0+dfsg-8+etch15" test_ref="oval:org.mitre.oval:tst:18691"/>
              <criterion comment="php5-curl DPKG is earlier than 5.2.0+dfsg-8+etch15" test_ref="oval:org.mitre.oval:tst:18671"/>
              <criterion comment="php5-snmp DPKG is earlier than 5.2.0+dfsg-8+etch15" test_ref="oval:org.mitre.oval:tst:18384"/>
              <criterion comment="php5-mysql DPKG is earlier than 5.2.0+dfsg-8+etch15" test_ref="oval:org.mitre.oval:tst:17857"/>
              <criterion comment="php5-odbc DPKG is earlier than 5.2.0+dfsg-8+etch15" test_ref="oval:org.mitre.oval:tst:18799"/>
              <criterion comment="php5-xsl DPKG is earlier than 5.2.0+dfsg-8+etch15" test_ref="oval:org.mitre.oval:tst:18823"/>
              <criterion comment="php5-gd DPKG is earlier than 5.2.0+dfsg-8+etch15" test_ref="oval:org.mitre.oval:tst:18681"/>
              <criterion comment="libapache2-mod-php5 DPKG is earlier than 5.2.0+dfsg-8+etch15" test_ref="oval:org.mitre.oval:tst:18858"/>
              <criterion comment="php5-mhash DPKG is earlier than 5.2.0+dfsg-8+etch15" test_ref="oval:org.mitre.oval:tst:18618"/>
              <criterion comment="php5-tidy DPKG is earlier than 5.2.0+dfsg-8+etch15" test_ref="oval:org.mitre.oval:tst:18827"/>
              <criterion comment="php5-mcrypt DPKG is earlier than 5.2.0+dfsg-8+etch15" test_ref="oval:org.mitre.oval:tst:18697"/>
              <criterion comment="php5-dev DPKG is earlier than 5.2.0+dfsg-8+etch15" test_ref="oval:org.mitre.oval:tst:18856"/>
              <criterion comment="php5-pgsql DPKG is earlier than 5.2.0+dfsg-8+etch15" test_ref="oval:org.mitre.oval:tst:18783"/>
              <criterion comment="php5-cgi DPKG is earlier than 5.2.0+dfsg-8+etch15" test_ref="oval:org.mitre.oval:tst:18777"/>
              <criterion comment="php5-imap DPKG is earlier than 5.2.0+dfsg-8+etch15" test_ref="oval:org.mitre.oval:tst:18640"/>
              <criterion comment="php5-sqlite DPKG is earlier than 5.2.0+dfsg-8+etch15" test_ref="oval:org.mitre.oval:tst:18721"/>
              <criterion comment="php5-ldap DPKG is earlier than 5.2.0+dfsg-8+etch15" test_ref="oval:org.mitre.oval:tst:18787"/>
              <criterion comment="php5-cli DPKG is earlier than 5.2.0+dfsg-8+etch15" test_ref="oval:org.mitre.oval:tst:18837"/>
              <criterion comment="php5-sybase DPKG is earlier than 5.2.0+dfsg-8+etch15" test_ref="oval:org.mitre.oval:tst:18730"/>
              <criterion comment="php5-pspell DPKG is earlier than 5.2.0+dfsg-8+etch15" test_ref="oval:org.mitre.oval:tst:18701"/>
              <criterion comment="php5-common DPKG is earlier than 5.2.0+dfsg-8+etch15" test_ref="oval:org.mitre.oval:tst:18658"/>
            </criteria>
            <criteria comment="Architecture dependent section" operator="AND">
              <criteria comment="Supported architectures section" operator="OR">
                <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
                <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
              </criteria>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="php5-interbase DPKG is earlier than 5.2.0+dfsg-8+etch15" test_ref="oval:org.mitre.oval:tst:18732"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:8161" class="patch">
      <metadata>
        <title>DSA-1911 pygresql -- missing escape function</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <platform>Debian GNU/Linux 4.0</platform>
          <product>pygresql</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2009/dsa-1911" ref_id="DSA-1911"/>
        <description>It was discovered that pygresql, a PostgreSQL module for Python, was missing a function to call PQescapeStringConn(). This is needed, because PQescapeStringConn() honours the charset of the connection and prevents insufficient escaping, when certain multibyte character encodings are used. The new function is called pg_escape_string(), which takes the database connection as a first argument. The old function escape_string() has been preserved as well for backwards compatibility. Developers using these bindings are encouraged to adjust their code to use the new function.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:07-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T07:54:12.896-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:04:42.097-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:03:31.740-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Platform section" operator="OR">
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Architecture dependent section" operator="AND">
              <criteria comment="Supported architectures section" operator="OR">
                <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
                <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
                <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
                <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
                <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
                <criterion comment="Installed architecture is armel" test_ref="oval:org.mitre.oval:tst:11101"/>
                <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
                <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
                <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
                <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
                <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
                <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
              </criteria>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="python-pygresql DPKG is earlier than 3.8.1-3+lenny1" test_ref="oval:org.mitre.oval:tst:15228"/>
                <criterion comment="python-pygresql-dbg DPKG is earlier than 3.8.1-3+lenny1" test_ref="oval:org.mitre.oval:tst:15800"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 4.0 is installed" definition_ref="oval:org.mitre.oval:def:6461"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Architecture dependent section" operator="AND">
              <criteria comment="Supported architectures section" operator="OR">
                <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
                <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
                <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
                <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
                <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
                <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
                <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
                <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
                <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
                <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
              </criteria>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="python-pygresql DPKG is earlier than 3.8.1-1etch2" test_ref="oval:org.mitre.oval:tst:16147"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:8160" class="patch">
      <metadata>
        <title>DSA-1854 apr, apr-util -- heap buffer overflow</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <platform>Debian GNU/Linux 4.0</platform>
          <product>apr</product>
          <product>apr-util</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2009/dsa-1854" ref_id="DSA-1854"/>
        <description>Matt Lewis discovered that the memory management code in the Apache Portable Runtime (APR) library does not guard against a wrap-around during size computations. This could cause the library to return a memory area which smaller than requested, resulting a heap overflow and possibly arbitrary code execution.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:11-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T07:58:52.593-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:04:41.369-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:03:31.187-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Platform section" operator="OR">
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Architecture dependent section" operator="AND">
              <criteria comment="Supported architectures section" operator="OR">
                <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
                <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
                <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
                <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
                <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
                <criterion comment="Installed architecture is armel" test_ref="oval:org.mitre.oval:tst:11101"/>
                <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
                <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
                <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
                <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
                <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
                <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
              </criteria>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="libapr1-dbg DPKG is earlier than 1.2.12-5+lenny1" test_ref="oval:org.mitre.oval:tst:18819"/>
                <criterion comment="libapr1 DPKG is earlier than 1.2.12-5+lenny1" test_ref="oval:org.mitre.oval:tst:19194"/>
                <criterion comment="libaprutil1 DPKG is earlier than 1.2.12+dfsg-8+lenny4" test_ref="oval:org.mitre.oval:tst:19070"/>
                <criterion comment="libapr1-dev DPKG is earlier than 1.2.12-5+lenny1" test_ref="oval:org.mitre.oval:tst:19214"/>
                <criterion comment="libaprutil1-dbg DPKG is earlier than 1.2.12+dfsg-8+lenny4" test_ref="oval:org.mitre.oval:tst:18920"/>
                <criterion comment="libaprutil1-dev DPKG is earlier than 1.2.12+dfsg-8+lenny4" test_ref="oval:org.mitre.oval:tst:18334"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 4.0 is installed" definition_ref="oval:org.mitre.oval:def:6461"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Architecture dependent section" operator="AND">
              <criteria comment="Supported architectures section" operator="OR">
                <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
                <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
                <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
                <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
                <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
                <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
                <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
                <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
                <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
                <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
              </criteria>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="libapr1-dbg DPKG is earlier than 1.2.7-9" test_ref="oval:org.mitre.oval:tst:19213"/>
                <criterion comment="libapr1 DPKG is earlier than 1.2.7-9" test_ref="oval:org.mitre.oval:tst:18954"/>
                <criterion comment="libaprutil1 DPKG is earlier than 1.2.7+dfsg-2+etch3" test_ref="oval:org.mitre.oval:tst:19235"/>
                <criterion comment="libapr1-dev DPKG is earlier than 1.2.7-9" test_ref="oval:org.mitre.oval:tst:19281"/>
                <criterion comment="libaprutil1-dbg DPKG is earlier than 1.2.7+dfsg-2+etch3" test_ref="oval:org.mitre.oval:tst:19330"/>
                <criterion comment="libaprutil1-dev DPKG is earlier than 1.2.7+dfsg-2+etch3" test_ref="oval:org.mitre.oval:tst:19147"/>
              </criteria>
            </criteria>
            <criteria comment="Architecture dependent section" operator="AND">
              <criteria comment="Supported architectures section" operator="OR">
                <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
              </criteria>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="libaprutil1-dbg DPKG is earlier than 1.2.7+dfsg-2+etch3" test_ref="oval:org.mitre.oval:tst:18655"/>
                <criterion comment="libaprutil1 DPKG is earlier than 1.2.7+dfsg-2+etch3" test_ref="oval:org.mitre.oval:tst:19166"/>
                <criterion comment="libaprutil1-dev DPKG is earlier than 1.2.7+dfsg-2+etch3" test_ref="oval:org.mitre.oval:tst:19218"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:8148" class="patch">
      <metadata>
        <title>DSA-1873 xulrunner -- programming error</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <product>xulrunner</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2009/dsa-1873" ref_id="DSA-1873"/>
        <description>Juan Pablo Lopez Yacubian discovered that incorrect handling of invalid URLs could be used for spoofing the location bar and the SSL certificate status of a web page. Xulrunner is no longer supported for the old stable distribution (etch).</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:06-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T07:53:48.496-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:04:37.966-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:03:28.851-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Release section" operator="AND">
        <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
        <criteria comment="Architecture section" operator="OR">
          <criteria comment="Architecture independent section" operator="AND">
            <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
            <criterion comment="libmozillainterfaces-java is earlier than 1.9.0.13-0lenny1" test_ref="oval:org.mitre.oval:tst:15630"/>
          </criteria>
          <criteria comment="Architecture dependent section" operator="AND">
            <criteria comment="Supported architectures section" operator="OR">
              <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
              <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
              <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
              <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
              <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
              <criterion comment="Installed architecture is armel" test_ref="oval:org.mitre.oval:tst:11101"/>
              <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
              <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
              <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
              <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
              <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
              <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
            </criteria>
            <criteria comment="Packages section" operator="OR">
              <criterion comment="libmozjs-dev DPKG is earlier than 1.9.0.13-0lenny1" test_ref="oval:org.mitre.oval:tst:15738"/>
              <criterion comment="spidermonkey-bin DPKG is earlier than 1.9.0.13-0lenny1" test_ref="oval:org.mitre.oval:tst:15458"/>
              <criterion comment="xulrunner-1.9-gnome-support DPKG is earlier than 1.9.0.13-0lenny1" test_ref="oval:org.mitre.oval:tst:15600"/>
              <criterion comment="xulrunner-1.9 DPKG is earlier than 1.9.0.13-0lenny1" test_ref="oval:org.mitre.oval:tst:15674"/>
              <criterion comment="libmozjs1d-dbg DPKG is earlier than 1.9.0.13-0lenny1" test_ref="oval:org.mitre.oval:tst:15664"/>
              <criterion comment="libmozjs1d DPKG is earlier than 1.9.0.13-0lenny1" test_ref="oval:org.mitre.oval:tst:15569"/>
              <criterion comment="python-xpcom DPKG is earlier than 1.9.0.13-0lenny1" test_ref="oval:org.mitre.oval:tst:15687"/>
              <criterion comment="xulrunner-1.9-dbg DPKG is earlier than 1.9.0.13-0lenny1" test_ref="oval:org.mitre.oval:tst:15691"/>
              <criterion comment="xulrunner-dev DPKG is earlier than 1.9.0.13-0lenny1" test_ref="oval:org.mitre.oval:tst:15155"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:8147" class="patch">
      <metadata>
        <title>DSA-1855 subversion -- heap overflow</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <platform>Debian GNU/Linux 4.0</platform>
          <product>subversion</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2009/dsa-1855" ref_id="DSA-1855"/>
        <description>Matt Lewis discovered that Subversion performs insufficient input validation of svndiff streams. Malicious servers could cause heap overflows in clients, and malicious clients with commit access could cause heap overflows in servers, possibly leading to arbitrary code execution in both cases.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:11-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T07:58:55.675-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:04:36.994-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:03:28.200-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Platform section" operator="OR">
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Architecture independent section" operator="AND">
              <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="subversion-tools is earlier than 1.5.1dfsg1-4" test_ref="oval:org.mitre.oval:tst:19283"/>
                <criterion comment="libsvn-doc is earlier than 1.5.1dfsg1-4" test_ref="oval:org.mitre.oval:tst:19251"/>
                <criterion comment="libsvn-ruby is earlier than 1.5.1dfsg1-4" test_ref="oval:org.mitre.oval:tst:19289"/>
              </criteria>
            </criteria>
            <criteria comment="Architecture dependent section" operator="AND">
              <criteria comment="Supported architectures section" operator="OR">
                <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
                <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
                <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
                <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
                <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
                <criterion comment="Installed architecture is armel" test_ref="oval:org.mitre.oval:tst:11101"/>
                <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
                <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
                <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
                <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
                <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
                <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
              </criteria>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="libsvn-dev DPKG is earlier than 1.5.1dfsg1-4" test_ref="oval:org.mitre.oval:tst:18830"/>
                <criterion comment="libapache2-svn DPKG is earlier than 1.5.1dfsg1-4" test_ref="oval:org.mitre.oval:tst:19326"/>
                <criterion comment="libsvn-ruby1.8 DPKG is earlier than 1.5.1dfsg1-4" test_ref="oval:org.mitre.oval:tst:18672"/>
                <criterion comment="python-subversion DPKG is earlier than 1.5.1dfsg1-4" test_ref="oval:org.mitre.oval:tst:19307"/>
                <criterion comment="libsvn1 DPKG is earlier than 1.5.1dfsg1-4" test_ref="oval:org.mitre.oval:tst:19300"/>
                <criterion comment="subversion DPKG is earlier than 1.5.1dfsg1-4" test_ref="oval:org.mitre.oval:tst:19248"/>
                <criterion comment="libsvn-perl DPKG is earlier than 1.5.1dfsg1-4" test_ref="oval:org.mitre.oval:tst:18862"/>
              </criteria>
            </criteria>
            <criteria comment="Architecture dependent section" operator="AND">
              <criteria comment="Supported architectures section" operator="OR">
                <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
                <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
                <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
                <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
                <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
                <criterion comment="Installed architecture is armel" test_ref="oval:org.mitre.oval:tst:11101"/>
                <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
              </criteria>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="libsvn-java DPKG is earlier than 1.5.1dfsg1-4" test_ref="oval:org.mitre.oval:tst:19273"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 4.0 is installed" definition_ref="oval:org.mitre.oval:def:6461"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Architecture independent section" operator="AND">
              <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="subversion-tools is earlier than 1.4.2dfsg1-3" test_ref="oval:org.mitre.oval:tst:19256"/>
                <criterion comment="libsvn-doc is earlier than 1.4.2dfsg1-3" test_ref="oval:org.mitre.oval:tst:19276"/>
                <criterion comment="libsvn-javahl is earlier than 1.4.2dfsg1-3" test_ref="oval:org.mitre.oval:tst:18913"/>
                <criterion comment="libsvn-ruby is earlier than 1.4.2dfsg1-3" test_ref="oval:org.mitre.oval:tst:19036"/>
              </criteria>
            </criteria>
            <criteria comment="Architecture dependent section" operator="AND">
              <criteria comment="Supported architectures section" operator="OR">
                <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
                <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
                <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
                <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
                <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
                <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
                <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
                <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
              </criteria>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="libsvn-dev DPKG is earlier than 1.4.2dfsg1-3" test_ref="oval:org.mitre.oval:tst:18959"/>
                <criterion comment="libapache2-svn DPKG is earlier than 1.4.2dfsg1-3" test_ref="oval:org.mitre.oval:tst:19230"/>
                <criterion comment="libsvn-ruby1.8 DPKG is earlier than 1.4.2dfsg1-3" test_ref="oval:org.mitre.oval:tst:19333"/>
                <criterion comment="python-subversion DPKG is earlier than 1.4.2dfsg1-3" test_ref="oval:org.mitre.oval:tst:19239"/>
                <criterion comment="libsvn1 DPKG is earlier than 1.4.2dfsg1-3" test_ref="oval:org.mitre.oval:tst:19087"/>
                <criterion comment="subversion DPKG is earlier than 1.4.2dfsg1-3" test_ref="oval:org.mitre.oval:tst:19211"/>
                <criterion comment="libsvn-perl DPKG is earlier than 1.4.2dfsg1-3" test_ref="oval:org.mitre.oval:tst:19078"/>
              </criteria>
            </criteria>
            <criteria comment="Architecture dependent section" operator="AND">
              <criteria comment="Supported architectures section" operator="OR">
                <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
                <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
                <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
                <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
                <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
              </criteria>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="libsvn-java DPKG is earlier than 1.4.2dfsg1-3" test_ref="oval:org.mitre.oval:tst:19232"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:8138" class="patch">
      <metadata>
        <title>DSA-1808 drupal6 -- insufficient input sanitising</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <product>drupal6</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2009/dsa-1808" ref_id="DSA-1808"/>
        <description>Markus Petrux discovered a cross-site scripting vulnerability in the taxonomy module of drupal6, a fully-featured content management framework. It is also possible that certain browsers using the UTF-7 encoding are vulnerable to a different cross-site scripting vulnerability.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:13-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T08:00:56.763-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:04:33.580-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:03:25.148-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Release section" operator="AND">
        <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
        <criteria comment="Architecture section" operator="OR">
          <criteria comment="Architecture independent section" operator="AND">
            <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
            <criterion comment="drupal6 is earlier than 6.6-3lenny2" test_ref="oval:org.mitre.oval:tst:19913"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:8135" class="patch">
      <metadata>
        <title>DSA-1866 kdegraphics -- several vulnerabilities</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <platform>Debian GNU/Linux 4.0</platform>
          <product>kdegraphics</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2009/dsa-1866" ref_id="DSA-1866"/>
        <description>Two security issues have been discovered in kdegraphics, the graphics apps from the official KDE release. The Common Vulnerabilities and Exposures project identifies the following problems: It was discovered that the KSVG animation element implementation suffers from a null pointer dereference flaw, which could lead to the execution of arbitrary code. It was discovered that the KSVG animation element implementation is prone to a use-after-free flaw, which could lead to the execution of arbitrary code.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:09-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T07:57:12.842-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:04:31.633-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:03:23.765-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Platform section" operator="OR">
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Architecture independent section" operator="AND">
              <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="kdegraphics is earlier than 3.5.9-3+lenny2" test_ref="oval:org.mitre.oval:tst:18343"/>
                <criterion comment="kdegraphics-doc-html is earlier than 3.5.9-3+lenny2" test_ref="oval:org.mitre.oval:tst:18434"/>
              </criteria>
            </criteria>
            <criteria comment="Architecture dependent section" operator="AND">
              <criteria comment="Supported architectures section" operator="OR">
                <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
                <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
                <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
                <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
                <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
                <criterion comment="Installed architecture is armel" test_ref="oval:org.mitre.oval:tst:11101"/>
                <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
                <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
                <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
                <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
                <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
              </criteria>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="kolourpaint DPKG is earlier than 3.5.9-3+lenny2" test_ref="oval:org.mitre.oval:tst:18339"/>
                <criterion comment="kdegraphics-kfile-plugins DPKG is earlier than 3.5.9-3+lenny2" test_ref="oval:org.mitre.oval:tst:17911"/>
                <criterion comment="ksvg DPKG is earlier than 3.5.9-3+lenny2" test_ref="oval:org.mitre.oval:tst:18263"/>
                <criterion comment="libkscan-dev DPKG is earlier than 3.5.9-3+lenny2" test_ref="oval:org.mitre.oval:tst:18421"/>
                <criterion comment="kgamma DPKG is earlier than 3.5.9-3+lenny2" test_ref="oval:org.mitre.oval:tst:18198"/>
                <criterion comment="libkscan1 DPKG is earlier than 3.5.9-3+lenny2" test_ref="oval:org.mitre.oval:tst:18353"/>
                <criterion comment="kooka DPKG is earlier than 3.5.9-3+lenny2" test_ref="oval:org.mitre.oval:tst:18424"/>
                <criterion comment="kdegraphics-dev DPKG is earlier than 3.5.9-3+lenny2" test_ref="oval:org.mitre.oval:tst:17814"/>
                <criterion comment="kghostview DPKG is earlier than 3.5.9-3+lenny2" test_ref="oval:org.mitre.oval:tst:18217"/>
                <criterion comment="kfaxview DPKG is earlier than 3.5.9-3+lenny2" test_ref="oval:org.mitre.oval:tst:18373"/>
                <criterion comment="kviewshell DPKG is earlier than 3.5.9-3+lenny2" test_ref="oval:org.mitre.oval:tst:18456"/>
                <criterion comment="kview DPKG is earlier than 3.5.9-3+lenny2" test_ref="oval:org.mitre.oval:tst:18378"/>
                <criterion comment="kfax DPKG is earlier than 3.5.9-3+lenny2" test_ref="oval:org.mitre.oval:tst:18308"/>
                <criterion comment="ksnapshot DPKG is earlier than 3.5.9-3+lenny2" test_ref="oval:org.mitre.oval:tst:18363"/>
                <criterion comment="kmrml DPKG is earlier than 3.5.9-3+lenny2" test_ref="oval:org.mitre.oval:tst:18333"/>
                <criterion comment="kpdf DPKG is earlier than 3.5.9-3+lenny2" test_ref="oval:org.mitre.oval:tst:18278"/>
                <criterion comment="kcoloredit DPKG is earlier than 3.5.9-3+lenny2" test_ref="oval:org.mitre.oval:tst:17952"/>
                <criterion comment="kiconedit DPKG is earlier than 3.5.9-3+lenny2" test_ref="oval:org.mitre.oval:tst:18106"/>
                <criterion comment="kruler DPKG is earlier than 3.5.9-3+lenny2" test_ref="oval:org.mitre.oval:tst:17567"/>
                <criterion comment="kuickshow DPKG is earlier than 3.5.9-3+lenny2" test_ref="oval:org.mitre.oval:tst:18304"/>
                <criterion comment="kdvi DPKG is earlier than 3.5.9-3+lenny2" test_ref="oval:org.mitre.oval:tst:17515"/>
                <criterion comment="kdegraphics-dbg DPKG is earlier than 3.5.9-3+lenny2" test_ref="oval:org.mitre.oval:tst:18235"/>
                <criterion comment="kpovmodeler DPKG is earlier than 3.5.9-3+lenny2" test_ref="oval:org.mitre.oval:tst:18429"/>
                <criterion comment="kamera DPKG is earlier than 3.5.9-3+lenny2" test_ref="oval:org.mitre.oval:tst:18227"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 4.0 is installed" definition_ref="oval:org.mitre.oval:def:6461"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Architecture independent section" operator="AND">
              <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="kdegraphics is earlier than 3.5.5-3etch4" test_ref="oval:org.mitre.oval:tst:18035"/>
                <criterion comment="kdegraphics-doc-html is earlier than 3.5.5-3etch4" test_ref="oval:org.mitre.oval:tst:18204"/>
              </criteria>
            </criteria>
            <criteria comment="Architecture dependent section" operator="AND">
              <criteria comment="Supported architectures section" operator="OR">
                <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
                <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
                <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
                <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
                <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
                <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
                <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
              </criteria>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="kolourpaint DPKG is earlier than 3.5.5-3etch4" test_ref="oval:org.mitre.oval:tst:18144"/>
                <criterion comment="kdegraphics-kfile-plugins DPKG is earlier than 3.5.5-3etch4" test_ref="oval:org.mitre.oval:tst:17693"/>
                <criterion comment="ksvg DPKG is earlier than 3.5.5-3etch4" test_ref="oval:org.mitre.oval:tst:17921"/>
                <criterion comment="libkscan-dev DPKG is earlier than 3.5.5-3etch4" test_ref="oval:org.mitre.oval:tst:17927"/>
                <criterion comment="kgamma DPKG is earlier than 3.5.5-3etch4" test_ref="oval:org.mitre.oval:tst:18306"/>
                <criterion comment="libkscan1 DPKG is earlier than 3.5.5-3etch4" test_ref="oval:org.mitre.oval:tst:18049"/>
                <criterion comment="kooka DPKG is earlier than 3.5.5-3etch4" test_ref="oval:org.mitre.oval:tst:18103"/>
                <criterion comment="kdegraphics-dev DPKG is earlier than 3.5.5-3etch4" test_ref="oval:org.mitre.oval:tst:18078"/>
                <criterion comment="kghostview DPKG is earlier than 3.5.5-3etch4" test_ref="oval:org.mitre.oval:tst:18311"/>
                <criterion comment="kfaxview DPKG is earlier than 3.5.5-3etch4" test_ref="oval:org.mitre.oval:tst:18435"/>
                <criterion comment="kviewshell DPKG is earlier than 3.5.5-3etch4" test_ref="oval:org.mitre.oval:tst:18196"/>
                <criterion comment="kview DPKG is earlier than 3.5.5-3etch4" test_ref="oval:org.mitre.oval:tst:18320"/>
                <criterion comment="kfax DPKG is earlier than 3.5.5-3etch4" test_ref="oval:org.mitre.oval:tst:17496"/>
                <criterion comment="ksnapshot DPKG is earlier than 3.5.5-3etch4" test_ref="oval:org.mitre.oval:tst:18329"/>
                <criterion comment="kmrml DPKG is earlier than 3.5.5-3etch4" test_ref="oval:org.mitre.oval:tst:17994"/>
                <criterion comment="kpdf DPKG is earlier than 3.5.5-3etch4" test_ref="oval:org.mitre.oval:tst:18277"/>
                <criterion comment="kcoloredit DPKG is earlier than 3.5.5-3etch4" test_ref="oval:org.mitre.oval:tst:18428"/>
                <criterion comment="kiconedit DPKG is earlier than 3.5.5-3etch4" test_ref="oval:org.mitre.oval:tst:18006"/>
                <criterion comment="kruler DPKG is earlier than 3.5.5-3etch4" test_ref="oval:org.mitre.oval:tst:18397"/>
                <criterion comment="kuickshow DPKG is earlier than 3.5.5-3etch4" test_ref="oval:org.mitre.oval:tst:18275"/>
                <criterion comment="kdvi DPKG is earlier than 3.5.5-3etch4" test_ref="oval:org.mitre.oval:tst:18148"/>
                <criterion comment="kdegraphics-dbg DPKG is earlier than 3.5.5-3etch4" test_ref="oval:org.mitre.oval:tst:18415"/>
                <criterion comment="kpovmodeler DPKG is earlier than 3.5.5-3etch4" test_ref="oval:org.mitre.oval:tst:17989"/>
                <criterion comment="kamera DPKG is earlier than 3.5.5-3etch4" test_ref="oval:org.mitre.oval:tst:18360"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:8132" class="patch">
      <metadata>
        <title>DSA-1859 libxml2 -- several vulnerabilities</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <platform>Debian GNU/Linux 4.0</platform>
          <product>libxml2</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2009/dsa-1859" ref_id="DSA-1859"/>
        <description>Rauli Kaksonen, Tero Rontti and Jukka Taimisto discovered several vulnerabilities in libxml2, a library for parsing and handling XML data files, which can lead to denial of service conditions or possibly arbitrary code execution in the application using the library. The Common Vulnerabilities and Exposures project identifies the following problems: An XML document with specially-crafted Notation or Enumeration attribute types in a DTD definition leads to the use of a pointers to memory areas which have already been freed. Missing checks for the depth of ELEMENT DTD definitions when parsing child content can lead to extensive stack-growth due to a function recursion which can be triggered via a crafted XML document.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:10-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T07:58:47.594-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:04:30.601-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:03:22.871-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Platform section" operator="OR">
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Architecture independent section" operator="AND">
              <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criterion comment="libxml2-doc is earlier than 2.6.32.dfsg-5+lenny1" test_ref="oval:org.mitre.oval:tst:18272"/>
            </criteria>
            <criteria comment="Architecture dependent section" operator="AND">
              <criteria comment="Supported architectures section" operator="OR">
                <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
                <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
                <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
                <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
                <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
                <criterion comment="Installed architecture is armel" test_ref="oval:org.mitre.oval:tst:11101"/>
                <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
                <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
                <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
                <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
                <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
                <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
              </criteria>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="libxml2 DPKG is earlier than 2.6.32.dfsg-5+lenny1" test_ref="oval:org.mitre.oval:tst:19242"/>
                <criterion comment="libxml2-utils DPKG is earlier than 2.6.32.dfsg-5+lenny1" test_ref="oval:org.mitre.oval:tst:19227"/>
                <criterion comment="python-libxml2 DPKG is earlier than 2.6.32.dfsg-5+lenny1" test_ref="oval:org.mitre.oval:tst:19190"/>
                <criterion comment="libxml2-dbg DPKG is earlier than 2.6.32.dfsg-5+lenny1" test_ref="oval:org.mitre.oval:tst:18433"/>
                <criterion comment="libxml2-dev DPKG is earlier than 2.6.32.dfsg-5+lenny1" test_ref="oval:org.mitre.oval:tst:18577"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 4.0 is installed" definition_ref="oval:org.mitre.oval:def:6461"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Architecture independent section" operator="AND">
              <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criterion comment="libxml2-doc is earlier than 2.6.27.dfsg-6+etch1" test_ref="oval:org.mitre.oval:tst:18581"/>
            </criteria>
            <criteria comment="Packages section" operator="OR">
              <criterion comment="libxml2 DPKG is earlier than 2.6.27.dfsg-6+etch1" test_ref="oval:org.mitre.oval:tst:19057"/>
              <criterion comment="libxml2-utils DPKG is earlier than 2.6.27.dfsg-6+etch1" test_ref="oval:org.mitre.oval:tst:18981"/>
              <criterion comment="python-libxml2 DPKG is earlier than 2.6.27.dfsg-6+etch1" test_ref="oval:org.mitre.oval:tst:18621"/>
              <criterion comment="libxml2-dbg DPKG is earlier than 2.6.27.dfsg-6+etch1" test_ref="oval:org.mitre.oval:tst:18906"/>
              <criterion comment="libxml2-dev DPKG is earlier than 2.6.27.dfsg-6+etch1" test_ref="oval:org.mitre.oval:tst:19002"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:8129" class="patch">
      <metadata>
        <title>DSA-1870 pidgin -- insufficient input validation</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <product>pidgin</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2009/dsa-1870" ref_id="DSA-1870"/>
        <description>Federico Muttis discovered that libpurple, the shared library that adds support for various instant messaging networks to the pidgin IM client, is vulnerable to a heap-based buffer overflow. This issue exists because of an incomplete fix for CVE-2008-2927 and CVE-2009-1376. An attacker can exploit this by sending two consecutive SLP packets to a victim via MSN. The first packet is used to create an SLP message object with an offset of zero, the second packet then contains a crafted offset which hits the vulnerable code originally fixed in CVE-2008-2927 and CVE-2009-1376 and allows an attacker to execute arbitrary code. Note: Users with the "Allow only the users below" setting are not vulnerable to this attack. If you can't install the below updates you may want to set this via Tools->Privacy.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:06-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T07:53:49.822-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:04:28.269-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:03:20.764-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Release section" operator="AND">
        <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
        <criteria comment="Architecture section" operator="OR">
          <criteria comment="Architecture independent section" operator="AND">
            <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
            <criteria comment="Packages section" operator="OR">
              <criterion comment="libpurple-dev is earlier than 2.4.3-4lenny3" test_ref="oval:org.mitre.oval:tst:14856"/>
              <criterion comment="finch-dev is earlier than 2.4.3-4lenny3" test_ref="oval:org.mitre.oval:tst:15221"/>
              <criterion comment="pidgin-dev is earlier than 2.4.3-4lenny3" test_ref="oval:org.mitre.oval:tst:15653"/>
              <criterion comment="libpurple-bin is earlier than 2.4.3-4lenny3" test_ref="oval:org.mitre.oval:tst:15646"/>
              <criterion comment="pidgin-data is earlier than 2.4.3-4lenny3" test_ref="oval:org.mitre.oval:tst:15020"/>
            </criteria>
          </criteria>
          <criteria comment="Architecture dependent section" operator="AND">
            <criteria comment="Supported architectures section" operator="OR">
              <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
              <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
              <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
              <criterion comment="Installed architecture is armel" test_ref="oval:org.mitre.oval:tst:11101"/>
              <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
              <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
              <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
              <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
              <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
            </criteria>
            <criteria comment="Packages section" operator="OR">
              <criterion comment="libpurple0 DPKG is earlier than 2.4.3-4lenny3" test_ref="oval:org.mitre.oval:tst:15091"/>
              <criterion comment="pidgin-dbg DPKG is earlier than 2.4.3-4lenny3" test_ref="oval:org.mitre.oval:tst:15465"/>
              <criterion comment="pidgin DPKG is earlier than 2.4.3-4lenny3" test_ref="oval:org.mitre.oval:tst:15417"/>
              <criterion comment="finch DPKG is earlier than 2.4.3-4lenny3" test_ref="oval:org.mitre.oval:tst:15702"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:8126" class="patch">
      <metadata>
        <title>DSA-1897 horde3 -- insufficient input sanitization</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <platform>Debian GNU/Linux 4.0</platform>
          <product>horde3</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2009/dsa-1897" ref_id="DSA-1897"/>
        <description>Stefan Esser discovered that Horde, a web application framework providing classes for dealing with preferences, compression, browser detection, connection tracking, MIME, and more, is insufficiently validating and escaping user provided input. The Horde_Form_Type_image form element allows to reuse a temporary filename on reuploads which are stored in a hidden HTML field and then trusted without prior validation. An attacker can use this to overwrite arbitrary files on the system or to upload PHP code and thus execute arbitrary code with the rights of the webserver.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:12-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T08:00:08.323-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:04:27.606-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:03:20.287-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Platform section" operator="OR">
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Architecture independent section" operator="AND">
              <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criterion comment="horde3 is earlier than 3.2.2+debian0-2+lenny1" test_ref="oval:org.mitre.oval:tst:19814"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 4.0 is installed" definition_ref="oval:org.mitre.oval:def:6461"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Architecture independent section" operator="AND">
              <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criterion comment="horde3 is earlier than 3.1.3-4etch6" test_ref="oval:org.mitre.oval:tst:19965"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:8114" class="patch">
      <metadata>
        <title>DSA-1823 samba -- several vulnerabilities</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <product>samba</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2009/dsa-1823" ref_id="DSA-1823"/>
        <description>Several vulnerabilities have been discovered in Samba, a SMB/CIFS file, print, and login server. The Common Vulnerabilities and Exposures project identifies the following problems: The smbclient utility contains a formatstring vulnerability where commands dealing with file names treat user input as format strings to asprintf. In the smbd daemon, if a user is trying to modify an access control list (ACL) and is denied permission, this deny may be overridden if the parameter "dos filemode" is set to "yes" in the smb.conf and the user already has write access to the file. The old stable distribution (etch) is not affected by these problems.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:08-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T07:55:59.193-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:04:19.762-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:03:13.482-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Release section" operator="AND">
        <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
        <criteria comment="Architecture section" operator="OR">
          <criteria comment="Architecture independent section" operator="AND">
            <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
            <criteria comment="Packages section" operator="OR">
              <criterion comment="samba-doc is earlier than 3.2.5-4lenny6" test_ref="oval:org.mitre.oval:tst:17301"/>
              <criterion comment="samba-doc-pdf is earlier than 3.2.5-4lenny6" test_ref="oval:org.mitre.oval:tst:17171"/>
            </criteria>
          </criteria>
          <criteria comment="Architecture dependent section" operator="AND">
            <criteria comment="Supported architectures section" operator="OR">
              <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
              <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
              <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
              <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
              <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
              <criterion comment="Installed architecture is armel" test_ref="oval:org.mitre.oval:tst:11101"/>
              <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
              <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
              <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
              <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
              <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
              <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
            </criteria>
            <criteria comment="Packages section" operator="OR">
              <criterion comment="smbfs DPKG is earlier than 3.2.5-4lenny6" test_ref="oval:org.mitre.oval:tst:16587"/>
              <criterion comment="samba DPKG is earlier than 3.2.5-4lenny6" test_ref="oval:org.mitre.oval:tst:16503"/>
              <criterion comment="swat DPKG is earlier than 3.2.5-4lenny6" test_ref="oval:org.mitre.oval:tst:16902"/>
              <criterion comment="samba-tools DPKG is earlier than 3.2.5-4lenny6" test_ref="oval:org.mitre.oval:tst:17387"/>
              <criterion comment="winbind DPKG is earlier than 3.2.5-4lenny6" test_ref="oval:org.mitre.oval:tst:16976"/>
              <criterion comment="smbclient DPKG is earlier than 3.2.5-4lenny6" test_ref="oval:org.mitre.oval:tst:17391"/>
              <criterion comment="libwbclient0 DPKG is earlier than 3.2.5-4lenny6" test_ref="oval:org.mitre.oval:tst:17205"/>
              <criterion comment="samba-dbg DPKG is earlier than 3.2.5-4lenny6" test_ref="oval:org.mitre.oval:tst:17336"/>
              <criterion comment="libsmbclient-dev DPKG is earlier than 3.2.5-4lenny6" test_ref="oval:org.mitre.oval:tst:17314"/>
              <criterion comment="samba-common DPKG is earlier than 3.2.5-4lenny6" test_ref="oval:org.mitre.oval:tst:17284"/>
              <criterion comment="libpam-smbpass DPKG is earlier than 3.2.5-4lenny6" test_ref="oval:org.mitre.oval:tst:17135"/>
              <criterion comment="libsmbclient DPKG is earlier than 3.2.5-4lenny6" test_ref="oval:org.mitre.oval:tst:16724"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:8112" class="patch">
      <metadata>
        <title>DSA-1920 nginx -- denial of service</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <platform>Debian GNU/Linux 4.0</platform>
          <product>nginx</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2009/dsa-1920" ref_id="DSA-1920"/>
        <description>A denial of service vulnerability has been found in nginx, a small and efficient web server. Jasson Bell discovered that a remote attacker could cause a denial of service (segmentation fault) by sending a crafted request.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:08-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T07:56:00.357-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:04:18.280-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:03:12.615-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Platform section" operator="OR">
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Architecture dependent section" operator="AND">
              <criteria comment="Supported architectures section" operator="OR">
                <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
                <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
                <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
                <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
                <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
                <criterion comment="Installed architecture is armel" test_ref="oval:org.mitre.oval:tst:11101"/>
                <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
                <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
                <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
                <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
                <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
                <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
              </criteria>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="nginx DPKG is earlier than 0.6.32-3+lenny3" test_ref="oval:org.mitre.oval:tst:17353"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 4.0 is installed" definition_ref="oval:org.mitre.oval:def:6461"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Packages section" operator="OR">
              <criterion comment="nginx DPKG is earlier than 0.4.13-2+etch3" test_ref="oval:org.mitre.oval:tst:17163"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:8111" class="patch">
      <metadata>
        <title>DSA-1874 nss -- several vulnerabilities</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <product>nss</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2009/dsa-1874" ref_id="DSA-1874"/>
        <description>Several vulnerabilities have been discovered in the Network Security Service libraries. The Common Vulnerabilities and Exposures project identifies the following problems: Moxie Marlinspike discovered that a buffer overflow in the regular expression parser could lead to the execution of arbitrary code. Dan Kaminsky discovered that NULL characters in certificate names could lead to man-in-the-middle attacks by tricking the user into accepting a rogue certificate. Certificates with MD2 hash signatures are no longer accepted since they're no longer considered cryptograhically secure. The old stable distribution (etch) doesn't contain nss.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:06-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T07:53:42.292-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:04:17.817-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:03:12.230-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Release section" operator="AND">
        <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
        <criteria comment="Architecture section" operator="OR">
          <criteria comment="Architecture dependent section" operator="AND">
            <criteria comment="Supported architectures section" operator="OR">
              <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
              <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
              <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
              <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
              <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
              <criterion comment="Installed architecture is armel" test_ref="oval:org.mitre.oval:tst:11101"/>
              <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
              <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
              <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
              <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
              <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
              <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
            </criteria>
            <criteria comment="Packages section" operator="OR">
              <criterion comment="libnss3-dev DPKG is earlier than 3.12.3.1-0lenny1" test_ref="oval:org.mitre.oval:tst:15554"/>
              <criterion comment="libnss3-1d-dbg DPKG is earlier than 3.12.3.1-0lenny1" test_ref="oval:org.mitre.oval:tst:14886"/>
              <criterion comment="libnss3-tools DPKG is earlier than 3.12.3.1-0lenny1" test_ref="oval:org.mitre.oval:tst:15437"/>
              <criterion comment="libnss3-1d DPKG is earlier than 3.12.3.1-0lenny1" test_ref="oval:org.mitre.oval:tst:15513"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:8107" class="patch">
      <metadata>
        <title>DSA-1776 slurm-llnl -- programming error</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <product>slurm-llnl</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2009/dsa-1776" ref_id="DSA-1776"/>
        <description>It was discovered that the Simple Linux Utility for Resource Management (SLURM), a cluster job management and scheduling system, did not drop the supplemental groups. These groups may be system groups with elevated privileges, which may allow a valid SLURM user to gain elevated privileges. The old stable distribution (etch) does not contain a slurm-llnl package.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:10-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T07:58:18.399-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:04:16.714-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:03:11.294-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Release section" operator="AND">
        <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
        <criteria comment="Architecture section" operator="OR">
          <criteria comment="Architecture independent section" operator="AND">
            <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
            <criterion comment="slurm-llnl-doc is earlier than 1.3.6-1lenny3" test_ref="oval:org.mitre.oval:tst:18680"/>
          </criteria>
          <criteria comment="Architecture dependent section" operator="AND">
            <criteria comment="Supported architectures section" operator="OR">
              <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
              <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
              <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
              <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
              <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
              <criterion comment="Installed architecture is armel" test_ref="oval:org.mitre.oval:tst:11101"/>
              <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
              <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
              <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
              <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
              <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
              <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
            </criteria>
            <criteria comment="Packages section" operator="OR">
              <criterion comment="libslurm13-dev DPKG is earlier than 1.3.6-1lenny3" test_ref="oval:org.mitre.oval:tst:18821"/>
              <criterion comment="libslurm13 DPKG is earlier than 1.3.6-1lenny3" test_ref="oval:org.mitre.oval:tst:18745"/>
              <criterion comment="slurm-llnl-basic-plugins-dev DPKG is earlier than 1.3.6-1lenny3" test_ref="oval:org.mitre.oval:tst:18955"/>
              <criterion comment="slurm-llnl-basic-plugins DPKG is earlier than 1.3.6-1lenny3" test_ref="oval:org.mitre.oval:tst:18941"/>
              <criterion comment="slurm-llnl DPKG is earlier than 1.3.6-1lenny3" test_ref="oval:org.mitre.oval:tst:18569"/>
              <criterion comment="libpmi0-dev DPKG is earlier than 1.3.6-1lenny3" test_ref="oval:org.mitre.oval:tst:18995"/>
              <criterion comment="slurm-llnl-slurmdbd DPKG is earlier than 1.3.6-1lenny3" test_ref="oval:org.mitre.oval:tst:18600"/>
              <criterion comment="libpmi0 DPKG is earlier than 1.3.6-1lenny3" test_ref="oval:org.mitre.oval:tst:18767"/>
              <criterion comment="slurm-llnl-sview DPKG is earlier than 1.3.6-1lenny3" test_ref="oval:org.mitre.oval:tst:19049"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:8105" class="patch">
      <metadata>
        <title>DSA-1747 glib2.0 -- integer overflow</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <platform>Debian GNU/Linux 4.0</platform>
          <product>glib2.0</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2009/dsa-1747" ref_id="DSA-1747"/>
        <description>Diego Pettenograve discovered that glib2.0, the GLib library of C routines, handles large strings insecurely via its Base64 encoding functions. This could possible lead to the execution of arbitrary code.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:12-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T07:59:58.492-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:04:12.881-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:03:08.790-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Platform section" operator="OR">
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Architecture independent section" operator="AND">
              <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="libglib2.0-doc is earlier than 2.16.6-1+lenny1" test_ref="oval:org.mitre.oval:tst:19714"/>
                <criterion comment="libglib2.0-data is earlier than 2.16.6-1+lenny1" test_ref="oval:org.mitre.oval:tst:19743"/>
              </criteria>
            </criteria>
            <criteria comment="Architecture dependent section" operator="AND">
              <criteria comment="Supported architectures section" operator="OR">
                <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
                <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
                <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
                <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
                <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
                <criterion comment="Installed architecture is armel" test_ref="oval:org.mitre.oval:tst:11101"/>
                <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
                <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
                <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
                <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
                <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
                <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
              </criteria>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="libglib2.0-0 DPKG is earlier than 2.16.6-1+lenny1" test_ref="oval:org.mitre.oval:tst:19862"/>
                <criterion comment="libglib2.0-0-dbg DPKG is earlier than 2.16.6-1+lenny1" test_ref="oval:org.mitre.oval:tst:19884"/>
                <criterion comment="libgio-fam DPKG is earlier than 2.16.6-1+lenny1" test_ref="oval:org.mitre.oval:tst:19836"/>
                <criterion comment="libglib2.0-dev DPKG is earlier than 2.16.6-1+lenny1" test_ref="oval:org.mitre.oval:tst:19630"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 4.0 is installed" definition_ref="oval:org.mitre.oval:def:6461"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Architecture independent section" operator="AND">
              <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="libglib2.0-doc is earlier than 2.12.4-2+etch1" test_ref="oval:org.mitre.oval:tst:19779"/>
                <criterion comment="libglib2.0-data is earlier than 2.12.4-2+etch1" test_ref="oval:org.mitre.oval:tst:19775"/>
              </criteria>
            </criteria>
            <criteria comment="Packages section" operator="OR">
              <criterion comment="libglib2.0-0 DPKG is earlier than 2.12.4-2+etch1" test_ref="oval:org.mitre.oval:tst:19866"/>
              <criterion comment="libglib2.0-0-dbg DPKG is earlier than 2.12.4-2+etch1" test_ref="oval:org.mitre.oval:tst:19643"/>
              <criterion comment="libglib2.0-dev DPKG is earlier than 2.12.4-2+etch1" test_ref="oval:org.mitre.oval:tst:20029"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:8100" class="patch">
      <metadata>
        <title>DSA-1818 gforge -- insufficient input sanitising</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <platform>Debian GNU/Linux 4.0</platform>
          <product>gforge</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2009/dsa-1818" ref_id="DSA-1818"/>
        <description>Laurent Almeras and Guillaume Smet have discovered a possible SQL injection vulnerability and cross-site scripting vulnerabilities in gforge, a collaborative development tool. Due to insufficient input sanitising, it was possible to inject arbitrary SQL statements and use several parameters to conduct cross-site scripting attacks.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:09-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T07:57:49.037-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:04:11.193-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:03:07.184-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Platform section" operator="OR">
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Architecture independent section" operator="AND">
              <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="gforge-mta-courier is earlier than 4.7~rc2-7lenny1" test_ref="oval:org.mitre.oval:tst:18588"/>
                <criterion comment="gforge is earlier than 4.7~rc2-7lenny1" test_ref="oval:org.mitre.oval:tst:18723"/>
                <criterion comment="gforge-plugin-scmcvs is earlier than 4.7~rc2-7lenny1" test_ref="oval:org.mitre.oval:tst:18705"/>
                <criterion comment="gforge-common is earlier than 4.7~rc2-7lenny1" test_ref="oval:org.mitre.oval:tst:18436"/>
                <criterion comment="gforge-shell-postgresql is earlier than 4.7~rc2-7lenny1" test_ref="oval:org.mitre.oval:tst:18607"/>
                <criterion comment="gforge-plugin-scmsvn is earlier than 4.7~rc2-7lenny1" test_ref="oval:org.mitre.oval:tst:18501"/>
                <criterion comment="gforge-web-apache2 is earlier than 4.7~rc2-7lenny1" test_ref="oval:org.mitre.oval:tst:18404"/>
                <criterion comment="gforge-mta-postfix is earlier than 4.7~rc2-7lenny1" test_ref="oval:org.mitre.oval:tst:18636"/>
                <criterion comment="gforge-mta-exim4 is earlier than 4.7~rc2-7lenny1" test_ref="oval:org.mitre.oval:tst:18747"/>
                <criterion comment="gforge-lists-mailman is earlier than 4.7~rc2-7lenny1" test_ref="oval:org.mitre.oval:tst:18335"/>
                <criterion comment="gforge-web-apache is earlier than 4.7~rc2-7lenny1" test_ref="oval:org.mitre.oval:tst:18366"/>
                <criterion comment="gforge-db-postgresql is earlier than 4.7~rc2-7lenny1" test_ref="oval:org.mitre.oval:tst:18651"/>
                <criterion comment="gforge-ftp-proftpd is earlier than 4.7~rc2-7lenny1" test_ref="oval:org.mitre.oval:tst:18624"/>
                <criterion comment="gforge-plugin-mediawiki is earlier than 4.7~rc2-7lenny1" test_ref="oval:org.mitre.oval:tst:18494"/>
                <criterion comment="gforge-dns-bind9 is earlier than 4.7~rc2-7lenny1" test_ref="oval:org.mitre.oval:tst:18561"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 4.0 is installed" definition_ref="oval:org.mitre.oval:def:6461"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Architecture independent section" operator="AND">
              <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="gforge-ldap-openldap is earlier than 4.5.14-22etch11" test_ref="oval:org.mitre.oval:tst:18654"/>
                <criterion comment="gforge-mta-courier is earlier than 4.5.14-22etch11" test_ref="oval:org.mitre.oval:tst:18686"/>
                <criterion comment="gforge-mta-exim is earlier than 4.5.14-22etch11" test_ref="oval:org.mitre.oval:tst:18497"/>
                <criterion comment="gforge is earlier than 4.5.14-22etch11" test_ref="oval:org.mitre.oval:tst:18743"/>
                <criterion comment="gforge-common is earlier than 4.5.14-22etch11" test_ref="oval:org.mitre.oval:tst:18603"/>
                <criterion comment="gforge-shell-postgresql is earlier than 4.5.14-22etch11" test_ref="oval:org.mitre.oval:tst:18510"/>
                <criterion comment="gforge-mta-postfix is earlier than 4.5.14-22etch11" test_ref="oval:org.mitre.oval:tst:18749"/>
                <criterion comment="gforge-mta-exim4 is earlier than 4.5.14-22etch11" test_ref="oval:org.mitre.oval:tst:18305"/>
                <criterion comment="gforge-shell-ldap is earlier than 4.5.14-22etch11" test_ref="oval:org.mitre.oval:tst:18594"/>
                <criterion comment="gforge-lists-mailman is earlier than 4.5.14-22etch11" test_ref="oval:org.mitre.oval:tst:18324"/>
                <criterion comment="gforge-web-apache is earlier than 4.5.14-22etch11" test_ref="oval:org.mitre.oval:tst:18538"/>
                <criterion comment="gforge-db-postgresql is earlier than 4.5.14-22etch11" test_ref="oval:org.mitre.oval:tst:18184"/>
                <criterion comment="gforge-ftp-proftpd is earlier than 4.5.14-22etch11" test_ref="oval:org.mitre.oval:tst:18574"/>
                <criterion comment="gforge-dns-bind9 is earlier than 4.5.14-22etch11" test_ref="oval:org.mitre.oval:tst:18409"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:8099" class="patch">
      <metadata>
        <title>DSA-1777 git-core -- file permission error</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <platform>Debian GNU/Linux 4.0</platform>
          <product>git-core</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2009/dsa-1777" ref_id="DSA-1777"/>
        <description>Peter Palfrader discovered that in the Git revision control system, on some architectures files under /usr/share/git-core/templates/ were owned by a non-root user. This allows a user with that uid on the local system to write to these files and possibly escalate their privileges. This issue only affects the DEC Alpha and MIPS (big and little endian) architectures.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:10-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T07:58:16.619-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:04:10.472-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:03:06.417-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Platform section" operator="OR">
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Architecture independent section" operator="AND">
              <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="gitweb is earlier than 1.5.6.5-3+lenny1" test_ref="oval:org.mitre.oval:tst:18916"/>
                <criterion comment="git-arch is earlier than 1.5.6.5-3+lenny1" test_ref="oval:org.mitre.oval:tst:18756"/>
                <criterion comment="gitk is earlier than 1.5.6.5-3+lenny1" test_ref="oval:org.mitre.oval:tst:18132"/>
                <criterion comment="git-gui is earlier than 1.5.6.5-3+lenny1" test_ref="oval:org.mitre.oval:tst:18647"/>
                <criterion comment="git-daemon-run is earlier than 1.5.6.5-3+lenny1" test_ref="oval:org.mitre.oval:tst:18935"/>
                <criterion comment="git-doc is earlier than 1.5.6.5-3+lenny1" test_ref="oval:org.mitre.oval:tst:18952"/>
                <criterion comment="git-svn is earlier than 1.5.6.5-3+lenny1" test_ref="oval:org.mitre.oval:tst:18788"/>
                <criterion comment="git-cvs is earlier than 1.5.6.5-3+lenny1" test_ref="oval:org.mitre.oval:tst:18901"/>
                <criterion comment="git-email is earlier than 1.5.6.5-3+lenny1" test_ref="oval:org.mitre.oval:tst:18814"/>
              </criteria>
            </criteria>
            <criteria comment="Architecture dependent section" operator="AND">
              <criteria comment="Supported architectures section" operator="OR">
                <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
                <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
                <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
                <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
                <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
                <criterion comment="Installed architecture is armel" test_ref="oval:org.mitre.oval:tst:11101"/>
                <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
                <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
                <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
                <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
                <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
                <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
              </criteria>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="git-core DPKG is earlier than 1.5.6.5-3+lenny1" test_ref="oval:org.mitre.oval:tst:18914"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 4.0 is installed" definition_ref="oval:org.mitre.oval:def:6461"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Architecture independent section" operator="AND">
              <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="gitweb is earlier than 1.4.4.4-4+etch2" test_ref="oval:org.mitre.oval:tst:18454"/>
                <criterion comment="git-arch is earlier than 1.4.4.4-4+etch2" test_ref="oval:org.mitre.oval:tst:18760"/>
                <criterion comment="gitk is earlier than 1.4.4.4-4+etch2" test_ref="oval:org.mitre.oval:tst:18552"/>
                <criterion comment="git-daemon-run is earlier than 1.4.4.4-4+etch2" test_ref="oval:org.mitre.oval:tst:18882"/>
                <criterion comment="git-doc is earlier than 1.4.4.4-4+etch2" test_ref="oval:org.mitre.oval:tst:18679"/>
                <criterion comment="git-svn is earlier than 1.4.4.4-4+etch2" test_ref="oval:org.mitre.oval:tst:19008"/>
                <criterion comment="git-cvs is earlier than 1.4.4.4-4+etch2" test_ref="oval:org.mitre.oval:tst:19041"/>
                <criterion comment="git-email is earlier than 1.4.4.4-4+etch2" test_ref="oval:org.mitre.oval:tst:18795"/>
              </criteria>
            </criteria>
            <criteria comment="Packages section" operator="OR">
              <criterion comment="git-core DPKG is earlier than 1.4.4.4-4+etch2" test_ref="oval:org.mitre.oval:tst:18944"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:8093" class="patch">
      <metadata>
        <title>DSA-1856 mantis -- information leak</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <product>mantis</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2009/dsa-1856" ref_id="DSA-1856"/>
        <description>It was discovered that the Debian Mantis package, a web based bug tracking system, installed the database credentials in a file with world-readable permissions onto the local filesystem. This allows local users to acquire the credentials used to control the Mantis database. This updated package corrects this problem for new installations and will carefully try to update existing ones. Administrators can check the permissions of the file /etc/mantis/config_db.php to see if they are safe for their environment. The old stable distribution (etch) does not contain a mantis package.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:11-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T07:58:56.408-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:04:07.603-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:03:04.172-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Release section" operator="AND">
        <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
        <criteria comment="Architecture section" operator="OR">
          <criteria comment="Architecture independent section" operator="AND">
            <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
            <criterion comment="mantis is earlier than 1.1.6+dfsg-2lenny1" test_ref="oval:org.mitre.oval:tst:19241"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:8089" class="patch">
      <metadata>
        <title>DSA-1786 acpid -- denial of service</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <platform>Debian GNU/Linux 4.0</platform>
          <product>acpid</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2009/dsa-1786" ref_id="DSA-1786"/>
        <description>It was discovered that acpid, a daemon for delivering ACPI events, is prone to a denial of service attack by opening a large number of UNIX sockets, which are not closed properly.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:10-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T07:58:10.370-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:04:05.767-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:03:02.724-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Platform section" operator="OR">
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Architecture dependent section" operator="AND">
              <criteria comment="Supported architectures section" operator="OR">
                <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
                <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
                <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
              </criteria>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="acpid DPKG is earlier than 1.0.8-1lenny1" test_ref="oval:org.mitre.oval:tst:18876"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 4.0 is installed" definition_ref="oval:org.mitre.oval:def:6461"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Architecture dependent section" operator="AND">
              <criteria comment="Supported architectures section" operator="OR">
                <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
                <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
                <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
              </criteria>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="acpid DPKG is earlier than 1.0.4-5etch1" test_ref="oval:org.mitre.oval:tst:18789"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:8086" class="patch">
      <metadata>
        <title>DSA-1867 kdelibs -- several vulnerabilities</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <platform>Debian GNU/Linux 4.0</platform>
          <product>kdelibs</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2009/dsa-1867" ref_id="DSA-1867"/>
        <description>Several security issues have been discovered in kdelibs, core libraries from the official KDE release. The Common Vulnerabilities and Exposures project identifies the following problems: It was discovered that there is a use-after-free flaw in handling certain DOM event handlers. This could lead to the execution of arbitrary code, when visiting a malicious website. It was discovered that there could be an uninitialised pointer when handling a Cascading Style Sheets (CSS) attr function call. This could lead to the execution of arbitrary code, when visiting a malicious website. It was discovered that the JavaScript garbage collector does not handle allocation failures properly, which could lead to the execution of arbitrary code when visiting a malicious website.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:09-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T07:57:07.804-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:04:04.658-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:03:01.821-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Platform section" operator="OR">
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Architecture independent section" operator="AND">
              <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="kdelibs4-doc is earlier than 3.5.10.dfsg.1-0lenny2" test_ref="oval:org.mitre.oval:tst:18414"/>
                <criterion comment="kdelibs is earlier than 3.5.10.dfsg.1-0lenny2" test_ref="oval:org.mitre.oval:tst:18097"/>
                <criterion comment="kdelibs-data is earlier than 3.5.10.dfsg.1-0lenny2" test_ref="oval:org.mitre.oval:tst:18276"/>
              </criteria>
            </criteria>
            <criteria comment="Architecture dependent section" operator="AND">
              <criteria comment="Supported architectures section" operator="OR">
                <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
                <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
                <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
                <criterion comment="Installed architecture is armel" test_ref="oval:org.mitre.oval:tst:11101"/>
                <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
                <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
                <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
                <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
                <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
              </criteria>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="kdelibs4-dev DPKG is earlier than 3.5.10.dfsg.1-0lenny2" test_ref="oval:org.mitre.oval:tst:18160"/>
                <criterion comment="kdelibs4c2a DPKG is earlier than 3.5.10.dfsg.1-0lenny2" test_ref="oval:org.mitre.oval:tst:18246"/>
                <criterion comment="kdelibs-dbg DPKG is earlier than 3.5.10.dfsg.1-0lenny2" test_ref="oval:org.mitre.oval:tst:18361"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 4.0 is installed" definition_ref="oval:org.mitre.oval:def:6461"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Architecture independent section" operator="AND">
              <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="kdelibs4-doc is earlier than 3.5.5a.dfsg.1-8etch2" test_ref="oval:org.mitre.oval:tst:18105"/>
                <criterion comment="kdelibs is earlier than 3.5.5a.dfsg.1-8etch2" test_ref="oval:org.mitre.oval:tst:18294"/>
                <criterion comment="kdelibs-data is earlier than 3.5.5a.dfsg.1-8etch2" test_ref="oval:org.mitre.oval:tst:18166"/>
              </criteria>
            </criteria>
            <criteria comment="Architecture dependent section" operator="AND">
              <criteria comment="Supported architectures section" operator="OR">
                <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
                <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
                <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
                <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
                <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
                <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
                <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
                <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
              </criteria>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="kdelibs4-dev DPKG is earlier than 3.5.5a.dfsg.1-8etch2" test_ref="oval:org.mitre.oval:tst:18399"/>
                <criterion comment="kdelibs4c2a DPKG is earlier than 3.5.5a.dfsg.1-8etch2" test_ref="oval:org.mitre.oval:tst:18202"/>
                <criterion comment="kdelibs-dbg DPKG is earlier than 3.5.5a.dfsg.1-8etch2" test_ref="oval:org.mitre.oval:tst:18402"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:8079" class="patch">
      <metadata>
        <title>DSA-1809 linux-2.6 -- denial of service, privilege escalation</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <product>linux-2.6</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2009/dsa-1809" ref_id="DSA-1809"/>
        <description>Several vulnerabilities have been discovered in the Linux kernel that may lead to a denial of service, or privilege escalation. The Common Vulnerabilities and Exposures project identifies the following problems: Frank Filz discovered that local users may be able to execute files without execute permission when accessed via an nfs4 mount. Jeff Layton and Suresh Jayaraman fixed several buffer overflows in the CIFS filesystem which allow remote servers to cause memory corruption. Jan Beulich discovered an issue in Xen where local guest users may cause a denial of service (oops). This update also fixes a regression introduced by the fix for CVE-2009-1184 in 2.6.26-15lenny3. This prevents a boot time panic on systems with SELinux enabled.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:13-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T08:00:55.866-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:04:01.462-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:02:59.378-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Release section" operator="AND">
        <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
        <criteria comment="Architecture section" operator="OR">
          <criteria comment="Architecture independent section" operator="AND">
            <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
            <criteria comment="Packages section" operator="OR">
              <criterion comment="linux-patch-debian-2.6.26 is earlier than 2.6.26-15lenny3" test_ref="oval:org.mitre.oval:tst:20713"/>
              <criterion comment="linux-support-2.6.26-2 is earlier than 2.6.26-15lenny3" test_ref="oval:org.mitre.oval:tst:20747"/>
              <criterion comment="linux-doc-2.6.26 is earlier than 2.6.26-15lenny3" test_ref="oval:org.mitre.oval:tst:20768"/>
              <criterion comment="linux-tree-2.6.26 is earlier than 2.6.26-15lenny3" test_ref="oval:org.mitre.oval:tst:19795"/>
              <criterion comment="linux-source-2.6.26 is earlier than 2.6.26-15lenny3" test_ref="oval:org.mitre.oval:tst:20697"/>
              <criterion comment="linux-manual-2.6.26 is earlier than 2.6.26-15lenny3" test_ref="oval:org.mitre.oval:tst:20122"/>
            </criteria>
          </criteria>
          <criteria comment="Architecture dependent section" operator="AND">
            <criteria comment="Supported architectures section" operator="OR">
              <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
            </criteria>
            <criteria comment="Packages section" operator="OR">
              <criterion comment="linux-headers-2.6.26-2-all DPKG is earlier than 2.6.26-15lenny3" test_ref="oval:org.mitre.oval:tst:20679"/>
              <criterion comment="linux-headers-2.6.26-2-s390 DPKG is earlier than 2.6.26-15lenny3" test_ref="oval:org.mitre.oval:tst:20217"/>
              <criterion comment="linux-image-2.6.26-2-vserver-s390x DPKG is earlier than 2.6.26-15lenny3" test_ref="oval:org.mitre.oval:tst:20579"/>
              <criterion comment="linux-image-2.6.26-2-s390 DPKG is earlier than 2.6.26-15lenny3" test_ref="oval:org.mitre.oval:tst:20101"/>
              <criterion comment="linux-headers-2.6.26-2-common-vserver DPKG is earlier than 2.6.26-15lenny3" test_ref="oval:org.mitre.oval:tst:20511"/>
              <criterion comment="linux-image-2.6.26-2-s390-tape DPKG is earlier than 2.6.26-15lenny3" test_ref="oval:org.mitre.oval:tst:20776"/>
              <criterion comment="linux-headers-2.6.26-2-all-s390 DPKG is earlier than 2.6.26-15lenny3" test_ref="oval:org.mitre.oval:tst:20623"/>
              <criterion comment="linux-headers-2.6.26-2-vserver-s390x DPKG is earlier than 2.6.26-15lenny3" test_ref="oval:org.mitre.oval:tst:20664"/>
              <criterion comment="linux-libc-dev DPKG is earlier than 2.6.26-15lenny3" test_ref="oval:org.mitre.oval:tst:20317"/>
              <criterion comment="linux-image-2.6.26-2-s390x DPKG is earlier than 2.6.26-15lenny3" test_ref="oval:org.mitre.oval:tst:20591"/>
              <criterion comment="linux-headers-2.6.26-2-common DPKG is earlier than 2.6.26-15lenny3" test_ref="oval:org.mitre.oval:tst:20626"/>
              <criterion comment="linux-headers-2.6.26-2-s390x DPKG is earlier than 2.6.26-15lenny3" test_ref="oval:org.mitre.oval:tst:20479"/>
            </criteria>
          </criteria>
          <criteria comment="Architecture dependent section" operator="AND">
            <criteria comment="Supported architectures section" operator="OR">
              <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
            </criteria>
            <criteria comment="Packages section" operator="OR">
              <criterion comment="xen-linux-system-2.6.26-2-xen-amd64 DPKG is earlier than 2.6.26-15lenny3" test_ref="oval:org.mitre.oval:tst:20650"/>
              <criterion comment="linux-headers-2.6.26-2-all DPKG is earlier than 2.6.26-15lenny3" test_ref="oval:org.mitre.oval:tst:20500"/>
              <criterion comment="linux-modules-2.6.26-2-xen-amd64 DPKG is earlier than 2.6.26-15lenny3" test_ref="oval:org.mitre.oval:tst:20717"/>
              <criterion comment="linux-headers-2.6.26-2-openvz-amd64 DPKG is earlier than 2.6.26-15lenny3" test_ref="oval:org.mitre.oval:tst:20443"/>
              <criterion comment="linux-headers-2.6.26-2-common-vserver DPKG is earlier than 2.6.26-15lenny3" test_ref="oval:org.mitre.oval:tst:20642"/>
              <criterion comment="linux-image-2.6.26-2-openvz-amd64 DPKG is earlier than 2.6.26-15lenny3" test_ref="oval:org.mitre.oval:tst:20564"/>
              <criterion comment="linux-image-2.6.26-2-amd64 DPKG is earlier than 2.6.26-15lenny3" test_ref="oval:org.mitre.oval:tst:20324"/>
              <criterion comment="user-mode-linux DPKG is earlier than 2.6.26-1um-2+15lenny3" test_ref="oval:org.mitre.oval:tst:20754"/>
              <criterion comment="linux-headers-2.6.26-2-common-openvz DPKG is earlier than 2.6.26-15lenny3" test_ref="oval:org.mitre.oval:tst:20543"/>
              <criterion comment="linux-image-2.6.26-2-vserver-amd64 DPKG is earlier than 2.6.26-15lenny3" test_ref="oval:org.mitre.oval:tst:20345"/>
              <criterion comment="linux-headers-2.6.26-2-all-amd64 DPKG is earlier than 2.6.26-15lenny3" test_ref="oval:org.mitre.oval:tst:20448"/>
              <criterion comment="linux-image-2.6.26-2-xen-amd64 DPKG is earlier than 2.6.26-15lenny3" test_ref="oval:org.mitre.oval:tst:20366"/>
              <criterion comment="linux-headers-2.6.26-2-common-xen DPKG is earlier than 2.6.26-15lenny3" test_ref="oval:org.mitre.oval:tst:20600"/>
              <criterion comment="linux-libc-dev DPKG is earlier than 2.6.26-15lenny3" test_ref="oval:org.mitre.oval:tst:20387"/>
              <criterion comment="linux-headers-2.6.26-2-xen-amd64 DPKG is earlier than 2.6.26-15lenny3" test_ref="oval:org.mitre.oval:tst:20716"/>
              <criterion comment="linux-headers-2.6.26-2-amd64 DPKG is earlier than 2.6.26-15lenny3" test_ref="oval:org.mitre.oval:tst:20405"/>
              <criterion comment="linux-headers-2.6.26-2-common DPKG is earlier than 2.6.26-15lenny3" test_ref="oval:org.mitre.oval:tst:19948"/>
              <criterion comment="linux-headers-2.6.26-2-vserver-amd64 DPKG is earlier than 2.6.26-15lenny3" test_ref="oval:org.mitre.oval:tst:20557"/>
            </criteria>
          </criteria>
          <criteria comment="Architecture depended section" operator="AND">
            <criteria comment="Supported platform section" operator="AND">
              <criterion comment="hppa architecture" test_ref="oval:org.mitre.oval:tst:11164"/>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="linux-headers-2.6.26-2-all DPKG is earlier than 2.6.26-15lenny3" test_ref="oval:org.mitre.oval:tst:20719"/>
                <criterion comment="linux-headers-2.6.26-2-parisc DPKG is earlier than 2.6.26-15lenny3" test_ref="oval:org.mitre.oval:tst:20818"/>
                <criterion comment="linux-image-2.6.26-2-parisc64 DPKG is earlier than 2.6.26-15lenny3" test_ref="oval:org.mitre.oval:tst:20654"/>
                <criterion comment="linux-image-2.6.26-2-parisc DPKG is earlier than 2.6.26-15lenny3" test_ref="oval:org.mitre.oval:tst:20799"/>
                <criterion comment="linux-headers-2.6.26-2-common DPKG is earlier than 2.6.26-15lenny3" test_ref="oval:org.mitre.oval:tst:20309"/>
                <criterion comment="linux-headers-2.6.26-2-all-hppa DPKG is earlier than 2.6.26-15lenny3" test_ref="oval:org.mitre.oval:tst:20809"/>
                <criterion comment="linux-image-2.6.26-2-parisc-smp DPKG is earlier than 2.6.26-15lenny3" test_ref="oval:org.mitre.oval:tst:20504"/>
                <criterion comment="linux-headers-2.6.26-2-parisc64-smp DPKG is earlier than 2.6.26-15lenny3" test_ref="oval:org.mitre.oval:tst:20486"/>
                <criterion comment="linux-headers-2.6.26-2-parisc64 DPKG is earlier than 2.6.26-15lenny3" test_ref="oval:org.mitre.oval:tst:20466"/>
                <criterion comment="linux-libc-dev DPKG is earlier than 2.6.26-15lenny3" test_ref="oval:org.mitre.oval:tst:20675"/>
                <criterion comment="linux-image-2.6.26-2-parisc64-smp DPKG is earlier than 2.6.26-15lenny3" test_ref="oval:org.mitre.oval:tst:20692"/>
                <criterion comment="linux-headers-2.6.26-2-parisc-smp DPKG is earlier than 2.6.26-15lenny3" test_ref="oval:org.mitre.oval:tst:20793"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:8074" class="patch">
      <metadata>
        <title>DSA-1811 cups, cupsys -- null ptr dereference</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <platform>Debian GNU/Linux 4.0</platform>
          <product>cups</product>
          <product>cupsys</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2009/dsa-1811" ref_id="DSA-1811"/>
        <description>Anibal Sacco discovered that cups, a general printing system for UNIX systems, suffers from null pointer dereference because of its handling of two consecutive IPP packets with certain tag attributes that are treated as IPP_TAG_UNSUPPORTED tags. This allows unauthenticated attackers to perform denial of service attacks by crashing the cups daemon.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:09-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T07:57:39.260-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:03:59.432-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:02:57.666-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Platform section" operator="OR">
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Architecture independent section" operator="AND">
              <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="cupsys-bsd is earlier than 1.3.8-1+lenny6" test_ref="oval:org.mitre.oval:tst:17665"/>
                <criterion comment="cupsys-client is earlier than 1.3.8-1+lenny6" test_ref="oval:org.mitre.oval:tst:18102"/>
                <criterion comment="libcupsys2-dev is earlier than 1.3.8-1+lenny6" test_ref="oval:org.mitre.oval:tst:18319"/>
                <criterion comment="cupsys-common is earlier than 1.3.8-1+lenny6" test_ref="oval:org.mitre.oval:tst:18514"/>
                <criterion comment="cups-common is earlier than 1.3.8-1+lenny6" test_ref="oval:org.mitre.oval:tst:17987"/>
                <criterion comment="cupsys-dbg is earlier than 1.3.8-1+lenny6" test_ref="oval:org.mitre.oval:tst:18316"/>
                <criterion comment="cupsys is earlier than 1.3.8-1+lenny6" test_ref="oval:org.mitre.oval:tst:17942"/>
                <criterion comment="libcupsys2 is earlier than 1.3.8-1+lenny6" test_ref="oval:org.mitre.oval:tst:18251"/>
              </criteria>
            </criteria>
            <criteria comment="Architecture dependent section" operator="AND">
              <criteria comment="Supported architectures section" operator="OR">
                <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
                <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
                <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
                <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
                <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
                <criterion comment="Installed architecture is armel" test_ref="oval:org.mitre.oval:tst:11101"/>
                <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
                <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
                <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
                <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
                <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
                <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
              </criteria>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="libcups2-dev DPKG is earlier than 1.3.8-1+lenny6" test_ref="oval:org.mitre.oval:tst:18539"/>
                <criterion comment="cups-bsd DPKG is earlier than 1.3.8-1+lenny6" test_ref="oval:org.mitre.oval:tst:18609"/>
                <criterion comment="libcupsimage2-dev DPKG is earlier than 1.3.8-1+lenny6" test_ref="oval:org.mitre.oval:tst:18550"/>
                <criterion comment="libcupsimage2 DPKG is earlier than 1.3.8-1+lenny6" test_ref="oval:org.mitre.oval:tst:18531"/>
                <criterion comment="cups-client DPKG is earlier than 1.3.8-1+lenny6" test_ref="oval:org.mitre.oval:tst:17917"/>
                <criterion comment="libcups2 DPKG is earlier than 1.3.8-1+lenny6" test_ref="oval:org.mitre.oval:tst:18513"/>
                <criterion comment="cups-dbg DPKG is earlier than 1.3.8-1+lenny6" test_ref="oval:org.mitre.oval:tst:18381"/>
                <criterion comment="cups DPKG is earlier than 1.3.8-1+lenny6" test_ref="oval:org.mitre.oval:tst:18083"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 4.0 is installed" definition_ref="oval:org.mitre.oval:def:6461"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Architecture independent section" operator="AND">
              <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="libcupsys2-gnutls10 is earlier than 1.2.7-4+etch8" test_ref="oval:org.mitre.oval:tst:18341"/>
                <criterion comment="cupsys-common is earlier than 1.2.7-4+etch8" test_ref="oval:org.mitre.oval:tst:18576"/>
              </criteria>
            </criteria>
            <criteria comment="Packages section" operator="OR">
              <criterion comment="cupsys-bsd DPKG is earlier than 1.2.7-4+etch8" test_ref="oval:org.mitre.oval:tst:17910"/>
              <criterion comment="cupsys-client DPKG is earlier than 1.2.7-4+etch8" test_ref="oval:org.mitre.oval:tst:18387"/>
              <criterion comment="libcupsys2-dev DPKG is earlier than 1.2.7-4+etch8" test_ref="oval:org.mitre.oval:tst:18517"/>
              <criterion comment="libcupsimage2-dev DPKG is earlier than 1.2.7-4+etch8" test_ref="oval:org.mitre.oval:tst:18592"/>
              <criterion comment="libcupsimage2 DPKG is earlier than 1.2.7-4+etch8" test_ref="oval:org.mitre.oval:tst:17859"/>
              <criterion comment="cupsys-dbg DPKG is earlier than 1.2.7-4+etch8" test_ref="oval:org.mitre.oval:tst:18450"/>
              <criterion comment="cupsys DPKG is earlier than 1.2.7-4+etch8" test_ref="oval:org.mitre.oval:tst:18292"/>
              <criterion comment="libcupsys2 DPKG is earlier than 1.2.7-4+etch8" test_ref="oval:org.mitre.oval:tst:18270"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:8072" class="patch">
      <metadata>
        <title>DSA-1871 wordpress -- several vulnerabilities</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <platform>Debian GNU/Linux 4.0</platform>
          <product>wordpress</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2009/dsa-1871" ref_id="DSA-1871"/>
        <description>Several vulnerabilities have been discovered in wordpress, weblog manager. The Common Vulnerabilities and Exposures project identifies the following problems: It was discovered that wordpress is prone to an open redirect vulnerability which allows remote attackers to conduct phishing atacks. It was discovered that remote attackers had the ability to trigger an application upgrade, which could lead to a denial of service attack. It was discovered that wordpress lacks authentication checks in the plugin configuration, which might leak sensitive information. It was discovered that wordpress lacks authentication checks in various actions, thus allowing remote attackers to produce unauthorised edits or additions. It was discovered that the administrator interface is prone to a cross-site scripting attack. It was discovered that remote attackers can gain privileges via certain direct requests. It was discovered that the _bad_protocol_once function in KSES, as used by wordpress, allows remote attackers to perform cross-site scripting attacks. It was discovered that wordpress lacks certain checks around user information, which could be used by attackers to change the password of a user. It was discovered that the get_category_template function is prone to a directory traversal vulnerability, which could lead to the execution of arbitrary code. It was discovered that the _httpsrequest function in the embedded snoopy version is prone to the execution of arbitrary commands via shell metacharacters in https URLs. It was discovered that wordpress relies on the REQUEST superglobal array in certain dangerous situations, which makes it easier to perform attacks via crafted cookies.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:06-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T07:53:50.427-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:03:59.174-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:02:57.415-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Platform section" operator="OR">
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Architecture independent section" operator="AND">
              <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criterion comment="wordpress is earlier than 2.5.1-11+lenny1" test_ref="oval:org.mitre.oval:tst:15367"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 4.0 is installed" definition_ref="oval:org.mitre.oval:def:6461"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Architecture independent section" operator="AND">
              <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criterion comment="wordpress is earlier than 2.0.10-1etch4" test_ref="oval:org.mitre.oval:tst:15675"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:8068" class="patch">
      <metadata>
        <title>DSA-1821 amule -- insufficient input sanitising</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <product>amule</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2009/dsa-1821" ref_id="DSA-1821"/>
        <description>Sam Hocevar discovered that amule, a client for the eD2k and Kad networks, does not properly sanitise the filename, when using the preview function. This could lead to the injection of arbitrary commands passed to the video player. The oldstable distribution (etch) is not affected by this issue.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:08-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T07:55:56.400-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:03:57.165-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:02:55.845-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Release section" operator="AND">
        <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
        <criteria comment="Architecture section" operator="OR">
          <criteria comment="Architecture independent section" operator="AND">
            <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
            <criterion comment="amule-common is earlier than 2.2.1-1+lenny2" test_ref="oval:org.mitre.oval:tst:17326"/>
          </criteria>
          <criteria comment="Architecture dependent section" operator="AND">
            <criteria comment="Supported architectures section" operator="OR">
              <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
              <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
              <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
              <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
              <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
              <criterion comment="Installed architecture is armel" test_ref="oval:org.mitre.oval:tst:11101"/>
              <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
              <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
              <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
              <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
              <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
              <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
            </criteria>
            <criteria comment="Packages section" operator="OR">
              <criterion comment="amule-utils DPKG is earlier than 2.2.1-1+lenny2" test_ref="oval:org.mitre.oval:tst:16865"/>
              <criterion comment="amule DPKG is earlier than 2.2.1-1+lenny2" test_ref="oval:org.mitre.oval:tst:16834"/>
              <criterion comment="amule-daemon DPKG is earlier than 2.2.1-1+lenny2" test_ref="oval:org.mitre.oval:tst:16803"/>
              <criterion comment="amule-utils-gui DPKG is earlier than 2.2.1-1+lenny2" test_ref="oval:org.mitre.oval:tst:17189"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:8066" class="patch">
      <metadata>
        <title>DSA-1937 gforge -- insufficient input sanitising</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <platform>Debian GNU/Linux 4.0</platform>
          <product>gforge</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2009/dsa-1937" ref_id="DSA-1937"/>
        <description>It was discovered that gforge, collaborative development tool, is prone to a cross-site scripting attack via the helpname parameter. Beside fixing this issue, the update also introduces some additional input sanitising. However, there are no known attack vectors. The oldstable distribution (etch), these problems have been fixed in version 4.5.14-22etch12.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:11-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T07:59:11.572-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:03:55.992-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:02:54.995-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Platform section" operator="OR">
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Architecture independent section" operator="AND">
              <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="gforge-mta-courier is earlier than 4.7~rc2-7lenny2" test_ref="oval:org.mitre.oval:tst:19076"/>
                <criterion comment="gforge is earlier than 4.7~rc2-7lenny2" test_ref="oval:org.mitre.oval:tst:19145"/>
                <criterion comment="gforge-plugin-scmcvs is earlier than 4.7~rc2-7lenny2" test_ref="oval:org.mitre.oval:tst:19134"/>
                <criterion comment="gforge-common is earlier than 4.7~rc2-7lenny2" test_ref="oval:org.mitre.oval:tst:18912"/>
                <criterion comment="gforge-shell-postgresql is earlier than 4.7~rc2-7lenny2" test_ref="oval:org.mitre.oval:tst:19462"/>
                <criterion comment="gforge-plugin-scmsvn is earlier than 4.7~rc2-7lenny2" test_ref="oval:org.mitre.oval:tst:19351"/>
                <criterion comment="gforge-web-apache2 is earlier than 4.7~rc2-7lenny2" test_ref="oval:org.mitre.oval:tst:19124"/>
                <criterion comment="gforge-mta-postfix is earlier than 4.7~rc2-7lenny2" test_ref="oval:org.mitre.oval:tst:19305"/>
                <criterion comment="gforge-mta-exim4 is earlier than 4.7~rc2-7lenny2" test_ref="oval:org.mitre.oval:tst:18870"/>
                <criterion comment="gforge-lists-mailman is earlier than 4.7~rc2-7lenny2" test_ref="oval:org.mitre.oval:tst:19368"/>
                <criterion comment="gforge-web-apache is earlier than 4.7~rc2-7lenny2" test_ref="oval:org.mitre.oval:tst:18818"/>
                <criterion comment="gforge-db-postgresql is earlier than 4.7~rc2-7lenny2" test_ref="oval:org.mitre.oval:tst:19233"/>
                <criterion comment="gforge-ftp-proftpd is earlier than 4.7~rc2-7lenny2" test_ref="oval:org.mitre.oval:tst:19284"/>
                <criterion comment="gforge-plugin-mediawiki is earlier than 4.7~rc2-7lenny2" test_ref="oval:org.mitre.oval:tst:19154"/>
                <criterion comment="gforge-dns-bind9 is earlier than 4.7~rc2-7lenny2" test_ref="oval:org.mitre.oval:tst:19086"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 4.0 is installed" definition_ref="oval:org.mitre.oval:def:6461"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Architecture independent section" operator="AND">
              <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="gforge-ldap-openldap is earlier than 4.5.14-22etch12" test_ref="oval:org.mitre.oval:tst:19362"/>
                <criterion comment="gforge-mta-exim4 is earlier than 4.5.14-22etch12" test_ref="oval:org.mitre.oval:tst:19208"/>
                <criterion comment="gforge-mta-courier is earlier than 4.5.14-22etch12" test_ref="oval:org.mitre.oval:tst:19228"/>
                <criterion comment="gforge-db-postgresql is earlier than 4.5.14-22etch12" test_ref="oval:org.mitre.oval:tst:19238"/>
                <criterion comment="gforge is earlier than 4.5.14-22etch12" test_ref="oval:org.mitre.oval:tst:19279"/>
                <criterion comment="gforge-common is earlier than 4.5.14-22etch12" test_ref="oval:org.mitre.oval:tst:19376"/>
                <criterion comment="gforge-mta-postfix is earlier than 4.5.14-22etch12" test_ref="oval:org.mitre.oval:tst:19006"/>
                <criterion comment="gforge-shell-postgresql is earlier than 4.5.14-22etch12" test_ref="oval:org.mitre.oval:tst:19337"/>
                <criterion comment="gforge-shell-ldap is earlier than 4.5.14-22etch12" test_ref="oval:org.mitre.oval:tst:19269"/>
                <criterion comment="gforge-lists-mailman is earlier than 4.5.14-22etch12" test_ref="oval:org.mitre.oval:tst:19435"/>
                <criterion comment="gforge-web-apache is earlier than 4.5.14-22etch12" test_ref="oval:org.mitre.oval:tst:19017"/>
                <criterion comment="gforge-mta-exim is earlier than 4.5.14-22etch12" test_ref="oval:org.mitre.oval:tst:18543"/>
                <criterion comment="gforge-ftp-proftpd is earlier than 4.5.14-22etch12" test_ref="oval:org.mitre.oval:tst:18899"/>
                <criterion comment="gforge-dns-bind9 is earlier than 4.5.14-22etch12" test_ref="oval:org.mitre.oval:tst:19121"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:8056" class="patch">
      <metadata>
        <title>DSA-1833 dhcp3 -- several vulnerabilities</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <platform>Debian GNU/Linux 4.0</platform>
          <product>dhcp3</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2009/dsa-1833" ref_id="DSA-1833"/>
        <description>Several remote vulnerabilities have been discovered in ISC's DHCP implementation: It was discovered that dhclient does not properly handle overlong subnet mask options, leading to a stack-based buffer overflow and possible arbitrary code execution. Christoph Biedl discovered that the DHCP server may terminate when receiving certain well-formed DHCP requests, provided that the server configuration mixes host definitions using "dhcp-client-identifier" and "hardware ethernet". This vulnerability only affects the lenny versions of dhcp3-server and dhcp3-server-ldap.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:05-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T07:52:37.719-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:03:51.842-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:02:51.567-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Platform section" operator="OR">
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Architecture independent section" operator="AND">
              <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criterion comment="dhcp-client is earlier than 3.1.1-6+lenny2" test_ref="oval:org.mitre.oval:tst:14173"/>
            </criteria>
            <criteria comment="Architecture dependent section" operator="AND">
              <criteria comment="Supported architectures section" operator="OR">
                <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
                <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
                <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
                <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
                <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
                <criterion comment="Installed architecture is armel" test_ref="oval:org.mitre.oval:tst:11101"/>
                <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
                <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
                <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
                <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
                <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
                <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
              </criteria>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="dhcp3-client DPKG is earlier than 3.1.1-6+lenny2" test_ref="oval:org.mitre.oval:tst:14590"/>
                <criterion comment="dhcp3-dev DPKG is earlier than 3.1.1-6+lenny2" test_ref="oval:org.mitre.oval:tst:14237"/>
                <criterion comment="dhcp3-relay DPKG is earlier than 3.1.1-6+lenny2" test_ref="oval:org.mitre.oval:tst:14559"/>
                <criterion comment="dhcp3-common DPKG is earlier than 3.1.1-6+lenny2" test_ref="oval:org.mitre.oval:tst:14689"/>
                <criterion comment="dhcp3-server-ldap DPKG is earlier than 3.1.1-6+lenny2" test_ref="oval:org.mitre.oval:tst:14185"/>
                <criterion comment="dhcp3-server DPKG is earlier than 3.1.1-6+lenny2" test_ref="oval:org.mitre.oval:tst:14484"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 4.0 is installed" definition_ref="oval:org.mitre.oval:def:6461"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Architecture dependent section" operator="AND">
              <criteria comment="Supported architectures section" operator="OR">
                <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
                <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
                <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
                <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
                <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
                <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
                <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
                <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
                <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
                <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
              </criteria>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="dhcp3-client DPKG is earlier than 3.0.4-13+etch2" test_ref="oval:org.mitre.oval:tst:14450"/>
                <criterion comment="dhcp3-common DPKG is earlier than 3.0.4-13+etch2" test_ref="oval:org.mitre.oval:tst:14139"/>
                <criterion comment="dhcp3-relay DPKG is earlier than 3.0.4-13+etch2" test_ref="oval:org.mitre.oval:tst:14757"/>
                <criterion comment="dhcp3-server DPKG is earlier than 3.0.4-13+etch2" test_ref="oval:org.mitre.oval:tst:14751"/>
                <criterion comment="dhcp3-dev DPKG is earlier than 3.0.4-13+etch2" test_ref="oval:org.mitre.oval:tst:14304"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:8051" class="patch">
      <metadata>
        <title>DSA-1804 ipsec-tools -- null pointer dereference, memory leaks</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <platform>Debian GNU/Linux 4.0</platform>
          <product>ipsec-tools</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2009/dsa-1804" ref_id="DSA-1804"/>
        <description>Several remote vulnerabilities have been discovered in racoon, the Internet Key Exchange daemon of ipsec-tools. The The Common Vulnerabilities and Exposures project identified the following problems: Neil Kettle discovered a NULL pointer dereference on crafted fragmented packets that contain no payload. This results in the daemon crashing which can be used for denial of service attacks. Various memory leaks in the X.509 certificate authentication handling and the NAT-Traversal keepalive implementation can result in memory exhaustion and thus denial of service.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:13-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T08:00:43.457-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:03:49.678-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:02:49.863-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Platform section" operator="OR">
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Architecture dependent section" operator="AND">
              <criteria comment="Supported architectures section" operator="OR">
                <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
                <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
                <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
                <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
                <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
                <criterion comment="Installed architecture is armel" test_ref="oval:org.mitre.oval:tst:11101"/>
                <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
                <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
                <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
                <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
                <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
              </criteria>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="racoon DPKG is earlier than 0.7.1-1.3+lenny2" test_ref="oval:org.mitre.oval:tst:20538"/>
                <criterion comment="ipsec-tools DPKG is earlier than 0.7.1-1.3+lenny2" test_ref="oval:org.mitre.oval:tst:20014"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 4.0 is installed" definition_ref="oval:org.mitre.oval:def:6461"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Architecture dependent section" operator="AND">
              <criteria comment="Supported architectures section" operator="OR">
                <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
                <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
                <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
                <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
                <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
                <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
                <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
                <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
                <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
                <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
              </criteria>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="racoon DPKG is earlier than 0.6.6-3.1etch3" test_ref="oval:org.mitre.oval:tst:20258"/>
                <criterion comment="ipsec-tools DPKG is earlier than 0.6.6-3.1etch3" test_ref="oval:org.mitre.oval:tst:19716"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:8047" class="patch">
      <metadata>
        <title>DSA-1899 strongswan -- several vulnerabilities</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <platform>Debian GNU/Linux 4.0</platform>
          <product>strongswan</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2009/dsa-1899" ref_id="DSA-1899"/>
        <description>Several remote vulnerabilities have been discovered in strongswan, an implementation of the IPSEC and IKE protocols. The Common Vulnerabilities and Exposures project identifies the following problems: The charon daemon can crash when processing certain crafted IKEv2 packets. (The old stable distribution (etch) was not affected by these two problems because it lacks IKEv2 support.) The pluto daemon could crash when processing a crafted X.509 certificate.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:12-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T08:00:02.972-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:03:48.424-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:02:49.190-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Platform section" operator="OR">
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Architecture dependent section" operator="AND">
              <criteria comment="Supported architectures section" operator="OR">
                <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
                <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
                <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
                <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
                <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
                <criterion comment="Installed architecture is armel" test_ref="oval:org.mitre.oval:tst:11101"/>
                <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
                <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
                <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
                <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
                <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
                <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
              </criteria>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="strongswan DPKG is earlier than 4.2.4-5+lenny3" test_ref="oval:org.mitre.oval:tst:19818"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 4.0 is installed" definition_ref="oval:org.mitre.oval:def:6461"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Packages section" operator="OR">
              <criterion comment="strongswan DPKG is earlier than 2.8.0+dfsg-1+etch2" test_ref="oval:org.mitre.oval:tst:19181"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:8046" class="patch">
      <metadata>
        <title>DSA-1815 libtorrent-rasterbar -- programming error</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <product>libtorrent-rasterbar</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2009/dsa-1815" ref_id="DSA-1815"/>
        <description>It was discovered that the Rasterbar Bittorrent library performed insufficient validation of path names specified in torrent files, which could lead to denial of service by overwriting files. The old stable distribution (etch) doesn't include libtorrent-rasterbar.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:09-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T07:57:32.125-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:03:47.839-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:02:48.696-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Release section" operator="AND">
        <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
        <criteria comment="Architecture section" operator="OR">
          <criteria comment="Architecture independent section" operator="AND">
            <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
            <criterion comment="libtorrent-rasterbar-doc is earlier than 0.13.1-2+lenny1" test_ref="oval:org.mitre.oval:tst:18444"/>
          </criteria>
          <criteria comment="Architecture dependent section" operator="AND">
            <criteria comment="Supported architectures section" operator="OR">
              <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
              <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
              <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
              <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
              <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
              <criterion comment="Installed architecture is armel" test_ref="oval:org.mitre.oval:tst:11101"/>
              <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
              <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
              <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
              <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
              <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
              <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
            </criteria>
            <criteria comment="Packages section" operator="OR">
              <criterion comment="libtorrent-rasterbar0 DPKG is earlier than 0.13.1-2+lenny1" test_ref="oval:org.mitre.oval:tst:18493"/>
              <criterion comment="libtorrent-rasterbar-dbg DPKG is earlier than 0.13.1-2+lenny1" test_ref="oval:org.mitre.oval:tst:18536"/>
              <criterion comment="libtorrent-rasterbar-dev DPKG is earlier than 0.13.1-2+lenny1" test_ref="oval:org.mitre.oval:tst:18401"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:8045" class="patch">
      <metadata>
        <title>DSA-1921 expat -- denial of service</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <platform>Debian GNU/Linux 4.0</platform>
          <product>expat</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2009/dsa-1921" ref_id="DSA-1921"/>
        <description>Peter Valchev discovered an error in expat, an XML parsing C library, when parsing certain UTF-8 sequences, which can be exploited to crash an application using the library.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:08-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T07:56:01.667-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:03:46.737-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:02:48.169-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Platform section" operator="OR">
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Architecture dependent section" operator="AND">
              <criteria comment="Supported architectures section" operator="OR">
                <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
                <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
                <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
                <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
              </criteria>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="lib64expat1 DPKG is earlier than 2.0.1-4+lenny1" test_ref="oval:org.mitre.oval:tst:17342"/>
                <criterion comment="lib64expat1-dev DPKG is earlier than 2.0.1-4+lenny1" test_ref="oval:org.mitre.oval:tst:17209"/>
                <criterion comment="expat DPKG is earlier than 2.0.1-4+lenny1" test_ref="oval:org.mitre.oval:tst:17288"/>
                <criterion comment="libexpat1-dev DPKG is earlier than 2.0.1-4+lenny1" test_ref="oval:org.mitre.oval:tst:17291"/>
                <criterion comment="libexpat1 DPKG is earlier than 2.0.1-4+lenny1" test_ref="oval:org.mitre.oval:tst:16715"/>
              </criteria>
            </criteria>
            <criteria comment="Architecture dependent section" operator="AND">
              <criteria comment="Supported architectures section" operator="OR">
                <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
                <criterion comment="Installed architecture is armel" test_ref="oval:org.mitre.oval:tst:11101"/>
                <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
                <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
                <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
                <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
                <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
              </criteria>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="libexpat1 DPKG is earlier than 2.0.1-4+lenny1" test_ref="oval:org.mitre.oval:tst:17218"/>
                <criterion comment="expat DPKG is earlier than 2.0.1-4+lenny1" test_ref="oval:org.mitre.oval:tst:17317"/>
                <criterion comment="libexpat1-dev DPKG is earlier than 2.0.1-4+lenny1" test_ref="oval:org.mitre.oval:tst:17044"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 4.0 is installed" definition_ref="oval:org.mitre.oval:def:6461"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Packages section" operator="OR">
              <criterion comment="expat DPKG is earlier than 1.95.8-3.4+etch1" test_ref="oval:org.mitre.oval:tst:17251"/>
              <criterion comment="libexpat1-dev DPKG is earlier than 1.95.8-3.4+etch1" test_ref="oval:org.mitre.oval:tst:17019"/>
              <criterion comment="libexpat1 DPKG is earlier than 1.95.8-3.4+etch1" test_ref="oval:org.mitre.oval:tst:16411"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:8043" class="patch">
      <metadata>
        <title>DSA-1836 fckeditor -- missing input sanitising</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <product>fckeditor</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2009/dsa-1836" ref_id="DSA-1836"/>
        <description>Vinny Guido discovered that multiple input sanitising vulnerabilities in Fckeditor, a rich text web editor component, may lead to the execution of arbitrary code. The old stable distribution (etch) doesn't contain fckeditor.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:05-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T07:52:39.600-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:03:45.514-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:02:47.410-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Release section" operator="AND">
        <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
        <criteria comment="Architecture section" operator="OR">
          <criteria comment="Architecture independent section" operator="AND">
            <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
            <criterion comment="fckeditor is earlier than 2.6.2-1lenny1" test_ref="oval:org.mitre.oval:tst:14661"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:8042" class="patch">
      <metadata>
        <title>DSA-1801 ntp -- buffer overflows</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <platform>Debian GNU/Linux 4.0</platform>
          <product>ntp</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2009/dsa-1801" ref_id="DSA-1801"/>
        <description>Several remote vulnerabilities have been discovered in NTP, the Network Time Protocol reference implementation. The Common Vulnerabilities and Exposures project identifies the following problems: A buffer overflow in ntpq allow a remote NTP server to create a denial of service attack or to execute arbitrary code via a crafted response. A buffer overflow in ntpd allows a remote attacker to create a denial of service attack or to execute arbitrary code when the autokey functionality is enabled.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:13-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T08:00:45.907-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:03:44.795-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:02:46.830-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Platform section" operator="OR">
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Architecture independent section" operator="AND">
              <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criterion comment="ntp-doc is earlier than 4.2.4p4+dfsg-8lenny2" test_ref="oval:org.mitre.oval:tst:20255"/>
            </criteria>
            <criteria comment="Architecture dependent section" operator="AND">
              <criteria comment="Supported architectures section" operator="OR">
                <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
                <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
                <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
                <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
                <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
                <criterion comment="Installed architecture is armel" test_ref="oval:org.mitre.oval:tst:11101"/>
                <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
                <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
                <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
                <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
                <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
                <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
              </criteria>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="ntp DPKG is earlier than 4.2.4p4+dfsg-8lenny2" test_ref="oval:org.mitre.oval:tst:20321"/>
                <criterion comment="ntpdate DPKG is earlier than 4.2.4p4+dfsg-8lenny2" test_ref="oval:org.mitre.oval:tst:20408"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 4.0 is installed" definition_ref="oval:org.mitre.oval:def:6461"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Architecture independent section" operator="AND">
              <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="ntp-doc is earlier than 4.2.2.p4+dfsg-2etch3" test_ref="oval:org.mitre.oval:tst:20524"/>
                <criterion comment="ntp-simple is earlier than 4.2.2.p4+dfsg-2etch3" test_ref="oval:org.mitre.oval:tst:20607"/>
                <criterion comment="ntp-refclock is earlier than 4.2.2.p4+dfsg-2etch3" test_ref="oval:org.mitre.oval:tst:20417"/>
              </criteria>
            </criteria>
            <criteria comment="Packages section" operator="OR">
              <criterion comment="ntpdate DPKG is earlier than 4.2.2.p4+dfsg-2etch3" test_ref="oval:org.mitre.oval:tst:20469"/>
              <criterion comment="ntp DPKG is earlier than 4.2.2.p4+dfsg-2etch3" test_ref="oval:org.mitre.oval:tst:20595"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:8038" class="patch">
      <metadata>
        <title>DSA-1763 openssl -- programming error</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <platform>Debian GNU/Linux 4.0</platform>
          <product>openssl</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2009/dsa-1763" ref_id="DSA-1763"/>
        <description>It was discovered that insufficient length validations in the ASN.1 handling of the OpenSSL crypto library may lead to denial of service when processing a manipulated certificate.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:07-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T07:54:53.549-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:03:43.493-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:02:45.678-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Platform section" operator="OR">
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Architecture dependent section" operator="AND">
              <criteria comment="Supported architectures section" operator="OR">
                <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
                <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
                <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
                <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
                <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
                <criterion comment="Installed architecture is armel" test_ref="oval:org.mitre.oval:tst:11101"/>
                <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
                <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
                <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
                <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
                <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
                <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
              </criteria>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="libssl-dev DPKG is earlier than 0.9.8g-15+lenny1" test_ref="oval:org.mitre.oval:tst:16786"/>
                <criterion comment="libssl0.9.8-dbg DPKG is earlier than 0.9.8g-15+lenny1" test_ref="oval:org.mitre.oval:tst:16497"/>
                <criterion comment="libssl0.9.8 DPKG is earlier than 0.9.8g-15+lenny1" test_ref="oval:org.mitre.oval:tst:16613"/>
                <criterion comment="openssl DPKG is earlier than 0.9.8g-15+lenny1" test_ref="oval:org.mitre.oval:tst:16809"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 4.0 is installed" definition_ref="oval:org.mitre.oval:def:6461"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Packages section" operator="OR">
              <criterion comment="libssl0.9.7-dbg DPKG is earlier than 0.9.7k-3.1etch3" test_ref="oval:org.mitre.oval:tst:16807"/>
              <criterion comment="libssl-dev DPKG is earlier than 0.9.8c-4etch5" test_ref="oval:org.mitre.oval:tst:16750"/>
              <criterion comment="libssl0.9.8-dbg DPKG is earlier than 0.9.8c-4etch5" test_ref="oval:org.mitre.oval:tst:16596"/>
              <criterion comment="openssl DPKG is earlier than 0.9.8c-4etch5" test_ref="oval:org.mitre.oval:tst:16570"/>
              <criterion comment="libssl0.9.8 DPKG is earlier than 0.9.8c-4etch5" test_ref="oval:org.mitre.oval:tst:16664"/>
              <criterion comment="libssl0.9.7 DPKG is earlier than 0.9.7k-3.1etch3" test_ref="oval:org.mitre.oval:tst:16480"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:8037" class="patch">
      <metadata>
        <title>DSA-1769 openjdk-6 -- several vulnerabilities</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <product>openjdk-6</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2009/dsa-1769" ref_id="DSA-1769"/>
        <description>Several vulnerabilities have been identified in OpenJDK, an implementation of the Java SE platform. Creation of large, temporary fonts could use up available disk space, leading to a denial of service condition. Several vulnerabilities existed in the embedded LittleCMS library, exploitable through crafted images: a memory leak, resulting in a denial of service condition (CVE-2009-0581), heap-based buffer overflows, potentially allowing arbitrary code execution (CVE-2009-0723, CVE-2009-0733), and a null-pointer dereference, leading to denial of service (CVE-2009-0793). The LDAP server implementation (in com.sun.jdni.ldap) did not properly close sockets if an error was encountered, leading to a denial-of-service condition. The LDAP client implementation (in com.sun.jdni.ldap) allowed malicious LDAP servers to execute arbitrary code on the client. The HTTP server implementation (sun.net.httpserver) contained an unspecified denial of service vulnerability. Several issues in Java Web Start have been addressed. The Debian packages currently do not support Java Web Start, so these issues are not directly exploitable, but the relevant code has been updated
          nevertheless.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:07-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T07:54:43.374-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:03:42.910-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:02:45.250-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Release section" operator="AND">
        <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
        <criteria comment="Architecture section" operator="OR">
          <criteria comment="Architecture independent section" operator="AND">
            <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
            <criteria comment="Packages section" operator="OR">
              <criterion comment="openjdk-6-jre-lib is earlier than 6b11-9.1+lenny2" test_ref="oval:org.mitre.oval:tst:16552"/>
              <criterion comment="openjdk-6-doc is earlier than 6b11-9.1+lenny2" test_ref="oval:org.mitre.oval:tst:16464"/>
              <criterion comment="openjdk-6-source is earlier than 6b11-9.1+lenny2" test_ref="oval:org.mitre.oval:tst:16344"/>
            </criteria>
          </criteria>
          <criteria comment="Architecture dependent section" operator="AND">
            <criteria comment="Supported architectures section" operator="OR">
              <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
              <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
              <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
              <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
              <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
              <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
              <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
              <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
            </criteria>
            <criteria comment="Packages section" operator="OR">
              <criterion comment="openjdk-6-jre-headless DPKG is earlier than 6b11-9.1+lenny2" test_ref="oval:org.mitre.oval:tst:16180"/>
              <criterion comment="openjdk-6-demo DPKG is earlier than 6b11-9.1+lenny2" test_ref="oval:org.mitre.oval:tst:16257"/>
              <criterion comment="openjdk-6-dbg DPKG is earlier than 6b11-9.1+lenny2" test_ref="oval:org.mitre.oval:tst:16500"/>
              <criterion comment="openjdk-6-jdk DPKG is earlier than 6b11-9.1+lenny2" test_ref="oval:org.mitre.oval:tst:16082"/>
              <criterion comment="openjdk-6-jre DPKG is earlier than 6b11-9.1+lenny2" test_ref="oval:org.mitre.oval:tst:16238"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:8036" class="patch">
      <metadata>
        <title>DSA-1830 icedove -- several vulnerabilities</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <product>icedove</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2009/dsa-1830" ref_id="DSA-1830"/>
        <description>Several remote vulnerabilities have been discovered in the Icedove mail client, an unbranded version of the Thunderbird mail client. The Common Vulnerabilities and Exposures project identifies the following problems: The execution of arbitrary code might be possible via a crafted PNG file that triggers a free of an uninitialized pointer in (1) the png_read_png function, (2) pCAL chunk handling, or (3) setup of 16-bit gamma tables. (MFSA 2009-10) It is possible to execute arbitrary code via vectors related to the layout engine. (MFSA 2009-01) It is possible to execute arbitrary code via vectors related to the JavaScript engine. (MFSA 2009-01) Bjoern Hoehrmann and Moxie Marlinspike discovered a possible spoofing attack via Unicode box drawing characters in internationalized domain names. (MFSA 2009-15) Memory corruption and assertion failures have been discovered in the layout engine, leading to the possible execution of arbitrary code. (MFSA 2009-07) The layout engine allows the execution of arbitrary code in vectors related to nsCSSStyleSheet::GetOwnerNode, events, and garbage collection. (MFSA 2009-07) The JavaScript engine is prone to the execution of arbitrary code via several vectors. (MFSA 2009-07) The layout engine allows the execution of arbitrary code via vectors related to gczeal. (MFSA 2009-07) Georgi Guninski discovered that it is possible to obtain xml data via an issue related to the nsIRDFService. (MFSA 2009-09) The browser engine is prone to a possible memory corruption via several vectors. (MFSA 2009-14) The browser engine is prone to a possible memory corruption via the nsSVGElement::BindToTree function. (MFSA 2009-14) Gregory Fleischer discovered that it is possible to bypass the Same Origin Policy when opening a Flash file via the view-source: scheme. (MFSA 2009-17) The possible arbitrary execution of code was discovered via vectors involving "double frame construction." (MFSA 2009-24) Several issues were discovered in the browser engine as used by icedove, which could lead to the possible execution of arbitrary code. (MFSA 2009-24) Shuo Chen, Ziqing Mao, Yi-Min Wang and Ming Zhang reported a potential man-in-the-middle attack, when using a proxy due to insufficient checks on a certain proxy response. (MFSA 2009-27) moz_bug_r_a4 discovered that it is possible to execute arbitrary JavaScript with chrome privileges due to an error in the garbage collection implementation. (MFSA 2009-29) moz_bug_r_a4 reported that it is possible for scripts from page content to run with elevated privileges and thus potentially executing arbitrary code with the object's chrome privileges. (MFSA 2009-32) Bernd Jendrissek discovered a potentially exploitable crash when viewing a multipart/alternative mail message with a text/enhanced part. (MFSA 2009-33)</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:05-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T07:52:38.527-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:03:42.471-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:02:44.813-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Release section" operator="AND">
        <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
        <criteria comment="Architecture section" operator="OR">
          <criteria comment="Architecture dependent section" operator="AND">
            <criteria comment="Supported architectures section" operator="OR">
              <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
              <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
              <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
              <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
              <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
              <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
              <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
              <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
              <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
              <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
              <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
            </criteria>
            <criteria comment="Packages section" operator="OR">
              <criterion comment="icedove-dev DPKG is earlier than 2.0.0.22-0lenny1" test_ref="oval:org.mitre.oval:tst:14203"/>
              <criterion comment="icedove-dbg DPKG is earlier than 2.0.0.22-0lenny1" test_ref="oval:org.mitre.oval:tst:14642"/>
              <criterion comment="icedove-gnome-support DPKG is earlier than 2.0.0.22-0lenny1" test_ref="oval:org.mitre.oval:tst:14573"/>
              <criterion comment="icedove DPKG is earlier than 2.0.0.22-0lenny1" test_ref="oval:org.mitre.oval:tst:13790"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:8035" class="patch">
      <metadata>
        <title>DSA-1826 eggdrop -- several vulnerabilities</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <platform>Debian GNU/Linux 4.0</platform>
          <product>eggdrop</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2009/dsa-1826" ref_id="DSA-1826"/>
        <description>Several vulnerabilities have been discovered in eggdrop, an advanced IRC robot. The Common Vulnerabilities and Exposures project identifies the following problems: It was discovered that eggdrop is vulnerable to a buffer overflow, which could result in a remote user executing arbitrary code. The previous DSA (DSA-1448-1) did not fix the issue correctly. It was discovered that eggdrop is vulnerable to a denial of service attack, that allows remote attackers to cause a crash via a crafted PRIVMSG.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:08-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T07:55:55.505-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:03:41.788-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:02:44.361-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Platform section" operator="OR">
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Architecture independent section" operator="AND">
              <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criterion comment="eggdrop-data is earlier than 1.6.19-1.1+lenny1" test_ref="oval:org.mitre.oval:tst:17229"/>
            </criteria>
            <criteria comment="Architecture dependent section" operator="AND">
              <criteria comment="Supported architectures section" operator="OR">
                <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
                <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
                <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
                <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
                <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
                <criterion comment="Installed architecture is armel" test_ref="oval:org.mitre.oval:tst:11101"/>
                <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
                <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
                <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
                <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
                <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
                <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
              </criteria>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="eggdrop DPKG is earlier than 1.6.19-1.1+lenny1" test_ref="oval:org.mitre.oval:tst:17123"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 4.0 is installed" definition_ref="oval:org.mitre.oval:def:6461"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Architecture independent section" operator="AND">
              <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criterion comment="eggdrop-data is earlier than 1.6.18-1etch2" test_ref="oval:org.mitre.oval:tst:17222"/>
            </criteria>
            <criteria comment="Packages section" operator="OR">
              <criterion comment="eggdrop DPKG is earlier than 1.6.18-1etch2" test_ref="oval:org.mitre.oval:tst:16946"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:8034" class="patch">
      <metadata>
        <title>DSA-1923 libhtml-parser-perl -- denial of service</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <platform>Debian GNU/Linux 4.0</platform>
          <product>libhtml-parser-perl</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2009/dsa-1923" ref_id="DSA-1923"/>
        <description>A denial of service vulnerability has been found in libhtml-parser-perl, a collection of modules to parse HTML in text documents which is used by several other projects like e.g. SpamAssassin. Mark Martinec discovered that the decode_entities() function will get stuck in an infinite loop when parsing certain HTML entities with invalid UTF-8 characters. An attacker can use this to perform denial of service attacks by submitting crafted HTML to an application using this functionality.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:08-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T07:56:03.409-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:03:41.337-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:02:43.891-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Platform section" operator="OR">
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Architecture dependent section" operator="AND">
              <criteria comment="Supported architectures section" operator="OR">
                <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
                <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
                <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
                <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
                <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
                <criterion comment="Installed architecture is armel" test_ref="oval:org.mitre.oval:tst:11101"/>
                <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
                <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
                <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
                <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
                <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
                <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
              </criteria>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="libhtml-parser-perl DPKG is earlier than 3.56-1+lenny1" test_ref="oval:org.mitre.oval:tst:16924"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 4.0 is installed" definition_ref="oval:org.mitre.oval:def:6461"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Packages section" operator="OR">
              <criterion comment="libhtml-parser-perl DPKG is earlier than 3.55-1+etch1" test_ref="oval:org.mitre.oval:tst:17446"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:8025" class="patch">
      <metadata>
        <title>DSA-1829 sork-passwd-h3 -- insufficient input sanitising</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <platform>Debian GNU/Linux 4.0</platform>
          <product>sork-passwd-h3</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2009/dsa-1829" ref_id="DSA-1829"/>
        <description>It was discovered that sork-passwd-h3, a Horde3 module for users to change their password, is prone to a cross-site scripting attack via the backend parameter.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:08-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T07:55:52.850-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:03:36.914-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:02:40.606-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Platform section" operator="OR">
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Architecture independent section" operator="AND">
              <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criterion comment="sork-passwd-h3 is earlier than 3.0-2+lenny1" test_ref="oval:org.mitre.oval:tst:17212"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 4.0 is installed" definition_ref="oval:org.mitre.oval:def:6461"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Architecture independent section" operator="AND">
              <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criterion comment="sork-passwd-h3 is earlier than 3.0-2+etch1" test_ref="oval:org.mitre.oval:tst:17004"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:8018" class="patch">
      <metadata>
        <title>DSA-1758 nss-ldapd -- insecure config file creation</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <product>nss-ldapd</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2009/dsa-1758" ref_id="DSA-1758"/>
        <description>Leigh James discovered that nss-ldapd, an NSS module for using LDAP as a naming service, by default creates the configuration file /etc/nss-ldapd.conf world-readable which could leak the configured LDAP password if one is used for connecting to the LDAP server. The old stable distribution (etch) doesn't contain nss-ldapd.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:04-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T07:51:14.210-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:03:33.826-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:02:38.407-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Release section" operator="AND">
        <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
        <criteria comment="Architecture section" operator="OR">
          <criteria comment="Architecture dependent section" operator="AND">
            <criteria comment="Supported architectures section" operator="OR">
              <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
              <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
              <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
              <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
              <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
              <criterion comment="Installed architecture is armel" test_ref="oval:org.mitre.oval:tst:11101"/>
              <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
              <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
              <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
              <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
              <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
              <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
            </criteria>
            <criteria comment="Packages section" operator="OR">
              <criterion comment="libnss-ldapd DPKG is earlier than 0.6.7.1" test_ref="oval:org.mitre.oval:tst:13158"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:8011" class="patch">
      <metadata>
        <title>DSA-1813 evolution-data-server -- Several vulnerabilities</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <platform>Debian GNU/Linux 4.0</platform>
          <product>evolution-data-server</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2009/dsa-1813" ref_id="DSA-1813"/>
        <description>Several vulnerabilities have been found in evolution-data-server, the database backend server for the evolution groupware suite. The Common Vulnerabilities and Exposures project identifies the following problems: It was discovered that evolution-data-server is prone to integer overflows triggered by large base64 strings. Joachim Breitner discovered that S/MIME signatures are not verified properly, which can lead to spoofing attacks. It was discovered that NTLM authentication challenge packets are not validated properly when using the NTLM authentication method, which could lead to an information disclosure or a denial of service.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:09-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T07:57:45.781-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:03:31.414-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:02:36.435-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Platform section" operator="OR">
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Architecture independent section" operator="AND">
              <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criterion comment="evolution-data-server-common is earlier than 2.22.3-1.1+lenny1" test_ref="oval:org.mitre.oval:tst:18491"/>
            </criteria>
            <criteria comment="Architecture dependent section" operator="AND">
              <criteria comment="Supported architectures section" operator="OR">
                <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
                <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
                <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
                <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
                <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
                <criterion comment="Installed architecture is armel" test_ref="oval:org.mitre.oval:tst:11101"/>
                <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
                <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
                <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
                <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
                <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
                <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
              </criteria>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="libecal1.2-dev DPKG is earlier than 2.22.3-1.1+lenny1" test_ref="oval:org.mitre.oval:tst:18535"/>
                <criterion comment="libegroupwise1.2-dev DPKG is earlier than 2.22.3-1.1+lenny1" test_ref="oval:org.mitre.oval:tst:18313"/>
                <criterion comment="libebook1.2-9 DPKG is earlier than 2.22.3-1.1+lenny1" test_ref="oval:org.mitre.oval:tst:18512"/>
                <criterion comment="libebook1.2-dev DPKG is earlier than 2.22.3-1.1+lenny1" test_ref="oval:org.mitre.oval:tst:18393"/>
                <criterion comment="libedata-cal1.2-dev DPKG is earlier than 2.22.3-1.1+lenny1" test_ref="oval:org.mitre.oval:tst:18471"/>
                <criterion comment="libedataserverui1.2-8 DPKG is earlier than 2.22.3-1.1+lenny1" test_ref="oval:org.mitre.oval:tst:18338"/>
                <criterion comment="libexchange-storage1.2-dev DPKG is earlier than 2.22.3-1.1+lenny1" test_ref="oval:org.mitre.oval:tst:18086"/>
                <criterion comment="libedata-book1.2-2 DPKG is earlier than 2.22.3-1.1+lenny1" test_ref="oval:org.mitre.oval:tst:18465"/>
                <criterion comment="libedata-book1.2-dev DPKG is earlier than 2.22.3-1.1+lenny1" test_ref="oval:org.mitre.oval:tst:18141"/>
                <criterion comment="libedataserver1.2-9 DPKG is earlier than 2.22.3-1.1+lenny1" test_ref="oval:org.mitre.oval:tst:18445"/>
                <criterion comment="evolution-data-server-dbg DPKG is earlier than 2.22.3-1.1+lenny1" test_ref="oval:org.mitre.oval:tst:18243"/>
                <criterion comment="libcamel1.2-dev DPKG is earlier than 2.22.3-1.1+lenny1" test_ref="oval:org.mitre.oval:tst:18134"/>
                <criterion comment="libgdata-google1.2-dev DPKG is earlier than 2.22.3-1.1+lenny1" test_ref="oval:org.mitre.oval:tst:18362"/>
                <criterion comment="libegroupwise1.2-13 DPKG is earlier than 2.22.3-1.1+lenny1" test_ref="oval:org.mitre.oval:tst:17973"/>
                <criterion comment="libedataserver1.2-dev DPKG is earlier than 2.22.3-1.1+lenny1" test_ref="oval:org.mitre.oval:tst:18323"/>
                <criterion comment="libexchange-storage1.2-3 DPKG is earlier than 2.22.3-1.1+lenny1" test_ref="oval:org.mitre.oval:tst:18478"/>
                <criterion comment="libgdata1.2-1 DPKG is earlier than 2.22.3-1.1+lenny1" test_ref="oval:org.mitre.oval:tst:18563"/>
                <criterion comment="libecal1.2-7 DPKG is earlier than 2.22.3-1.1+lenny1" test_ref="oval:org.mitre.oval:tst:17754"/>
                <criterion comment="libgdata1.2-dev DPKG is earlier than 2.22.3-1.1+lenny1" test_ref="oval:org.mitre.oval:tst:18674"/>
                <criterion comment="libgdata-google1.2-1 DPKG is earlier than 2.22.3-1.1+lenny1" test_ref="oval:org.mitre.oval:tst:18629"/>
                <criterion comment="evolution-data-server DPKG is earlier than 2.22.3-1.1+lenny1" test_ref="oval:org.mitre.oval:tst:18466"/>
                <criterion comment="libedataserverui1.2-dev DPKG is earlier than 2.22.3-1.1+lenny1" test_ref="oval:org.mitre.oval:tst:18739"/>
                <criterion comment="libedata-cal1.2-6 DPKG is earlier than 2.22.3-1.1+lenny1" test_ref="oval:org.mitre.oval:tst:18610"/>
                <criterion comment="libcamel1.2-11 DPKG is earlier than 2.22.3-1.1+lenny1" test_ref="oval:org.mitre.oval:tst:18604"/>
                <criterion comment="evolution-data-server-dev DPKG is earlier than 2.22.3-1.1+lenny1" test_ref="oval:org.mitre.oval:tst:18589"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 4.0 is installed" definition_ref="oval:org.mitre.oval:def:6461"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Architecture independent section" operator="AND">
              <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criterion comment="evolution-data-server-common is earlier than 1.6.3-5etch2" test_ref="oval:org.mitre.oval:tst:18635"/>
            </criteria>
            <criteria comment="Architecture dependent section" operator="AND">
              <criteria comment="Supported architectures section" operator="OR">
                <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
                <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
                <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
                <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
                <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
                <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
                <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
                <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
                <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
                <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
              </criteria>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="libcamel1.2-8 DPKG is earlier than 1.6.3-5etch2" test_ref="oval:org.mitre.oval:tst:18369"/>
                <criterion comment="libebook1.2-5 DPKG is earlier than 1.6.3-5etch2" test_ref="oval:org.mitre.oval:tst:18074"/>
                <criterion comment="libedata-book1.2-2 DPKG is earlier than 1.6.3-5etch2" test_ref="oval:org.mitre.oval:tst:18507"/>
                <criterion comment="libedataserver1.2-7 DPKG is earlier than 1.6.3-5etch2" test_ref="oval:org.mitre.oval:tst:18726"/>
                <criterion comment="evolution-data-server-dev DPKG is earlier than 1.6.3-5etch2" test_ref="oval:org.mitre.oval:tst:18045"/>
                <criterion comment="evolution-data-server DPKG is earlier than 1.6.3-5etch2" test_ref="oval:org.mitre.oval:tst:18689"/>
                <criterion comment="libegroupwise1.2-dev DPKG is earlier than 1.6.3-5etch2" test_ref="oval:org.mitre.oval:tst:18508"/>
                <criterion comment="libedata-book1.2-dev DPKG is earlier than 1.6.3-5etch2" test_ref="oval:org.mitre.oval:tst:18255"/>
                <criterion comment="libexchange-storage1.2-1 DPKG is earlier than 1.6.3-5etch2" test_ref="oval:org.mitre.oval:tst:18633"/>
                <criterion comment="libedataserverui1.2-dev DPKG is earlier than 1.6.3-5etch2" test_ref="oval:org.mitre.oval:tst:18518"/>
                <criterion comment="libedata-cal1.2-5 DPKG is earlier than 1.6.3-5etch2" test_ref="oval:org.mitre.oval:tst:18112"/>
                <criterion comment="evolution-data-server-dbg DPKG is earlier than 1.6.3-5etch2" test_ref="oval:org.mitre.oval:tst:18608"/>
                <criterion comment="libcamel1.2-dev DPKG is earlier than 1.6.3-5etch2" test_ref="oval:org.mitre.oval:tst:18628"/>
                <criterion comment="libecal1.2-dev DPKG is earlier than 1.6.3-5etch2" test_ref="oval:org.mitre.oval:tst:18685"/>
                <criterion comment="libedata-cal1.2-dev DPKG is earlier than 1.6.3-5etch2" test_ref="oval:org.mitre.oval:tst:18427"/>
                <criterion comment="libedataserverui1.2-6 DPKG is earlier than 1.6.3-5etch2" test_ref="oval:org.mitre.oval:tst:18737"/>
                <criterion comment="libexchange-storage1.2-dev DPKG is earlier than 1.6.3-5etch2" test_ref="oval:org.mitre.oval:tst:18367"/>
                <criterion comment="libedataserver1.2-dev DPKG is earlier than 1.6.3-5etch2" test_ref="oval:org.mitre.oval:tst:18554"/>
                <criterion comment="libecal1.2-6 DPKG is earlier than 1.6.3-5etch2" test_ref="oval:org.mitre.oval:tst:18455"/>
                <criterion comment="libebook1.2-dev DPKG is earlier than 1.6.3-5etch2" test_ref="oval:org.mitre.oval:tst:18719"/>
                <criterion comment="libegroupwise1.2-10 DPKG is earlier than 1.6.3-5etch2" test_ref="oval:org.mitre.oval:tst:18283"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:8008" class="patch">
      <metadata>
        <title>DSA-1886 iceweasel -- several vulnerabilities</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <product>iceweasel</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2009/dsa-1886" ref_id="DSA-1886"/>
        <description>Several remote vulnerabilities have been discovered in the Iceweasel web browser, an unbranded version of the Firefox browser. The Common Vulnerabilities and Exposures project identifies the following problems: "moz_bug_r_a4" discovered that a programming error in the FeedWriter module could lead to the execution of Javascript code with elevated privileges. Prateek Saxena discovered a cross-site scripting vulnerability in the MozSearch plugin interface.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:04-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T07:51:22.639-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:03:30.476-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:02:35.531-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Release section" operator="AND">
        <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
        <criteria comment="Architecture section" operator="OR">
          <criteria comment="Architecture independent section" operator="AND">
            <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
            <criterion comment="iceweasel-gnome-support is earlier than 3.0.6-3" test_ref="oval:org.mitre.oval:tst:13377"/>
          </criteria>
          <criteria comment="Architecture dependent section" operator="AND">
            <criteria comment="Supported architectures section" operator="OR">
              <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
              <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
              <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
              <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
              <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
              <criterion comment="Installed architecture is armel" test_ref="oval:org.mitre.oval:tst:11101"/>
              <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
              <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
              <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
              <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
              <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
              <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
            </criteria>
            <criteria comment="Packages section" operator="OR">
              <criterion comment="iceweasel-dbg DPKG is earlier than 3.0.6-3" test_ref="oval:org.mitre.oval:tst:13508"/>
              <criterion comment="iceweasel DPKG is earlier than 3.0.6-3" test_ref="oval:org.mitre.oval:tst:13587"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:8007" class="patch">
      <metadata>
        <title>DSA-1880 openoffice.org -- several vulnerabilities</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <platform>Debian GNU/Linux 4.0</platform>
          <product>openoffice.org</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2009/dsa-1880" ref_id="DSA-1880"/>
        <description>Several vulnerabilities have been discovered in the OpenOffice.org office suite. The Common Vulnerabilities and Exposures project identifies the following problems: Dyon Balding of Secunia Research has discovered a vulnerability, which can be exploited by opening a specially crafted Microsoft Word document. When reading a Microsoft Word document, a bug in the parser of sprmTDelete records can result in an integer underflow that may lead to heap-based buffer overflows. Successful exploitation may allow arbitrary code execution in the context of the OpenOffice.org process. Dyon Balding of Secunia Research has discovered a vulnerability, which can be exploited by opening a specially crafted Microsoft Word document. When reading a Microsoft Word document, a bug in the parser of sprmTDelete records can result in heap-based buffer overflows. Successful exploitation may allow arbitrary code execution in the context of the OpenOffice.org process. A vulnerability has been discovered in the parser of EMF files of OpenOffice/Go-oo 2.x and 3.x that can be triggered by a specially crafted document and lead to the execution of arbitrary commands the privileges of the user running OpenOffice.org/Go-oo. This vulnerability does not exist in the packages for oldstable, testing and unstable.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:04-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T07:51:55.155-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:03:24.416-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:02:31.219-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Platform section" operator="OR">
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Architecture independent section" operator="AND">
              <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="openoffice.org-dtd-officedocument1.0 is earlier than 2.4.1+dfsg-1+lenny3" test_ref="oval:org.mitre.oval:tst:13287"/>
                <criterion comment="openoffice.org-l10n-cy is earlier than 2.4.1+dfsg-1+lenny3" test_ref="oval:org.mitre.oval:tst:13522"/>
                <criterion comment="openoffice.org-l10n-cs is earlier than 2.4.1+dfsg-1+lenny3" test_ref="oval:org.mitre.oval:tst:13185"/>
                <criterion comment="openoffice.org-help-hu is earlier than 2.4.1+dfsg-1+lenny3" test_ref="oval:org.mitre.oval:tst:13352"/>
                <criterion comment="openoffice.org-l10n-vi is earlier than 2.4.1+dfsg-1+lenny3" test_ref="oval:org.mitre.oval:tst:13459"/>
                <criterion comment="openoffice.org-l10n-ca is earlier than 2.4.1+dfsg-1+lenny3" test_ref="oval:org.mitre.oval:tst:13251"/>
                <criterion comment="openoffice.org-style-industrial is earlier than 2.4.1+dfsg-1+lenny3" test_ref="oval:org.mitre.oval:tst:13280"/>
                <criterion comment="openoffice.org-help-en-us is earlier than 2.4.1+dfsg-1+lenny3" test_ref="oval:org.mitre.oval:tst:13490"/>
                <criterion comment="ttf-opensymbol is earlier than 2.4.1+dfsg-1+lenny3" test_ref="oval:org.mitre.oval:tst:13545"/>
                <criterion comment="openoffice.org-l10n-ka is earlier than 2.4.1+dfsg-1+lenny3" test_ref="oval:org.mitre.oval:tst:12651"/>
                <criterion comment="openoffice.org-l10n-km is earlier than 2.4.1+dfsg-1+lenny3" test_ref="oval:org.mitre.oval:tst:13624"/>
                <criterion comment="openoffice.org-l10n-ko is earlier than 2.4.1+dfsg-1+lenny3" test_ref="oval:org.mitre.oval:tst:13520"/>
                <criterion comment="openoffice.org-l10n-pl is earlier than 2.4.1+dfsg-1+lenny3" test_ref="oval:org.mitre.oval:tst:13427"/>
                <criterion comment="broffice.org is earlier than 2.4.1+dfsg-1+lenny3" test_ref="oval:org.mitre.oval:tst:13201"/>
                <criterion comment="openoffice.org-l10n-ku is earlier than 2.4.1+dfsg-1+lenny3" test_ref="oval:org.mitre.oval:tst:13419"/>
                <criterion comment="openoffice.org-l10n-pt is earlier than 2.4.1+dfsg-1+lenny3" test_ref="oval:org.mitre.oval:tst:13572"/>
                <criterion comment="openoffice.org-l10n-xh is earlier than 2.4.1+dfsg-1+lenny3" test_ref="oval:org.mitre.oval:tst:13189"/>
                <criterion comment="openoffice.org-help-pt is earlier than 2.4.1+dfsg-1+lenny3" test_ref="oval:org.mitre.oval:tst:13496"/>
                <criterion comment="openoffice.org-help-it is earlier than 2.4.1+dfsg-1+lenny3" test_ref="oval:org.mitre.oval:tst:13227"/>
                <criterion comment="openoffice.org-help-pl is earlier than 2.4.1+dfsg-1+lenny3" test_ref="oval:org.mitre.oval:tst:13648"/>
                <criterion comment="openoffice.org-l10n-be-by is earlier than 2.4.1+dfsg-1+lenny3" test_ref="oval:org.mitre.oval:tst:13621"/>
                <criterion comment="openoffice.org-l10n-eu is earlier than 2.4.1+dfsg-1+lenny3" test_ref="oval:org.mitre.oval:tst:13226"/>
                <criterion comment="openoffice.org-l10n-hr is earlier than 2.4.1+dfsg-1+lenny3" test_ref="oval:org.mitre.oval:tst:13626"/>
                <criterion comment="openoffice.org-l10n-hu is earlier than 2.4.1+dfsg-1+lenny3" test_ref="oval:org.mitre.oval:tst:13100"/>
                <criterion comment="openoffice.org-l10n-mk is earlier than 2.4.1+dfsg-1+lenny3" test_ref="oval:org.mitre.oval:tst:13489"/>
                <criterion comment="openoffice.org-l10n-sr-cs is earlier than 2.4.1+dfsg-1+lenny3" test_ref="oval:org.mitre.oval:tst:13504"/>
                <criterion comment="openoffice.org-l10n-he is earlier than 2.4.1+dfsg-1+lenny3" test_ref="oval:org.mitre.oval:tst:13576"/>
                <criterion comment="openoffice.org-l10n-en-za is earlier than 2.4.1+dfsg-1+lenny3" test_ref="oval:org.mitre.oval:tst:13215"/>
                <criterion comment="libuno-cli-types1.1-cil is earlier than 1.1.13.0+OOo2.4.1+dfsg-1+lenny3" test_ref="oval:org.mitre.oval:tst:13541"/>
                <criterion comment="openoffice.org-l10n-as-in is earlier than 2.4.1+dfsg-1+lenny3" test_ref="oval:org.mitre.oval:tst:13237"/>
                <criterion comment="openoffice.org-l10n-ta-in is earlier than 2.4.1+dfsg-1+lenny3" test_ref="oval:org.mitre.oval:tst:13399"/>
                <criterion comment="openoffice.org-l10n-te-in is earlier than 2.4.1+dfsg-1+lenny3" test_ref="oval:org.mitre.oval:tst:13268"/>
                <criterion comment="openoffice.org-help-nl is earlier than 2.4.1+dfsg-1+lenny3" test_ref="oval:org.mitre.oval:tst:13517"/>
                <criterion comment="openoffice.org-l10n-eo is earlier than 2.4.1+dfsg-1+lenny3" test_ref="oval:org.mitre.oval:tst:12740"/>
                <criterion comment="openoffice.org-l10n-el is earlier than 2.4.1+dfsg-1+lenny3" test_ref="oval:org.mitre.oval:tst:13183"/>
                <criterion comment="openoffice.org-l10n-ro is earlier than 2.4.1+dfsg-1+lenny3" test_ref="oval:org.mitre.oval:tst:12973"/>
                <criterion comment="openoffice.org-l10n-zu is earlier than 2.4.1+dfsg-1+lenny3" test_ref="oval:org.mitre.oval:tst:13494"/>
                <criterion comment="openoffice.org-l10n-hi-in is earlier than 2.4.1+dfsg-1+lenny3" test_ref="oval:org.mitre.oval:tst:13682"/>
                <criterion comment="openoffice.org-l10n-zh-tw is earlier than 2.4.1+dfsg-1+lenny3" test_ref="oval:org.mitre.oval:tst:13391"/>
                <criterion comment="openoffice.org-l10n-za is earlier than 2.4.1+dfsg-1+lenny3" test_ref="oval:org.mitre.oval:tst:13397"/>
                <criterion comment="openoffice.org-l10n-et is earlier than 2.4.1+dfsg-1+lenny3" test_ref="oval:org.mitre.oval:tst:13607"/>
                <criterion comment="openoffice.org-help-fr is earlier than 2.4.1+dfsg-1+lenny3" test_ref="oval:org.mitre.oval:tst:13720"/>
                <criterion comment="openoffice.org-l10n-rw is earlier than 2.4.1+dfsg-1+lenny3" test_ref="oval:org.mitre.oval:tst:13296"/>
                <criterion comment="openoffice.org-l10n-es is earlier than 2.4.1+dfsg-1+lenny3" test_ref="oval:org.mitre.oval:tst:13726"/>
                <criterion comment="openoffice.org-l10n-ru is earlier than 2.4.1+dfsg-1+lenny3" test_ref="oval:org.mitre.oval:tst:13039"/>
                <criterion comment="openoffice.org-l10n-bs is earlier than 2.4.1+dfsg-1+lenny3" test_ref="oval:org.mitre.oval:tst:13327"/>
                <criterion comment="openoffice.org-l10n-br is earlier than 2.4.1+dfsg-1+lenny3" test_ref="oval:org.mitre.oval:tst:13372"/>
                <criterion comment="openoffice.org-style-tango is earlier than 2.4.1+dfsg-1+lenny3" test_ref="oval:org.mitre.oval:tst:13540"/>
                <criterion comment="openoffice.org-style-andromeda is earlier than 2.4.1+dfsg-1+lenny3" test_ref="oval:org.mitre.oval:tst:13655"/>
                <criterion comment="openoffice.org-l10n-bn is earlier than 2.4.1+dfsg-1+lenny3" test_ref="oval:org.mitre.oval:tst:13059"/>
                <criterion comment="openoffice.org-l10n-bg is earlier than 2.4.1+dfsg-1+lenny3" test_ref="oval:org.mitre.oval:tst:13617"/>
                <criterion comment="openoffice.org-l10n-sl is earlier than 2.4.1+dfsg-1+lenny3" test_ref="oval:org.mitre.oval:tst:13728"/>
                <criterion comment="openoffice.org-l10n-ja is earlier than 2.4.1+dfsg-1+lenny3" test_ref="oval:org.mitre.oval:tst:13274"/>
                <criterion comment="openoffice.org-l10n-en-gb is earlier than 2.4.1+dfsg-1+lenny3" test_ref="oval:org.mitre.oval:tst:13532"/>
                <criterion comment="openoffice.org-help-gl is earlier than 2.4.1+dfsg-1+lenny3" test_ref="oval:org.mitre.oval:tst:13298"/>
                <criterion comment="openoffice.org-l10n-sk is earlier than 2.4.1+dfsg-1+lenny3" test_ref="oval:org.mitre.oval:tst:13091"/>
                <criterion comment="openoffice.org-l10n-st is earlier than 2.4.1+dfsg-1+lenny3" test_ref="oval:org.mitre.oval:tst:13620"/>
                <criterion comment="openoffice.org-l10n-sv is earlier than 2.4.1+dfsg-1+lenny3" test_ref="oval:org.mitre.oval:tst:13142"/>
                <criterion comment="openoffice.org-l10n-sr is earlier than 2.4.1+dfsg-1+lenny3" test_ref="oval:org.mitre.oval:tst:13693"/>
                <criterion comment="openoffice.org-l10n-ss is earlier than 2.4.1+dfsg-1+lenny3" test_ref="oval:org.mitre.oval:tst:13669"/>
                <criterion comment="openoffice.org-help-sv is earlier than 2.4.1+dfsg-1+lenny3" test_ref="oval:org.mitre.oval:tst:12980"/>
                <criterion comment="openoffice.org-style-hicontrast is earlier than 2.4.1+dfsg-1+lenny3" test_ref="oval:org.mitre.oval:tst:13709"/>
                <criterion comment="openoffice.org-help-dz is earlier than 2.4.1+dfsg-1+lenny3" test_ref="oval:org.mitre.oval:tst:13595"/>
                <criterion comment="openoffice.org-help-da is earlier than 2.4.1+dfsg-1+lenny3" test_ref="oval:org.mitre.oval:tst:12956"/>
                <criterion comment="openoffice.org-help-de is earlier than 2.4.1+dfsg-1+lenny3" test_ref="oval:org.mitre.oval:tst:13438"/>
                <criterion comment="openoffice.org-help-sl is earlier than 2.4.1+dfsg-1+lenny3" test_ref="oval:org.mitre.oval:tst:13700"/>
                <criterion comment="openoffice.org-l10n-gl is earlier than 2.4.1+dfsg-1+lenny3" test_ref="oval:org.mitre.oval:tst:13442"/>
                <criterion comment="openoffice.org-java-common is earlier than 2.4.1+dfsg-1+lenny3" test_ref="oval:org.mitre.oval:tst:13667"/>
                <criterion comment="openoffice.org-l10n-ga is earlier than 2.4.1+dfsg-1+lenny3" test_ref="oval:org.mitre.oval:tst:13675"/>
                <criterion comment="openoffice.org-l10n-ts is earlier than 2.4.1+dfsg-1+lenny3" test_ref="oval:org.mitre.oval:tst:13533"/>
                <criterion comment="openoffice.org-l10n-tr is earlier than 2.4.1+dfsg-1+lenny3" test_ref="oval:org.mitre.oval:tst:13175"/>
                <criterion comment="openoffice.org-l10n-tn is earlier than 2.4.1+dfsg-1+lenny3" test_ref="oval:org.mitre.oval:tst:13604"/>
                <criterion comment="openoffice.org-l10n-th is earlier than 2.4.1+dfsg-1+lenny3" test_ref="oval:org.mitre.oval:tst:13410"/>
                <criterion comment="openoffice.org-l10n-tg is earlier than 2.4.1+dfsg-1+lenny3" test_ref="oval:org.mitre.oval:tst:13662"/>
                <criterion comment="openoffice.org-help-et is earlier than 2.4.1+dfsg-1+lenny3" test_ref="oval:org.mitre.oval:tst:13223"/>
                <criterion comment="openoffice.org-help-eu is earlier than 2.4.1+dfsg-1+lenny3" test_ref="oval:org.mitre.oval:tst:13588"/>
                <criterion comment="libuno-cli-basetypes1.0-cil is earlier than 1.0.10.0+OOo2.4.1+dfsg-1+lenny3" test_ref="oval:org.mitre.oval:tst:13477"/>
                <criterion comment="openoffice.org-help-es is earlier than 2.4.1+dfsg-1+lenny3" test_ref="oval:org.mitre.oval:tst:13736"/>
                <criterion comment="openoffice.org-filter-mobiledev is earlier than 2.4.1+dfsg-1+lenny3" test_ref="oval:org.mitre.oval:tst:13344"/>
                <criterion comment="openoffice.org-emailmerge is earlier than 2.4.1+dfsg-1+lenny3" test_ref="oval:org.mitre.oval:tst:13698"/>
                <criterion comment="openoffice.org-l10n-or-in is earlier than 2.4.1+dfsg-1+lenny3" test_ref="oval:org.mitre.oval:tst:13591"/>
                <criterion comment="openoffice.org-l10n-lt is earlier than 2.4.1+dfsg-1+lenny3" test_ref="oval:org.mitre.oval:tst:13600"/>
                <criterion comment="openoffice.org-l10n-lv is earlier than 2.4.1+dfsg-1+lenny3" test_ref="oval:org.mitre.oval:tst:13396"/>
                <criterion comment="openoffice.org-l10n-uz is earlier than 2.4.1+dfsg-1+lenny3" test_ref="oval:org.mitre.oval:tst:13350"/>
                <criterion comment="openoffice.org-l10n-de is earlier than 2.4.1+dfsg-1+lenny3" test_ref="oval:org.mitre.oval:tst:13612"/>
                <criterion comment="openoffice.org-l10n-da is earlier than 2.4.1+dfsg-1+lenny3" test_ref="oval:org.mitre.oval:tst:13544"/>
                <criterion comment="openoffice.org-l10n-uk is earlier than 2.4.1+dfsg-1+lenny3" test_ref="oval:org.mitre.oval:tst:13546"/>
                <criterion comment="openoffice.org-l10n-dz is earlier than 2.4.1+dfsg-1+lenny3" test_ref="oval:org.mitre.oval:tst:13293"/>
                <criterion comment="libuno-cli-cppuhelper1.0-cil is earlier than 1.0.13.0+OOo2.4.1+dfsg-1+lenny3" test_ref="oval:org.mitre.oval:tst:13149"/>
                <criterion comment="openoffice.org-l10n-lo is earlier than 2.4.1+dfsg-1+lenny3" test_ref="oval:org.mitre.oval:tst:13365"/>
                <criterion comment="libuno-cli-ure1.0-cil is earlier than 1.0.13.0+OOo2.4.1+dfsg-1+lenny3" test_ref="oval:org.mitre.oval:tst:13717"/>
                <criterion comment="openoffice.org-l10n-ar is earlier than 2.4.1+dfsg-1+lenny3" test_ref="oval:org.mitre.oval:tst:13714"/>
                <criterion comment="openoffice.org-l10n-ml-in is earlier than 2.4.1+dfsg-1+lenny3" test_ref="oval:org.mitre.oval:tst:13255"/>
                <criterion comment="openoffice.org-help-en-gb is earlier than 2.4.1+dfsg-1+lenny3" test_ref="oval:org.mitre.oval:tst:13497"/>
                <criterion comment="openoffice.org-l10n-af is earlier than 2.4.1+dfsg-1+lenny3" test_ref="oval:org.mitre.oval:tst:13437"/>
                <criterion comment="openoffice.org-common is earlier than 2.4.1+dfsg-1+lenny3" test_ref="oval:org.mitre.oval:tst:13501"/>
                <criterion comment="openoffice.org-help-ja is earlier than 2.4.1+dfsg-1+lenny3" test_ref="oval:org.mitre.oval:tst:13238"/>
                <criterion comment="openoffice.org-l10n-zh-cn is earlier than 2.4.1+dfsg-1+lenny3" test_ref="oval:org.mitre.oval:tst:13638"/>
                <criterion comment="openoffice.org-l10n-ve is earlier than 2.4.1+dfsg-1+lenny3" test_ref="oval:org.mitre.oval:tst:13334"/>
                <criterion comment="openoffice.org-help-zh-cn is earlier than 2.4.1+dfsg-1+lenny3" test_ref="oval:org.mitre.oval:tst:13305"/>
                <criterion comment="openoffice.org-l10n-it is earlier than 2.4.1+dfsg-1+lenny3" test_ref="oval:org.mitre.oval:tst:13321"/>
                <criterion comment="openoffice.org-l10n-gu-in is earlier than 2.4.1+dfsg-1+lenny3" test_ref="oval:org.mitre.oval:tst:13233"/>
                <criterion comment="openoffice.org-l10n-in is earlier than 2.4.1+dfsg-1+lenny3" test_ref="oval:org.mitre.oval:tst:13461"/>
                <criterion comment="openoffice.org-help-zh-tw is earlier than 2.4.1+dfsg-1+lenny3" test_ref="oval:org.mitre.oval:tst:12972"/>
                <criterion comment="openoffice.org-style-crystal is earlier than 2.4.1+dfsg-1+lenny3" test_ref="oval:org.mitre.oval:tst:13708"/>
                <criterion comment="openoffice.org-l10n-mr-in is earlier than 2.4.1+dfsg-1+lenny3" test_ref="oval:org.mitre.oval:tst:13307"/>
                <criterion comment="openoffice.org-help-ru is earlier than 2.4.1+dfsg-1+lenny3" test_ref="oval:org.mitre.oval:tst:13633"/>
                <criterion comment="openoffice.org-l10n-fr is earlier than 2.4.1+dfsg-1+lenny3" test_ref="oval:org.mitre.oval:tst:13689"/>
                <criterion comment="openoffice.org-l10n-pt-br is earlier than 2.4.1+dfsg-1+lenny3" test_ref="oval:org.mitre.oval:tst:13615"/>
                <criterion comment="openoffice.org-report-builder is earlier than 1.0.2+OOo2.4.1+dfsg-1+lenny3" test_ref="oval:org.mitre.oval:tst:13364"/>
                <criterion comment="openoffice.org-help-pt-br is earlier than 2.4.1+dfsg-1+lenny3" test_ref="oval:org.mitre.oval:tst:13632"/>
                <criterion comment="openoffice.org-help-ko is earlier than 2.4.1+dfsg-1+lenny3" test_ref="oval:org.mitre.oval:tst:12975"/>
                <criterion comment="openoffice.org-help-km is earlier than 2.4.1+dfsg-1+lenny3" test_ref="oval:org.mitre.oval:tst:13686"/>
                <criterion comment="openoffice.org-l10n-fa is earlier than 2.4.1+dfsg-1+lenny3" test_ref="oval:org.mitre.oval:tst:13724"/>
                <criterion comment="openoffice.org-l10n-fi is earlier than 2.4.1+dfsg-1+lenny3" test_ref="oval:org.mitre.oval:tst:13699"/>
                <criterion comment="openoffice.org-qa-api-tests is earlier than 2.4.1+dfsg-1+lenny3" test_ref="oval:org.mitre.oval:tst:13316"/>
                <criterion comment="openoffice.org-help-hi-in is earlier than 2.4.1+dfsg-1+lenny3" test_ref="oval:org.mitre.oval:tst:13570"/>
                <criterion comment="openoffice.org-l10n-ns is earlier than 2.4.1+dfsg-1+lenny3" test_ref="oval:org.mitre.oval:tst:13301"/>
                <criterion comment="openoffice.org-l10n-nr is earlier than 2.4.1+dfsg-1+lenny3" test_ref="oval:org.mitre.oval:tst:13524"/>
                <criterion comment="openoffice.org-dev-doc is earlier than 2.4.1+dfsg-1+lenny3" test_ref="oval:org.mitre.oval:tst:13109"/>
                <criterion comment="openoffice.org-l10n-nn is earlier than 2.4.1+dfsg-1+lenny3" test_ref="oval:org.mitre.oval:tst:13672"/>
                <criterion comment="openoffice.org-l10n-nl is earlier than 2.4.1+dfsg-1+lenny3" test_ref="oval:org.mitre.oval:tst:13740"/>
                <criterion comment="openoffice.org-help-cs is earlier than 2.4.1+dfsg-1+lenny3" test_ref="oval:org.mitre.oval:tst:13663"/>
                <criterion comment="openoffice.org-l10n-ne is earlier than 2.4.1+dfsg-1+lenny3" test_ref="oval:org.mitre.oval:tst:13679"/>
                <criterion comment="openoffice.org-l10n-pa-in is earlier than 2.4.1+dfsg-1+lenny3" test_ref="oval:org.mitre.oval:tst:13431"/>
                <criterion comment="openoffice.org-l10n-nb is earlier than 2.4.1+dfsg-1+lenny3" test_ref="oval:org.mitre.oval:tst:13623"/>
              </criteria>
            </criteria>
            <criteria comment="Architecture dependent section" operator="AND">
              <criteria comment="Supported architectures section" operator="OR">
                <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
                <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
                <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
                <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
                <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
                <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
                <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
                <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
              </criteria>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="openoffice.org DPKG is earlier than 2.4.1+dfsg-1+lenny3" test_ref="oval:org.mitre.oval:tst:12786"/>
                <criterion comment="openoffice.org-dbg DPKG is earlier than 2.4.1+dfsg-1+lenny3" test_ref="oval:org.mitre.oval:tst:13246"/>
                <criterion comment="python-uno DPKG is earlier than 2.4.1+dfsg-1+lenny3" test_ref="oval:org.mitre.oval:tst:13140"/>
                <criterion comment="openoffice.org-draw DPKG is earlier than 2.4.1+dfsg-1+lenny3" test_ref="oval:org.mitre.oval:tst:12825"/>
                <criterion comment="openoffice.org-kde DPKG is earlier than 2.4.1+dfsg-1+lenny3" test_ref="oval:org.mitre.oval:tst:13536"/>
                <criterion comment="openoffice.org-filter-binfilter DPKG is earlier than 2.4.1+dfsg-1+lenny3" test_ref="oval:org.mitre.oval:tst:13690"/>
                <criterion comment="openoffice.org-base DPKG is earlier than 2.4.1+dfsg-1+lenny3" test_ref="oval:org.mitre.oval:tst:13406"/>
                <criterion comment="mozilla-openoffice.org DPKG is earlier than 2.4.1+dfsg-1+lenny3" test_ref="oval:org.mitre.oval:tst:13710"/>
                <criterion comment="openoffice.org-headless DPKG is earlier than 2.4.1+dfsg-1+lenny3" test_ref="oval:org.mitre.oval:tst:13665"/>
                <criterion comment="openoffice.org-impress DPKG is earlier than 2.4.1+dfsg-1+lenny3" test_ref="oval:org.mitre.oval:tst:13212"/>
                <criterion comment="libmythes-dev DPKG is earlier than 2.4.1+dfsg-1+lenny3" test_ref="oval:org.mitre.oval:tst:13598"/>
                <criterion comment="openoffice.org-gnome DPKG is earlier than 2.4.1+dfsg-1+lenny3" test_ref="oval:org.mitre.oval:tst:13674"/>
                <criterion comment="openoffice.org-evolution DPKG is earlier than 2.4.1+dfsg-1+lenny3" test_ref="oval:org.mitre.oval:tst:13154"/>
                <criterion comment="openoffice.org-math DPKG is earlier than 2.4.1+dfsg-1+lenny3" test_ref="oval:org.mitre.oval:tst:13678"/>
                <criterion comment="openoffice.org-calc DPKG is earlier than 2.4.1+dfsg-1+lenny3" test_ref="oval:org.mitre.oval:tst:12911"/>
                <criterion comment="openoffice.org-base-core DPKG is earlier than 2.4.1+dfsg-1+lenny3" test_ref="oval:org.mitre.oval:tst:13444"/>
                <criterion comment="openoffice.org-report-builder-bin DPKG is earlier than 2.4.1+dfsg-1+lenny3" test_ref="oval:org.mitre.oval:tst:13688"/>
                <criterion comment="openoffice.org-sdbc-postgresql DPKG is earlier than 0.7.6+OOo2.4.1+dfsg-1+lenny3" test_ref="oval:org.mitre.oval:tst:12979"/>
                <criterion comment="openoffice.org-dev DPKG is earlier than 2.4.1+dfsg-1+lenny3" test_ref="oval:org.mitre.oval:tst:13450"/>
                <criterion comment="openoffice.org-core DPKG is earlier than 2.4.1+dfsg-1+lenny3" test_ref="oval:org.mitre.oval:tst:13606"/>
                <criterion comment="ure DPKG is earlier than 1.4+OOo2.4.1+dfsg-1+lenny3" test_ref="oval:org.mitre.oval:tst:13093"/>
                <criterion comment="openoffice.org-writer DPKG is earlier than 2.4.1+dfsg-1+lenny3" test_ref="oval:org.mitre.oval:tst:13257"/>
                <criterion comment="ure-dbg DPKG is earlier than 1.4+OOo2.4.1+dfsg-1+lenny3" test_ref="oval:org.mitre.oval:tst:12909"/>
                <criterion comment="openoffice.org-gtk DPKG is earlier than 2.4.1+dfsg-1+lenny3" test_ref="oval:org.mitre.oval:tst:13513"/>
                <criterion comment="openoffice.org-officebean DPKG is earlier than 2.4.1+dfsg-1+lenny3" test_ref="oval:org.mitre.oval:tst:13271"/>
                <criterion comment="openoffice.org-presentation-minimizer DPKG is earlier than 1.0+OOo2.4.1+dfsg-1+lenny3" test_ref="oval:org.mitre.oval:tst:13169"/>
              </criteria>
            </criteria>
            <criteria comment="Architecture dependent section" operator="AND">
              <criteria comment="Supported architectures section" operator="OR">
                <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
                <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
                <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
              </criteria>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="openoffice.org-gcj DPKG is earlier than 2.4.1+dfsg-1+lenny3" test_ref="oval:org.mitre.oval:tst:13635"/>
                <criterion comment="openoffice.org-ogltrans DPKG is earlier than 2.4.1+dfsg-1+lenny3" test_ref="oval:org.mitre.oval:tst:13645"/>
                <criterion comment="openoffice.org-qa-tools DPKG is earlier than 2.4.1+dfsg-1+lenny3" test_ref="oval:org.mitre.oval:tst:13434"/>
              </criteria>
            </criteria>
            <criteria comment="Architecture depended section" operator="AND">
              <criteria comment="Supported platform section" operator="AND">
                <criterion comment="mipsel architecture" test_ref="oval:org.mitre.oval:tst:11110"/>
                <criteria comment="Packages section" operator="OR">
                  <criterion comment="openoffice.org-gcj DPKG is earlier than 2.4.1+dfsg-1+lenny3" test_ref="oval:org.mitre.oval:tst:13264"/>
                  <criterion comment="openoffice.org-qa-tools DPKG is earlier than 2.4.1+dfsg-1+lenny3" test_ref="oval:org.mitre.oval:tst:13186"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 4.0 is installed" definition_ref="oval:org.mitre.oval:def:6461"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Architecture independent section" operator="AND">
              <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="openoffice.org-dtd-officedocument1.0 is earlier than 2.0.4.dfsg.2-7etch7" test_ref="oval:org.mitre.oval:tst:13315"/>
                <criterion comment="openoffice.org-l10n-cy is earlier than 2.0.4.dfsg.2-7etch7" test_ref="oval:org.mitre.oval:tst:13499"/>
                <criterion comment="openoffice.org-l10n-cs is earlier than 2.0.4.dfsg.2-7etch7" test_ref="oval:org.mitre.oval:tst:13346"/>
                <criterion comment="openoffice.org-help-hu is earlier than 2.0.4.dfsg.2-7etch7" test_ref="oval:org.mitre.oval:tst:13537"/>
                <criterion comment="openoffice.org-l10n-vi is earlier than 2.0.4.dfsg.2-7etch7" test_ref="oval:org.mitre.oval:tst:13458"/>
                <criterion comment="openoffice.org-l10n-ca is earlier than 2.0.4.dfsg.2-7etch7" test_ref="oval:org.mitre.oval:tst:13080"/>
                <criterion comment="openoffice.org-help-en-us is earlier than 2.0.4.dfsg.2-7etch7" test_ref="oval:org.mitre.oval:tst:13590"/>
                <criterion comment="ttf-opensymbol is earlier than 2.0.4.dfsg.2-7etch7" test_ref="oval:org.mitre.oval:tst:13713"/>
                <criterion comment="openoffice.org-l10n-ka is earlier than 2.0.4.dfsg.2-7etch7" test_ref="oval:org.mitre.oval:tst:13266"/>
                <criterion comment="openoffice.org-l10n-km is earlier than 2.0.4.dfsg.2-7etch7" test_ref="oval:org.mitre.oval:tst:13557"/>
                <criterion comment="openoffice.org-l10n-ko is earlier than 2.0.4.dfsg.2-7etch7" test_ref="oval:org.mitre.oval:tst:13244"/>
                <criterion comment="openoffice.org-l10n-pl is earlier than 2.0.4.dfsg.2-7etch7" test_ref="oval:org.mitre.oval:tst:12848"/>
                <criterion comment="broffice.org is earlier than 2.0.4.dfsg.2-7etch7" test_ref="oval:org.mitre.oval:tst:13627"/>
                <criterion comment="openoffice.org-l10n-ku is earlier than 2.0.4.dfsg.2-7etch7" test_ref="oval:org.mitre.oval:tst:13721"/>
                <criterion comment="openoffice.org-l10n-pt is earlier than 2.0.4.dfsg.2-7etch7" test_ref="oval:org.mitre.oval:tst:13559"/>
                <criterion comment="openoffice.org-l10n-xh is earlier than 2.0.4.dfsg.2-7etch7" test_ref="oval:org.mitre.oval:tst:13654"/>
                <criterion comment="openoffice.org-help-it is earlier than 2.0.4.dfsg.2-7etch7" test_ref="oval:org.mitre.oval:tst:13381"/>
                <criterion comment="openoffice.org-help-pl is earlier than 2.0.4.dfsg.2-7etch7" test_ref="oval:org.mitre.oval:tst:13342"/>
                <criterion comment="openoffice.org-l10n-be-by is earlier than 2.0.4.dfsg.2-7etch7" test_ref="oval:org.mitre.oval:tst:13177"/>
                <criterion comment="openoffice.org-l10n-hr is earlier than 2.0.4.dfsg.2-7etch7" test_ref="oval:org.mitre.oval:tst:13096"/>
                <criterion comment="openoffice.org-l10n-hu is earlier than 2.0.4.dfsg.2-7etch7" test_ref="oval:org.mitre.oval:tst:13471"/>
                <criterion comment="openoffice.org-l10n-mk is earlier than 2.0.4.dfsg.2-7etch7" test_ref="oval:org.mitre.oval:tst:13117"/>
                <criterion comment="openoffice.org-l10n-hi is earlier than 2.0.4.dfsg.2-7etch7" test_ref="oval:org.mitre.oval:tst:12755"/>
                <criterion comment="openoffice.org-l10n-sr-cs is earlier than 2.0.4.dfsg.2-7etch7" test_ref="oval:org.mitre.oval:tst:13174"/>
                <criterion comment="openoffice.org-l10n-he is earlier than 2.0.4.dfsg.2-7etch7" test_ref="oval:org.mitre.oval:tst:13171"/>
                <criterion comment="openoffice.org-l10n-en-za is earlier than 2.0.4.dfsg.2-7etch7" test_ref="oval:org.mitre.oval:tst:13734"/>
                <criterion comment="openoffice.org-l10n-as-in is earlier than 2.0.4.dfsg.2-7etch7" test_ref="oval:org.mitre.oval:tst:13668"/>
                <criterion comment="openoffice.org-l10n-ta-in is earlier than 2.0.4.dfsg.2-7etch7" test_ref="oval:org.mitre.oval:tst:13658"/>
                <criterion comment="openoffice.org-l10n-te-in is earlier than 2.0.4.dfsg.2-7etch7" test_ref="oval:org.mitre.oval:tst:13423"/>
                <criterion comment="openoffice.org-help-nl is earlier than 2.0.4.dfsg.2-7etch7" test_ref="oval:org.mitre.oval:tst:13511"/>
                <criterion comment="openoffice.org-l10n-eo is earlier than 2.0.4.dfsg.2-7etch7" test_ref="oval:org.mitre.oval:tst:13578"/>
                <criterion comment="openoffice.org-l10n-el is earlier than 2.0.4.dfsg.2-7etch7" test_ref="oval:org.mitre.oval:tst:13219"/>
                <criterion comment="openoffice.org-l10n-zu is earlier than 2.0.4.dfsg.2-7etch7" test_ref="oval:org.mitre.oval:tst:13703"/>
                <criterion comment="openoffice.org-l10n-hi-in is earlier than 2.0.4.dfsg.2-7etch7" test_ref="oval:org.mitre.oval:tst:13610"/>
                <criterion comment="openoffice.org-l10n-zh-tw is earlier than 2.0.4.dfsg.2-7etch7" test_ref="oval:org.mitre.oval:tst:13636"/>
                <criterion comment="openoffice.org-l10n-za is earlier than 2.0.4.dfsg.2-7etch7" test_ref="oval:org.mitre.oval:tst:13510"/>
                <criterion comment="openoffice.org-l10n-et is earlier than 2.0.4.dfsg.2-7etch7" test_ref="oval:org.mitre.oval:tst:13681"/>
                <criterion comment="openoffice.org-help-fr is earlier than 2.0.4.dfsg.2-7etch7" test_ref="oval:org.mitre.oval:tst:13735"/>
                <criterion comment="openoffice.org-l10n-rw is earlier than 2.0.4.dfsg.2-7etch7" test_ref="oval:org.mitre.oval:tst:13531"/>
                <criterion comment="openoffice.org-l10n-es is earlier than 2.0.4.dfsg.2-7etch7" test_ref="oval:org.mitre.oval:tst:13426"/>
                <criterion comment="openoffice.org-l10n-ru is earlier than 2.0.4.dfsg.2-7etch7" test_ref="oval:org.mitre.oval:tst:13685"/>
                <criterion comment="openoffice.org-l10n-bs is earlier than 2.0.4.dfsg.2-7etch7" test_ref="oval:org.mitre.oval:tst:13313"/>
                <criterion comment="openoffice.org-l10n-br is earlier than 2.0.4.dfsg.2-7etch7" test_ref="oval:org.mitre.oval:tst:12915"/>
                <criterion comment="openoffice.org-l10n-bn is earlier than 2.0.4.dfsg.2-7etch7" test_ref="oval:org.mitre.oval:tst:12781"/>
                <criterion comment="openoffice.org-l10n-bg is earlier than 2.0.4.dfsg.2-7etch7" test_ref="oval:org.mitre.oval:tst:13379"/>
                <criterion comment="openoffice.org-l10n-sl is earlier than 2.0.4.dfsg.2-7etch7" test_ref="oval:org.mitre.oval:tst:12767"/>
                <criterion comment="openoffice.org-l10n-ja is earlier than 2.0.4.dfsg.2-7etch7" test_ref="oval:org.mitre.oval:tst:13258"/>
                <criterion comment="openoffice.org-l10n-en-gb is earlier than 2.0.4.dfsg.2-7etch7" test_ref="oval:org.mitre.oval:tst:13028"/>
                <criterion comment="openoffice.org-l10n-sk is earlier than 2.0.4.dfsg.2-7etch7" test_ref="oval:org.mitre.oval:tst:13602"/>
                <criterion comment="openoffice.org-l10n-st is earlier than 2.0.4.dfsg.2-7etch7" test_ref="oval:org.mitre.oval:tst:13306"/>
                <criterion comment="openoffice.org-l10n-sv is earlier than 2.0.4.dfsg.2-7etch7" test_ref="oval:org.mitre.oval:tst:13574"/>
                <criterion comment="openoffice.org-l10n-ss is earlier than 2.0.4.dfsg.2-7etch7" test_ref="oval:org.mitre.oval:tst:13339"/>
                <criterion comment="openoffice.org-help-sv is earlier than 2.0.4.dfsg.2-7etch7" test_ref="oval:org.mitre.oval:tst:13439"/>
                <criterion comment="openoffice.org-help-dz is earlier than 2.0.4.dfsg.2-7etch7" test_ref="oval:org.mitre.oval:tst:13503"/>
                <criterion comment="openoffice.org-help-da is earlier than 2.0.4.dfsg.2-7etch7" test_ref="oval:org.mitre.oval:tst:13331"/>
                <criterion comment="openoffice.org-help-de is earlier than 2.0.4.dfsg.2-7etch7" test_ref="oval:org.mitre.oval:tst:13507"/>
                <criterion comment="openoffice.org-help-sl is earlier than 2.0.4.dfsg.2-7etch7" test_ref="oval:org.mitre.oval:tst:13152"/>
                <criterion comment="openoffice.org-java-common is earlier than 2.0.4.dfsg.2-7etch7" test_ref="oval:org.mitre.oval:tst:13694"/>
                <criterion comment="openoffice.org-l10n-ga is earlier than 2.0.4.dfsg.2-7etch7" test_ref="oval:org.mitre.oval:tst:13761"/>
                <criterion comment="openoffice.org-l10n-ts is earlier than 2.0.4.dfsg.2-7etch7" test_ref="oval:org.mitre.oval:tst:13260"/>
                <criterion comment="openoffice.org-l10n-tr is earlier than 2.0.4.dfsg.2-7etch7" test_ref="oval:org.mitre.oval:tst:13585"/>
                <criterion comment="openoffice.org-l10n-tn is earlier than 2.0.4.dfsg.2-7etch7" test_ref="oval:org.mitre.oval:tst:13518"/>
                <criterion comment="openoffice.org-l10n-th is earlier than 2.0.4.dfsg.2-7etch7" test_ref="oval:org.mitre.oval:tst:13400"/>
                <criterion comment="openoffice.org-l10n-tg is earlier than 2.0.4.dfsg.2-7etch7" test_ref="oval:org.mitre.oval:tst:13605"/>
                <criterion comment="openoffice.org-help-et is earlier than 2.0.4.dfsg.2-7etch7" test_ref="oval:org.mitre.oval:tst:13579"/>
                <criterion comment="openoffice.org-help-es is earlier than 2.0.4.dfsg.2-7etch7" test_ref="oval:org.mitre.oval:tst:13718"/>
                <criterion comment="openoffice.org-filter-mobiledev is earlier than 2.0.4.dfsg.2-7etch7" test_ref="oval:org.mitre.oval:tst:13482"/>
                <criterion comment="openoffice.org-l10n-or-in is earlier than 2.0.4.dfsg.2-7etch7" test_ref="oval:org.mitre.oval:tst:13608"/>
                <criterion comment="openoffice.org-help-en is earlier than 2.0.4.dfsg.2-7etch7" test_ref="oval:org.mitre.oval:tst:13161"/>
                <criterion comment="openoffice.org-l10n-lt is earlier than 2.0.4.dfsg.2-7etch7" test_ref="oval:org.mitre.oval:tst:13512"/>
                <criterion comment="openoffice.org-l10n-lv is earlier than 2.0.4.dfsg.2-7etch7" test_ref="oval:org.mitre.oval:tst:12914"/>
                <criterion comment="openoffice.org-l10n-de is earlier than 2.0.4.dfsg.2-7etch7" test_ref="oval:org.mitre.oval:tst:13273"/>
                <criterion comment="openoffice.org-l10n-da is earlier than 2.0.4.dfsg.2-7etch7" test_ref="oval:org.mitre.oval:tst:13707"/>
                <criterion comment="openoffice.org-l10n-uk is earlier than 2.0.4.dfsg.2-7etch7" test_ref="oval:org.mitre.oval:tst:13389"/>
                <criterion comment="openoffice.org-l10n-dz is earlier than 2.0.4.dfsg.2-7etch7" test_ref="oval:org.mitre.oval:tst:13611"/>
                <criterion comment="openoffice.org-l10n-lo is earlier than 2.0.4.dfsg.2-7etch7" test_ref="oval:org.mitre.oval:tst:13637"/>
                <criterion comment="openoffice.org-l10n-ml-in is earlier than 2.0.4.dfsg.2-7etch7" test_ref="oval:org.mitre.oval:tst:13506"/>
                <criterion comment="openoffice.org-help-en-gb is earlier than 2.0.4.dfsg.2-7etch7" test_ref="oval:org.mitre.oval:tst:13422"/>
                <criterion comment="openoffice.org-l10n-af is earlier than 2.0.4.dfsg.2-7etch7" test_ref="oval:org.mitre.oval:tst:13652"/>
                <criterion comment="openoffice.org-common is earlier than 2.0.4.dfsg.2-7etch7" test_ref="oval:org.mitre.oval:tst:13220"/>
                <criterion comment="openoffice.org-help-ja is earlier than 2.0.4.dfsg.2-7etch7" test_ref="oval:org.mitre.oval:tst:12819"/>
                <criterion comment="openoffice.org-l10n-zh-cn is earlier than 2.0.4.dfsg.2-7etch7" test_ref="oval:org.mitre.oval:tst:13745"/>
                <criterion comment="openoffice.org-l10n-ve is earlier than 2.0.4.dfsg.2-7etch7" test_ref="oval:org.mitre.oval:tst:13528"/>
                <criterion comment="openoffice.org-help-zh-cn is earlier than 2.0.4.dfsg.2-7etch7" test_ref="oval:org.mitre.oval:tst:13354"/>
                <criterion comment="openoffice.org-l10n-it is earlier than 2.0.4.dfsg.2-7etch7" test_ref="oval:org.mitre.oval:tst:13762"/>
                <criterion comment="openoffice.org-l10n-gu-in is earlier than 2.0.4.dfsg.2-7etch7" test_ref="oval:org.mitre.oval:tst:13731"/>
                <criterion comment="openoffice.org-l10n-in is earlier than 2.0.4.dfsg.2-7etch7" test_ref="oval:org.mitre.oval:tst:13628"/>
                <criterion comment="openoffice.org-help-zh-tw is earlier than 2.0.4.dfsg.2-7etch7" test_ref="oval:org.mitre.oval:tst:12989"/>
                <criterion comment="openoffice.org-help-ru is earlier than 2.0.4.dfsg.2-7etch7" test_ref="oval:org.mitre.oval:tst:13639"/>
                <criterion comment="openoffice.org-l10n-fr is earlier than 2.0.4.dfsg.2-7etch7" test_ref="oval:org.mitre.oval:tst:13684"/>
                <criterion comment="openoffice.org-l10n-pt-br is earlier than 2.0.4.dfsg.2-7etch7" test_ref="oval:org.mitre.oval:tst:13673"/>
                <criterion comment="openoffice.org-help-pt-br is earlier than 2.0.4.dfsg.2-7etch7" test_ref="oval:org.mitre.oval:tst:13680"/>
                <criterion comment="openoffice.org-help-ko is earlier than 2.0.4.dfsg.2-7etch7" test_ref="oval:org.mitre.oval:tst:13384"/>
                <criterion comment="openoffice.org-help-km is earlier than 2.0.4.dfsg.2-7etch7" test_ref="oval:org.mitre.oval:tst:13432"/>
                <criterion comment="openoffice.org-l10n-fa is earlier than 2.0.4.dfsg.2-7etch7" test_ref="oval:org.mitre.oval:tst:13819"/>
                <criterion comment="openoffice.org-l10n-fi is earlier than 2.0.4.dfsg.2-7etch7" test_ref="oval:org.mitre.oval:tst:13763"/>
                <criterion comment="openoffice.org-qa-api-tests is earlier than 2.0.4.dfsg.2-7etch7" test_ref="oval:org.mitre.oval:tst:13785"/>
                <criterion comment="openoffice.org-help-hi-in is earlier than 2.0.4.dfsg.2-7etch7" test_ref="oval:org.mitre.oval:tst:13786"/>
                <criterion comment="openoffice.org-l10n-ns is earlier than 2.0.4.dfsg.2-7etch7" test_ref="oval:org.mitre.oval:tst:13695"/>
                <criterion comment="openoffice.org-l10n-nr is earlier than 2.0.4.dfsg.2-7etch7" test_ref="oval:org.mitre.oval:tst:13744"/>
                <criterion comment="openoffice.org-dev-doc is earlier than 2.0.4.dfsg.2-7etch7" test_ref="oval:org.mitre.oval:tst:13742"/>
                <criterion comment="openoffice.org-l10n-nn is earlier than 2.0.4.dfsg.2-7etch7" test_ref="oval:org.mitre.oval:tst:13722"/>
                <criterion comment="openoffice.org-l10n-nl is earlier than 2.0.4.dfsg.2-7etch7" test_ref="oval:org.mitre.oval:tst:13748"/>
                <criterion comment="openoffice.org-help-cs is earlier than 2.0.4.dfsg.2-7etch7" test_ref="oval:org.mitre.oval:tst:13582"/>
                <criterion comment="openoffice.org-l10n-ne is earlier than 2.0.4.dfsg.2-7etch7" test_ref="oval:org.mitre.oval:tst:13081"/>
                <criterion comment="openoffice.org-l10n-pa-in is earlier than 2.0.4.dfsg.2-7etch7" test_ref="oval:org.mitre.oval:tst:13460"/>
                <criterion comment="openoffice.org-l10n-nb is earlier than 2.0.4.dfsg.2-7etch7" test_ref="oval:org.mitre.oval:tst:13505"/>
              </criteria>
            </criteria>
            <criteria comment="Architecture dependent section" operator="AND">
              <criteria comment="Supported architectures section" operator="OR">
                <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
                <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
                <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
                <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
                <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
                <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
                <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
              </criteria>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="libmythes-dev DPKG is earlier than 2.0.4.dfsg.2-7etch7" test_ref="oval:org.mitre.oval:tst:13465"/>
              </criteria>
            </criteria>
            <criteria comment="Architecture dependent section" operator="AND">
              <criteria comment="Supported architectures section" operator="OR">
                <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
                <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
                <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
              </criteria>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="openoffice.org-filter-so52 DPKG is earlier than 2.0.4.dfsg.2-7etch7" test_ref="oval:org.mitre.oval:tst:13551"/>
                <criterion comment="openoffice.org-impress DPKG is earlier than 2.0.4.dfsg.2-7etch7" test_ref="oval:org.mitre.oval:tst:12875"/>
                <criterion comment="openoffice.org-evolution DPKG is earlier than 2.0.4.dfsg.2-7etch7" test_ref="oval:org.mitre.oval:tst:12858"/>
                <criterion comment="openoffice.org-base DPKG is earlier than 2.0.4.dfsg.2-7etch7" test_ref="oval:org.mitre.oval:tst:13467"/>
                <criterion comment="openoffice.org DPKG is earlier than 2.0.4.dfsg.2-7etch7" test_ref="oval:org.mitre.oval:tst:13619"/>
                <criterion comment="openoffice.org-math DPKG is earlier than 2.0.4.dfsg.2-7etch7" test_ref="oval:org.mitre.oval:tst:13500"/>
                <criterion comment="openoffice.org-calc DPKG is earlier than 2.0.4.dfsg.2-7etch7" test_ref="oval:org.mitre.oval:tst:13730"/>
                <criterion comment="openoffice.org-qa-tools DPKG is earlier than 2.0.4.dfsg.2-7etch7" test_ref="oval:org.mitre.oval:tst:13575"/>
                <criterion comment="openoffice.org-dbg DPKG is earlier than 2.0.4.dfsg.2-7etch7" test_ref="oval:org.mitre.oval:tst:13567"/>
                <criterion comment="openoffice.org-gtk DPKG is earlier than 2.0.4.dfsg.2-7etch7" test_ref="oval:org.mitre.oval:tst:13813"/>
                <criterion comment="openoffice.org-officebean DPKG is earlier than 2.0.4.dfsg.2-7etch7" test_ref="oval:org.mitre.oval:tst:13683"/>
                <criterion comment="python-uno DPKG is earlier than 2.0.4.dfsg.2-7etch7" test_ref="oval:org.mitre.oval:tst:13716"/>
                <criterion comment="openoffice.org-gtk-gnome DPKG is earlier than 2.0.4.dfsg.2-7etch7" test_ref="oval:org.mitre.oval:tst:13727"/>
                <criterion comment="openoffice.org-writer DPKG is earlier than 2.0.4.dfsg.2-7etch7" test_ref="oval:org.mitre.oval:tst:12878"/>
                <criterion comment="openoffice.org-dev DPKG is earlier than 2.0.4.dfsg.2-7etch7" test_ref="oval:org.mitre.oval:tst:13851"/>
                <criterion comment="openoffice.org-gcj DPKG is earlier than 2.0.4.dfsg.2-7etch7" test_ref="oval:org.mitre.oval:tst:13741"/>
                <criterion comment="openoffice.org-kde DPKG is earlier than 2.0.4.dfsg.2-7etch7" test_ref="oval:org.mitre.oval:tst:13746"/>
                <criterion comment="openoffice.org-draw DPKG is earlier than 2.0.4.dfsg.2-7etch7" test_ref="oval:org.mitre.oval:tst:13552"/>
                <criterion comment="openoffice.org-gnome DPKG is earlier than 2.0.4.dfsg.2-7etch7" test_ref="oval:org.mitre.oval:tst:13782"/>
                <criterion comment="openoffice.org-core DPKG is earlier than 2.0.4.dfsg.2-7etch7" test_ref="oval:org.mitre.oval:tst:13809"/>
              </criteria>
            </criteria>
            <criteria comment="Architecture depended section" operator="AND">
              <criteria comment="Supported platform section" operator="AND">
                <criterion comment="arm architecture" test_ref="oval:org.mitre.oval:tst:10933"/>
                <criteria comment="Packages section" operator="OR">
                  <criterion comment="libmythes-dev DPKG is earlier than 2.0.4.dfsg.2-7etch6" test_ref="oval:org.mitre.oval:tst:13401"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:8005" class="patch">
      <metadata>
        <title>DSA-1760 openswan -- denial of service</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <platform>Debian GNU/Linux 4.0</platform>
          <product>openswan</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2009/dsa-1760" ref_id="DSA-1760"/>
        <description>Two vulnerabilities have been discovered in openswan, an IPSec implementation for linux. The Common Vulnerabilities and Exposures project identifies the following problems: Dmitry E. Oboukhov discovered that the livetest tool is using temporary files insecurely, which could lead to a denial of service attack. Gerd v. Egidy discovered that the Pluto IKE daemon in openswan is prone to a denial of service attack via a malicious packet.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:07-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T07:54:54.624-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:03:23.389-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:02:30.624-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Platform section" operator="OR">
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Architecture independent section" operator="AND">
              <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="linux-patch-openswan is earlier than 2.4.12+dfsg-1.3+lenny1" test_ref="oval:org.mitre.oval:tst:15844"/>
                <criterion comment="openswan-modules-source is earlier than 2.4.12+dfsg-1.3+lenny1" test_ref="oval:org.mitre.oval:tst:16771"/>
              </criteria>
            </criteria>
            <criteria comment="Architecture dependent section" operator="AND">
              <criteria comment="Supported architectures section" operator="OR">
                <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
                <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
                <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
                <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
                <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
                <criterion comment="Installed architecture is armel" test_ref="oval:org.mitre.oval:tst:11101"/>
                <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
                <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
                <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
                <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
                <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
                <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
              </criteria>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="openswan DPKG is earlier than 2.4.12+dfsg-1.3+lenny1" test_ref="oval:org.mitre.oval:tst:16530"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 4.0 is installed" definition_ref="oval:org.mitre.oval:def:6461"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Architecture independent section" operator="AND">
              <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="linux-patch-openswan is earlier than 2.4.6+dfsg.2-1.1+etch1" test_ref="oval:org.mitre.oval:tst:16797"/>
                <criterion comment="openswan-modules-source is earlier than 2.4.6+dfsg.2-1.1+etch1" test_ref="oval:org.mitre.oval:tst:16059"/>
              </criteria>
            </criteria>
            <criteria comment="Packages section" operator="OR">
              <criterion comment="openswan DPKG is earlier than 2.4.6+dfsg.2-1.1+etch1" test_ref="oval:org.mitre.oval:tst:16292"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:7997" class="patch">
      <metadata>
        <title>DSA-1814 libsndfile -- heap-based buffer overflow</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <platform>Debian GNU/Linux 4.0</platform>
          <product>libsndfile</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2009/dsa-1814" ref_id="DSA-1814"/>
        <description>Two vulnerabilities have been found in libsndfile, a library to read and write sampled audio data. The Common Vulnerabilities and Exposures project identified the following problems: Tobias Klein discovered that the VOC parsing routines suffer of a heap-based buffer overflow which can be triggered by an attacker via a crafted VOC header. The vendor discovered that the AIFF parsing routines suffer of a heap-based buffer overflow similar to CVE-2009-1788 which can be triggered by an attacker via a crafted AIFF header. In both cases the overflowing data is not completely attacker controlled but still leads to application crashes or under some circumstances might still lead to arbitrary code execution.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:09-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T07:57:31.130-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:03:19.591-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:02:27.383-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Platform section" operator="OR">
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Architecture dependent section" operator="AND">
              <criteria comment="Supported architectures section" operator="OR">
                <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
                <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
                <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
                <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
                <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
                <criterion comment="Installed architecture is armel" test_ref="oval:org.mitre.oval:tst:11101"/>
                <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
                <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
                <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
                <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
                <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
                <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
              </criteria>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="libsndfile1 DPKG is earlier than 1.0.17-4+lenny2" test_ref="oval:org.mitre.oval:tst:18254"/>
                <criterion comment="libsndfile1-dev DPKG is earlier than 1.0.17-4+lenny2" test_ref="oval:org.mitre.oval:tst:17563"/>
                <criterion comment="sndfile-programs DPKG is earlier than 1.0.17-4+lenny2" test_ref="oval:org.mitre.oval:tst:18300"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 4.0 is installed" definition_ref="oval:org.mitre.oval:def:6461"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Architecture dependent section" operator="AND">
              <criteria comment="Supported architectures section" operator="OR">
                <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
                <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
                <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
                <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
                <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
                <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
                <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
                <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
                <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
                <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
              </criteria>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="libsndfile1 DPKG is earlier than 1.0.16-2+etch2" test_ref="oval:org.mitre.oval:tst:18398"/>
                <criterion comment="libsndfile1-dev DPKG is earlier than 1.0.16-2+etch2" test_ref="oval:org.mitre.oval:tst:18169"/>
                <criterion comment="sndfile-programs DPKG is earlier than 1.0.16-2+etch2" test_ref="oval:org.mitre.oval:tst:18031"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:7994" class="patch">
      <metadata>
        <title>DSA-1896 opensaml, shibboleth-sp -- several vulnerabilities</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <platform>Debian GNU/Linux 4.0</platform>
          <product>opensaml</product>
          <product>shibboleth-sp</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2009/dsa-1896" ref_id="DSA-1896"/>
        <description>Several vulnerabilities have been discovered in the opensaml and shibboleth-sp packages, as used by Shibboleth 1.x: Chris Ries discovered that decoding a crafted URL leads to a crash (and potentially, arbitrary code execution). Ian Young discovered that embedded NUL characters in certificate names were not correctly handled, exposing configurations using PKIX trust validation to impersonation attacks. Incorrect processing of SAML metadata ignored key usage constraints.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:12-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T08:00:07.543-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:03:18.297-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:02:26.519-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Platform section" operator="OR">
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Architecture independent section" operator="AND">
              <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criterion comment="opensaml-schemas is earlier than 1.1.1-2+lenny1" test_ref="oval:org.mitre.oval:tst:20072"/>
            </criteria>
            <criteria comment="Architecture dependent section" operator="AND">
              <criteria comment="Supported architectures section" operator="OR">
                <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
                <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
                <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
                <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
                <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
                <criterion comment="Installed architecture is armel" test_ref="oval:org.mitre.oval:tst:11101"/>
                <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
                <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
                <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
                <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
                <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
                <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
              </criteria>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="libshib6 DPKG is earlier than 1.3.1.dfsg1-3+lenny1" test_ref="oval:org.mitre.oval:tst:20025"/>
                <criterion comment="libshib-dev DPKG is earlier than 1.3.1.dfsg1-3+lenny1" test_ref="oval:org.mitre.oval:tst:19671"/>
                <criterion comment="libsaml5 DPKG is earlier than 1.1.1-2+lenny1" test_ref="oval:org.mitre.oval:tst:19938"/>
                <criterion comment="libapache2-mod-shib DPKG is earlier than 1.3.1.dfsg1-3+lenny1" test_ref="oval:org.mitre.oval:tst:19951"/>
                <criterion comment="libsaml-dev DPKG is earlier than 1.1.1-2+lenny1" test_ref="oval:org.mitre.oval:tst:20159"/>
                <criterion comment="libshib-target5 DPKG is earlier than 1.3.1.dfsg1-3+lenny1" test_ref="oval:org.mitre.oval:tst:19868"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 4.0 is installed" definition_ref="oval:org.mitre.oval:def:6461"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Architecture independent section" operator="AND">
              <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criterion comment="opensaml-schemas is earlier than 1.1a-2+etch1" test_ref="oval:org.mitre.oval:tst:19548"/>
            </criteria>
            <criteria comment="Packages section" operator="OR">
              <criterion comment="libshib6 DPKG is earlier than 1.3f.dfsg1-2+etch1" test_ref="oval:org.mitre.oval:tst:20111"/>
              <criterion comment="libshib-dev DPKG is earlier than 1.3f.dfsg1-2+etch1" test_ref="oval:org.mitre.oval:tst:19997"/>
              <criterion comment="libsaml5 DPKG is earlier than 1.1a-2+etch1" test_ref="oval:org.mitre.oval:tst:19992"/>
              <criterion comment="libapache2-mod-shib DPKG is earlier than 1.3f.dfsg1-2+etch1" test_ref="oval:org.mitre.oval:tst:19952"/>
              <criterion comment="libsaml-dev DPKG is earlier than 1.1a-2+etch1" test_ref="oval:org.mitre.oval:tst:19812"/>
              <criterion comment="libshib-target5 DPKG is earlier than 1.3f.dfsg1-2+etch1" test_ref="oval:org.mitre.oval:tst:20120"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:7990" class="patch">
      <metadata>
        <title>DSA-1751 xulrunner -- several vulnerabilities</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <product>xulrunner</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2009/dsa-1751" ref_id="DSA-1751"/>
        <description>Several remote vulnerabilities have been discovered in Xulrunner, a runtime environment for XUL applications, such as the Iceweasel web browser. The Common Vulnerabilities and Exposures project identifies the following problems: Martijn Wargers, Jesse Ruderman and Josh Soref discovered crashes in the layout engine, which might allow the execution of arbitrary code. Jesse Ruderman discovered crashes in the layout engine, which might allow the execution of arbitrary code. Gary Kwong, and Timothee Groleau discovered crashes in the Javascript engine, which might allow the execution of arbitrary code. Gary Kwong discovered crashes in the Javascript engine, which might allow the execution of arbitrary code. It was discovered that incorrect memory management in the DOM element handling may lead to the execution of arbitrary code. Georgi Guninski discovered a violation of the same-origin policy through RDFXMLDataSource and cross-domain redirects. As indicated in the Etch release notes, security support for the Mozilla products in the oldstable distribution needed to be stopped before the end of the regular Etch security maintenance life cycle. You are strongly encouraged to upgrade to stable or switch to a still supported browser.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:05-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T07:52:55.693-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:03:15.801-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:02:24.637-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Release section" operator="AND">
        <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
        <criteria comment="Architecture section" operator="OR">
          <criteria comment="Architecture independent section" operator="AND">
            <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
            <criterion comment="libmozillainterfaces-java is earlier than 1.9.0.7-0lenny1" test_ref="oval:org.mitre.oval:tst:14390"/>
          </criteria>
          <criteria comment="Architecture dependent section" operator="AND">
            <criteria comment="Supported architectures section" operator="OR">
              <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
              <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
              <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
              <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
              <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
              <criterion comment="Installed architecture is armel" test_ref="oval:org.mitre.oval:tst:11101"/>
              <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
              <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
              <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
              <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
              <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
              <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
            </criteria>
            <criteria comment="Packages section" operator="OR">
              <criterion comment="libmozjs-dev DPKG is earlier than 1.9.0.7-0lenny1" test_ref="oval:org.mitre.oval:tst:14605"/>
              <criterion comment="spidermonkey-bin DPKG is earlier than 1.9.0.7-0lenny1" test_ref="oval:org.mitre.oval:tst:13967"/>
              <criterion comment="xulrunner-1.9-gnome-support DPKG is earlier than 1.9.0.7-0lenny1" test_ref="oval:org.mitre.oval:tst:14801"/>
              <criterion comment="xulrunner-1.9 DPKG is earlier than 1.9.0.7-0lenny1" test_ref="oval:org.mitre.oval:tst:14812"/>
              <criterion comment="libmozjs1d-dbg DPKG is earlier than 1.9.0.7-0lenny1" test_ref="oval:org.mitre.oval:tst:14647"/>
              <criterion comment="libmozjs1d DPKG is earlier than 1.9.0.7-0lenny1" test_ref="oval:org.mitre.oval:tst:14863"/>
              <criterion comment="python-xpcom DPKG is earlier than 1.9.0.7-0lenny1" test_ref="oval:org.mitre.oval:tst:14403"/>
              <criterion comment="xulrunner-1.9-dbg DPKG is earlier than 1.9.0.7-0lenny1" test_ref="oval:org.mitre.oval:tst:14765"/>
              <criterion comment="xulrunner-dev DPKG is earlier than 1.9.0.7-0lenny1" test_ref="oval:org.mitre.oval:tst:14607"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:7974" class="patch">
      <metadata>
        <title>DSA-1879 silc-client/silc-toolkit -- several vulnerabilities</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <product>silc-client/silc-toolkit</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2009/dsa-1879" ref_id="DSA-1879"/>
        <description>Several vulnerabilities have been discovered in the software suite for the SILC protocol, a network protocol designed to provide end-to-end security for conferencing services. The Common Vulnerabilities and Exposures project identifies the following problems: An incorrect format string in sscanf() used in the ASN1 encoder to scan an OID value could overwrite a neighbouring variable on the stack as the destination data type is smaller than the source type on 64-bit. On 64-bit architectures this could result in unexpected application behaviour or even code execution in some cases. Various format string vulnerabilities when handling parsed SILC messages allow an attacker to execute arbitrary code with the rights of the victim running the SILC client via crafted nick names or channel names containing format strings. CVE-2008-7160 An incorrect format string in a sscanf() call used in the HTTP server component of silcd could result in overwriting a neighbouring variable on the stack as the destination data type is smaller than the source type on 64-bit. An attacker could exploit this by using crafted Content-Length header values resulting in unexpected application behaviour or even code execution in some cases. silc-server doesn't need an update as it uses the shared library provided by silc-toolkit. silc-client/silc-toolkit in the oldstable distribution (etch) is not affected by this problem.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:06-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T07:53:51.719-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:03:09.686-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:02:20.390-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Release section" operator="AND">
        <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
        <criteria comment="Architecture section" operator="OR">
          <criteria comment="Architecture dependent section" operator="AND">
            <criteria comment="Supported architectures section" operator="OR">
              <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
              <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
              <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
              <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
              <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
              <criterion comment="Installed architecture is armel" test_ref="oval:org.mitre.oval:tst:11101"/>
              <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
              <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
              <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
              <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
              <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
            </criteria>
            <criteria comment="Packages section" operator="OR">
              <criterion comment="silc DPKG is earlier than 1.1.4-1+lenny1" test_ref="oval:org.mitre.oval:tst:15443"/>
              <criterion comment="libsilc-1.1-2 DPKG is earlier than 1.1.7-2+lenny1" test_ref="oval:org.mitre.oval:tst:15699"/>
              <criterion comment="libsilc-1.1-2-dbg DPKG is earlier than 1.1.7-2+lenny1" test_ref="oval:org.mitre.oval:tst:15436"/>
              <criterion comment="libsilc-1.1-2-dev DPKG is earlier than 1.1.7-2+lenny1" test_ref="oval:org.mitre.oval:tst:15053"/>
              <criterion comment="irssi-plugin-silc DPKG is earlier than 1.1.4-1+lenny1" test_ref="oval:org.mitre.oval:tst:14772"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:7970" class="patch">
      <metadata>
        <title>DSA-1862 linux-2.6 -- privilege escalation</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <product>linux-2.6</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2009/dsa-1862" ref_id="DSA-1862"/>
        <description>A vulnerability has been discovered in the Linux kernel that may lead to privilege escalation. The Common Vulnerabilities and Exposures project identifies the following problem: Tavis Ormandy and Julien Tinnes discovered an issue with how the sendpage function is initialized in the proto_ops structure. Local users can exploit this vulnerability to gain elevated privileges.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:08-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T07:56:58.276-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:03:08.145-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:02:18.611-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Release section" operator="AND">
        <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
        <criteria comment="Architecture section" operator="OR">
          <criteria comment="Architecture independent section" operator="AND">
            <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
            <criteria comment="Packages section" operator="OR">
              <criterion comment="linux-patch-debian-2.6.26 is earlier than 2.6.26-17lenny2" test_ref="oval:org.mitre.oval:tst:18000"/>
              <criterion comment="linux-support-2.6.26-2 is earlier than 2.6.26-17lenny2" test_ref="oval:org.mitre.oval:tst:17113"/>
              <criterion comment="linux-doc-2.6.26 is earlier than 2.6.26-17lenny2" test_ref="oval:org.mitre.oval:tst:17773"/>
              <criterion comment="linux-tree-2.6.26 is earlier than 2.6.26-17lenny2" test_ref="oval:org.mitre.oval:tst:17691"/>
              <criterion comment="linux-source-2.6.26 is earlier than 2.6.26-17lenny2" test_ref="oval:org.mitre.oval:tst:17517"/>
              <criterion comment="linux-manual-2.6.26 is earlier than 2.6.26-17lenny2" test_ref="oval:org.mitre.oval:tst:17968"/>
            </criteria>
          </criteria>
          <criteria comment="Architecture dependent section" operator="AND">
            <criteria comment="Supported architectures section" operator="OR">
              <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
            </criteria>
            <criteria comment="Packages section" operator="OR">
              <criterion comment="linux-headers-2.6.26-2-all DPKG is earlier than 2.6.26-17lenny2" test_ref="oval:org.mitre.oval:tst:18037"/>
              <criterion comment="linux-image-2.6.26-2-vserver-s390x DPKG is earlier than 2.6.26-17lenny2" test_ref="oval:org.mitre.oval:tst:17639"/>
              <criterion comment="linux-image-2.6.26-2-s390 DPKG is earlier than 2.6.26-17lenny2" test_ref="oval:org.mitre.oval:tst:17672"/>
              <criterion comment="linux-headers-2.6.26-2-s390 DPKG is earlier than 2.6.26-17lenny2" test_ref="oval:org.mitre.oval:tst:17992"/>
              <criterion comment="linux-image-2.6.26-2-s390-tape DPKG is earlier than 2.6.26-17lenny2" test_ref="oval:org.mitre.oval:tst:17405"/>
              <criterion comment="linux-headers-2.6.26-2-all-s390 DPKG is earlier than 2.6.26-17lenny2" test_ref="oval:org.mitre.oval:tst:17948"/>
              <criterion comment="linux-headers-2.6.26-2-vserver-s390x DPKG is earlier than 2.6.26-17lenny2" test_ref="oval:org.mitre.oval:tst:17724"/>
              <criterion comment="linux-headers-2.6.26-2-common-vserver DPKG is earlier than 2.6.26-17lenny2" test_ref="oval:org.mitre.oval:tst:17658"/>
              <criterion comment="linux-libc-dev DPKG is earlier than 2.6.26-17lenny2" test_ref="oval:org.mitre.oval:tst:17512"/>
              <criterion comment="linux-image-2.6.26-2-s390x DPKG is earlier than 2.6.26-17lenny2" test_ref="oval:org.mitre.oval:tst:17966"/>
              <criterion comment="linux-headers-2.6.26-2-common DPKG is earlier than 2.6.26-17lenny2" test_ref="oval:org.mitre.oval:tst:17878"/>
              <criterion comment="linux-headers-2.6.26-2-s390x DPKG is earlier than 2.6.26-17lenny2" test_ref="oval:org.mitre.oval:tst:17543"/>
            </criteria>
          </criteria>
          <criteria comment="Architecture dependent section" operator="AND">
            <criteria comment="Supported architectures section" operator="OR">
              <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
            </criteria>
            <criteria comment="Packages section" operator="OR">
              <criterion comment="xen-linux-system-2.6.26-2-xen-amd64 DPKG is earlier than 2.6.26-17lenny2" test_ref="oval:org.mitre.oval:tst:18043"/>
              <criterion comment="linux-headers-2.6.26-2-all DPKG is earlier than 2.6.26-17lenny2" test_ref="oval:org.mitre.oval:tst:17078"/>
              <criterion comment="linux-modules-2.6.26-2-xen-amd64 DPKG is earlier than 2.6.26-17lenny2" test_ref="oval:org.mitre.oval:tst:17770"/>
              <criterion comment="linux-headers-2.6.26-2-openvz-amd64 DPKG is earlier than 2.6.26-17lenny2" test_ref="oval:org.mitre.oval:tst:17950"/>
              <criterion comment="linux-headers-2.6.26-2-common-vserver DPKG is earlier than 2.6.26-17lenny2" test_ref="oval:org.mitre.oval:tst:17829"/>
              <criterion comment="linux-image-2.6.26-2-openvz-amd64 DPKG is earlier than 2.6.26-17lenny2" test_ref="oval:org.mitre.oval:tst:17825"/>
              <criterion comment="linux-libc-dev DPKG is earlier than 2.6.26-17lenny2" test_ref="oval:org.mitre.oval:tst:17947"/>
              <criterion comment="linux-headers-2.6.26-2-common-openvz DPKG is earlier than 2.6.26-17lenny2" test_ref="oval:org.mitre.oval:tst:18028"/>
              <criterion comment="linux-image-2.6.26-2-vserver-amd64 DPKG is earlier than 2.6.26-17lenny2" test_ref="oval:org.mitre.oval:tst:17894"/>
              <criterion comment="linux-headers-2.6.26-2-all-amd64 DPKG is earlier than 2.6.26-17lenny2" test_ref="oval:org.mitre.oval:tst:17661"/>
              <criterion comment="linux-image-2.6.26-2-xen-amd64 DPKG is earlier than 2.6.26-17lenny2" test_ref="oval:org.mitre.oval:tst:17926"/>
              <criterion comment="linux-headers-2.6.26-2-common-xen DPKG is earlier than 2.6.26-17lenny2" test_ref="oval:org.mitre.oval:tst:17854"/>
              <criterion comment="linux-image-2.6.26-2-amd64 DPKG is earlier than 2.6.26-17lenny2" test_ref="oval:org.mitre.oval:tst:17600"/>
              <criterion comment="linux-headers-2.6.26-2-xen-amd64 DPKG is earlier than 2.6.26-17lenny2" test_ref="oval:org.mitre.oval:tst:18052"/>
              <criterion comment="linux-headers-2.6.26-2-amd64 DPKG is earlier than 2.6.26-17lenny2" test_ref="oval:org.mitre.oval:tst:17682"/>
              <criterion comment="linux-headers-2.6.26-2-common DPKG is earlier than 2.6.26-17lenny2" test_ref="oval:org.mitre.oval:tst:17597"/>
              <criterion comment="linux-headers-2.6.26-2-vserver-amd64 DPKG is earlier than 2.6.26-17lenny2" test_ref="oval:org.mitre.oval:tst:17909"/>
            </criteria>
          </criteria>
          <criteria comment="Architecture depended section" operator="AND">
            <criteria comment="Supported platform section" operator="AND">
              <criterion comment="hppa architecture" test_ref="oval:org.mitre.oval:tst:11164"/>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="linux-headers-2.6.26-2-all DPKG is earlier than 2.6.26-17lenny2" test_ref="oval:org.mitre.oval:tst:18023"/>
                <criterion comment="linux-headers-2.6.26-2-parisc DPKG is earlier than 2.6.26-17lenny2" test_ref="oval:org.mitre.oval:tst:17981"/>
                <criterion comment="linux-image-2.6.26-2-parisc64 DPKG is earlier than 2.6.26-17lenny2" test_ref="oval:org.mitre.oval:tst:18155"/>
                <criterion comment="linux-image-2.6.26-2-parisc DPKG is earlier than 2.6.26-17lenny2" test_ref="oval:org.mitre.oval:tst:18162"/>
                <criterion comment="linux-headers-2.6.26-2-common DPKG is earlier than 2.6.26-17lenny2" test_ref="oval:org.mitre.oval:tst:17228"/>
                <criterion comment="linux-headers-2.6.26-2-all-hppa DPKG is earlier than 2.6.26-17lenny2" test_ref="oval:org.mitre.oval:tst:17863"/>
                <criterion comment="linux-headers-2.6.26-2-parisc64 DPKG is earlier than 2.6.26-17lenny2" test_ref="oval:org.mitre.oval:tst:18201"/>
                <criterion comment="linux-headers-2.6.26-2-parisc64-smp DPKG is earlier than 2.6.26-17lenny2" test_ref="oval:org.mitre.oval:tst:18214"/>
                <criterion comment="linux-libc-dev DPKG is earlier than 2.6.26-17lenny2" test_ref="oval:org.mitre.oval:tst:17864"/>
                <criterion comment="linux-image-2.6.26-2-parisc64-smp DPKG is earlier than 2.6.26-17lenny2" test_ref="oval:org.mitre.oval:tst:17796"/>
                <criterion comment="linux-headers-2.6.26-2-parisc-smp DPKG is earlier than 2.6.26-17lenny2" test_ref="oval:org.mitre.oval:tst:17752"/>
                <criterion comment="linux-image-2.6.26-2-parisc-smp DPKG is earlier than 2.6.26-17lenny2" test_ref="oval:org.mitre.oval:tst:17977"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:7963" class="patch">
      <metadata>
        <title>DSA-1727 proftpd-dfsg -- SQL injection vulnerabilites</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <product>proftpd-dfsg</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2009/dsa-1727" ref_id="DSA-1727"/>
        <description>Two SQL injection vulnerabilities have been found in proftpd, a virtual-hosting FTP daemon. The Common Vulnerabilities and Exposures project identifies the following problems: Shino discovered that proftpd is prone to an SQL injection vulnerability via the use of certain characters in the username. TJ Saunders discovered that proftpd is prone to an SQL injection vulnerability due to insufficient escaping mechanisms, when multybite character encodings are used.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:08-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T07:56:30.285-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:03:05.723-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:02:16.883-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Release section" operator="AND">
        <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
        <criteria comment="Architecture section" operator="OR">
          <criteria comment="Architecture independent section" operator="AND">
            <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
            <criteria comment="Packages section" operator="OR">
              <criterion comment="proftpd is earlier than 1.3.1-17lenny1" test_ref="oval:org.mitre.oval:tst:17316"/>
              <criterion comment="proftpd-doc is earlier than 1.3.1-17lenny1" test_ref="oval:org.mitre.oval:tst:17574"/>
            </criteria>
          </criteria>
          <criteria comment="Architecture dependent section" operator="AND">
            <criteria comment="Supported architectures section" operator="OR">
              <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
              <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
              <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
              <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
              <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
              <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
              <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
              <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
              <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
            </criteria>
            <criteria comment="Packages section" operator="OR">
              <criterion comment="proftpd-mod-mysql DPKG is earlier than 1.3.1-17lenny1" test_ref="oval:org.mitre.oval:tst:17690"/>
              <criterion comment="proftpd-mod-pgsql DPKG is earlier than 1.3.1-17lenny1" test_ref="oval:org.mitre.oval:tst:17679"/>
              <criterion comment="proftpd-mod-ldap DPKG is earlier than 1.3.1-17lenny1" test_ref="oval:org.mitre.oval:tst:17548"/>
              <criterion comment="proftpd-basic DPKG is earlier than 1.3.1-17lenny1" test_ref="oval:org.mitre.oval:tst:17578"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:7960" class="patch">
      <metadata>
        <title>DSA-1773 cups -- integer overflow</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <platform>Debian GNU/Linux 4.0</platform>
          <product>cups</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2009/dsa-1773" ref_id="DSA-1773"/>
        <description>It was discovered that the imagetops filter in cups, the Common UNIX Printing System, is prone to an integer overflow when reading malicious TIFF images.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:10-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T07:58:23.625-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:03:03.948-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:02:15.150-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Platform section" operator="OR">
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Architecture independent section" operator="AND">
              <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="cupsys-bsd is earlier than 1.3.8-1lenny5" test_ref="oval:org.mitre.oval:tst:18982"/>
                <criterion comment="cups-common is earlier than 1.3.8-1lenny5" test_ref="oval:org.mitre.oval:tst:18927"/>
                <criterion comment="libcupsys2-dev is earlier than 1.3.8-1lenny5" test_ref="oval:org.mitre.oval:tst:19023"/>
                <criterion comment="cupsys-common is earlier than 1.3.8-1lenny5" test_ref="oval:org.mitre.oval:tst:18794"/>
                <criterion comment="cupsys-client is earlier than 1.3.8-1lenny5" test_ref="oval:org.mitre.oval:tst:18595"/>
                <criterion comment="cupsys-dbg is earlier than 1.3.8-1lenny5" test_ref="oval:org.mitre.oval:tst:19021"/>
                <criterion comment="cupsys is earlier than 1.3.8-1lenny5" test_ref="oval:org.mitre.oval:tst:19033"/>
                <criterion comment="libcupsys2 is earlier than 1.3.8-1lenny5" test_ref="oval:org.mitre.oval:tst:18480"/>
              </criteria>
            </criteria>
            <criteria comment="Architecture dependent section" operator="AND">
              <criteria comment="Supported architectures section" operator="OR">
                <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
                <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
                <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
                <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
                <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
                <criterion comment="Installed architecture is armel" test_ref="oval:org.mitre.oval:tst:11101"/>
                <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
                <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
                <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
                <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
                <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
                <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
              </criteria>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="libcups2-dev DPKG is earlier than 1.3.8-1lenny5" test_ref="oval:org.mitre.oval:tst:18872"/>
                <criterion comment="cups-bsd DPKG is earlier than 1.3.8-1lenny5" test_ref="oval:org.mitre.oval:tst:18211"/>
                <criterion comment="libcupsimage2-dev DPKG is earlier than 1.3.8-1lenny5" test_ref="oval:org.mitre.oval:tst:18874"/>
                <criterion comment="libcupsimage2 DPKG is earlier than 1.3.8-1lenny5" test_ref="oval:org.mitre.oval:tst:18919"/>
                <criterion comment="cups-client DPKG is earlier than 1.3.8-1lenny5" test_ref="oval:org.mitre.oval:tst:18693"/>
                <criterion comment="libcups2 DPKG is earlier than 1.3.8-1lenny5" test_ref="oval:org.mitre.oval:tst:18895"/>
                <criterion comment="cups-dbg DPKG is earlier than 1.3.8-1lenny5" test_ref="oval:org.mitre.oval:tst:18548"/>
                <criterion comment="cups DPKG is earlier than 1.3.8-1lenny5" test_ref="oval:org.mitre.oval:tst:18793"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 4.0 is installed" definition_ref="oval:org.mitre.oval:def:6461"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Architecture independent section" operator="AND">
              <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="libcupsys2-gnutls10 is earlier than 1.2.7-4etch7" test_ref="oval:org.mitre.oval:tst:18998"/>
                <criterion comment="cupsys-common is earlier than 1.2.7-4etch7" test_ref="oval:org.mitre.oval:tst:18579"/>
              </criteria>
            </criteria>
            <criteria comment="Architecture dependent section" operator="AND">
              <criteria comment="Supported architectures section" operator="OR">
                <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
                <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
                <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
                <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
                <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
                <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
                <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
                <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
                <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
              </criteria>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="cupsys-bsd DPKG is earlier than 1.2.7-4etch7" test_ref="oval:org.mitre.oval:tst:18740"/>
                <criterion comment="cupsys-client DPKG is earlier than 1.2.7-4etch7" test_ref="oval:org.mitre.oval:tst:18933"/>
                <criterion comment="libcupsimage2 DPKG is earlier than 1.2.7-4etch7" test_ref="oval:org.mitre.oval:tst:18831"/>
                <criterion comment="libcupsimage2-dev DPKG is earlier than 1.2.7-4etch7" test_ref="oval:org.mitre.oval:tst:18725"/>
                <criterion comment="libcupsys2-dev DPKG is earlier than 1.2.7-4etch7" test_ref="oval:org.mitre.oval:tst:18879"/>
                <criterion comment="cupsys-dbg DPKG is earlier than 1.2.7-4etch7" test_ref="oval:org.mitre.oval:tst:18965"/>
                <criterion comment="cupsys DPKG is earlier than 1.2.7-4etch7" test_ref="oval:org.mitre.oval:tst:19022"/>
                <criterion comment="libcupsys2 DPKG is earlier than 1.2.7-4etch7" test_ref="oval:org.mitre.oval:tst:18854"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:7959" class="patch">
      <metadata>
        <title>DSA-1910 mysql-ocaml -- missing escape function</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <platform>Debian GNU/Linux 4.0</platform>
          <product>mysql-ocaml</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2009/dsa-1910" ref_id="DSA-1910"/>
        <description>It was discovered that mysql-ocaml, OCaml bindings for MySql, was missing a function to call mysql_real_escape_string(). This is needed, because mysql_real_escape_string() honours the charset of the connection and prevents insufficient escaping, when certain multibyte character encodings are used. The added function is called real_escape() and takes the established database connection as a first argument. The old escape_string() was kept for backwards compatibility. Developers using these bindings are encouraged to adjust their code to use the new function.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:07-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T07:54:13.747-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:03:03.440-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:02:14.426-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Platform section" operator="OR">
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Architecture dependent section" operator="AND">
              <criteria comment="Supported architectures section" operator="OR">
                <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
                <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
                <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
                <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
                <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
                <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
                <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
                <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
                <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
                <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
                <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
              </criteria>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="libmysql-ocaml DPKG is earlier than 1.0.4-4+lenny1" test_ref="oval:org.mitre.oval:tst:15173"/>
                <criterion comment="libmysql-ocaml-dev DPKG is earlier than 1.0.4-4+lenny1" test_ref="oval:org.mitre.oval:tst:15736"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 4.0 is installed" definition_ref="oval:org.mitre.oval:def:6461"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Architecture dependent section" operator="AND">
              <criteria comment="Supported architectures section" operator="OR">
                <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
                <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
                <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
                <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
              </criteria>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="libmysql-ocaml DPKG is earlier than 1.0.4-2+etch1" test_ref="oval:org.mitre.oval:tst:15655"/>
                <criterion comment="libmysql-ocaml-dev DPKG is earlier than 1.0.4-2+etch1" test_ref="oval:org.mitre.oval:tst:15903"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:7956" class="patch">
      <metadata>
        <title>DSA-1912 camlimages -- integer overflow</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <platform>Debian GNU/Linux 4.0</platform>
          <product>camlimages</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2009/dsa-1912" ref_id="DSA-1912"/>
        <description>It was discovered that CamlImages, an open source image processing library, suffers from several integer overflows, which may lead to a potentially exploitable heap overflow and result in arbitrary code execution. This advisory addresses issues with the reading of TIFF files. It also expands the patch for CVE-2009-2660 to cover another potential overflow in the processing of JPEG images.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:07-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T07:54:15.106-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:03:02.108-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:02:13.130-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Platform section" operator="OR">
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Architecture independent section" operator="AND">
              <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criterion comment="libcamlimages-ocaml-doc is earlier than 2.2.0-4+lenny3" test_ref="oval:org.mitre.oval:tst:16146"/>
            </criteria>
            <criteria comment="Architecture dependent section" operator="AND">
              <criteria comment="Supported architectures section" operator="OR">
                <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
                <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
                <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
                <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
                <criterion comment="Installed architecture is armel" test_ref="oval:org.mitre.oval:tst:11101"/>
                <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
                <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
                <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
                <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
                <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
                <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
              </criteria>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="libcamlimages-ocaml DPKG is earlier than 2.2.0-4+lenny3" test_ref="oval:org.mitre.oval:tst:15327"/>
                <criterion comment="libcamlimages-ocaml-dev DPKG is earlier than 2.2.0-4+lenny3" test_ref="oval:org.mitre.oval:tst:15869"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 4.0 is installed" definition_ref="oval:org.mitre.oval:def:6461"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Architecture independent section" operator="AND">
              <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criterion comment="libcamlimages-ocaml-doc is earlier than 2.20-8+etch3" test_ref="oval:org.mitre.oval:tst:15837"/>
            </criteria>
            <criteria comment="Architecture dependent section" operator="AND">
              <criteria comment="Supported architectures section" operator="OR">
                <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
                <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
                <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
                <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
                <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
                <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
                <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
                <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
                <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
                <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
              </criteria>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="libcamlimages-ocaml DPKG is earlier than 2.20-8+etch3" test_ref="oval:org.mitre.oval:tst:15841"/>
                <criterion comment="libcamlimages-ocaml-dev DPKG is earlier than 2.20-8+etch3" test_ref="oval:org.mitre.oval:tst:15183"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:7952" class="patch">
      <metadata>
        <title>DSA-1757 auth2db -- SQL injection</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <product>auth2db</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2009/dsa-1757" ref_id="DSA-1757"/>
        <description>It was discovered that auth2db, an IDS logger, log viewer and alert generator, is prone to an SQL injection vulnerability, when used with multibyte character encodings. The oldstable distribution (etch) doesn't contain auth2db.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:04-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T07:51:14.978-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:03:00.940-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:02:12.131-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Release section" operator="AND">
        <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
        <criteria comment="Architecture section" operator="OR">
          <criteria comment="Architecture independent section" operator="AND">
            <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
            <criteria comment="Packages section" operator="OR">
              <criterion comment="auth2db-frontend is earlier than 0.2.5-2+dfsg-1+lenny1" test_ref="oval:org.mitre.oval:tst:13058"/>
              <criterion comment="auth2db is earlier than 0.2.5-2+dfsg-1+lenny1" test_ref="oval:org.mitre.oval:tst:13324"/>
              <criterion comment="auth2db-common is earlier than 0.2.5-2+dfsg-1+lenny1" test_ref="oval:org.mitre.oval:tst:13387"/>
              <criterion comment="auth2db-filters is earlier than 0.2.5-2+dfsg-1+lenny1" test_ref="oval:org.mitre.oval:tst:13166"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:7951" class="patch">
      <metadata>
        <title>DSA-1831 djbdns -- programming error</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <product>djbdns</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2009/dsa-1831" ref_id="DSA-1831"/>
        <description>Matthew Dempsky discovered that Daniel J. Bernstein's djbdns, a Domain Name System server, does not constrain offsets in the required manner, which allows remote attackers with control over a third-party subdomain served by tinydns and axfrdns, to trigger DNS responses containing arbitrary records via crafted zone data for this subdomain. The old stable distribution (etch) does not contain djbdns.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:05-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T07:52:39.176-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:03:00.461-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:02:11.478-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Release section" operator="AND">
        <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
        <criteria comment="Architecture section" operator="OR">
          <criteria comment="Architecture independent section" operator="AND">
            <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
            <criterion comment="dnscache-run is earlier than 1.05-4+lenny1" test_ref="oval:org.mitre.oval:tst:14295"/>
          </criteria>
          <criteria comment="Architecture dependent section" operator="AND">
            <criteria comment="Supported architectures section" operator="OR">
              <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
              <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
              <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
              <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
              <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
              <criterion comment="Installed architecture is armel" test_ref="oval:org.mitre.oval:tst:11101"/>
              <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
              <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
              <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
              <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
              <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
              <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
            </criteria>
            <criteria comment="Packages section" operator="OR">
              <criterion comment="djbdns DPKG is earlier than 1.05-4+lenny1" test_ref="oval:org.mitre.oval:tst:14784"/>
              <criterion comment="dbndns DPKG is earlier than 1.05-4+lenny1" test_ref="oval:org.mitre.oval:tst:14777"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:7945" class="patch">
      <metadata>
        <title>DSA-1922 xulrunner -- several vulnerabilities</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <product>xulrunner</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2009/dsa-1922" ref_id="DSA-1922"/>
        <description>Several remote vulnerabilities have been discovered in Xulrunner, a runtime environment for XUL applications, such as the Iceweasel web browser. The Common Vulnerabilities and Exposures project identifies the following problems: Vladimir Vukicevic, Jesse Ruderman, Martijn Wargers, Daniel Banchero, David Keeler and Boris Zbarsky reported crashes in layout engine, which might allow the execution of arbitrary code. Carsten Book reported a crash in the layout engine, which might allow the execution of arbitrary code. Jesse Ruderman and Sid Stamm discovered spoofing vulnerability in the file download dialog. Gregory Fleischer discovered a bypass of the same-origin policy using the document.getSelection() function. "moz_bug_r_a4" discovered a privilege escalation to Chrome status in the XPCOM utility XPCVariant::VariantDataToJS. "regenrecht" discovered a buffer overflow in the GIF parser, which might lead to the execution of arbitrary code. Marco C. discovered that a programming error in the proxy auto configuration code might lead to denial of service or the execution of arbitrary code. Jeremy Brown discovered that the filename of a downloaded file which is opened by the user is predictable, which might lead to tricking the user into a malicious file if the attacker has local access to the system. Paul Stone discovered that history information from web forms could be stolen.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:08-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T07:56:02.867-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:02:58.179-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:02:09.430-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Release section" operator="AND">
        <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
        <criteria comment="Architecture section" operator="OR">
          <criteria comment="Architecture independent section" operator="AND">
            <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
            <criterion comment="libmozillainterfaces-java is earlier than 1.9.0.15-0lenny1" test_ref="oval:org.mitre.oval:tst:17010"/>
          </criteria>
          <criteria comment="Packages section" operator="OR">
            <criterion comment="libmozjs-dev DPKG is earlier than 1.9.0.15-0lenny1" test_ref="oval:org.mitre.oval:tst:17045"/>
            <criterion comment="spidermonkey-bin DPKG is earlier than 1.9.0.15-0lenny1" test_ref="oval:org.mitre.oval:tst:17050"/>
            <criterion comment="xulrunner-1.9-gnome-support DPKG is earlier than 1.9.0.15-0lenny1" test_ref="oval:org.mitre.oval:tst:17354"/>
            <criterion comment="xulrunner-1.9 DPKG is earlier than 1.9.0.15-0lenny1" test_ref="oval:org.mitre.oval:tst:17357"/>
            <criterion comment="libmozjs1d-dbg DPKG is earlier than 1.9.0.15-0lenny1" test_ref="oval:org.mitre.oval:tst:17292"/>
            <criterion comment="libmozjs1d DPKG is earlier than 1.9.0.15-0lenny1" test_ref="oval:org.mitre.oval:tst:17346"/>
            <criterion comment="python-xpcom DPKG is earlier than 1.9.0.15-0lenny1" test_ref="oval:org.mitre.oval:tst:16472"/>
            <criterion comment="xulrunner-1.9-dbg DPKG is earlier than 1.9.0.15-0lenny1" test_ref="oval:org.mitre.oval:tst:16940"/>
            <criterion comment="xulrunner-dev DPKG is earlier than 1.9.0.15-0lenny1" test_ref="oval:org.mitre.oval:tst:16719"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:7942" class="patch">
      <metadata>
        <title>DSA-1913 bugzilla -- SQL injection vulnerability</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <product>bugzilla</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2009/dsa-1913" ref_id="DSA-1913"/>
        <description>Max Kanat-Alexander, Bradley Baetz, and Fr?Å d?Å ric Buclin discovered an SQL injection vulnerability in the Bug.create WebService function in Bugzilla, a web-based bug tracking system, which allows remote attackers to execute arbitrary SQL commands. The oldstable distribution (etch) isn't affected by this problem.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:07-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T07:54:14.357-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:02:57.252-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:02:08.271-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Release section" operator="AND">
        <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
        <criteria comment="Architecture section" operator="OR">
          <criteria comment="Architecture independent section" operator="AND">
            <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
            <criteria comment="Packages section" operator="OR">
              <criterion comment="bugzilla3 is earlier than 3.0.4.1-2+lenny2" test_ref="oval:org.mitre.oval:tst:15833"/>
              <criterion comment="bugzilla3-doc is earlier than 3.0.4.1-2+lenny2" test_ref="oval:org.mitre.oval:tst:16044"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:7932" class="patch">
      <metadata>
        <title>DSA-1849 xml-security-c -- design flaw</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <platform>Debian GNU/Linux 4.0</platform>
          <product>xml-security-c</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2009/dsa-1849" ref_id="DSA-1849"/>
        <description>It was discovered that the W3C XML Signature recommendation contains a protocol-level vulnerability related to HMAC output truncation. This update implements the proposed workaround in the C++ version of the Apache implementation of this standard, xml-security-c, by preventing truncation to output strings shorter than 80 bits or half of the original HMAC output, whichever is greater.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:03-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T07:50:05.181-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:02:51.184-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:02:02.713-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Platform section" operator="OR">
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Architecture dependent section" operator="AND">
              <criteria comment="Supported architectures section" operator="OR">
                <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
                <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
                <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
                <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
                <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
                <criterion comment="Installed architecture is armel" test_ref="oval:org.mitre.oval:tst:11101"/>
                <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
                <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
                <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
                <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
                <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
                <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
              </criteria>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="libxml-security-c-dev DPKG is earlier than 1.4.0-3+lenny2" test_ref="oval:org.mitre.oval:tst:12170"/>
                <criterion comment="libxml-security-c14 DPKG is earlier than 1.4.0-3+lenny2" test_ref="oval:org.mitre.oval:tst:12652"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 4.0 is installed" definition_ref="oval:org.mitre.oval:def:6461"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Architecture independent section" operator="AND">
              <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criterion comment="libxml-security-c-doc is earlier than 1.2.1-3+etch1" test_ref="oval:org.mitre.oval:tst:12663"/>
            </criteria>
            <criteria comment="Packages section" operator="OR">
              <criterion comment="libxml-security-c12 DPKG is earlier than 1.2.1-3+etch1" test_ref="oval:org.mitre.oval:tst:12692"/>
              <criterion comment="libxml-security-c-dev DPKG is earlier than 1.2.1-3+etch1" test_ref="oval:org.mitre.oval:tst:12650"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:7924" class="patch">
      <metadata>
        <title>DSA-1918 phpmyadmin -- several vulnerabilities</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <platform>Debian GNU/Linux 4.0</platform>
          <product>phpmyadmin</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2009/dsa-1918" ref_id="DSA-1918"/>
        <description>Several remote vulnerabilities have been discovered in phpMyAdmin, a tool to administer MySQL over the web. The Common Vulnerabilities and Exposures project identifies the following problems: Cross-site scripting (XSS) vulnerability allows remote attackers to inject arbitrary web script or HTML via a crafted MySQL table name. SQL injection vulnerability in the PDF schema generator functionality allows remote attackers to execute arbitrary SQL commands. This issue does not apply to the version in Debian 4.0 Etch. Additionally, extra fortification has been added for the web based setup.php script. Although the shipped web server configuration should ensure that this script is protected, in practice this turned out not always to be the case. The config.inc.php file is not writable anymore by the webserver user. See README.Debian for details on how to enable the setup.php script if and when you need it.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:07-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T07:54:12.358-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:02:48.427-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:02:00.845-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Platform section" operator="OR">
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Architecture independent section" operator="AND">
              <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criterion comment="phpmyadmin is earlier than 2.11.8.1-5+lenny3" test_ref="oval:org.mitre.oval:tst:15375"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 4.0 is installed" definition_ref="oval:org.mitre.oval:def:6461"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Architecture independent section" operator="AND">
              <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criterion comment="phpmyadmin is earlier than 2.9.1.1-13" test_ref="oval:org.mitre.oval:tst:16110"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:7920" class="patch">
      <metadata>
        <title>DSA-1876 dnsmasq -- buffer overflow</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <product>dnsmasq</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2009/dsa-1876" ref_id="DSA-1876"/>
        <description>Several remote vulnerabilities have been discovered in the TFTP component of dnsmasq. The Common Vulnerabilities and Exposures project identifies the following problems: A buffer overflow in TFTP processing may enable arbitrary code execution to attackers which are permitted to use the TFTP service. Malicious TFTP clients may crash dnsmasq, leading to denial of service. The old stable distribution is not affected by these problems.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:06-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T07:53:39.668-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:02:44.899-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:01:59.187-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Release section" operator="AND">
        <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
        <criteria comment="Architecture section" operator="OR">
          <criteria comment="Architecture independent section" operator="AND">
            <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
            <criterion comment="dnsmasq is earlier than 2.45-1+lenny1" test_ref="oval:org.mitre.oval:tst:15357"/>
          </criteria>
          <criteria comment="Architecture dependent section" operator="AND">
            <criteria comment="Supported architectures section" operator="OR">
              <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
              <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
              <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
              <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
              <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
              <criterion comment="Installed architecture is armel" test_ref="oval:org.mitre.oval:tst:11101"/>
              <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
              <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
              <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
              <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
              <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
              <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
            </criteria>
            <criteria comment="Packages section" operator="OR">
              <criterion comment="dnsmasq-base DPKG is earlier than 2.45-1+lenny1" test_ref="oval:org.mitre.oval:tst:14986"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:7918" class="patch">
      <metadata>
        <title>DSA-1796 libwmf -- pointer use-after-free</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <platform>Debian GNU/Linux 4.0</platform>
          <product>libwmf</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2009/dsa-1796" ref_id="DSA-1796"/>
        <description>Tavis Ormandy discovered that the embedded GD library copy in libwmf, a library to parse windows metafiles (WMF), makes use of a pointer after it was already freed. An attacker using a crafted WMF file can cause a denial of service or possibly the execute arbitrary code via applications using this library.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:03-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T07:49:06.901-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:02:43.518-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:01:58.145-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Platform section" operator="OR">
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Architecture independent section" operator="AND">
              <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criterion comment="libwmf-doc is earlier than 0.2.8.4-6+lenny1" test_ref="oval:org.mitre.oval:tst:11961"/>
            </criteria>
            <criteria comment="Architecture dependent section" operator="AND">
              <criteria comment="Supported architectures section" operator="OR">
                <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
                <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
                <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
                <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
                <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
                <criterion comment="Installed architecture is armel" test_ref="oval:org.mitre.oval:tst:11101"/>
                <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
                <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
                <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
                <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
                <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
                <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
              </criteria>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="libwmf-dev DPKG is earlier than 0.2.8.4-6+lenny1" test_ref="oval:org.mitre.oval:tst:11138"/>
                <criterion comment="libwmf0.2-7 DPKG is earlier than 0.2.8.4-6+lenny1" test_ref="oval:org.mitre.oval:tst:12130"/>
                <criterion comment="libwmf-bin DPKG is earlier than 0.2.8.4-6+lenny1" test_ref="oval:org.mitre.oval:tst:12125"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 4.0 is installed" definition_ref="oval:org.mitre.oval:def:6461"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Architecture independent section" operator="AND">
              <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criterion comment="libwmf-doc is earlier than 0.2.8.4-2+etch1" test_ref="oval:org.mitre.oval:tst:11221"/>
            </criteria>
            <criteria comment="Architecture dependent section" operator="AND">
              <criteria comment="Supported architectures section" operator="OR">
                <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
                <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
                <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
                <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
                <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
                <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
                <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
                <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
                <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
                <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
              </criteria>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="libwmf-dev DPKG is earlier than 0.2.8.4-2+etch1" test_ref="oval:org.mitre.oval:tst:11999"/>
                <criterion comment="libwmf0.2-7 DPKG is earlier than 0.2.8.4-2+etch1" test_ref="oval:org.mitre.oval:tst:11700"/>
                <criterion comment="libwmf-bin DPKG is earlier than 0.2.8.4-2+etch1" test_ref="oval:org.mitre.oval:tst:12054"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:7916" class="patch">
      <metadata>
        <title>DSA-1761 moodle -- missing input sanitization</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <platform>Debian GNU/Linux 4.0</platform>
          <product>moodle</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2009/dsa-1761" ref_id="DSA-1761"/>
        <description>Christian J. Eibl discovered that the TeX filter of Moodle, a web-based course management system, doesn't check user input for certain TeX commands which allows an attacker to include and display the content of arbitrary system files. Note that this doesn't affect installations that only use the mimetex environment.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:07-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T07:54:55.239-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:02:42.635-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:01:57.505-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Platform section" operator="OR">
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Architecture independent section" operator="AND">
              <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criterion comment="moodle is earlier than 1.8.2.dfsg-3+lenny2" test_ref="oval:org.mitre.oval:tst:16713"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 4.0 is installed" definition_ref="oval:org.mitre.oval:def:6461"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Architecture independent section" operator="AND">
              <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criterion comment="moodle is earlier than 1.6.3-2+etch3" test_ref="oval:org.mitre.oval:tst:16325"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:7911" class="patch">
      <metadata>
        <title>DSA-1919 smarty -- several vulnerabilities</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <platform>Debian GNU/Linux 4.0</platform>
          <product>smarty</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2009/dsa-1919" ref_id="DSA-1919"/>
        <description>Several remote vulnerabilities have been discovered in Smarty, a PHP templating engine. The Common Vulnerabilities and Exposures project identifies the following problems: The _expand_quoted_text function allows for certain restrictions in templates, like function calling and PHP execution, to be bypassed. The smarty_function_math function allows context-dependent attackers to execute arbitrary commands via shell metacharacters in the equation attribute of the math function.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:06-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T07:54:11.878-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:02:38.762-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:01:55.911-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Platform section" operator="OR">
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Architecture independent section" operator="AND">
              <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criterion comment="smarty is earlier than 2.6.20-1.2" test_ref="oval:org.mitre.oval:tst:15867"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 4.0 is installed" definition_ref="oval:org.mitre.oval:def:6461"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Architecture independent section" operator="AND">
              <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criterion comment="smarty is earlier than 2.6.14-1etch2" test_ref="oval:org.mitre.oval:tst:15769"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:7910" class="patch">
      <metadata>
        <title>DSA-1904 wget -- insufficient input validation</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <platform>Debian GNU/Linux 4.0</platform>
          <product>wget</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2009/dsa-1904" ref_id="DSA-1904"/>
        <description>Daniel Stenberg discovered that wget, a network utility to retrieve files from the Web using HTTP(S) and FTP, is vulnerable to the "Null Prefix Attacks Against SSL/TLS Certificates" published at the Blackhat conference some time ago. This allows an attacker to perform undetected man-in-the-middle attacks via a crafted ITU-T X.509 certificate with an injected null byte in the Common Name field.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:04-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T07:50:41.781-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:02:38.298-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:01:55.498-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Platform section" operator="OR">
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Architecture dependent section" operator="AND">
              <criteria comment="Supported architectures section" operator="OR">
                <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
                <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
                <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
                <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
                <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
                <criterion comment="Installed architecture is armel" test_ref="oval:org.mitre.oval:tst:11101"/>
                <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
                <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
                <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
                <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
                <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
                <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
              </criteria>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="wget DPKG is earlier than 1.11.4-2+lenny1" test_ref="oval:org.mitre.oval:tst:12841"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 4.0 is installed" definition_ref="oval:org.mitre.oval:def:6461"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Architecture dependent section" operator="AND">
              <criteria comment="Supported architectures section" operator="OR">
                <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
                <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
                <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
                <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
                <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
                <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
                <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
                <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
                <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
                <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
              </criteria>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="wget DPKG is earlier than 1.10.2-2+etch1" test_ref="oval:org.mitre.oval:tst:13050"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:7908" class="patch">
      <metadata>
        <title>DSA-1837 dbus -- programming error</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <platform>Debian GNU/Linux 4.0</platform>
          <product>dbus</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2009/dsa-1837" ref_id="DSA-1837"/>
        <description>It was discovered that the dbus_signature_validate function in dbus, a simple interprocess messaging system, is prone to a denial of service attack. This issue was caused by an incorrect fix for DSA-1658-1.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:05-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T07:52:40.733-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:02:36.811-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:01:54.399-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Platform section" operator="OR">
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Architecture independent section" operator="AND">
              <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criterion comment="dbus-1-doc is earlier than 1.2.1-5+lenny1" test_ref="oval:org.mitre.oval:tst:14776"/>
            </criteria>
            <criteria comment="Architecture dependent section" operator="AND">
              <criteria comment="Supported architectures section" operator="OR">
                <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
                <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
                <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
                <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
                <criterion comment="Installed architecture is armel" test_ref="oval:org.mitre.oval:tst:11101"/>
                <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
                <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
                <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
                <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
                <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
                <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
              </criteria>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="libdbus-1-3 DPKG is earlier than 1.2.1-5+lenny1" test_ref="oval:org.mitre.oval:tst:14600"/>
                <criterion comment="dbus-x11 DPKG is earlier than 1.2.1-5+lenny1" test_ref="oval:org.mitre.oval:tst:14200"/>
                <criterion comment="dbus DPKG is earlier than 1.2.1-5+lenny1" test_ref="oval:org.mitre.oval:tst:14480"/>
                <criterion comment="libdbus-1-dev DPKG is earlier than 1.2.1-5+lenny1" test_ref="oval:org.mitre.oval:tst:14676"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 4.0 is installed" definition_ref="oval:org.mitre.oval:def:6461"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Architecture independent section" operator="AND">
              <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criterion comment="dbus-1-doc is earlier than 1.0.2-1+etch3" test_ref="oval:org.mitre.oval:tst:14504"/>
            </criteria>
            <criteria comment="Architecture dependent section" operator="AND">
              <criteria comment="Supported architectures section" operator="OR">
                <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
                <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
                <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
                <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
                <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
                <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
                <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
                <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
                <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
              </criteria>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="dbus-1-utils DPKG is earlier than 1.0.2-1+etch3" test_ref="oval:org.mitre.oval:tst:14710"/>
                <criterion comment="libdbus-1-3 DPKG is earlier than 1.0.2-1+etch3" test_ref="oval:org.mitre.oval:tst:14230"/>
                <criterion comment="dbus DPKG is earlier than 1.0.2-1+etch3" test_ref="oval:org.mitre.oval:tst:14729"/>
                <criterion comment="libdbus-1-dev DPKG is earlier than 1.0.2-1+etch3" test_ref="oval:org.mitre.oval:tst:14552"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:7907" class="patch">
      <metadata>
        <title>DSA-1759 strongswan -- denial of service</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <platform>Debian GNU/Linux 4.0</platform>
          <product>strongswan</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2009/dsa-1759" ref_id="DSA-1759"/>
        <description>Gerd v. Egidy discovered that the Pluto IKE daemon in strongswan, an IPSec implementation for linux, is prone to a denial of service attack via a malicious packet.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:04-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T07:51:13.604-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:02:36.181-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:01:53.973-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Platform section" operator="OR">
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Architecture dependent section" operator="AND">
              <criteria comment="Supported architectures section" operator="OR">
                <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
                <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
                <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
                <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
                <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
                <criterion comment="Installed architecture is armel" test_ref="oval:org.mitre.oval:tst:11101"/>
                <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
                <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
                <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
                <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
                <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
                <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
              </criteria>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="strongswan DPKG is earlier than 4.2.4-5+lenny1" test_ref="oval:org.mitre.oval:tst:12930"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 4.0 is installed" definition_ref="oval:org.mitre.oval:def:6461"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Packages section" operator="OR">
              <criterion comment="strongswan DPKG is earlier than 2.8.0+dfsg-1+etch1" test_ref="oval:org.mitre.oval:tst:13383"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:7905" class="patch">
      <metadata>
        <title>DSA-1877 mysql-dfsg-5.0 -- denial of service/execution of arbitrary code</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <platform>Debian GNU/Linux 4.0</platform>
          <product>mysql-dfsg-5.0</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2009/dsa-1877" ref_id="DSA-1877"/>
        <description>In MySQL 4.0.0 through 5.0.83, multiple format string vulnerabilities in the dispatch_command() function in libmysqld/sql_parse.cc in mysqld allow remote authenticated users to cause a denial of service (daemon crash) and potentially the execution of arbitrary code via format string specifiers in a database name in a COM_CREATE_DB or COM_DROP_DB request.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:06-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T07:53:41.365-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:02:35.390-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:01:53.415-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Platform section" operator="OR">
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Architecture independent section" operator="AND">
              <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="mysql-client is earlier than 5.0.51a-24+lenny2" test_ref="oval:org.mitre.oval:tst:15340"/>
                <criterion comment="mysql-common is earlier than 5.0.51a-24+lenny2" test_ref="oval:org.mitre.oval:tst:15503"/>
                <criterion comment="mysql-server is earlier than 5.0.51a-24+lenny2" test_ref="oval:org.mitre.oval:tst:15373"/>
              </criteria>
            </criteria>
            <criteria comment="Architecture dependent section" operator="AND">
              <criteria comment="Supported architectures section" operator="OR">
                <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
                <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
                <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
                <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
                <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
                <criterion comment="Installed architecture is armel" test_ref="oval:org.mitre.oval:tst:11101"/>
                <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
                <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
                <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
                <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
                <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
                <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
              </criteria>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="libmysqlclient15-dev DPKG is earlier than 5.0.51a-24+lenny2" test_ref="oval:org.mitre.oval:tst:15555"/>
                <criterion comment="mysql-client-5.0 DPKG is earlier than 5.0.51a-24+lenny2" test_ref="oval:org.mitre.oval:tst:15463"/>
                <criterion comment="libmysqlclient15off DPKG is earlier than 5.0.51a-24+lenny2" test_ref="oval:org.mitre.oval:tst:15483"/>
                <criterion comment="mysql-server-5.0 DPKG is earlier than 5.0.51a-24+lenny2" test_ref="oval:org.mitre.oval:tst:15305"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 4.0 is installed" definition_ref="oval:org.mitre.oval:def:6461"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Architecture independent section" operator="AND">
              <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="mysql-client is earlier than 5.0.32-7etch11" test_ref="oval:org.mitre.oval:tst:15522"/>
                <criterion comment="mysql-common is earlier than 5.0.32-7etch11" test_ref="oval:org.mitre.oval:tst:15299"/>
                <criterion comment="mysql-server is earlier than 5.0.32-7etch11" test_ref="oval:org.mitre.oval:tst:15197"/>
              </criteria>
            </criteria>
            <criteria comment="Architecture dependent section" operator="AND">
              <criteria comment="Supported architectures section" operator="OR">
                <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
                <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
                <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
                <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
                <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
                <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
                <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
                <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
                <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
              </criteria>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="libmysqlclient15-dev DPKG is earlier than 5.0.32-7etch11" test_ref="oval:org.mitre.oval:tst:14608"/>
                <criterion comment="mysql-client-5.0 DPKG is earlier than 5.0.32-7etch11" test_ref="oval:org.mitre.oval:tst:15442"/>
                <criterion comment="mysql-server-4.1 DPKG is earlier than 5.0.32-7etch11" test_ref="oval:org.mitre.oval:tst:15330"/>
                <criterion comment="mysql-server-5.0 DPKG is earlier than 5.0.32-7etch11" test_ref="oval:org.mitre.oval:tst:15254"/>
                <criterion comment="libmysqlclient15off DPKG is earlier than 5.0.32-7etch11" test_ref="oval:org.mitre.oval:tst:15532"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:7904" class="patch">
      <metadata>
        <title>DSA-1742 libsndfile -- integer overflow</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <platform>Debian GNU/Linux 4.0</platform>
          <product>libsndfile</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2009/dsa-1742" ref_id="DSA-1742"/>
        <description>Alan Rad Pop discovered that libsndfile, a library to read and write sampled audio data, is prone to an integer overflow. This causes a heap-based buffer overflow when processing crafted CAF description chunks possibly leading to arbitrary code execution.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:12-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T08:00:00.827-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:02:34.223-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:01:52.855-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Platform section" operator="OR">
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Packages section" operator="OR">
              <criterion comment="libsndfile1 DPKG is earlier than 1.0.17-4+lenny1" test_ref="oval:org.mitre.oval:tst:19881"/>
              <criterion comment="libsndfile1-dev DPKG is earlier than 1.0.17-4+lenny1" test_ref="oval:org.mitre.oval:tst:20068"/>
              <criterion comment="sndfile-programs DPKG is earlier than 1.0.17-4+lenny1" test_ref="oval:org.mitre.oval:tst:20007"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 4.0 is installed" definition_ref="oval:org.mitre.oval:def:6461"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Architecture dependent section" operator="AND">
              <criteria comment="Supported architectures section" operator="OR">
                <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
                <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
                <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
                <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
                <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
                <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
                <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
                <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
                <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
                <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
              </criteria>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="libsndfile1 DPKG is earlier than 1.0.16-2+etch1" test_ref="oval:org.mitre.oval:tst:20059"/>
                <criterion comment="libsndfile1-dev DPKG is earlier than 1.0.16-2+etch1" test_ref="oval:org.mitre.oval:tst:19903"/>
                <criterion comment="sndfile-programs DPKG is earlier than 1.0.16-2+etch1" test_ref="oval:org.mitre.oval:tst:20051"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:7899" class="patch">
      <metadata>
        <title>DSA-1943 openldap openldap2.3 -- insufficient input validation</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <platform>Debian GNU/Linux 4.0</platform>
          <product>openldap</product>
          <product>openldap2.3</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2009/dsa-1943" ref_id="DSA-1943"/>
        <description>It was discovered that OpenLDAP, a free implementation of the Lightweight Directory Access Protocol, when OpenSSL is used, does not properly handle a "\0" character in a domain name in the subject's Common Name (CN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:02-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T07:48:37.528-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:02:32.443-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:01:51.858-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Platform section" operator="OR">
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Architecture dependent section" operator="AND">
              <criteria comment="Supported architectures section" operator="OR">
                <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
                <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
                <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
                <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
                <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
                <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
                <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
                <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
                <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
              </criteria>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="slapd-dbg DPKG is earlier than 2.4.11-1+lenny1" test_ref="oval:org.mitre.oval:tst:11774"/>
                <criterion comment="libldap-2.4-2 DPKG is earlier than 2.4.11-1+lenny1" test_ref="oval:org.mitre.oval:tst:11398"/>
                <criterion comment="libldap-2.4-2-dbg DPKG is earlier than 2.4.11-1+lenny1" test_ref="oval:org.mitre.oval:tst:11486"/>
                <criterion comment="ldap-utils DPKG is earlier than 2.4.11-1+lenny1" test_ref="oval:org.mitre.oval:tst:11753"/>
                <criterion comment="libldap2-dev DPKG is earlier than 2.4.11-1+lenny1" test_ref="oval:org.mitre.oval:tst:11742"/>
                <criterion comment="slapd DPKG is earlier than 2.4.11-1+lenny1" test_ref="oval:org.mitre.oval:tst:11908"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 4.0 is installed" definition_ref="oval:org.mitre.oval:def:6461"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Packages section" operator="OR">
              <criterion comment="libldap-2.3-0 DPKG is earlier than 2.3.30-5+etch3" test_ref="oval:org.mitre.oval:tst:11732"/>
              <criterion comment="ldap-utils DPKG is earlier than 2.3.30-5+etch3" test_ref="oval:org.mitre.oval:tst:11968"/>
              <criterion comment="slapd DPKG is earlier than 2.3.30-5+etch3" test_ref="oval:org.mitre.oval:tst:11707"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:7898" class="patch">
      <metadata>
        <title>DSA-1756 xulrunner -- multiple vulnerabilities</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <product>xulrunner</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2009/dsa-1756" ref_id="DSA-1756"/>
        <description>Several remote vulnerabilities have been discovered in Xulrunner, a runtime environment for XUL applications, such as the Iceweasel web browser. The Common Vulnerabilities and Exposures project identifies the following problems: Security researcher Guido Landi discovered that a XSL stylesheet could be used to crash the browser during a XSL transformation. An attacker could potentially use this crash to run arbitrary code on a victim's computer. Security researcher Nils reported via TippingPoint's Zero Day Initiative that the XUL tree method _moveToEdgeShift was in some cases triggering garbage collection routines on objects which were still in use. In such cases, the browser would crash when attempting to access a previously destroyed object and this crash could be used by an attacker to run arbitrary code on a victim's computer. Note that after installing these updates, you will need to restart any packages using xulrunner, typically iceweasel or epiphany. As indicated in the Etch release notes, security support for the Mozilla products in the oldstable distribution needed to be stopped before the end of the regular Etch security maintenance life cycle. You are strongly encouraged to upgrade to stable or switch to a still supported browser.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:04-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T07:51:16.287-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:02:31.499-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:01:51.515-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Release section" operator="AND">
        <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
        <criteria comment="Architecture section" operator="OR">
          <criteria comment="Architecture independent section" operator="AND">
            <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
            <criterion comment="libmozillainterfaces-java is earlier than 1.9.0.7-0lenny2" test_ref="oval:org.mitre.oval:tst:12982"/>
          </criteria>
          <criteria comment="Packages section" operator="OR">
            <criterion comment="libmozjs-dev DPKG is earlier than 1.9.0.7-0lenny2" test_ref="oval:org.mitre.oval:tst:12513"/>
            <criterion comment="spidermonkey-bin DPKG is earlier than 1.9.0.7-0lenny2" test_ref="oval:org.mitre.oval:tst:13312"/>
            <criterion comment="xulrunner-1.9-gnome-support DPKG is earlier than 1.9.0.7-0lenny2" test_ref="oval:org.mitre.oval:tst:13239"/>
            <criterion comment="xulrunner-1.9 DPKG is earlier than 1.9.0.7-0lenny2" test_ref="oval:org.mitre.oval:tst:12695"/>
            <criterion comment="libmozjs1d-dbg DPKG is earlier than 1.9.0.7-0lenny2" test_ref="oval:org.mitre.oval:tst:12889"/>
            <criterion comment="libmozjs1d DPKG is earlier than 1.9.0.7-0lenny2" test_ref="oval:org.mitre.oval:tst:12564"/>
            <criterion comment="python-xpcom DPKG is earlier than 1.9.0.7-0lenny2" test_ref="oval:org.mitre.oval:tst:12823"/>
            <criterion comment="xulrunner-1.9-dbg DPKG is earlier than 1.9.0.7-0lenny2" test_ref="oval:org.mitre.oval:tst:13221"/>
            <criterion comment="xulrunner-dev DPKG is earlier than 1.9.0.7-0lenny2" test_ref="oval:org.mitre.oval:tst:13527"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:7895" class="patch">
      <metadata>
        <title>DSA-1908 samba -- several vulnerabilities</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <product>samba</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2009/dsa-1908" ref_id="DSA-1908"/>
        <description>Several vulnerabilities have been discovered in samba, an implementation of the SMB/CIFS protocol for Unix systems, providing support for cross-platform file and printer sharing with other operating systems and more. The Common Vulnerabilities and Exposures project identifies the following problems: The mount.cifs utility is missing proper checks for file permissions when used in verbose mode. This allows local users to partly disclose the content of arbitrary files by specifying the file as credentials file and attempting to mount a samba share. A reply to an oplock break notification which samba doesn't expect could lead to the service getting stuck in an infinite loop. An attacker can use this to perform denial of service attacks via a specially crafted SMB request. A lack of error handling in case no home directory was configured/specified for the user could lead to file disclosure. In case the automated [homes] share is enabled or an explicit share is created with that username, samba fails to enforce sharing restrictions which results in an attacker being able to access the file system from the root directory.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:03-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T07:50:39.836-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:02:29.520-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:01:50.610-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Release section" operator="AND">
        <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
        <criteria comment="Architecture section" operator="OR">
          <criteria comment="Architecture independent section" operator="AND">
            <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
            <criteria comment="Packages section" operator="OR">
              <criterion comment="samba-doc is earlier than 3.2.5-4lenny7" test_ref="oval:org.mitre.oval:tst:12828"/>
              <criterion comment="samba-doc-pdf is earlier than 3.2.5-4lenny7" test_ref="oval:org.mitre.oval:tst:13125"/>
            </criteria>
          </criteria>
          <criteria comment="Architecture dependent section" operator="AND">
            <criteria comment="Supported architectures section" operator="OR">
              <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
              <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
              <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
              <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
              <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
              <criterion comment="Installed architecture is armel" test_ref="oval:org.mitre.oval:tst:11101"/>
              <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
              <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
              <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
              <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
              <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
              <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
            </criteria>
            <criteria comment="Packages section" operator="OR">
              <criterion comment="smbfs DPKG is earlier than 3.2.5-4lenny7" test_ref="oval:org.mitre.oval:tst:13014"/>
              <criterion comment="samba DPKG is earlier than 3.2.5-4lenny7" test_ref="oval:org.mitre.oval:tst:13162"/>
              <criterion comment="swat DPKG is earlier than 3.2.5-4lenny7" test_ref="oval:org.mitre.oval:tst:12725"/>
              <criterion comment="samba-tools DPKG is earlier than 3.2.5-4lenny7" test_ref="oval:org.mitre.oval:tst:12327"/>
              <criterion comment="libsmbclient DPKG is earlier than 3.2.5-4lenny7" test_ref="oval:org.mitre.oval:tst:13256"/>
              <criterion comment="smbclient DPKG is earlier than 3.2.5-4lenny7" test_ref="oval:org.mitre.oval:tst:13245"/>
              <criterion comment="libwbclient0 DPKG is earlier than 3.2.5-4lenny7" test_ref="oval:org.mitre.oval:tst:12891"/>
              <criterion comment="winbind DPKG is earlier than 3.2.5-4lenny7" test_ref="oval:org.mitre.oval:tst:12990"/>
              <criterion comment="samba-dbg DPKG is earlier than 3.2.5-4lenny7" test_ref="oval:org.mitre.oval:tst:13112"/>
              <criterion comment="libsmbclient-dev DPKG is earlier than 3.2.5-4lenny7" test_ref="oval:org.mitre.oval:tst:12997"/>
              <criterion comment="samba-common DPKG is earlier than 3.2.5-4lenny7" test_ref="oval:org.mitre.oval:tst:12731"/>
              <criterion comment="libpam-smbpass DPKG is earlier than 3.2.5-4lenny7" test_ref="oval:org.mitre.oval:tst:12336"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:7890" class="patch">
      <metadata>
        <title>DSA-1940 php5 -- multiple issues</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <platform>Debian GNU/Linux 4.0</platform>
          <product>php5</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2009/dsa-1940" ref_id="DSA-1940"/>
        <description>Several remote vulnerabilities have been discovered in the PHP 5 hypertext preprocessor. The Common Vulnerabilities and Exposures project identifies the following problems: The following issues have been fixed in both the stable (lenny) and the oldstable (etch) distributions: CVE-2009-2687, CVE-2009-3292. The exif module did not properly handle malformed jpeg files, allowing an attacker to cause a segfault, resulting in a denial of service. The php_openssl_apply_verification_policy() function did not properly perform certificate validation. Bogdan Calin discovered that a remote attacker could cause a denial of service by uploading a large number of files in using multipart/ form-data requests, causing the creation of a large number of temporary files. To address this issue, the max_file_uploads option introduced in PHP 5.3.1 has been backported. This option limits the maximum number of files uploaded per request. The default value for this new option is 50. See NEWS.Debian for more information. The following issue has been fixed in the stable (lenny) distribution: A flaw in the ini_restore() function could lead to a memory disclosure, possibly leading to the disclosure of sensitive data. In the oldstable (etch) distribution, this update also fixes a regression introduced by the fix for CVE-2008-5658 in DSA-1789-1 (bug #527560).</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:02-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T07:48:43.786-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:02:26.277-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:01:47.974-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Platform section" operator="OR">
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Architecture independent section" operator="AND">
              <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="php-pear is earlier than 5.2.6.dfsg.1-1+lenny4" test_ref="oval:org.mitre.oval:tst:11551"/>
                <criterion comment="php5 is earlier than 5.2.6.dfsg.1-1+lenny4" test_ref="oval:org.mitre.oval:tst:11427"/>
              </criteria>
            </criteria>
            <criteria comment="Architecture dependent section" operator="AND">
              <criteria comment="Supported architectures section" operator="OR">
                <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
                <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
                <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
                <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
                <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
                <criterion comment="Installed architecture is armel" test_ref="oval:org.mitre.oval:tst:11101"/>
                <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
                <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
                <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
                <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
                <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
                <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
              </criteria>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="php5-recode DPKG is earlier than 5.2.6.dfsg.1-1+lenny4" test_ref="oval:org.mitre.oval:tst:11657"/>
                <criterion comment="php5-cgi DPKG is earlier than 5.2.6.dfsg.1-1+lenny4" test_ref="oval:org.mitre.oval:tst:11785"/>
                <criterion comment="php5-curl DPKG is earlier than 5.2.6.dfsg.1-1+lenny4" test_ref="oval:org.mitre.oval:tst:11838"/>
                <criterion comment="php5-snmp DPKG is earlier than 5.2.6.dfsg.1-1+lenny4" test_ref="oval:org.mitre.oval:tst:11453"/>
                <criterion comment="php5-mysql DPKG is earlier than 5.2.6.dfsg.1-1+lenny4" test_ref="oval:org.mitre.oval:tst:11388"/>
                <criterion comment="php5-odbc DPKG is earlier than 5.2.6.dfsg.1-1+lenny4" test_ref="oval:org.mitre.oval:tst:11586"/>
                <criterion comment="php5-xsl DPKG is earlier than 5.2.6.dfsg.1-1+lenny4" test_ref="oval:org.mitre.oval:tst:11393"/>
                <criterion comment="php5-gd DPKG is earlier than 5.2.6.dfsg.1-1+lenny4" test_ref="oval:org.mitre.oval:tst:11877"/>
                <criterion comment="libapache2-mod-php5 DPKG is earlier than 5.2.6.dfsg.1-1+lenny4" test_ref="oval:org.mitre.oval:tst:11521"/>
                <criterion comment="php5-mhash DPKG is earlier than 5.2.6.dfsg.1-1+lenny4" test_ref="oval:org.mitre.oval:tst:11910"/>
                <criterion comment="php5-tidy DPKG is earlier than 5.2.6.dfsg.1-1+lenny4" test_ref="oval:org.mitre.oval:tst:11676"/>
                <criterion comment="php5-mcrypt DPKG is earlier than 5.2.6.dfsg.1-1+lenny4" test_ref="oval:org.mitre.oval:tst:11623"/>
                <criterion comment="php5-dev DPKG is earlier than 5.2.6.dfsg.1-1+lenny4" test_ref="oval:org.mitre.oval:tst:11512"/>
                <criterion comment="php5-pgsql DPKG is earlier than 5.2.6.dfsg.1-1+lenny4" test_ref="oval:org.mitre.oval:tst:11919"/>
                <criterion comment="php5-gmp DPKG is earlier than 5.2.6.dfsg.1-1+lenny4" test_ref="oval:org.mitre.oval:tst:11006"/>
                <criterion comment="php5-xmlrpc DPKG is earlier than 5.2.6.dfsg.1-1+lenny4" test_ref="oval:org.mitre.oval:tst:11905"/>
                <criterion comment="php5-imap DPKG is earlier than 5.2.6.dfsg.1-1+lenny4" test_ref="oval:org.mitre.oval:tst:11793"/>
                <criterion comment="php5-sqlite DPKG is earlier than 5.2.6.dfsg.1-1+lenny4" test_ref="oval:org.mitre.oval:tst:11776"/>
                <criterion comment="php5-ldap DPKG is earlier than 5.2.6.dfsg.1-1+lenny4" test_ref="oval:org.mitre.oval:tst:11478"/>
                <criterion comment="php5-cli DPKG is earlier than 5.2.6.dfsg.1-1+lenny4" test_ref="oval:org.mitre.oval:tst:11667"/>
                <criterion comment="php5-sybase DPKG is earlier than 5.2.6.dfsg.1-1+lenny4" test_ref="oval:org.mitre.oval:tst:11191"/>
                <criterion comment="php5-pspell DPKG is earlier than 5.2.6.dfsg.1-1+lenny4" test_ref="oval:org.mitre.oval:tst:11994"/>
                <criterion comment="libapache2-mod-php5filter DPKG is earlier than 5.2.6.dfsg.1-1+lenny4" test_ref="oval:org.mitre.oval:tst:11750"/>
                <criterion comment="php5-common DPKG is earlier than 5.2.6.dfsg.1-1+lenny4" test_ref="oval:org.mitre.oval:tst:11944"/>
                <criterion comment="php5-dbg DPKG is earlier than 5.2.6.dfsg.1-1+lenny4" test_ref="oval:org.mitre.oval:tst:11152"/>
              </criteria>
            </criteria>
            <criteria comment="Architecture dependent section" operator="AND">
              <criteria comment="Supported architectures section" operator="OR">
                <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
                <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
                <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
                <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
              </criteria>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="php5-interbase DPKG is earlier than 5.2.6.dfsg.1-1+lenny4" test_ref="oval:org.mitre.oval:tst:11782"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 4.0 is installed" definition_ref="oval:org.mitre.oval:def:6461"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Architecture independent section" operator="AND">
              <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="php5 is earlier than 5.2.0+dfsg-8+etch16" test_ref="oval:org.mitre.oval:tst:11870"/>
                <criterion comment="php-pear is earlier than 5.2.0+dfsg-8+etch16" test_ref="oval:org.mitre.oval:tst:11942"/>
              </criteria>
            </criteria>
            <criteria comment="Packages section" operator="OR">
              <criterion comment="libapache-mod-php5 DPKG is earlier than 5.2.0+dfsg-8+etch16" test_ref="oval:org.mitre.oval:tst:11979"/>
              <criterion comment="php5-recode DPKG is earlier than 5.2.0+dfsg-8+etch16" test_ref="oval:org.mitre.oval:tst:11570"/>
              <criterion comment="php5-xmlrpc DPKG is earlier than 5.2.0+dfsg-8+etch16" test_ref="oval:org.mitre.oval:tst:11720"/>
              <criterion comment="php5-curl DPKG is earlier than 5.2.0+dfsg-8+etch16" test_ref="oval:org.mitre.oval:tst:11163"/>
              <criterion comment="php5-snmp DPKG is earlier than 5.2.0+dfsg-8+etch16" test_ref="oval:org.mitre.oval:tst:11980"/>
              <criterion comment="php5-mysql DPKG is earlier than 5.2.0+dfsg-8+etch16" test_ref="oval:org.mitre.oval:tst:11043"/>
              <criterion comment="php5-odbc DPKG is earlier than 5.2.0+dfsg-8+etch16" test_ref="oval:org.mitre.oval:tst:11963"/>
              <criterion comment="php5-xsl DPKG is earlier than 5.2.0+dfsg-8+etch16" test_ref="oval:org.mitre.oval:tst:11807"/>
              <criterion comment="php5-gd DPKG is earlier than 5.2.0+dfsg-8+etch16" test_ref="oval:org.mitre.oval:tst:12021"/>
              <criterion comment="libapache2-mod-php5 DPKG is earlier than 5.2.0+dfsg-8+etch16" test_ref="oval:org.mitre.oval:tst:11911"/>
              <criterion comment="php5-mhash DPKG is earlier than 5.2.0+dfsg-8+etch16" test_ref="oval:org.mitre.oval:tst:11695"/>
              <criterion comment="php5-tidy DPKG is earlier than 5.2.0+dfsg-8+etch16" test_ref="oval:org.mitre.oval:tst:11734"/>
              <criterion comment="php5-mcrypt DPKG is earlier than 5.2.0+dfsg-8+etch16" test_ref="oval:org.mitre.oval:tst:12035"/>
              <criterion comment="php5-dev DPKG is earlier than 5.2.0+dfsg-8+etch16" test_ref="oval:org.mitre.oval:tst:11236"/>
              <criterion comment="php5-pgsql DPKG is earlier than 5.2.0+dfsg-8+etch16" test_ref="oval:org.mitre.oval:tst:11850"/>
              <criterion comment="php5-cgi DPKG is earlier than 5.2.0+dfsg-8+etch16" test_ref="oval:org.mitre.oval:tst:11081"/>
              <criterion comment="php5-imap DPKG is earlier than 5.2.0+dfsg-8+etch16" test_ref="oval:org.mitre.oval:tst:11970"/>
              <criterion comment="php5-sqlite DPKG is earlier than 5.2.0+dfsg-8+etch16" test_ref="oval:org.mitre.oval:tst:11840"/>
              <criterion comment="php5-ldap DPKG is earlier than 5.2.0+dfsg-8+etch16" test_ref="oval:org.mitre.oval:tst:11791"/>
              <criterion comment="php5-cli DPKG is earlier than 5.2.0+dfsg-8+etch16" test_ref="oval:org.mitre.oval:tst:12009"/>
              <criterion comment="php5-sybase DPKG is earlier than 5.2.0+dfsg-8+etch16" test_ref="oval:org.mitre.oval:tst:11620"/>
              <criterion comment="php5-pspell DPKG is earlier than 5.2.0+dfsg-8+etch16" test_ref="oval:org.mitre.oval:tst:11733"/>
              <criterion comment="php5-common DPKG is earlier than 5.2.0+dfsg-8+etch16" test_ref="oval:org.mitre.oval:tst:11981"/>
            </criteria>
            <criteria comment="Architecture dependent section" operator="AND">
              <criteria comment="Supported architectures section" operator="OR">
                <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
                <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
              </criteria>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="php5-interbase DPKG is earlier than 5.2.0+dfsg-8+etch16" test_ref="oval:org.mitre.oval:tst:11866"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:7880" class="patch">
      <metadata>
        <title>DSA-1791 moin -- insufficient input sanitising</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <product>moin</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2009/dsa-1791" ref_id="DSA-1791"/>
        <description>It was discovered that the AttachFile action in moin, a python clone of WikiWiki, is prone to cross-site scripting attacks when renaming attachements or performing other sub-actions. The oldstable distribution (etch) is not vulnerable.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:03-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T07:49:03.072-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:02:21.249-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:01:43.801-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Release section" operator="AND">
        <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
        <criteria comment="Architecture section" operator="OR">
          <criteria comment="Architecture independent section" operator="AND">
            <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
            <criterion comment="python-moinmoin is earlier than 1.7.1-3+lenny2" test_ref="oval:org.mitre.oval:tst:12036"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:7879" class="patch">
      <metadata>
        <title>DSA-1893 cyrus-imapd-2.2 kolab-cyrus-imapd -- buffer overflow</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <platform>Debian GNU/Linux 4.0</platform>
          <product>cyrus-imapd-2.2</product>
          <product>kolab-cyrus-imapd</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2009/dsa-1893" ref_id="DSA-1893"/>
        <description>It was discovered that the SIEVE component of cyrus-imapd and kolab-cyrus-imapd, the Cyrus mail system, is vulnerable to a buffer overflow when processing SIEVE scripts. This can be used to elevate privileges to the cyrus system user. An attacker who is able to install SIEVE scripts executed by the server is therefore able to read and modify arbitrary email messages on the system. The update introduced by DSA 1881-1 was incomplete and the issue has been given an additional CVE id due to its complexity.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:12-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T08:00:24.550-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:02:20.133-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:01:42.975-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Platform section" operator="OR">
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Architecture independent section" operator="AND">
              <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="cyrus-doc-2.2 is earlier than 2.2.13-14+lenny3" test_ref="oval:org.mitre.oval:tst:19636"/>
                <criterion comment="kolab-cyrus-admin is earlier than 2.2.13-5+lenny2" test_ref="oval:org.mitre.oval:tst:19537"/>
                <criterion comment="cyrus-admin-2.2 is earlier than 2.2.13-14+lenny3" test_ref="oval:org.mitre.oval:tst:19840"/>
              </criteria>
            </criteria>
            <criteria comment="Architecture dependent section" operator="AND">
              <criteria comment="Supported architectures section" operator="OR">
                <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
                <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
                <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
                <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
                <criterion comment="Installed architecture is armel" test_ref="oval:org.mitre.oval:tst:11101"/>
                <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
                <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
                <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
                <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
                <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
                <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
              </criteria>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="cyrus-clients-2.2 DPKG is earlier than 2.2.13-14+lenny3" test_ref="oval:org.mitre.oval:tst:20084"/>
                <criterion comment="kolab-libcyrus-imap-perl DPKG is earlier than 2.2.13-5+lenny2" test_ref="oval:org.mitre.oval:tst:20024"/>
                <criterion comment="kolab-cyrus-common DPKG is earlier than 2.2.13-5+lenny2" test_ref="oval:org.mitre.oval:tst:19914"/>
                <criterion comment="cyrus-nntpd-2.2 DPKG is earlier than 2.2.13-14+lenny3" test_ref="oval:org.mitre.oval:tst:19723"/>
                <criterion comment="cyrus-imapd-2.2 DPKG is earlier than 2.2.13-14+lenny3" test_ref="oval:org.mitre.oval:tst:20204"/>
                <criterion comment="kolab-cyrus-imapd DPKG is earlier than 2.2.13-5+lenny2" test_ref="oval:org.mitre.oval:tst:20227"/>
                <criterion comment="cyrus-dev-2.2 DPKG is earlier than 2.2.13-14+lenny3" test_ref="oval:org.mitre.oval:tst:20144"/>
                <criterion comment="cyrus-pop3d-2.2 DPKG is earlier than 2.2.13-14+lenny3" test_ref="oval:org.mitre.oval:tst:20216"/>
                <criterion comment="cyrus-common-2.2 DPKG is earlier than 2.2.13-14+lenny3" test_ref="oval:org.mitre.oval:tst:20171"/>
                <criterion comment="libcyrus-imap-perl22 DPKG is earlier than 2.2.13-14+lenny3" test_ref="oval:org.mitre.oval:tst:20035"/>
                <criterion comment="kolab-cyrus-pop3d DPKG is earlier than 2.2.13-5+lenny2" test_ref="oval:org.mitre.oval:tst:20023"/>
                <criterion comment="kolab-cyrus-clients DPKG is earlier than 2.2.13-5+lenny2" test_ref="oval:org.mitre.oval:tst:19619"/>
                <criterion comment="cyrus-murder-2.2 DPKG is earlier than 2.2.13-14+lenny3" test_ref="oval:org.mitre.oval:tst:20097"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 4.0 is installed" definition_ref="oval:org.mitre.oval:def:6461"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Architecture independent section" operator="AND">
              <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="cyrus-doc-2.2 is earlier than 2.2.13-10+etch4" test_ref="oval:org.mitre.oval:tst:20118"/>
                <criterion comment="kolab-cyrus-admin is earlier than 2.2.13-2+etch2" test_ref="oval:org.mitre.oval:tst:20233"/>
                <criterion comment="cyrus-admin-2.2 is earlier than 2.2.13-10+etch4" test_ref="oval:org.mitre.oval:tst:20129"/>
              </criteria>
            </criteria>
            <criteria comment="Packages section" operator="OR">
              <criterion comment="cyrus-clients-2.2 DPKG is earlier than 2.2.13-10+etch4" test_ref="oval:org.mitre.oval:tst:20187"/>
              <criterion comment="cyrus-nntpd-2.2 DPKG is earlier than 2.2.13-10+etch4" test_ref="oval:org.mitre.oval:tst:19741"/>
              <criterion comment="cyrus-imapd-2.2 DPKG is earlier than 2.2.13-10+etch4" test_ref="oval:org.mitre.oval:tst:20034"/>
              <criterion comment="cyrus-dev-2.2 DPKG is earlier than 2.2.13-10+etch4" test_ref="oval:org.mitre.oval:tst:20150"/>
              <criterion comment="cyrus-pop3d-2.2 DPKG is earlier than 2.2.13-10+etch4" test_ref="oval:org.mitre.oval:tst:19566"/>
              <criterion comment="cyrus-common-2.2 DPKG is earlier than 2.2.13-10+etch4" test_ref="oval:org.mitre.oval:tst:19829"/>
              <criterion comment="libcyrus-imap-perl22 DPKG is earlier than 2.2.13-10+etch4" test_ref="oval:org.mitre.oval:tst:19549"/>
              <criterion comment="cyrus-murder-2.2 DPKG is earlier than 2.2.13-10+etch4" test_ref="oval:org.mitre.oval:tst:20098"/>
            </criteria>
            <criteria comment="Architecture dependent section" operator="AND">
              <criteria comment="Supported architectures section" operator="OR">
                <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
                <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
                <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
                <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
                <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
                <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
                <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
                <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
                <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
              </criteria>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="kolab-libcyrus-imap-perl DPKG is earlier than 2.2.13-2+etch2" test_ref="oval:org.mitre.oval:tst:20114"/>
                <criterion comment="kolab-cyrus-pop3d DPKG is earlier than 2.2.13-2+etch2" test_ref="oval:org.mitre.oval:tst:19272"/>
                <criterion comment="kolab-cyrus-clients DPKG is earlier than 2.2.13-2+etch2" test_ref="oval:org.mitre.oval:tst:20221"/>
                <criterion comment="kolab-cyrus-common DPKG is earlier than 2.2.13-2+etch2" test_ref="oval:org.mitre.oval:tst:19947"/>
                <criterion comment="kolab-cyrus-imapd DPKG is earlier than 2.2.13-2+etch2" test_ref="oval:org.mitre.oval:tst:19708"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:7877" class="patch">
      <metadata>
        <title>DSA-1783 mysql-dfsg-5.0 -- multiple vulnerabilities</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <platform>Debian GNU/Linux 4.0</platform>
          <product>mysql-dfsg-5.0</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2009/dsa-1783" ref_id="DSA-1783"/>
        <description>Multiple vulnerabilities have been identified affecting MySQL, a relational database server, and its associated interactive client application. The Common Vulnerabilities and Exposures project identifies the following two problems: Kay Roepke reported that the MySQL server would not properly handle an empty bit-string literal in an SQL statement, allowing an authenticated remote attacker to cause a denial of service (a crash) in mysqld. This issue affects the oldstable distribution (etch), but not the stable distribution (lenny). Thomas Henlich reported that the MySQL commandline client application did not encode HTML special characters when run in HTML output mode (that is, "mysql --html ..."). This could potentially lead to cross-site scripting or unintended script privilege escalation if the resulting output is viewed in a browser or incorporated into a web site.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:10-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T07:58:07.988-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:02:18.606-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:01:41.895-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Platform section" operator="OR">
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Architecture independent section" operator="AND">
              <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="mysql-client is earlier than 5.0.51a-24+lenny1" test_ref="oval:org.mitre.oval:tst:18419"/>
                <criterion comment="mysql-common is earlier than 5.0.51a-24+lenny1" test_ref="oval:org.mitre.oval:tst:18765"/>
                <criterion comment="mysql-server is earlier than 5.0.51a-24+lenny1" test_ref="oval:org.mitre.oval:tst:18631"/>
              </criteria>
            </criteria>
            <criteria comment="Architecture dependent section" operator="AND">
              <criteria comment="Supported architectures section" operator="OR">
                <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
                <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
                <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
                <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
                <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
                <criterion comment="Installed architecture is armel" test_ref="oval:org.mitre.oval:tst:11101"/>
                <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
                <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
                <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
                <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
                <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
                <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
              </criteria>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="libmysqlclient15-dev DPKG is earlier than 5.0.51a-24+lenny1" test_ref="oval:org.mitre.oval:tst:18687"/>
                <criterion comment="mysql-client-5.0 DPKG is earlier than 5.0.51a-24+lenny1" test_ref="oval:org.mitre.oval:tst:18487"/>
                <criterion comment="mysql-server-5.0 DPKG is earlier than 5.0.51a-24+lenny1" test_ref="oval:org.mitre.oval:tst:18744"/>
                <criterion comment="libmysqlclient15off DPKG is earlier than 5.0.51a-24+lenny1" test_ref="oval:org.mitre.oval:tst:17890"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 4.0 is installed" definition_ref="oval:org.mitre.oval:def:6461"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Architecture independent section" operator="AND">
              <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="mysql-client is earlier than 5.0.32-7etch10" test_ref="oval:org.mitre.oval:tst:18632"/>
                <criterion comment="mysql-common is earlier than 5.0.32-7etch10" test_ref="oval:org.mitre.oval:tst:18178"/>
                <criterion comment="mysql-server is earlier than 5.0.32-7etch10" test_ref="oval:org.mitre.oval:tst:18770"/>
              </criteria>
            </criteria>
            <criteria comment="Architecture dependent section" operator="AND">
              <criteria comment="Supported architectures section" operator="OR">
                <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
                <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
                <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
                <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
                <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
                <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
                <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
                <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
                <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
                <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
              </criteria>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="libmysqlclient15-dev DPKG is earlier than 5.0.32-7etch10" test_ref="oval:org.mitre.oval:tst:18542"/>
                <criterion comment="mysql-server-4.1 DPKG is earlier than 5.0.32-7etch10" test_ref="oval:org.mitre.oval:tst:18626"/>
                <criterion comment="mysql-client-5.0 DPKG is earlier than 5.0.32-7etch10" test_ref="oval:org.mitre.oval:tst:18390"/>
                <criterion comment="libmysqlclient15off DPKG is earlier than 5.0.32-7etch10" test_ref="oval:org.mitre.oval:tst:18848"/>
                <criterion comment="mysql-server-5.0 DPKG is earlier than 5.0.32-7etch10" test_ref="oval:org.mitre.oval:tst:18526"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:7873" class="patch">
      <metadata>
        <title>DSA-1799 qemu -- several vulnerabilities</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <platform>Debian GNU/Linux 4.0</platform>
          <product>qemu</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2009/dsa-1799" ref_id="DSA-1799"/>
        <description>Several vulnerabilities have been discovered in the QEMU processor emulator. The Common Vulnerabilities and Exposures project identifies the following problems: Ian Jackson discovered that range checks of file operations on emulated disk devices were insufficiently enforced. It was discovered that an error in the format auto detection of removable media could lead to the disclosure of files in the host system. A buffer overflow has been found in the emulation of the Cirrus graphics adaptor.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:02-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T07:48:54.212-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:02:16.884-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:01:40.750-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Platform section" operator="OR">
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Architecture dependent section" operator="AND">
              <criteria comment="Supported architectures section" operator="OR">
                <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
                <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
                <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
                <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
              </criteria>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="qemu DPKG is earlier than 0.9.1-10lenny1" test_ref="oval:org.mitre.oval:tst:11573"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 4.0 is installed" definition_ref="oval:org.mitre.oval:def:6461"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Architecture dependent section" operator="AND">
              <criteria comment="Supported architectures section" operator="OR">
                <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
                <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
              </criteria>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="qemu DPKG is earlier than 0.8.2-4etch3" test_ref="oval:org.mitre.oval:tst:11949"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:7872" class="patch">
      <metadata>
        <title>DSA-1820 xulrunner -- several vulnerabilities</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <product>xulrunner</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2009/dsa-1820" ref_id="DSA-1820"/>
        <description>Several remote vulnerabilities have been discovered in Xulrunner, a runtime environment for XUL applications, such as the Iceweasel web browser. The Common Vulnerabilities and Exposures project identifies the following problems: Several issues in the browser engine have been discovered, which can result in the execution of arbitrary code. (MFSA 2009-24) It is possible to execute arbitrary code via vectors involving "double frame construction." (MFSA 2009-24) Jesse Ruderman and Adam Hauner discovered a problem in the JavaScript engine, which could lead to the execution of arbitrary code. (MFSA 2009-24) Pavel Cvrcek discovered a potential issue leading to a spoofing attack on the location bar related to certain invalid unicode characters. (MFSA 2009-25) Gregory Fleischer discovered that it is possible to read arbitrary cookies via a crafted HTML document. (MFSA 2009-26) Shuo Chen, Ziqing Mao, Yi-Min Wang and Ming Zhang reported a potential man-in-the-middle attack, when using a proxy due to insufficient checks on a certain proxy response. (MFSA 2009-27) Jakob Balle and Carsten Eiram reported a race condition in the NPObjWrapper_NewResolve function that can be used to execute arbitrary code. (MFSA 2009-28) moz_bug_r_a4 discovered that it is possible to execute arbitrary JavaScript with chrome privileges due to an error in the garbage-collection implementation. (MFSA 2009-29) Adam Barth and Collin Jackson reported a potential privilege escalation when loading a file::resource via the location bar. (MFSA 2009-30) Wladimir Palant discovered that it is possible to bypass access restrictions due to a lack of content policy check, when loading a script file into a XUL document. (MFSA 2009-31) moz_bug_r_a4 reported that it is possible for scripts from page content to run with elevated privileges and thus potentially executing arbitrary code with the object's chrome privileges. (MFSA 2009-32)</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:08-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T07:55:57.554-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:02:16.364-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:01:40.251-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Release section" operator="AND">
        <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
        <criteria comment="Architecture section" operator="OR">
          <criteria comment="Architecture independent section" operator="AND">
            <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
            <criterion comment="libmozillainterfaces-java is earlier than 1.9.0.11-0lenny1" test_ref="oval:org.mitre.oval:tst:17320"/>
          </criteria>
          <criteria comment="Architecture dependent section" operator="AND">
            <criteria comment="Supported architectures section" operator="OR">
              <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
              <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
              <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
              <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
              <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
              <criterion comment="Installed architecture is armel" test_ref="oval:org.mitre.oval:tst:11101"/>
              <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
              <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
              <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
              <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
              <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
              <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
            </criteria>
            <criteria comment="Packages section" operator="OR">
              <criterion comment="libmozjs-dev DPKG is earlier than 1.9.0.11-0lenny1" test_ref="oval:org.mitre.oval:tst:16391"/>
              <criterion comment="spidermonkey-bin DPKG is earlier than 1.9.0.11-0lenny1" test_ref="oval:org.mitre.oval:tst:17100"/>
              <criterion comment="xulrunner-dev DPKG is earlier than 1.9.0.11-0lenny1" test_ref="oval:org.mitre.oval:tst:17290"/>
              <criterion comment="xulrunner-1.9 DPKG is earlier than 1.9.0.11-0lenny1" test_ref="oval:org.mitre.oval:tst:17344"/>
              <criterion comment="libmozjs1d-dbg DPKG is earlier than 1.9.0.11-0lenny1" test_ref="oval:org.mitre.oval:tst:17347"/>
              <criterion comment="libmozjs1d DPKG is earlier than 1.9.0.11-0lenny1" test_ref="oval:org.mitre.oval:tst:16845"/>
              <criterion comment="python-xpcom DPKG is earlier than 1.9.0.11-0lenny1" test_ref="oval:org.mitre.oval:tst:17144"/>
              <criterion comment="xulrunner-1.9-dbg DPKG is earlier than 1.9.0.11-0lenny1" test_ref="oval:org.mitre.oval:tst:17374"/>
              <criterion comment="xulrunner-1.9-gnome-support DPKG is earlier than 1.9.0.11-0lenny1" test_ref="oval:org.mitre.oval:tst:17324"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:7870" class="patch">
      <metadata>
        <title>DSA-1914 mapserver -- several vulnerabilities</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <platform>Debian GNU/Linux 4.0</platform>
          <product>mapserver</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2009/dsa-1914" ref_id="DSA-1914"/>
        <description>Several vulnerabilities have been discovered in mapserver, a CGI-based web framework to publish spatial data and interactive mapping applications. The Common Vulnerabilities and Exposures project identifies the following problems: Missing input validation on a user supplied map queryfile name can be used by an attacker to check for the existence of a specific file by using the queryfile GET parameter and checking for differences in error messages. A lack of file type verification when parsing a map file can lead to partial disclosure of content from arbitrary files through parser error messages. Due to missing input validation when saving map files under certain conditions it is possible to perform directory traversal attacks and to create arbitrary files. NOTE: Unless the attacker is able to create directories in the image path or there is already a readable directory this doesn't affect installations on Linux as the fopen() syscall will fail in case a sub path is not readable. It was discovered that mapserver is vulnerable to a stack-based buffer overflow when processing certain GET parameters. An attacker can use this to execute arbitrary code on the server via crafted id parameters. An integer overflow leading to a heap-based buffer overflow when processing the Content-Length header of an HTTP request can be used by an attacker to execute arbitrary code via crafted POST requests containing negative Content-Length values. An integer overflow when processing HTTP requests can lead to a heap-based buffer overflow. An attacker can use this to execute arbitrary code either via crafted Content-Length values or large HTTP request. This is partly because of an incomplete fix for CVE-2009-0840.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:07-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T07:54:21.897-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:02:14.485-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:01:38.487-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Platform section" operator="OR">
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Architecture independent section" operator="AND">
              <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="mapserver-doc is earlier than 5.0.3-3+lenny4" test_ref="oval:org.mitre.oval:tst:15901"/>
                <criterion comment="libmapscript-ruby is earlier than 5.0.3-3+lenny4" test_ref="oval:org.mitre.oval:tst:16241"/>
              </criteria>
            </criteria>
            <criteria comment="Architecture dependent section" operator="AND">
              <criteria comment="Supported architectures section" operator="OR">
                <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
                <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
                <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
                <criterion comment="Installed architecture is armel" test_ref="oval:org.mitre.oval:tst:11101"/>
                <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
                <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
                <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
                <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
                <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
              </criteria>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="mapserver-bin DPKG is earlier than 5.0.3-3+lenny4" test_ref="oval:org.mitre.oval:tst:16361"/>
                <criterion comment="python-mapscript DPKG is earlier than 5.0.3-3+lenny4" test_ref="oval:org.mitre.oval:tst:16222"/>
                <criterion comment="libmapscript-ruby1.8 DPKG is earlier than 5.0.3-3+lenny4" test_ref="oval:org.mitre.oval:tst:16080"/>
                <criterion comment="libmapscript-ruby1.9 DPKG is earlier than 5.0.3-3+lenny4" test_ref="oval:org.mitre.oval:tst:15908"/>
                <criterion comment="perl-mapscript DPKG is earlier than 5.0.3-3+lenny4" test_ref="oval:org.mitre.oval:tst:15856"/>
                <criterion comment="php5-mapscript DPKG is earlier than 5.0.3-3+lenny4" test_ref="oval:org.mitre.oval:tst:16389"/>
                <criterion comment="cgi-mapserver DPKG is earlier than 5.0.3-3+lenny4" test_ref="oval:org.mitre.oval:tst:16327"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 4.0 is installed" definition_ref="oval:org.mitre.oval:def:6461"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Architecture independent section" operator="AND">
              <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criterion comment="mapserver-doc is earlier than 4.10.0-5.1+etch4" test_ref="oval:org.mitre.oval:tst:16169"/>
            </criteria>
            <criteria comment="Architecture dependent section" operator="AND">
              <criteria comment="Supported architectures section" operator="OR">
                <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
                <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
                <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
                <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
                <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
                <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
                <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
                <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
              </criteria>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="mapserver-bin DPKG is earlier than 4.10.0-5.1+etch4" test_ref="oval:org.mitre.oval:tst:16315"/>
                <criterion comment="python-mapscript DPKG is earlier than 4.10.0-5.1+etch4" test_ref="oval:org.mitre.oval:tst:16284"/>
                <criterion comment="perl-mapscript DPKG is earlier than 4.10.0-5.1+etch4" test_ref="oval:org.mitre.oval:tst:16164"/>
                <criterion comment="php5-mapscript DPKG is earlier than 4.10.0-5.1+etch4" test_ref="oval:org.mitre.oval:tst:16175"/>
                <criterion comment="cgi-mapserver DPKG is earlier than 4.10.0-5.1+etch4" test_ref="oval:org.mitre.oval:tst:16338"/>
                <criterion comment="php4-mapscript DPKG is earlier than 4.10.0-5.1+etch4" test_ref="oval:org.mitre.oval:tst:15472"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:7866" class="patch">
      <metadata>
        <title>DSA-1841 git-core -- denial of service</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <platform>Debian GNU/Linux 4.0</platform>
          <product>git-core</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2009/dsa-1841" ref_id="DSA-1841"/>
        <description>It was discovered that git-daemon which is part of git-core, a popular distributed revision control system, is vulnerable to denial of service attacks caused by a programming mistake in handling requests containing extra unrecognized arguments which results in an infinite loop. While this is no problem for the daemon itself as every request will spawn a new git-daemon instance, this still results in a very high CPU consumption and might lead to denial of service conditions.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:03-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T07:50:09.927-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:02:11.862-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:01:37.232-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Platform section" operator="OR">
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Architecture independent section" operator="AND">
              <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="gitweb is earlier than 1.5.6.5-3+lenny2" test_ref="oval:org.mitre.oval:tst:12655"/>
                <criterion comment="git-arch is earlier than 1.5.6.5-3+lenny2" test_ref="oval:org.mitre.oval:tst:12008"/>
                <criterion comment="gitk is earlier than 1.5.6.5-3+lenny2" test_ref="oval:org.mitre.oval:tst:12432"/>
                <criterion comment="git-gui is earlier than 1.5.6.5-3+lenny2" test_ref="oval:org.mitre.oval:tst:12754"/>
                <criterion comment="git-daemon-run is earlier than 1.5.6.5-3+lenny2" test_ref="oval:org.mitre.oval:tst:12570"/>
                <criterion comment="git-doc is earlier than 1.5.6.5-3+lenny2" test_ref="oval:org.mitre.oval:tst:12675"/>
                <criterion comment="git-svn is earlier than 1.5.6.5-3+lenny2" test_ref="oval:org.mitre.oval:tst:12255"/>
                <criterion comment="git-cvs is earlier than 1.5.6.5-3+lenny2" test_ref="oval:org.mitre.oval:tst:12277"/>
                <criterion comment="git-email is earlier than 1.5.6.5-3+lenny2" test_ref="oval:org.mitre.oval:tst:12486"/>
              </criteria>
            </criteria>
            <criteria comment="Architecture dependent section" operator="AND">
              <criteria comment="Supported architectures section" operator="OR">
                <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
                <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
                <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
                <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
                <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
                <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
                <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
                <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
              </criteria>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="git-core DPKG is earlier than 1.5.6.5-3+lenny2" test_ref="oval:org.mitre.oval:tst:12569"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 4.0 is installed" definition_ref="oval:org.mitre.oval:def:6461"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Architecture independent section" operator="AND">
              <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="gitweb is earlier than 1.4.4.4-4+etch3" test_ref="oval:org.mitre.oval:tst:12713"/>
                <criterion comment="git-arch is earlier than 1.4.4.4-4+etch3" test_ref="oval:org.mitre.oval:tst:12615"/>
                <criterion comment="gitk is earlier than 1.4.4.4-4+etch3" test_ref="oval:org.mitre.oval:tst:12711"/>
                <criterion comment="git-daemon-run is earlier than 1.4.4.4-4+etch3" test_ref="oval:org.mitre.oval:tst:12748"/>
                <criterion comment="git-doc is earlier than 1.4.4.4-4+etch3" test_ref="oval:org.mitre.oval:tst:12683"/>
                <criterion comment="git-svn is earlier than 1.4.4.4-4+etch3" test_ref="oval:org.mitre.oval:tst:11796"/>
                <criterion comment="git-cvs is earlier than 1.4.4.4-4+etch3" test_ref="oval:org.mitre.oval:tst:12136"/>
                <criterion comment="git-email is earlier than 1.4.4.4-4+etch3" test_ref="oval:org.mitre.oval:tst:12714"/>
              </criteria>
            </criteria>
            <criteria comment="Architecture dependent section" operator="AND">
              <criteria comment="Supported architectures section" operator="OR">
                <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
                <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
                <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
                <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
                <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
                <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
                <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
                <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
                <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
              </criteria>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="git-core DPKG is earlier than 1.4.4.4-4+etch3" test_ref="oval:org.mitre.oval:tst:12619"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7864" version="1" class="patch">
      <metadata>
        <title>DSA-1793 kdegraphics -- multiple vulnerabilities</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <platform>Debian GNU/Linux 4.0</platform>
          <product>kdegraphics</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2009/dsa-1793" ref_id="DSA-1793"/>
        <description>kpdf, a Portable Document Format (PDF) viewer for KDE, is based on the xpdf program and thus suffers from similar flaws to those described in DSA-1790. The Common Vulnerabilities and Exposures project identifies the following problems: Multiple buffer overflows in the JBIG2 decoder in kpdf allow remote attackers to cause a denial of service (crash) via a crafted PDF file, related to (1) JBIG2SymbolDict::setBitmap and (2) JBIG2Stream::readSymbolDictSeg. Multiple integer overflows in the JBIG2 decoder in kpdf allow remote attackers to cause a denial of service (crash) via a crafted PDF file, related to (1) JBIG2Stream::readSymbolDictSeg, (2) JBIG2Stream::readSymbolDictSeg, and (3) JBIG2Stream::readGenericBitmap. Integer overflow in the JBIG2 decoder in kpdf has unspecified impact related to "g*allocn." The JBIG2 decoder in kpdf allows remote attackers to cause a denial of service (crash) via a crafted PDF file that triggers a free of uninitialized memory. The JBIG2 decoder in kpdf allows remote attackers to cause a denial of service (crash) via a crafted PDF file that triggers an out-of-bounds read. Multiple "input validation flaws" in the JBIG2 decoder in kpdf allow remote attackers to execute arbitrary code via a crafted PDF file. Integer overflow in the JBIG2 decoder in kpdf allows remote attackers to execute arbitrary code via a crafted PDF file. The JBIG2 decoder in kpdf allows remote attackers to execute arbitrary code via a crafted PDF file that triggers a free of invalid data. The JBIG2 decoder in kpdf allows remote attackers to cause a denial of service (crash) via a crafted PDF file that triggers a NULL pointer dereference. Multiple buffer overflows in the JBIG2 MMR decoder in kpdf allow remote attackers to execute arbitrary code via a crafted PDF file. The JBIG2 MMR decoder in kpdf allows remote attackers to cause a denial of service (infinite loop and hang) via a crafted PDF file. The old stable distribution (etch), these problems have been fixed in version 3.5.5-3etch3.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:02-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T07:49:01.580-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:02:10.551-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:01:36.129-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Release section">
          <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
          <criteria operator="OR" comment="Architecture section">
            <criteria operator="AND" comment="Architecture independent section">
              <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criteria operator="OR" comment="Packages section">
                <criterion comment="kdegraphics is earlier than 3.5.9-3+lenny1" test_ref="oval:org.mitre.oval:tst:11739"/>
                <criterion comment="kdegraphics-doc-html is earlier than 3.5.9-3+lenny1" test_ref="oval:org.mitre.oval:tst:41028"/>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Architecture dependent section">
              <criteria operator="OR" comment="Supported architectures section">
                <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
                <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
                <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
                <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
                <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
                <criterion comment="Installed architecture is armel" test_ref="oval:org.mitre.oval:tst:11101"/>
                <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
                <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
                <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
                <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
                <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
                <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
              </criteria>
              <criteria operator="OR" comment="Packages section">
                <criterion comment="kdegraphics-kfile-plugins is earlier than 3.5.9-3+lenny1" test_ref="oval:org.mitre.oval:tst:11465"/>
                <criterion comment="ksvg is earlier than 3.5.9-3+lenny1" test_ref="oval:org.mitre.oval:tst:41742"/>
                <criterion comment="libkscan-dev is earlier than 3.5.9-3+lenny1" test_ref="oval:org.mitre.oval:tst:11769"/>
                <criterion comment="kgamma is earlier than 3.5.9-3+lenny1" test_ref="oval:org.mitre.oval:tst:11735"/>
                <criterion comment="libkscan1 is earlier than 3.5.9-3+lenny1" test_ref="oval:org.mitre.oval:tst:11170"/>
                <criterion comment="kpovmodeler is earlier than 3.5.9-3+lenny1" test_ref="oval:org.mitre.oval:tst:11935"/>
                <criterion comment="kooka is earlier than 3.5.9-3+lenny1" test_ref="oval:org.mitre.oval:tst:11597"/>
                <criterion comment="kdegraphics-dev is earlier than 3.5.9-3+lenny1" test_ref="oval:org.mitre.oval:tst:12015"/>
                <criterion comment="kghostview is earlier than 3.5.9-3+lenny1" test_ref="oval:org.mitre.oval:tst:11990"/>
                <criterion comment="kfaxview is earlier than 3.5.9-3+lenny1" test_ref="oval:org.mitre.oval:tst:11869"/>
                <criterion comment="kviewshell is earlier than 3.5.9-3+lenny1" test_ref="oval:org.mitre.oval:tst:11652"/>
                <criterion comment="kview is earlier than 3.5.9-3+lenny1" test_ref="oval:org.mitre.oval:tst:12052"/>
                <criterion comment="kfax is earlier than 3.5.9-3+lenny1" test_ref="oval:org.mitre.oval:tst:41005"/>
                <criterion comment="ksnapshot is earlier than 3.5.9-3+lenny1" test_ref="oval:org.mitre.oval:tst:11812"/>
                <criterion comment="kmrml is earlier than 3.5.9-3+lenny1" test_ref="oval:org.mitre.oval:tst:11746"/>
                <criterion comment="kpdf is earlier than 3.5.9-3+lenny1" test_ref="oval:org.mitre.oval:tst:11693"/>
                <criterion comment="kcoloredit is earlier than 3.5.9-3+lenny1" test_ref="oval:org.mitre.oval:tst:41845"/>
                <criterion comment="kiconedit is earlier than 3.5.9-3+lenny1" test_ref="oval:org.mitre.oval:tst:11212"/>
                <criterion comment="kruler is earlier than 3.5.9-3+lenny1" test_ref="oval:org.mitre.oval:tst:11758"/>
                <criterion comment="kuickshow is earlier than 3.5.9-3+lenny1" test_ref="oval:org.mitre.oval:tst:11862"/>
                <criterion comment="kdvi is earlier than 3.5.9-3+lenny1" test_ref="oval:org.mitre.oval:tst:12000"/>
                <criterion comment="kdegraphics-dbg is earlier than 3.5.9-3+lenny1" test_ref="oval:org.mitre.oval:tst:11730"/>
                <criterion comment="kolourpaint is earlier than 3.5.9-3+lenny1" test_ref="oval:org.mitre.oval:tst:11818"/>
                <criterion comment="kamera is earlier than 3.5.9-3+lenny1" test_ref="oval:org.mitre.oval:tst:11650"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Release section">
          <extend_definition comment="Debian 4.0 is installed." definition_ref="oval:org.mitre.oval:def:6461"/>
          <criteria operator="OR" comment="Architecture section">
            <criteria operator="AND" comment="Architecture independent section">
              <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criteria operator="OR" comment="Packages section">
                <criterion comment="kdegraphics is earlier than 3.5.5-3etch3" test_ref="oval:org.mitre.oval:tst:11715"/>
                <criterion comment="kdegraphics-doc-html is earlier than 3.5.5-3etch3" test_ref="oval:org.mitre.oval:tst:11997"/>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Architecture dependent section">
              <criteria operator="OR" comment="Supported architectures section">
                <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
                <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
                <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
                <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
                <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
                <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
                <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
                <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
                <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
                <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
              </criteria>
              <criteria operator="OR" comment="Packages section">
                <criterion comment="kdegraphics-kfile-plugins is earlier than 3.5.5-3etch3" test_ref="oval:org.mitre.oval:tst:12045"/>
                <criterion comment="ksvg is earlier than 3.5.5-3etch3" test_ref="oval:org.mitre.oval:tst:12043"/>
                <criterion comment="libkscan-dev is earlier than 3.5.5-3etch3" test_ref="oval:org.mitre.oval:tst:11888"/>
                <criterion comment="kgamma is earlier than 3.5.5-3etch3" test_ref="oval:org.mitre.oval:tst:12050"/>
                <criterion comment="libkscan1 is earlier than 3.5.5-3etch3" test_ref="oval:org.mitre.oval:tst:11855"/>
                <criterion comment="kpovmodeler is earlier than 3.5.5-3etch3" test_ref="oval:org.mitre.oval:tst:11483"/>
                <criterion comment="kooka is earlier than 3.5.5-3etch3" test_ref="oval:org.mitre.oval:tst:11762"/>
                <criterion comment="kdegraphics-dev is earlier than 3.5.5-3etch3" test_ref="oval:org.mitre.oval:tst:11952"/>
                <criterion comment="kghostview is earlier than 3.5.5-3etch3" test_ref="oval:org.mitre.oval:tst:12004"/>
                <criterion comment="kfaxview is earlier than 3.5.5-3etch3" test_ref="oval:org.mitre.oval:tst:11928"/>
                <criterion comment="kviewshell is earlier than 3.5.5-3etch3" test_ref="oval:org.mitre.oval:tst:11319"/>
                <criterion comment="kview is earlier than 3.5.5-3etch3" test_ref="oval:org.mitre.oval:tst:12034"/>
                <criterion comment="kfax is earlier than 3.5.5-3etch3" test_ref="oval:org.mitre.oval:tst:11916"/>
                <criterion comment="ksnapshot is earlier than 3.5.5-3etch3" test_ref="oval:org.mitre.oval:tst:11616"/>
                <criterion comment="kmrml is earlier than 3.5.5-3etch3" test_ref="oval:org.mitre.oval:tst:11709"/>
                <criterion comment="kpdf is earlier than 3.5.5-3etch3" test_ref="oval:org.mitre.oval:tst:11953"/>
                <criterion comment="kcoloredit is earlier than 3.5.5-3etch3" test_ref="oval:org.mitre.oval:tst:11332"/>
                <criterion comment="kiconedit is earlier than 3.5.5-3etch3" test_ref="oval:org.mitre.oval:tst:11921"/>
                <criterion comment="kruler is earlier than 3.5.5-3etch3" test_ref="oval:org.mitre.oval:tst:11781"/>
                <criterion comment="kuickshow is earlier than 3.5.5-3etch3" test_ref="oval:org.mitre.oval:tst:11978"/>
                <criterion comment="kdvi is earlier than 3.5.5-3etch3" test_ref="oval:org.mitre.oval:tst:12059"/>
                <criterion comment="kdegraphics-dbg is earlier than 3.5.5-3etch3" test_ref="oval:org.mitre.oval:tst:11914"/>
                <criterion comment="kolourpaint is earlier than 3.5.5-3etch3" test_ref="oval:org.mitre.oval:tst:11445"/>
                <criterion comment="kamera is earlier than 3.5.5-3etch3" test_ref="oval:org.mitre.oval:tst:11085"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:7863" class="patch">
      <metadata>
        <title>DSA-1842 openexr -- several vulnerabilities</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <platform>Debian GNU/Linux 4.0</platform>
          <product>openexr</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2009/dsa-1842" ref_id="DSA-1842"/>
        <description>Several vulnerabilities have been discovered in the OpenEXR image library, which can lead to the execution of arbitrary code. The Common Vulnerabilities and Exposures project identifies the following problems: Drew Yao discovered integer overflows in the preview and compression code. Drew Yao discovered that an uninitialised pointer could be freed in the decompression code. A buffer overflow was discovered in the compression code.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:03-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T07:50:07.678-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:02:09.338-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:01:35.634-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Platform section" operator="OR">
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Architecture dependent section" operator="AND">
              <criteria comment="Supported architectures section" operator="OR">
                <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
                <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
                <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
                <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
                <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
                <criterion comment="Installed architecture is armel" test_ref="oval:org.mitre.oval:tst:11101"/>
                <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
                <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
                <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
                <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
                <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
                <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
              </criteria>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="libopenexr-dev DPKG is earlier than 1.6.1-3+lenny3" test_ref="oval:org.mitre.oval:tst:12512"/>
                <criterion comment="openexr DPKG is earlier than 1.6.1-3+lenny3" test_ref="oval:org.mitre.oval:tst:12326"/>
                <criterion comment="libopenexr6 DPKG is earlier than 1.6.1-3+lenny3" test_ref="oval:org.mitre.oval:tst:12696"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 4.0 is installed" definition_ref="oval:org.mitre.oval:def:6461"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Packages section" operator="OR">
              <criterion comment="openexr DPKG is earlier than 1.2.2-4.3+etch2" test_ref="oval:org.mitre.oval:tst:12744"/>
              <criterion comment="libopenexr-dev DPKG is earlier than 1.2.2-4.3+etch2" test_ref="oval:org.mitre.oval:tst:12707"/>
              <criterion comment="libopenexr2c2a DPKG is earlier than 1.2.2-4.3+etch2" test_ref="oval:org.mitre.oval:tst:12737"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:7859" class="patch">
      <metadata>
        <title>DSA-1875 ikiwiki -- missing input sanitising</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <product>ikiwiki</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2009/dsa-1875" ref_id="DSA-1875"/>
        <description>Josh Triplett discovered that the blacklist for potentially harmful TeX code of the teximg module of the Ikiwiki wiki compiler was incomplete, resulting in information disclosure. The old stable distribution (etch) is not affected.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:06-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T07:53:42.746-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:02:08.965-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:01:35.421-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Release section" operator="AND">
        <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
        <criteria comment="Architecture section" operator="OR">
          <criteria comment="Architecture independent section" operator="AND">
            <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
            <criterion comment="ikiwiki is earlier than 2.53.4" test_ref="oval:org.mitre.oval:tst:15315"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:7856" class="patch">
      <metadata>
        <title>DSA-1792 drupal6 -- multiple vulnerabilities</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <product>drupal6</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2009/dsa-1792" ref_id="DSA-1792"/>
        <description>Multiple vulnerabilities have been discovered in drupal, a web content management system. The Common Vulnerabilities and Exposures project identifies the following problems: pod.Edge discovered a cross-site scripting vulnerability due that can be triggered when some browsers interpret UTF-8 strings as UTF-7 if they appear before the generated HTML document defines its Content-Type. This allows a malicious user to execute arbitrary javascript in the context of the web site if they're allowed to post content. Moritz Naumann discovered an information disclosure vulnerability. If a user is tricked into visiting the site via a specially crafted URL and then submits a form (such as the search box) from that page, the information in their form submission may be directed to a third-party site determined by the URL and thus disclosed to the third party. The third party site may then execute a cross-site request forgery attack against the submitted form. The old stable distribution (etch) does not contain drupal and is not affected.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:03-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T07:49:02.760-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:02:07.476-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:01:34.503-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Release section" operator="AND">
        <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
        <criteria comment="Architecture section" operator="OR">
          <criteria comment="Architecture independent section" operator="AND">
            <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
            <criterion comment="drupal6 is earlier than 6.6-3lenny1" test_ref="oval:org.mitre.oval:tst:11475"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7855" version="1" class="patch">
      <metadata>
        <title>DSA-1944 request-tracker3.4 request-tracker3.6 -- session hijack</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <platform>Debian GNU/Linux 4.0</platform>
          <product>request-tracker3.4</product>
          <product>request-tracker3.6</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2009/dsa-1944" ref_id="DSA-1944"/>
        <description>Mikal Gule discovered that request-tracker, an extensible trouble-ticket tracking system, is prone to an attack, where an attacker with access to the same domain can hijack a user's RT session.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:02-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T07:48:49.782-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:02:06.727-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:01:33.934-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Release section">
          <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
          <criteria operator="OR" comment="Architecture section">
            <criteria operator="AND" comment="Architecture independent section">
              <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criteria operator="OR" comment="Packages section">
                <criterion comment="rt3.6-db-sqlite is earlier than 3.6.7-5+lenny3" test_ref="oval:org.mitre.oval:tst:11777"/>
                <criterion comment="rt3.6-db-postgresql is earlier than 3.6.7-5+lenny3" test_ref="oval:org.mitre.oval:tst:11982"/>
                <criterion comment="request-tracker3.6 is earlier than 3.6.7-5+lenny3" test_ref="oval:org.mitre.oval:tst:11615"/>
                <criterion comment="rt3.6-apache2 is earlier than 3.6.7-5+lenny3" test_ref="oval:org.mitre.oval:tst:11592"/>
                <criterion comment="rt3.6-db-mysql is earlier than 3.6.7-5+lenny3" test_ref="oval:org.mitre.oval:tst:11973"/>
                <criterion comment="rt3.6-clients is earlier than 3.6.7-5+lenny3" test_ref="oval:org.mitre.oval:tst:11992"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Release section">
          <extend_definition comment="Debian 4.0 is installed." definition_ref="oval:org.mitre.oval:def:6461"/>
          <criteria operator="OR" comment="Architecture section">
            <criteria operator="AND" comment="Architecture independent section">
              <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criteria operator="OR" comment="Packages section">
                <criterion comment="request-tracker3.4 is earlier than 3.4.5-2+etch1" test_ref="oval:org.mitre.oval:tst:41392"/>
                <criterion comment="rt3.4-clients is earlier than 3.4.5-2+etch1" test_ref="oval:org.mitre.oval:tst:12032"/>
                <criterion comment="rt3.4-apache is earlier than 3.4.5-2+etch1" test_ref="oval:org.mitre.oval:tst:11061"/>
                <criterion comment="rt3.6-apache2 is earlier than 3.6.1-4+etch1" test_ref="oval:org.mitre.oval:tst:11805"/>
                <criterion comment="rt3.4-apache2 is earlier than 3.4.5-2+etch1" test_ref="oval:org.mitre.oval:tst:11518"/>
                <criterion comment="rt3.6-apache is earlier than 3.6.1-4+etch1" test_ref="oval:org.mitre.oval:tst:11630"/>
                <criterion comment="request-tracker3.6 is earlier than 3.6.1-4+etch1" test_ref="oval:org.mitre.oval:tst:11813"/>
                <criterion comment="rt3.6-clients is earlier than 3.6.1-4+etch1" test_ref="oval:org.mitre.oval:tst:11867"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:7853" class="patch">
      <metadata>
        <title>DSA-1860 ruby1.8, ruby1.9 -- several vulnerabilities</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <platform>Debian GNU/Linux 4.0</platform>
          <product>ruby1.8</product>
          <product>ruby1.9</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2009/dsa-1860" ref_id="DSA-1860"/>
        <description>Several vulnerabilities have been discovered in Ruby. The Common Vulnerabilities and Exposures project identifies the following problems: The return value from the OCSP_basic_verify function was not checked properly, allowing continued use of a revoked certificate. An issue in parsing BigDecimal numbers can result in a denial-of-service condition (crash). The following matrix identifies fixed versions: We recommend that you upgrade your Ruby packages.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:08-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T07:56:51.963-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:02:04.648-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:01:32.216-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Platform section" operator="OR">
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Architecture independent section" operator="AND">
              <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="rdoc1.8 is earlier than 1.8.7.72-3lenny1" test_ref="oval:org.mitre.oval:tst:17006"/>
                <criterion comment="rdoc1.9 is earlier than 1.9.0.2-9lenny1" test_ref="oval:org.mitre.oval:tst:17811"/>
                <criterion comment="ri1.9 is earlier than 1.9.0.2-9lenny1" test_ref="oval:org.mitre.oval:tst:17795"/>
                <criterion comment="ri1.8 is earlier than 1.8.7.72-3lenny1" test_ref="oval:org.mitre.oval:tst:17876"/>
                <criterion comment="ruby1.8-examples is earlier than 1.8.7.72-3lenny1" test_ref="oval:org.mitre.oval:tst:17495"/>
                <criterion comment="ruby1.9-examples is earlier than 1.9.0.2-9lenny1" test_ref="oval:org.mitre.oval:tst:17879"/>
                <criterion comment="ruby1.8-elisp is earlier than 1.8.7.72-3lenny1" test_ref="oval:org.mitre.oval:tst:17836"/>
                <criterion comment="ruby1.9-elisp is earlier than 1.9.0.2-9lenny1" test_ref="oval:org.mitre.oval:tst:17780"/>
                <criterion comment="irb1.8 is earlier than 1.8.7.72-3lenny1" test_ref="oval:org.mitre.oval:tst:17919"/>
                <criterion comment="irb1.9 is earlier than 1.9.0.2-9lenny1" test_ref="oval:org.mitre.oval:tst:17757"/>
              </criteria>
            </criteria>
            <criteria comment="Architecture dependent section" operator="AND">
              <criteria comment="Supported architectures section" operator="OR">
                <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
                <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
                <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
                <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
                <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
                <criterion comment="Installed architecture is armel" test_ref="oval:org.mitre.oval:tst:11101"/>
                <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
                <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
                <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
                <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
                <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
              </criteria>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="ruby1.8 DPKG is earlier than 1.8.7.72-3lenny1" test_ref="oval:org.mitre.oval:tst:17940"/>
                <criterion comment="libdbm-ruby1.8 DPKG is earlier than 1.8.7.72-3lenny1" test_ref="oval:org.mitre.oval:tst:17789"/>
                <criterion comment="ruby1.9-dev DPKG is earlier than 1.9.0.2-9lenny1" test_ref="oval:org.mitre.oval:tst:17372"/>
                <criterion comment="libopenssl-ruby1.9 DPKG is earlier than 1.9.0.2-9lenny1" test_ref="oval:org.mitre.oval:tst:17556"/>
                <criterion comment="libopenssl-ruby1.8 DPKG is earlier than 1.8.7.72-3lenny1" test_ref="oval:org.mitre.oval:tst:17591"/>
                <criterion comment="ruby1.8-dev DPKG is earlier than 1.8.7.72-3lenny1" test_ref="oval:org.mitre.oval:tst:17882"/>
                <criterion comment="libtcltk-ruby1.9 DPKG is earlier than 1.9.0.2-9lenny1" test_ref="oval:org.mitre.oval:tst:17790"/>
                <criterion comment="libreadline-ruby1.8 DPKG is earlier than 1.8.7.72-3lenny1" test_ref="oval:org.mitre.oval:tst:17787"/>
                <criterion comment="libreadline-ruby1.9 DPKG is earlier than 1.9.0.2-9lenny1" test_ref="oval:org.mitre.oval:tst:17988"/>
                <criterion comment="ruby1.9 DPKG is earlier than 1.9.0.2-9lenny1" test_ref="oval:org.mitre.oval:tst:17261"/>
                <criterion comment="libruby1.9-dbg DPKG is earlier than 1.9.0.2-9lenny1" test_ref="oval:org.mitre.oval:tst:17871"/>
                <criterion comment="libtcltk-ruby1.8 DPKG is earlier than 1.8.7.72-3lenny1" test_ref="oval:org.mitre.oval:tst:17140"/>
                <criterion comment="libgdbm-ruby1.8 DPKG is earlier than 1.8.7.72-3lenny1" test_ref="oval:org.mitre.oval:tst:17867"/>
                <criterion comment="libgdbm-ruby1.9 DPKG is earlier than 1.9.0.2-9lenny1" test_ref="oval:org.mitre.oval:tst:17023"/>
                <criterion comment="libdbm-ruby1.9 DPKG is earlier than 1.9.0.2-9lenny1" test_ref="oval:org.mitre.oval:tst:17529"/>
                <criterion comment="libruby1.8-dbg DPKG is earlier than 1.8.7.72-3lenny1" test_ref="oval:org.mitre.oval:tst:17804"/>
                <criterion comment="libruby1.8 DPKG is earlier than 1.8.7.72-3lenny1" test_ref="oval:org.mitre.oval:tst:17769"/>
                <criterion comment="libruby1.9 DPKG is earlier than 1.9.0.2-9lenny1" test_ref="oval:org.mitre.oval:tst:17129"/>
              </criteria>
            </criteria>
            <criteria comment="Architecture dependent section" operator="AND">
              <criteria comment="Supported architectures section" operator="OR">
                <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
              </criteria>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="libreadline-ruby1.8 DPKG is earlier than 1.8.7.72-3lenny1" test_ref="oval:org.mitre.oval:tst:17960"/>
                <criterion comment="libdbm-ruby1.8 DPKG is earlier than 1.8.7.72-3lenny1" test_ref="oval:org.mitre.oval:tst:17570"/>
                <criterion comment="libopenssl-ruby1.8 DPKG is earlier than 1.8.7.72-3lenny1" test_ref="oval:org.mitre.oval:tst:17841"/>
                <criterion comment="ruby1.8-dev DPKG is earlier than 1.8.7.72-3lenny1" test_ref="oval:org.mitre.oval:tst:17042"/>
                <criterion comment="ruby1.8 DPKG is earlier than 1.8.7.72-3lenny1" test_ref="oval:org.mitre.oval:tst:17958"/>
                <criterion comment="libgdbm-ruby1.8 DPKG is earlier than 1.8.7.72-3lenny1" test_ref="oval:org.mitre.oval:tst:17855"/>
                <criterion comment="libtcltk-ruby1.8 DPKG is earlier than 1.8.7.72-3lenny1" test_ref="oval:org.mitre.oval:tst:17920"/>
                <criterion comment="libruby1.8-dbg DPKG is earlier than 1.8.7.72-3lenny1" test_ref="oval:org.mitre.oval:tst:17972"/>
                <criterion comment="libruby1.8 DPKG is earlier than 1.8.7.72-3lenny1" test_ref="oval:org.mitre.oval:tst:17743"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 4.0 is installed" definition_ref="oval:org.mitre.oval:def:6461"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Architecture independent section" operator="AND">
              <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="rdoc1.8 is earlier than 1.8.5-4etch5" test_ref="oval:org.mitre.oval:tst:17785"/>
                <criterion comment="rdoc1.9 is earlier than 1.9.0+20060609-1etch5" test_ref="oval:org.mitre.oval:tst:17901"/>
                <criterion comment="ri1.9 is earlier than 1.9.0+20060609-1etch5" test_ref="oval:org.mitre.oval:tst:17638"/>
                <criterion comment="ri1.8 is earlier than 1.8.5-4etch5" test_ref="oval:org.mitre.oval:tst:17721"/>
                <criterion comment="ruby1.8-examples is earlier than 1.8.5-4etch5" test_ref="oval:org.mitre.oval:tst:17908"/>
                <criterion comment="ruby1.9-examples is earlier than 1.9.0+20060609-1etch5" test_ref="oval:org.mitre.oval:tst:17963"/>
                <criterion comment="ruby1.8-elisp is earlier than 1.8.5-4etch5" test_ref="oval:org.mitre.oval:tst:17643"/>
                <criterion comment="ruby1.9-elisp is earlier than 1.9.0+20060609-1etch5" test_ref="oval:org.mitre.oval:tst:17726"/>
                <criterion comment="irb1.8 is earlier than 1.8.5-4etch5" test_ref="oval:org.mitre.oval:tst:18014"/>
                <criterion comment="irb1.9 is earlier than 1.9.0+20060609-1etch5" test_ref="oval:org.mitre.oval:tst:17588"/>
              </criteria>
            </criteria>
            <criteria comment="Architecture dependent section" operator="AND">
              <criteria comment="Supported architectures section" operator="OR">
                <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
                <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
                <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
                <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
                <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
                <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
                <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
                <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
                <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
              </criteria>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="ruby1.8 DPKG is earlier than 1.8.5-4etch5" test_ref="oval:org.mitre.oval:tst:17766"/>
                <criterion comment="libdbm-ruby1.8 DPKG is earlier than 1.8.5-4etch5" test_ref="oval:org.mitre.oval:tst:17258"/>
                <criterion comment="libdbm-ruby1.9 DPKG is earlier than 1.9.0+20060609-1etch5" test_ref="oval:org.mitre.oval:tst:17774"/>
                <criterion comment="libopenssl-ruby1.9 DPKG is earlier than 1.9.0+20060609-1etch5" test_ref="oval:org.mitre.oval:tst:17985"/>
                <criterion comment="libopenssl-ruby1.8 DPKG is earlier than 1.8.5-4etch5" test_ref="oval:org.mitre.oval:tst:17803"/>
                <criterion comment="ruby1.8-dev DPKG is earlier than 1.8.5-4etch5" test_ref="oval:org.mitre.oval:tst:17428"/>
                <criterion comment="libtcltk-ruby1.9 DPKG is earlier than 1.9.0+20060609-1etch5" test_ref="oval:org.mitre.oval:tst:17997"/>
                <criterion comment="libreadline-ruby1.8 DPKG is earlier than 1.8.5-4etch5" test_ref="oval:org.mitre.oval:tst:17819"/>
                <criterion comment="libreadline-ruby1.9 DPKG is earlier than 1.9.0+20060609-1etch5" test_ref="oval:org.mitre.oval:tst:17886"/>
                <criterion comment="ruby1.9-dev DPKG is earlier than 1.9.0+20060609-1etch5" test_ref="oval:org.mitre.oval:tst:17675"/>
                <criterion comment="ruby1.9 DPKG is earlier than 1.9.0+20060609-1etch5" test_ref="oval:org.mitre.oval:tst:17870"/>
                <criterion comment="libruby1.9-dbg DPKG is earlier than 1.9.0+20060609-1etch5" test_ref="oval:org.mitre.oval:tst:17885"/>
                <criterion comment="libgdbm-ruby1.9 DPKG is earlier than 1.9.0+20060609-1etch5" test_ref="oval:org.mitre.oval:tst:17842"/>
                <criterion comment="libgdbm-ruby1.8 DPKG is earlier than 1.8.5-4etch5" test_ref="oval:org.mitre.oval:tst:17798"/>
                <criterion comment="libtcltk-ruby1.8 DPKG is earlier than 1.8.5-4etch5" test_ref="oval:org.mitre.oval:tst:17848"/>
                <criterion comment="libruby1.8-dbg DPKG is earlier than 1.8.5-4etch5" test_ref="oval:org.mitre.oval:tst:17900"/>
                <criterion comment="libruby1.8 DPKG is earlier than 1.8.5-4etch5" test_ref="oval:org.mitre.oval:tst:17995"/>
                <criterion comment="libruby1.9 DPKG is earlier than 1.9.0+20060609-1etch5" test_ref="oval:org.mitre.oval:tst:17191"/>
              </criteria>
            </criteria>
            <criteria comment="Architecture dependent section" operator="AND">
              <criteria comment="Supported architectures section" operator="OR">
                <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
              </criteria>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="ruby1.9 DPKG is earlier than 1.9.0+20060609-1etch5" test_ref="oval:org.mitre.oval:tst:17470"/>
                <criterion comment="libdbm-ruby1.9 DPKG is earlier than 1.9.0+20060609-1etch5" test_ref="oval:org.mitre.oval:tst:17777"/>
                <criterion comment="libopenssl-ruby1.9 DPKG is earlier than 1.9.0+20060609-1etch5" test_ref="oval:org.mitre.oval:tst:17776"/>
                <criterion comment="ruby1.9-dev DPKG is earlier than 1.9.0+20060609-1etch5" test_ref="oval:org.mitre.oval:tst:17486"/>
                <criterion comment="libreadline-ruby1.9 DPKG is earlier than 1.9.0+20060609-1etch5" test_ref="oval:org.mitre.oval:tst:17832"/>
                <criterion comment="libruby1.9-dbg DPKG is earlier than 1.9.0+20060609-1etch5" test_ref="oval:org.mitre.oval:tst:17525"/>
                <criterion comment="libtcltk-ruby1.9 DPKG is earlier than 1.9.0+20060609-1etch5" test_ref="oval:org.mitre.oval:tst:17043"/>
                <criterion comment="libgdbm-ruby1.9 DPKG is earlier than 1.9.0+20060609-1etch5" test_ref="oval:org.mitre.oval:tst:18042"/>
                <criterion comment="libruby1.9 DPKG is earlier than 1.9.0+20060609-1etch5" test_ref="oval:org.mitre.oval:tst:17710"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:7843" class="patch">
      <metadata>
        <title>DSA-1781 ffmpeg-debian -- several vulnerabilities</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <platform>Debian GNU/Linux 4.0</platform>
          <product>ffmpeg-debian</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2009/dsa-1781" ref_id="DSA-1781"/>
        <description>Several vulnerabilities have been discovered in ffmpeg, a multimedia player, server and encoder. The Common Vulnerabilities and Exposures project identifies the following problems: It was discovered that watching a malformed 4X movie file could lead to the execution of arbitrary code. It was discovered that using a crafted STR file can lead to the execution of arbitrary code.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:10-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T07:58:05.557-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:02:00.609-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:01:28.951-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Platform section" operator="OR">
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Architecture independent section" operator="AND">
              <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criterion comment="ffmpeg-doc is earlier than 0.svn20080206-17+lenny1" test_ref="oval:org.mitre.oval:tst:18143"/>
            </criteria>
            <criteria comment="Architecture dependent section" operator="AND">
              <criteria comment="Supported architectures section" operator="OR">
                <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
                <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
                <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
                <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
                <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
                <criterion comment="Installed architecture is armel" test_ref="oval:org.mitre.oval:tst:11101"/>
                <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
                <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
                <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
                <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
                <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
                <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
              </criteria>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="ffmpeg-dbg DPKG is earlier than 0.svn20080206-17+lenny1" test_ref="oval:org.mitre.oval:tst:18834"/>
                <criterion comment="libavcodec51 DPKG is earlier than 0.svn20080206-17+lenny1" test_ref="oval:org.mitre.oval:tst:18573"/>
                <criterion comment="ffmpeg DPKG is earlier than 0.svn20080206-17+lenny1" test_ref="oval:org.mitre.oval:tst:18690"/>
                <criterion comment="libswscale0 DPKG is earlier than 0.svn20080206-17+lenny1" test_ref="oval:org.mitre.oval:tst:18459"/>
                <criterion comment="libavutil-dev DPKG is earlier than 0.svn20080206-17+lenny1" test_ref="oval:org.mitre.oval:tst:18773"/>
                <criterion comment="libavformat52 DPKG is earlier than 0.svn20080206-17+lenny1" test_ref="oval:org.mitre.oval:tst:18403"/>
                <criterion comment="libpostproc-dev DPKG is earlier than 0.svn20080206-17+lenny1" test_ref="oval:org.mitre.oval:tst:18258"/>
                <criterion comment="libpostproc51 DPKG is earlier than 0.svn20080206-17+lenny1" test_ref="oval:org.mitre.oval:tst:18625"/>
                <criterion comment="libavdevice52 DPKG is earlier than 0.svn20080206-17+lenny1" test_ref="oval:org.mitre.oval:tst:18779"/>
                <criterion comment="libavcodec-dev DPKG is earlier than 0.svn20080206-17+lenny1" test_ref="oval:org.mitre.oval:tst:18388"/>
                <criterion comment="libswscale-dev DPKG is earlier than 0.svn20080206-17+lenny1" test_ref="oval:org.mitre.oval:tst:18724"/>
                <criterion comment="libavutil49 DPKG is earlier than 0.svn20080206-17+lenny1" test_ref="oval:org.mitre.oval:tst:18731"/>
                <criterion comment="libavformat-dev DPKG is earlier than 0.svn20080206-17+lenny1" test_ref="oval:org.mitre.oval:tst:18370"/>
                <criterion comment="libavdevice-dev DPKG is earlier than 0.svn20080206-17+lenny1" test_ref="oval:org.mitre.oval:tst:18778"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 4.0 is installed" definition_ref="oval:org.mitre.oval:def:6461"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Packages section" operator="OR">
              <criterion comment="ffmpeg DPKG is earlier than 0.cvs20060823-8+etch1" test_ref="oval:org.mitre.oval:tst:18645"/>
              <criterion comment="libavcodec-dev DPKG is earlier than 0.cvs20060823-8+etch1" test_ref="oval:org.mitre.oval:tst:18843"/>
              <criterion comment="libavcodec0d DPKG is earlier than 0.cvs20060823-8+etch1" test_ref="oval:org.mitre.oval:tst:18181"/>
              <criterion comment="libavformat0d DPKG is earlier than 0.cvs20060823-8+etch1" test_ref="oval:org.mitre.oval:tst:18714"/>
              <criterion comment="libpostproc0d DPKG is earlier than 0.cvs20060823-8+etch1" test_ref="oval:org.mitre.oval:tst:18709"/>
              <criterion comment="libavformat-dev DPKG is earlier than 0.cvs20060823-8+etch1" test_ref="oval:org.mitre.oval:tst:18349"/>
              <criterion comment="libpostproc-dev DPKG is earlier than 0.cvs20060823-8+etch1" test_ref="oval:org.mitre.oval:tst:18234"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:7833" class="patch">
      <metadata>
        <title>DSA-1857 camlimages -- integer overflow</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <platform>Debian GNU/Linux 4.0</platform>
          <product>camlimages</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2009/dsa-1857" ref_id="DSA-1857"/>
        <description>Tielei Wang discovered that CamlImages, an open source image processing library, suffers from several integer overflows which may lead to a potentially exploitable heap overflow and result in arbitrary code execution. This advisory addresses issues with the reading of JPEG and GIF Images, while DSA 1832-1 addressed the issue with PNG images.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:11-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T07:58:57.121-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:01:59.450-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:01:27.904-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Platform section" operator="OR">
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Architecture independent section" operator="AND">
              <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criterion comment="libcamlimages-ocaml-doc is earlier than 2.2.0-4+lenny2" test_ref="oval:org.mitre.oval:tst:19083"/>
            </criteria>
            <criteria comment="Architecture dependent section" operator="AND">
              <criteria comment="Supported architectures section" operator="OR">
                <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
                <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
                <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
                <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
                <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
                <criterion comment="Installed architecture is armel" test_ref="oval:org.mitre.oval:tst:11101"/>
                <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
                <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
                <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
                <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
                <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
                <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
              </criteria>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="libcamlimages-ocaml DPKG is earlier than 2.2.0-4+lenny2" test_ref="oval:org.mitre.oval:tst:18925"/>
                <criterion comment="libcamlimages-ocaml-dev DPKG is earlier than 2.2.0-4+lenny2" test_ref="oval:org.mitre.oval:tst:19106"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 4.0 is installed" definition_ref="oval:org.mitre.oval:def:6461"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Architecture independent section" operator="AND">
              <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criterion comment="libcamlimages-ocaml-doc is earlier than 2.20-8+etch2" test_ref="oval:org.mitre.oval:tst:18638"/>
            </criteria>
            <criteria comment="Architecture dependent section" operator="AND">
              <criteria comment="Supported architectures section" operator="OR">
                <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
                <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
                <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
                <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
                <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
                <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
                <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
                <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
                <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
                <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
              </criteria>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="libcamlimages-ocaml DPKG is earlier than 2.20-8+etch2" test_ref="oval:org.mitre.oval:tst:19020"/>
                <criterion comment="libcamlimages-ocaml-dev DPKG is earlier than 2.20-8+etch2" test_ref="oval:org.mitre.oval:tst:19270"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:7832" class="patch">
      <metadata>
        <title>DSA-1840 xulrunner -- several vulnerabilities</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <product>xulrunner</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2009/dsa-1840" ref_id="DSA-1840"/>
        <description>Several remote vulnerabilities have been discovered in Xulrunner, a runtime environment for XUL applications, such as the Iceweasel web browser. The Common Vulnerabilities and Exposures project identifies the following problems: Martijn Wargers, Arno Renevier, Jesse Ruderman, Olli Pettay and Blake Kaplan disocvered several issues in the browser engine that could potentially lead to the execution of arbitrary code. (MFSA 2009-34) monarch2020 reported an integer overflow in a base64 decoding function. (MFSA 2009-34) Christophe Charron reported a possibly exploitable crash occuring when multiple RDF files were loaded in a XUL tree element. (MFSA 2009-34) Yongqian Li reported that an unsafe memory condition could be created by specially crafted document. (MFSA 2009-34) Peter Van der Beken, Mike Shaver, Jesse Ruderman, and Carsten Book discovered several issues in the JavaScript engine that could possibly lead to the execution of arbitrary JavaScript. (MFSA 2009-34) Attila Suszter discovered an issue related to a specially crafted Flash object, which could be used to run arbitrary code. (MFSA 2009-35) PenPal discovered that it is possible to execute arbitrary code via a specially crafted SVG element. (MFSA 2009-37) Blake Kaplan discovered a flaw in the JavaScript engine that might allow an attacker to execute arbitrary JavaScript with chrome privileges. (MFSA 2009-39) moz_bug_r_a4 discovered an issue in the JavaScript engine that could be used to perform cross-site scripting attacks. (MFSA 2009-40)</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:03-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T07:50:11.394-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:01:58.813-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:01:27.430-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Release section" operator="AND">
        <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
        <criteria comment="Architecture section" operator="OR">
          <criteria comment="Architecture independent section" operator="AND">
            <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
            <criterion comment="libmozillainterfaces-java is earlier than 1.9.0.12-0lenny1" test_ref="oval:org.mitre.oval:tst:12664"/>
          </criteria>
          <criteria comment="Architecture dependent section" operator="AND">
            <criteria comment="Supported architectures section" operator="OR">
              <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
              <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
              <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
              <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
              <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
              <criterion comment="Installed architecture is armel" test_ref="oval:org.mitre.oval:tst:11101"/>
              <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
              <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
              <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
            </criteria>
            <criteria comment="Packages section" operator="OR">
              <criterion comment="libmozjs-dev DPKG is earlier than 1.9.0.12-0lenny1" test_ref="oval:org.mitre.oval:tst:12042"/>
              <criterion comment="spidermonkey-bin DPKG is earlier than 1.9.0.12-0lenny1" test_ref="oval:org.mitre.oval:tst:12746"/>
              <criterion comment="xulrunner-dev DPKG is earlier than 1.9.0.12-0lenny1" test_ref="oval:org.mitre.oval:tst:12783"/>
              <criterion comment="xulrunner-1.9 DPKG is earlier than 1.9.0.12-0lenny1" test_ref="oval:org.mitre.oval:tst:12776"/>
              <criterion comment="libmozjs1d-dbg DPKG is earlier than 1.9.0.12-0lenny1" test_ref="oval:org.mitre.oval:tst:12791"/>
              <criterion comment="libmozjs1d DPKG is earlier than 1.9.0.12-0lenny1" test_ref="oval:org.mitre.oval:tst:12631"/>
              <criterion comment="python-xpcom DPKG is earlier than 1.9.0.12-0lenny1" test_ref="oval:org.mitre.oval:tst:12360"/>
              <criterion comment="xulrunner-1.9-dbg DPKG is earlier than 1.9.0.12-0lenny1" test_ref="oval:org.mitre.oval:tst:12601"/>
              <criterion comment="xulrunner-1.9-gnome-support DPKG is earlier than 1.9.0.12-0lenny1" test_ref="oval:org.mitre.oval:tst:12435"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:7831" class="patch">
      <metadata>
        <title>DSA-1832 camlimages -- integer overflow</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <platform>Debian GNU/Linux 4.0</platform>
          <product>camlimages</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2009/dsa-1832" ref_id="DSA-1832"/>
        <description>Tielei Wang discovered that CamlImages, an open source image processing library, suffers from several integer overflows which may lead to a potentially exploitable heap overflow and result in arbitrary code execution.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:05-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T07:52:36.173-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:01:58.308-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:01:26.901-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Platform section" operator="OR">
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Architecture independent section" operator="AND">
              <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criterion comment="libcamlimages-ocaml-doc is earlier than 2.2.0-4+lenny1" test_ref="oval:org.mitre.oval:tst:14708"/>
            </criteria>
            <criteria comment="Architecture dependent section" operator="AND">
              <criteria comment="Supported architectures section" operator="OR">
                <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
                <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
                <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
                <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
                <criterion comment="Installed architecture is armel" test_ref="oval:org.mitre.oval:tst:11101"/>
                <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
                <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
                <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
                <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
                <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
                <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
              </criteria>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="libcamlimages-ocaml DPKG is earlier than 2.2.0-4+lenny1" test_ref="oval:org.mitre.oval:tst:14667"/>
                <criterion comment="libcamlimages-ocaml-dev DPKG is earlier than 2.2.0-4+lenny1" test_ref="oval:org.mitre.oval:tst:14664"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 4.0 is installed" definition_ref="oval:org.mitre.oval:def:6461"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Architecture independent section" operator="AND">
              <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criterion comment="libcamlimages-ocaml-doc is earlier than 2.20-8+etch1" test_ref="oval:org.mitre.oval:tst:14359"/>
            </criteria>
            <criteria comment="Architecture dependent section" operator="AND">
              <criteria comment="Supported architectures section" operator="OR">
                <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
                <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
                <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
                <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
                <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
                <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
                <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
                <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
                <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
                <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
              </criteria>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="libcamlimages-ocaml DPKG is earlier than 2.20-8+etch1" test_ref="oval:org.mitre.oval:tst:14589"/>
                <criterion comment="libcamlimages-ocaml-dev DPKG is earlier than 2.20-8+etch1" test_ref="oval:org.mitre.oval:tst:14287"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:7828" class="patch">
      <metadata>
        <title>DSA-1900 postgresql-7.4, postgresql-8.1, postgresql-8.3, postgresql-8.4 -- several vulnerabilities</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <platform>Debian GNU/Linux 4.0</platform>
          <product>postgresql-7.4</product>
          <product>postgresql-8.1</product>
          <product>postgresql-8.3</product>
          <product>postgresql-8.4</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2009/dsa-1900" ref_id="DSA-1900"/>
        <description>Several vulnerabilities have been discovered in PostgreSQL, an SQL database system. The Common Vulnerabilities and Exposures project identifies the following problems: Authenticated users can shut down the backend server by re-LOAD-ing libraries in $libdir/plugins, if any libraries are present there. (The old stable distribution (etch) is not affected by this issue.) Authenticated non-superusers can gain database superuser privileges if they can create functions and tables due to incorrect execution of functions in functional indexes. If PostgreSQL is configured with LDAP authentication, and the LDAP configuration allows anonymous binds, it is possible for a user to authenticate themselves with an empty password. (The old stable distribution (etch) is not affected by this issue.) In addition, this update contains reliability improvements which do not target security issues.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:04-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T07:50:51.125-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:01:56.420-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:01:25.313-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Platform section" operator="OR">
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Architecture independent section" operator="AND">
              <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="postgresql-doc is earlier than 8.3.8-0lenny1" test_ref="oval:org.mitre.oval:tst:13224"/>
                <criterion comment="postgresql-doc-8.3 is earlier than 8.3.8-0lenny1" test_ref="oval:org.mitre.oval:tst:13111"/>
                <criterion comment="postgresql-contrib is earlier than 8.3.8-0lenny1" test_ref="oval:org.mitre.oval:tst:13198"/>
                <criterion comment="postgresql-client is earlier than 8.3.8-0lenny1" test_ref="oval:org.mitre.oval:tst:12804"/>
                <criterion comment="postgresql is earlier than 8.3.8-0lenny1" test_ref="oval:org.mitre.oval:tst:13240"/>
              </criteria>
            </criteria>
            <criteria comment="Architecture dependent section" operator="AND">
              <criteria comment="Supported architectures section" operator="OR">
                <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
                <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
                <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
                <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
                <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
                <criterion comment="Installed architecture is armel" test_ref="oval:org.mitre.oval:tst:11101"/>
                <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
                <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
                <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
                <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
                <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
                <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
              </criteria>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="postgresql-client-8.3 DPKG is earlier than 8.3.8-0lenny1" test_ref="oval:org.mitre.oval:tst:12852"/>
                <criterion comment="postgresql-plperl-8.3 DPKG is earlier than 8.3.8-0lenny1" test_ref="oval:org.mitre.oval:tst:12976"/>
                <criterion comment="postgresql-8.3 DPKG is earlier than 8.3.8-0lenny1" test_ref="oval:org.mitre.oval:tst:13150"/>
                <criterion comment="libecpg6 DPKG is earlier than 8.3.8-0lenny1" test_ref="oval:org.mitre.oval:tst:13230"/>
                <criterion comment="libpq5 DPKG is earlier than 8.3.8-0lenny1" test_ref="oval:org.mitre.oval:tst:12816"/>
                <criterion comment="postgresql-plpython-8.3 DPKG is earlier than 8.3.8-0lenny1" test_ref="oval:org.mitre.oval:tst:13017"/>
                <criterion comment="postgresql-pltcl-8.3 DPKG is earlier than 8.3.8-0lenny1" test_ref="oval:org.mitre.oval:tst:13065"/>
                <criterion comment="postgresql-server-dev-8.3 DPKG is earlier than 8.3.8-0lenny1" test_ref="oval:org.mitre.oval:tst:13267"/>
                <criterion comment="libecpg-dev DPKG is earlier than 8.3.8-0lenny1" test_ref="oval:org.mitre.oval:tst:13205"/>
                <criterion comment="postgresql-contrib-8.3 DPKG is earlier than 8.3.8-0lenny1" test_ref="oval:org.mitre.oval:tst:13311"/>
                <criterion comment="libpq-dev DPKG is earlier than 8.3.8-0lenny1" test_ref="oval:org.mitre.oval:tst:12949"/>
                <criterion comment="libpgtypes3 DPKG is earlier than 8.3.8-0lenny1" test_ref="oval:org.mitre.oval:tst:13229"/>
                <criterion comment="libecpg-compat3 DPKG is earlier than 8.3.8-0lenny1" test_ref="oval:org.mitre.oval:tst:12709"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 4.0 is installed" definition_ref="oval:org.mitre.oval:def:6461"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Architecture independent section" operator="AND">
              <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="postgresql-doc-8.1 is earlier than 8.1.18-0etch1" test_ref="oval:org.mitre.oval:tst:13320"/>
                <criterion comment="postgresql-server-dev-7.4 is earlier than 7.4.26-0etch1" test_ref="oval:org.mitre.oval:tst:13040"/>
                <criterion comment="postgresql-doc-7.4 is earlier than 7.4.26-0etch1" test_ref="oval:org.mitre.oval:tst:13318"/>
              </criteria>
            </criteria>
            <criteria comment="Architecture dependent section" operator="AND">
              <criteria comment="Supported architectures section" operator="OR">
                <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
                <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
                <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
                <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
                <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
                <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
                <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
                <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
                <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
                <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
              </criteria>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="postgresql-7.4 DPKG is earlier than 7.4.26-0etch1" test_ref="oval:org.mitre.oval:tst:12422"/>
                <criterion comment="postgresql-client-8.1 DPKG is earlier than 8.1.18-0etch1" test_ref="oval:org.mitre.oval:tst:12922"/>
                <criterion comment="postgresql-8.1 DPKG is earlier than 8.1.18-0etch1" test_ref="oval:org.mitre.oval:tst:12978"/>
                <criterion comment="libpq-dev DPKG is earlier than 8.1.18-0etch1" test_ref="oval:org.mitre.oval:tst:13022"/>
                <criterion comment="postgresql-plpython-7.4 DPKG is earlier than 7.4.26-0etch1" test_ref="oval:org.mitre.oval:tst:13420"/>
                <criterion comment="postgresql-contrib-8.1 DPKG is earlier than 8.1.18-0etch1" test_ref="oval:org.mitre.oval:tst:13386"/>
                <criterion comment="postgresql-contrib-7.4 DPKG is earlier than 7.4.26-0etch1" test_ref="oval:org.mitre.oval:tst:13378"/>
                <criterion comment="libecpg5 DPKG is earlier than 8.1.18-0etch1" test_ref="oval:org.mitre.oval:tst:12667"/>
                <criterion comment="postgresql-pltcl-8.1 DPKG is earlier than 8.1.18-0etch1" test_ref="oval:org.mitre.oval:tst:13338"/>
                <criterion comment="postgresql-client-7.4 DPKG is earlier than 7.4.26-0etch1" test_ref="oval:org.mitre.oval:tst:13098"/>
                <criterion comment="postgresql-plpython-8.1 DPKG is earlier than 8.1.18-0etch1" test_ref="oval:org.mitre.oval:tst:13259"/>
                <criterion comment="postgresql-server-dev-8.1 DPKG is earlier than 8.1.18-0etch1" test_ref="oval:org.mitre.oval:tst:13011"/>
                <criterion comment="libecpg-dev DPKG is earlier than 8.1.18-0etch1" test_ref="oval:org.mitre.oval:tst:13023"/>
                <criterion comment="libpgtypes2 DPKG is earlier than 8.1.18-0etch1" test_ref="oval:org.mitre.oval:tst:13326"/>
                <criterion comment="libpq4 DPKG is earlier than 8.1.18-0etch1" test_ref="oval:org.mitre.oval:tst:13037"/>
                <criterion comment="postgresql-plperl-7.4 DPKG is earlier than 7.4.26-0etch1" test_ref="oval:org.mitre.oval:tst:12451"/>
                <criterion comment="postgresql-plperl-8.1 DPKG is earlier than 8.1.18-0etch1" test_ref="oval:org.mitre.oval:tst:13146"/>
                <criterion comment="postgresql-pltcl-7.4 DPKG is earlier than 7.4.26-0etch1" test_ref="oval:org.mitre.oval:tst:13133"/>
                <criterion comment="libecpg-compat2 DPKG is earlier than 8.1.18-0etch1" test_ref="oval:org.mitre.oval:tst:13155"/>
              </criteria>
            </criteria>
            <criteria comment="Architecture dependent section" operator="AND">
              <criteria comment="Supported architectures section" operator="OR">
                <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
              </criteria>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="postgresql-client-8.1 DPKG is earlier than 8.1.18-0etch1" test_ref="oval:org.mitre.oval:tst:13393"/>
                <criterion comment="postgresql-8.1 DPKG is earlier than 8.1.18-0etch1" test_ref="oval:org.mitre.oval:tst:13373"/>
                <criterion comment="postgresql-contrib-8.1 DPKG is earlier than 8.1.18-0etch1" test_ref="oval:org.mitre.oval:tst:13417"/>
                <criterion comment="libecpg5 DPKG is earlier than 8.1.18-0etch1" test_ref="oval:org.mitre.oval:tst:13408"/>
                <criterion comment="postgresql-pltcl-8.1 DPKG is earlier than 8.1.18-0etch1" test_ref="oval:org.mitre.oval:tst:13101"/>
                <criterion comment="postgresql-server-dev-8.1 DPKG is earlier than 8.1.18-0etch1" test_ref="oval:org.mitre.oval:tst:13388"/>
                <criterion comment="postgresql-plpython-8.1 DPKG is earlier than 8.1.18-0etch1" test_ref="oval:org.mitre.oval:tst:13340"/>
                <criterion comment="libecpg-dev DPKG is earlier than 8.1.18-0etch1" test_ref="oval:org.mitre.oval:tst:12491"/>
                <criterion comment="libpgtypes2 DPKG is earlier than 8.1.18-0etch1" test_ref="oval:org.mitre.oval:tst:13486"/>
                <criterion comment="libpq4 DPKG is earlier than 8.1.18-0etch1" test_ref="oval:org.mitre.oval:tst:12845"/>
                <criterion comment="libpq-dev DPKG is earlier than 8.1.18-0etch1" test_ref="oval:org.mitre.oval:tst:12974"/>
                <criterion comment="postgresql-plperl-8.1 DPKG is earlier than 8.1.18-0etch1" test_ref="oval:org.mitre.oval:tst:13284"/>
                <criterion comment="libecpg-compat2 DPKG is earlier than 8.1.18-0etch1" test_ref="oval:org.mitre.oval:tst:13118"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:7827" class="patch">
      <metadata>
        <title>DSA-1843 squid3 -- several vulnerabilities</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <product>squid3</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2009/dsa-1843" ref_id="DSA-1843"/>
        <description>It was discovered that squid3, a high-performance proxy caching server for web clients, is prone to several denial of service attacks. Due to incorrect bounds checking and insufficient validation while processing response and request data an attacker is able to crash the squid daemon via crafted requests or responses. The squid package in the oldstable distribution (etch) is not affected by this problem.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:03-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T07:50:06.633-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:01:55.949-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:01:24.822-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Release section" operator="AND">
        <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
        <criteria comment="Architecture section" operator="OR">
          <criteria comment="Architecture independent section" operator="AND">
            <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
            <criterion comment="squid3-common is earlier than 3.0.STABLE8-3+lenny1" test_ref="oval:org.mitre.oval:tst:11906"/>
          </criteria>
          <criteria comment="Architecture dependent section" operator="AND">
            <criteria comment="Supported architectures section" operator="OR">
              <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
              <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
              <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
              <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
              <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
              <criterion comment="Installed architecture is armel" test_ref="oval:org.mitre.oval:tst:11101"/>
              <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
              <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
              <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
              <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
              <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
            </criteria>
            <criteria comment="Packages section" operator="OR">
              <criterion comment="squidclient DPKG is earlier than 3.0.STABLE8-3+lenny1" test_ref="oval:org.mitre.oval:tst:11789"/>
              <criterion comment="squid3-cgi DPKG is earlier than 3.0.STABLE8-3+lenny1" test_ref="oval:org.mitre.oval:tst:12017"/>
              <criterion comment="squid3 DPKG is earlier than 3.0.STABLE8-3+lenny1" test_ref="oval:org.mitre.oval:tst:12771"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:7824" class="patch">
      <metadata>
        <title>DSA-1810 libapache-mod-jk -- information disclosure</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <platform>Debian GNU/Linux 4.0</platform>
          <product>libapache-mod-jk</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2009/dsa-1810" ref_id="DSA-1810"/>
        <description>An information disclosure flaw was found in mod_jk, the Tomcat Connector module for Apache. If a buggy client included the "Content-Length" header without providing request body data, or if a client sent repeated requests very quickly, one client could obtain a response intended for another client. The oldstable distribution (etch), this problem has been fixed in version 1:1.2.18-3etch2.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:09-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T07:57:36.454-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:01:55.420-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:01:24.360-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Platform section" operator="OR">
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Architecture independent section" operator="AND">
              <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criterion comment="libapache-mod-jk-doc is earlier than 1.2.26-2+lenny1" test_ref="oval:org.mitre.oval:tst:18511"/>
            </criteria>
            <criteria comment="Architecture dependent section" operator="AND">
              <criteria comment="Supported architectures section" operator="OR">
                <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
                <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
                <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
                <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
                <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
                <criterion comment="Installed architecture is armel" test_ref="oval:org.mitre.oval:tst:11101"/>
                <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
                <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
                <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
                <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
                <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
                <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
              </criteria>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="libapache2-mod-jk DPKG is earlier than 1.2.26-2+lenny1" test_ref="oval:org.mitre.oval:tst:18317"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 4.0 is installed" definition_ref="oval:org.mitre.oval:def:6461"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Architecture independent section" operator="AND">
              <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criterion comment="libapache-mod-jk-doc is earlier than 1.2.18-3etch2" test_ref="oval:org.mitre.oval:tst:18482"/>
            </criteria>
            <criteria comment="Packages section" operator="OR">
              <criterion comment="libapache-mod-jk DPKG is earlier than 1.2.18-3etch2" test_ref="oval:org.mitre.oval:tst:18532"/>
              <criterion comment="libapache2-mod-jk DPKG is earlier than 1.2.18-3etch2" test_ref="oval:org.mitre.oval:tst:18109"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:7820" class="patch">
      <metadata>
        <title>DSA-1847 bind9 -- improper assert</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <platform>Debian GNU/Linux 4.0</platform>
          <product>bind9</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2009/dsa-1847" ref_id="DSA-1847"/>
        <description>It was discovered that the BIND DNS server terminates when processing a specially crafted dynamic DNS update. This vulnerability affects all BIND servers which serve at least one DNS zone authoritatively, as a master, even if dynamic updates are not enabled. The default Debian configuration for resolvers includes several authoritative zones, too, so resolvers are also affected by this issue unless these zones have been removed.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:03-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T07:50:14.569-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:01:54.319-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:01:23.295-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Platform section" operator="OR">
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Architecture independent section" operator="AND">
              <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criterion comment="bind9-doc is earlier than 9.5.1.dfsg.P3-1" test_ref="oval:org.mitre.oval:tst:12669"/>
            </criteria>
            <criteria comment="Architecture dependent section" operator="AND">
              <criteria comment="Supported architectures section" operator="OR">
                <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
                <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
                <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
                <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
                <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
                <criterion comment="Installed architecture is armel" test_ref="oval:org.mitre.oval:tst:11101"/>
                <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
                <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
                <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
                <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
                <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
              </criteria>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="dnsutils DPKG is earlier than 9.5.1.dfsg.P3-1" test_ref="oval:org.mitre.oval:tst:11956"/>
                <criterion comment="libbind-dev DPKG is earlier than 9.5.1.dfsg.P3-1" test_ref="oval:org.mitre.oval:tst:12772"/>
                <criterion comment="libisccc40 DPKG is earlier than 9.5.1.dfsg.P3-1" test_ref="oval:org.mitre.oval:tst:12622"/>
                <criterion comment="libisccfg40 DPKG is earlier than 9.5.1.dfsg.P3-1" test_ref="oval:org.mitre.oval:tst:12753"/>
                <criterion comment="bind9utils DPKG is earlier than 9.5.1.dfsg.P3-1" test_ref="oval:org.mitre.oval:tst:12728"/>
                <criterion comment="libisc45 DPKG is earlier than 9.5.1.dfsg.P3-1" test_ref="oval:org.mitre.oval:tst:12516"/>
                <criterion comment="liblwres40 DPKG is earlier than 9.5.1.dfsg.P3-1" test_ref="oval:org.mitre.oval:tst:12764"/>
                <criterion comment="libbind9-40 DPKG is earlier than 9.5.1.dfsg.P3-1" test_ref="oval:org.mitre.oval:tst:12605"/>
                <criterion comment="libdns45 DPKG is earlier than 9.5.1.dfsg.P3-1" test_ref="oval:org.mitre.oval:tst:12730"/>
                <criterion comment="bind9-host DPKG is earlier than 9.5.1.dfsg.P3-1" test_ref="oval:org.mitre.oval:tst:12219"/>
                <criterion comment="bind9 DPKG is earlier than 9.5.1.dfsg.P3-1" test_ref="oval:org.mitre.oval:tst:11801"/>
                <criterion comment="lwresd DPKG is earlier than 9.5.1.dfsg.P3-1" test_ref="oval:org.mitre.oval:tst:12191"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 4.0 is installed" definition_ref="oval:org.mitre.oval:def:6461"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Architecture independent section" operator="AND">
              <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criterion comment="bind9-doc is earlier than 9.3.4-2etch5" test_ref="oval:org.mitre.oval:tst:12529"/>
            </criteria>
            <criteria comment="Architecture dependent section" operator="AND">
              <criteria comment="Supported architectures section" operator="OR">
                <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
                <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
                <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
                <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
                <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
                <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
                <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
                <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
              </criteria>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="dnsutils DPKG is earlier than 9.3.4-2etch5" test_ref="oval:org.mitre.oval:tst:12395"/>
                <criterion comment="libbind-dev DPKG is earlier than 9.3.4-2etch5" test_ref="oval:org.mitre.oval:tst:11811"/>
                <criterion comment="libdns22 DPKG is earlier than 9.3.4-2etch5" test_ref="oval:org.mitre.oval:tst:12478"/>
                <criterion comment="libisccfg1 DPKG is earlier than 9.3.4-2etch5" test_ref="oval:org.mitre.oval:tst:12710"/>
                <criterion comment="libisccc0 DPKG is earlier than 9.3.4-2etch5" test_ref="oval:org.mitre.oval:tst:12808"/>
                <criterion comment="libisc11 DPKG is earlier than 9.3.4-2etch5" test_ref="oval:org.mitre.oval:tst:12691"/>
                <criterion comment="libbind9-0 DPKG is earlier than 9.3.4-2etch5" test_ref="oval:org.mitre.oval:tst:12046"/>
                <criterion comment="bind9-host DPKG is earlier than 9.3.4-2etch5" test_ref="oval:org.mitre.oval:tst:12679"/>
                <criterion comment="bind9 DPKG is earlier than 9.3.4-2etch5" test_ref="oval:org.mitre.oval:tst:12778"/>
                <criterion comment="liblwres9 DPKG is earlier than 9.3.4-2etch5" test_ref="oval:org.mitre.oval:tst:12765"/>
                <criterion comment="lwresd DPKG is earlier than 9.3.4-2etch5" test_ref="oval:org.mitre.oval:tst:12600"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:7815" class="patch">
      <metadata>
        <title>DSA-1822 mahara -- insufficient input sanitization</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <product>mahara</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2009/dsa-1822" ref_id="DSA-1822"/>
        <description>It was discovered that mahara, an electronic portfolio, weblog, and resume builder is prone to several cross-site scripting attacks, which allow an attacker to inject arbitrary HTML or script code and steal potential sensitive data from other users. The oldstable distribution (etch) does not contain mahara.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:08-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T07:55:59.988-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:01:50.626-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:01:21.169-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Release section" operator="AND">
        <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
        <criteria comment="Architecture section" operator="OR">
          <criteria comment="Architecture independent section" operator="AND">
            <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
            <criteria comment="Packages section" operator="OR">
              <criterion comment="mahara-apache2 is earlier than 1.0.4-4+lenny3" test_ref="oval:org.mitre.oval:tst:17274"/>
              <criterion comment="mahara is earlier than 1.0.4-4+lenny3" test_ref="oval:org.mitre.oval:tst:17210"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:7813" class="patch">
      <metadata>
        <title>DSA-1746 ghostscript -- several vulnerabilities</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <platform>Debian GNU/Linux 4.0</platform>
          <product>ghostscript</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2009/dsa-1746" ref_id="DSA-1746"/>
        <description>Two security issues have been discovered in ghostscript, the GPL Ghostscript PostScript/PDF interpreter. The Common Vulnerabilities and Exposures project identifies the following problems: Jan Lieskovsky discovered multiple integer overflows in the ICC library, which allow the execution of arbitrary code via crafted ICC profiles in PostScript files with embedded images. Jan Lieskovsky discovered insufficient upper-bounds checks on certain variable sizes in the ICC library, which allow the execution of arbitrary code via crafted ICC profiles in PostScript files with embedded images.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:12-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T07:59:56.955-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:01:49.994-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:01:20.584-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Platform section" operator="OR">
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Architecture independent section" operator="AND">
              <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="gs-aladdin is earlier than 8.62.dfsg.1-3.2lenny1" test_ref="oval:org.mitre.oval:tst:20065"/>
                <criterion comment="gs is earlier than 8.62.dfsg.1-3.2lenny1" test_ref="oval:org.mitre.oval:tst:20040"/>
                <criterion comment="gs-esp is earlier than 8.62.dfsg.1-3.2lenny1" test_ref="oval:org.mitre.oval:tst:20052"/>
                <criterion comment="gs-gpl is earlier than 8.62.dfsg.1-3.2lenny1" test_ref="oval:org.mitre.oval:tst:20032"/>
                <criterion comment="ghostscript-doc is earlier than 8.62.dfsg.1-3.2lenny1" test_ref="oval:org.mitre.oval:tst:20060"/>
                <criterion comment="gs-common is earlier than 8.62.dfsg.1-3.2lenny1" test_ref="oval:org.mitre.oval:tst:19976"/>
              </criteria>
            </criteria>
            <criteria comment="Architecture dependent section" operator="AND">
              <criteria comment="Supported architectures section" operator="OR">
                <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
                <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
                <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
                <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
                <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
                <criterion comment="Installed architecture is armel" test_ref="oval:org.mitre.oval:tst:11101"/>
                <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
                <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
                <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
                <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
                <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
                <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
              </criteria>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="libgs-dev DPKG is earlier than 8.62.dfsg.1-3.2lenny1" test_ref="oval:org.mitre.oval:tst:19891"/>
                <criterion comment="ghostscript-x DPKG is earlier than 8.62.dfsg.1-3.2lenny1" test_ref="oval:org.mitre.oval:tst:19521"/>
                <criterion comment="ghostscript DPKG is earlier than 8.62.dfsg.1-3.2lenny1" test_ref="oval:org.mitre.oval:tst:19261"/>
                <criterion comment="libgs8 DPKG is earlier than 8.62.dfsg.1-3.2lenny1" test_ref="oval:org.mitre.oval:tst:19996"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 4.0 is installed" definition_ref="oval:org.mitre.oval:def:6461"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Architecture independent section" operator="AND">
              <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criterion comment="gs is earlier than 8.54.dfsg.1-5etch2" test_ref="oval:org.mitre.oval:tst:19765"/>
            </criteria>
            <criteria comment="Packages section" operator="OR">
              <criterion comment="gs-gpl DPKG is earlier than 8.54.dfsg.1-5etch2" test_ref="oval:org.mitre.oval:tst:19897"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:7773" class="patch">
      <metadata>
        <title>DSA-1744 weechat -- missing input sanitization</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <product>weechat</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2009/dsa-1744" ref_id="DSA-1744"/>
        <description>Sebastien Helleu discovered that an error in the handling of color codes in the weechat IRC client could cause an out-of-bounds read of an internal color array. This can be used by an attacker to crash user clients via a crafted PRIVMSG command. The weechat version in the oldstable distribution (etch) is not affected by this problem.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:12-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T07:59:54.515-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:01:39.866-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:01:13.158-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Release section" operator="AND">
        <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
        <criteria comment="Architecture section" operator="OR">
          <criteria comment="Architecture independent section" operator="AND">
            <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
            <criteria comment="Packages section" operator="OR">
              <criterion comment="weechat-common is earlier than 0.2.6-1+lenny1" test_ref="oval:org.mitre.oval:tst:19518"/>
              <criterion comment="weechat is earlier than 0.2.6-1+lenny1" test_ref="oval:org.mitre.oval:tst:19870"/>
            </criteria>
          </criteria>
          <criteria comment="Architecture dependent section" operator="AND">
            <criteria comment="Supported architectures section" operator="OR">
              <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
              <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
              <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
              <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
              <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
              <criterion comment="Installed architecture is armel" test_ref="oval:org.mitre.oval:tst:11101"/>
              <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
              <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
              <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
              <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
              <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
            </criteria>
            <criteria comment="Packages section" operator="OR">
              <criterion comment="weechat-plugins DPKG is earlier than 0.2.6-1+lenny1" test_ref="oval:org.mitre.oval:tst:19921"/>
              <criterion comment="weechat-curses DPKG is earlier than 0.2.6-1+lenny1" test_ref="oval:org.mitre.oval:tst:19995"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:7772" class="patch">
      <metadata>
        <title>DSA-1755 systemtap -- race condition</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <product>systemtap</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2009/dsa-1755" ref_id="DSA-1755"/>
        <description>Erik Sjoelund discovered that a race condition in the stap tool shipped by Systemtap, an instrumentation system for Linux 2.6, allows local privilege escalation for members of the stapusr group. The old stable distribution (etch) isn't affected.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:04-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T07:51:16.683-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:01:39.547-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:01:12.821-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Release section" operator="AND">
        <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
        <criteria comment="Architecture section" operator="OR">
          <criteria comment="Architecture dependent section" operator="AND">
            <criteria comment="Supported architectures section" operator="OR">
              <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
              <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
              <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
              <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
              <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
              <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
            </criteria>
            <criteria comment="Packages section" operator="OR">
              <criterion comment="systemtap DPKG is earlier than 0.0.20080705-1+lenny1" test_ref="oval:org.mitre.oval:tst:13277"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:7766" class="patch">
      <metadata>
        <title>DSA-1885 xulrunner -- several vulnerabilities</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <product>xulrunner</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2009/dsa-1885" ref_id="DSA-1885"/>
        <description>Several remote vulnerabilities have been discovered in Xulrunner, a runtime environment for XUL applications, such as the Iceweasel web browser. The Common Vulnerabilities and Exposures project identifies the following problems: Jesse Ruderman discovered crashes in the layout engine, which might allow the execution of arbitrary code. Daniel Holbert, Jesse Ruderman, Olli Pettay and "toshi" discovered crashes in the layout engine, which might allow the execution of arbitrary code. Josh Soref, Jesse Ruderman and Martin Wargers discovered crashes in the layout engine, which might allow the execution of arbitrary code. Jesse Ruderman discovered a crash in the Javascript engine, which might allow the execution of arbitrary code. Carsten Book and "Taral" discovered crashes in the layout engine, which might allow the execution of arbitrary code. Jesse Ruderman discovered that the user interface for installing/ removing PCKS #11 securiy modules wasn't informative enough, which might allow social engineering attacks. It was discovered that incorrect pointer handling in the XUL parser could lead to the execution of arbitrary code. Juan Pablo Lopez Yacubian discovered that incorrent rendering of some Unicode font characters could lead to spoofing attacks on the location bar.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:04-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T07:51:23.869-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:01:37.944-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:01:11.603-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Release section" operator="AND">
        <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
        <criteria comment="Architecture section" operator="OR">
          <criteria comment="Architecture independent section" operator="AND">
            <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
            <criterion comment="libmozillainterfaces-java is earlier than 1.9.0.14-0lenny1" test_ref="oval:org.mitre.oval:tst:13351"/>
          </criteria>
          <criteria comment="Architecture dependent section" operator="AND">
            <criteria comment="Supported architectures section" operator="OR">
              <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
              <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
              <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
              <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
              <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
              <criterion comment="Installed architecture is armel" test_ref="oval:org.mitre.oval:tst:11101"/>
              <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
              <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
              <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
              <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
              <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
              <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
            </criteria>
            <criteria comment="Packages section" operator="OR">
              <criterion comment="libmozjs-dev DPKG is earlier than 1.9.0.14-0lenny1" test_ref="oval:org.mitre.oval:tst:13032"/>
              <criterion comment="spidermonkey-bin DPKG is earlier than 1.9.0.14-0lenny1" test_ref="oval:org.mitre.oval:tst:13067"/>
              <criterion comment="xulrunner-1.9-gnome-support DPKG is earlier than 1.9.0.14-0lenny1" test_ref="oval:org.mitre.oval:tst:13523"/>
              <criterion comment="xulrunner-1.9 DPKG is earlier than 1.9.0.14-0lenny1" test_ref="oval:org.mitre.oval:tst:13357"/>
              <criterion comment="libmozjs1d-dbg DPKG is earlier than 1.9.0.14-0lenny1" test_ref="oval:org.mitre.oval:tst:12950"/>
              <criterion comment="libmozjs1d DPKG is earlier than 1.9.0.14-0lenny1" test_ref="oval:org.mitre.oval:tst:13462"/>
              <criterion comment="python-xpcom DPKG is earlier than 1.9.0.14-0lenny1" test_ref="oval:org.mitre.oval:tst:13581"/>
              <criterion comment="xulrunner-1.9-dbg DPKG is earlier than 1.9.0.14-0lenny1" test_ref="oval:org.mitre.oval:tst:12924"/>
              <criterion comment="xulrunner-dev DPKG is earlier than 1.9.0.14-0lenny1" test_ref="oval:org.mitre.oval:tst:13241"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:7762" class="patch">
      <metadata>
        <title>DSA-1887 rails -- missing input sanitising</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <product>rails</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2009/dsa-1887" ref_id="DSA-1887"/>
        <description>Brian Mastenbrook discovered that rails, the MVC ruby based framework geared for web application development, is prone to cross-site scripting attacks via malformed strings in the form helper.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:04-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T07:51:22.257-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:01:37.200-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:01:11.114-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Release section" operator="AND">
        <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
        <criteria comment="Architecture section" operator="OR">
          <criteria comment="Architecture independent section" operator="AND">
            <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
            <criterion comment="rails is earlier than 2.1.0-7" test_ref="oval:org.mitre.oval:tst:13361"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:7760" class="patch">
      <metadata>
        <title>DSA-1907 kvm -- several vulnerabilities</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <product>kvm</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2009/dsa-1907" ref_id="DSA-1907"/>
        <description>Several vulnerabilities have been discovered in kvm, a full virtualization system. The Common Vulnerabilities and Exposures project identifies the following problems: Chris Webb discovered an off-by-one bug limiting KVM's VNC passwords to 7 characters. This flaw might make it easier for remote attackers to guess the VNC password, which is limited to seven characters where eight was intended. It was discovered that the kvm_emulate_hypercall function in KVM does not prevent access to MMU hypercalls from ring 0, which allows local guest OS users to cause a denial of service (guest kernel crash) and read or write guest kernel memory. The oldstable distribution (etch) does not contain kvm.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:03-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T07:50:41.382-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:01:36.753-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:01:10.808-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Release section" operator="AND">
        <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
        <criteria comment="Architecture section" operator="OR">
          <criteria comment="Architecture independent section" operator="AND">
            <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
            <criterion comment="kvm-source is earlier than 72+dfsg-5~lenny3" test_ref="oval:org.mitre.oval:tst:12927"/>
          </criteria>
          <criteria comment="Architecture dependent section" operator="AND">
            <criteria comment="Supported architectures section" operator="OR">
              <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
              <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
            </criteria>
            <criteria comment="Packages section" operator="OR">
              <criterion comment="kvm DPKG is earlier than 72+dfsg-5~lenny3" test_ref="oval:org.mitre.oval:tst:13322"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:7752" class="patch">
      <metadata>
        <title>DSA-1882 xapian-omega -- missing input sanitization</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <platform>Debian GNU/Linux 4.0</platform>
          <product>xapian-omega</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2009/dsa-1882" ref_id="DSA-1882"/>
        <description>It was discovered that xapian-omega, a CGI interface for searching xapian databases, is not properly escaping user supplied input when printing exceptions. An attacker can use this to conduct cross-site scripting attacks via crafted search queries resulting in an exception and steal potentially sensitive data from web applications running on the same domain or embedding the search engine into a website.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:04-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T07:51:25.868-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:01:34.875-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:01:09.392-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Platform section" operator="OR">
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Architecture dependent section" operator="AND">
              <criteria comment="Supported architectures section" operator="OR">
                <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
                <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
                <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
                <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
                <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
                <criterion comment="Installed architecture is armel" test_ref="oval:org.mitre.oval:tst:11101"/>
                <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
                <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
                <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
                <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
                <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
                <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
              </criteria>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="xapian-omega DPKG is earlier than 1.0.7-3+lenny1" test_ref="oval:org.mitre.oval:tst:13283"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 4.0 is installed" definition_ref="oval:org.mitre.oval:def:6461"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Packages section" operator="OR">
              <criterion comment="xapian-omega DPKG is earlier than 0.9.9-1+etch1" test_ref="oval:org.mitre.oval:tst:13414"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:7718" class="patch">
      <metadata>
        <title>DSA-1790 xpdf -- multiple vulnerabilities</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <platform>Debian GNU/Linux 4.0</platform>
          <product>xpdf</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2009/dsa-1790" ref_id="DSA-1790"/>
        <description>Several vulnerabilities have been identified in xpdf, a suite of tools for viewing and converting Portable Document Format (PDF) files. The Common Vulnerabilities and Exposures project identifies the following problems: Multiple buffer overflows in the JBIG2 decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, and other products allow remote attackers to cause a denial of service (crash) via a crafted PDF file, related to (1) JBIG2SymbolDict::setBitmap and (2) JBIG2Stream::readSymbolDictSeg. Multiple integer overflows in the JBIG2 decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, and other products allow remote attackers to cause a denial of service (crash) via a crafted PDF file, related to (1) JBIG2Stream::readSymbolDictSeg, (2) JBIG2Stream::readSymbolDictSeg, and (3) JBIG2Stream::readGenericBitmap. Integer overflow in the JBIG2 decoder in Xpdf 3.02pl2 and earlier, as used in Poppler and other products, when running on Mac OS X, has unspecified impact, related to "g*allocn." The JBIG2 decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, and other products allows remote attackers to cause a denial of service (crash) via a crafted PDF file that triggers a free of uninitialized memory. The JBIG2 decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, Poppler before 0.10.6, and other products allows remote attackers to cause a denial of service (crash) via a crafted PDF file that triggers an out-of-bounds read. Multiple "input validation flaws" in the JBIG2 decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, Poppler before 0.10.6, and other products allow remote attackers to execute arbitrary code via a crafted PDF file. Integer overflow in the JBIG2 decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, Poppler before 0.10.6, and other products allows remote attackers to execute arbitrary code via a crafted PDF file. The JBIG2 decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, Poppler before 0.10.6, and other products allows remote attackers to execute arbitrary code via a crafted PDF file that triggers a free of invalid data. The JBIG2 decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, Poppler before 0.10.6, and other products allows remote attackers to cause a denial of service (crash) via a crafted PDF file that triggers a NULL pointer dereference. Multiple buffer overflows in the JBIG2 MMR decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, Poppler before 0.10.6, and other products allow remote attackers to execute arbitrary code via a crafted PDF file. The JBIG2 MMR decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, Poppler before 0.10.6, and other products allows remote attackers to cause a denial of service (infinite loop and hang) via a crafted PDF file.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:03-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T07:49:04.002-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:01:31.189-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:01:06.283-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Platform section" operator="OR">
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Architecture independent section" operator="AND">
              <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="xpdf-common is earlier than 3.02-1.4+lenny1" test_ref="oval:org.mitre.oval:tst:11091"/>
                <criterion comment="xpdf is earlier than 3.02-1.4+lenny1" test_ref="oval:org.mitre.oval:tst:12002"/>
              </criteria>
            </criteria>
            <criteria comment="Architecture dependent section" operator="AND">
              <criteria comment="Supported architectures section" operator="OR">
                <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
                <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
                <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
                <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
                <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
                <criterion comment="Installed architecture is armel" test_ref="oval:org.mitre.oval:tst:11101"/>
                <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
                <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
                <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
                <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
                <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
                <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
              </criteria>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="xpdf-utils DPKG is earlier than 3.02-1.4+lenny1" test_ref="oval:org.mitre.oval:tst:12078"/>
                <criterion comment="xpdf-reader DPKG is earlier than 3.02-1.4+lenny1" test_ref="oval:org.mitre.oval:tst:12068"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 4.0 is installed" definition_ref="oval:org.mitre.oval:def:6461"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Architecture independent section" operator="AND">
              <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="xpdf-common is earlier than 3.01-9.1+etch6" test_ref="oval:org.mitre.oval:tst:11547"/>
                <criterion comment="xpdf is earlier than 3.01-9.1+etch6" test_ref="oval:org.mitre.oval:tst:11390"/>
              </criteria>
            </criteria>
            <criteria comment="Architecture dependent section" operator="AND">
              <criteria comment="Supported architectures section" operator="OR">
                <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
                <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
                <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
                <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
                <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
                <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
                <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
                <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
                <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
                <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
              </criteria>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="xpdf-utils DPKG is earlier than 3.01-9.1+etch6" test_ref="oval:org.mitre.oval:tst:11784"/>
                <criterion comment="xpdf-reader DPKG is earlier than 3.01-9.1+etch6" test_ref="oval:org.mitre.oval:tst:12076"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:7703" class="patch">
      <metadata>
        <title>DSA-1926 typo3-src -- several vulnerabilities</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <platform>Debian GNU/Linux 4.0</platform>
          <product>typo3-src</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2009/dsa-1926" ref_id="DSA-1926"/>
        <description>Several remote vulnerabilities have been discovered in the TYPO3 web content management framework. The Common Vulnerabilities and Exposures project identifies the following problems: The Backend subcomponent allows remote authenticated users to determine an encryption key via crafted input to a form field. Multiple cross-site scripting (XSS) vulnerabilities in the Backend subcomponent allow remote authenticated users to inject arbitrary web script or HTML. The Backend subcomponent allows remote authenticated users to place arbitrary web sites in TYPO3 backend framesets via crafted parameters. The Backend subcomponent, when the DAM extension or ftp upload is enabled, allows remote authenticated users to execute arbitrary commands via shell metacharacters in a filename. SQL injection vulnerability in the traditional frontend editing feature in the Frontend Editing subcomponent allows remote authenticated users to execute arbitrary SQL commands. Cross-site scripting (XSS) vulnerability allows remote attackers to inject arbitrary web script. Cross-site scripting (XSS) vulnerability in the Frontend Login Box (aka felogin) subcomponent allows remote attackers to inject arbitrary web script or HTML. The Install Tool subcomponent allows remote attackers to gain access by using only the password's md5 hash as a credential. Cross-site scripting (XSS) vulnerability in the Install Tool subcomponent allows remote attackers to inject arbitrary web script or HTML.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:08-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T07:56:06.001-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:01:30.513-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:01:05.115-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Platform section" operator="OR">
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Architecture independent section" operator="AND">
              <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="typo3 is earlier than 4.2.5-1+lenny2" test_ref="oval:org.mitre.oval:tst:17055"/>
                <criterion comment="typo3-src-4.2 is earlier than 4.2.5-1+lenny2" test_ref="oval:org.mitre.oval:tst:16861"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 4.0 is installed" definition_ref="oval:org.mitre.oval:def:6461"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Architecture independent section" operator="AND">
              <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="typo3 is earlier than 4.0.2+debian-9" test_ref="oval:org.mitre.oval:tst:16813"/>
                <criterion comment="typo3-src-4.0 is earlier than 4.0.2+debian-9" test_ref="oval:org.mitre.oval:tst:17439"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:7691" class="patch">
      <metadata>
        <title>DSA-1768 openafs -- several vulnerabilities</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <platform>Debian GNU/Linux 4.0</platform>
          <product>openafs</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2009/dsa-1768" ref_id="DSA-1768"/>
        <description>Two vulnerabilities were discovered in the client part of OpenAFS, a distributed file system. An attacker with control of a file server or the ability to forge RX packets may be able to execute arbitrary code in kernel mode on an OpenAFS client, due to a vulnerability in XDR array decoding. An attacker with control of a file server or the ability to forge RX packets may crash OpenAFS clients because of wrongly handled error return codes in the kernel module. Note that in order to apply this security update, you must rebuild the OpenAFS kernel module. Be sure to also upgrade openafs-modules-source, build a new kernel module for your system following the instructions in /usr/share/doc/openafs-client/README.modules.gz, and then either stop and restart openafs-client or reboot the system to reload the kernel module.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:07-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T07:54:41.472-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:01:28.710-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:01:03.748-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Platform section" operator="OR">
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Architecture independent section" operator="AND">
              <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="openafs-modules-source is earlier than 1.4.7.dfsg1-6+lenny1" test_ref="oval:org.mitre.oval:tst:16601"/>
                <criterion comment="openafs-doc is earlier than 1.4.7.dfsg1-6+lenny1" test_ref="oval:org.mitre.oval:tst:16288"/>
              </criteria>
            </criteria>
            <criteria comment="Architecture dependent section" operator="AND">
              <criteria comment="Supported architectures section" operator="OR">
                <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
                <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
                <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
                <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
                <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
                <criterion comment="Installed architecture is armel" test_ref="oval:org.mitre.oval:tst:11101"/>
                <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
                <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
                <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
              </criteria>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="openafs-client DPKG is earlier than 1.4.7.dfsg1-6+lenny1" test_ref="oval:org.mitre.oval:tst:16614"/>
                <criterion comment="openafs-dbserver DPKG is earlier than 1.4.7.dfsg1-6+lenny1" test_ref="oval:org.mitre.oval:tst:16562"/>
                <criterion comment="openafs-dbg DPKG is earlier than 1.4.7.dfsg1-6+lenny1" test_ref="oval:org.mitre.oval:tst:16574"/>
                <criterion comment="openafs-fileserver DPKG is earlier than 1.4.7.dfsg1-6+lenny1" test_ref="oval:org.mitre.oval:tst:15802"/>
                <criterion comment="libpam-openafs-kaserver DPKG is earlier than 1.4.7.dfsg1-6+lenny1" test_ref="oval:org.mitre.oval:tst:16208"/>
                <criterion comment="libopenafs-dev DPKG is earlier than 1.4.7.dfsg1-6+lenny1" test_ref="oval:org.mitre.oval:tst:16600"/>
                <criterion comment="openafs-krb5 DPKG is earlier than 1.4.7.dfsg1-6+lenny1" test_ref="oval:org.mitre.oval:tst:16608"/>
                <criterion comment="openafs-kpasswd DPKG is earlier than 1.4.7.dfsg1-6+lenny1" test_ref="oval:org.mitre.oval:tst:16561"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 4.0 is installed" definition_ref="oval:org.mitre.oval:def:6461"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Architecture independent section" operator="AND">
              <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="openafs-modules-source is earlier than 1.4.2-6etch2" test_ref="oval:org.mitre.oval:tst:16029"/>
                <criterion comment="openafs-doc is earlier than 1.4.2-6etch2" test_ref="oval:org.mitre.oval:tst:16571"/>
              </criteria>
            </criteria>
            <criteria comment="Architecture dependent section" operator="AND">
              <criteria comment="Supported architectures section" operator="OR">
                <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
                <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
                <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
                <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
                <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
                <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
                <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
                <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
              </criteria>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="openafs-client DPKG is earlier than 1.4.2-6etch2" test_ref="oval:org.mitre.oval:tst:16451"/>
                <criterion comment="openafs-dbserver DPKG is earlier than 1.4.2-6etch2" test_ref="oval:org.mitre.oval:tst:15719"/>
                <criterion comment="openafs-dbg DPKG is earlier than 1.4.2-6etch2" test_ref="oval:org.mitre.oval:tst:16595"/>
                <criterion comment="openafs-fileserver DPKG is earlier than 1.4.2-6etch2" test_ref="oval:org.mitre.oval:tst:15801"/>
                <criterion comment="openafs-krb5 DPKG is earlier than 1.4.2-6etch2" test_ref="oval:org.mitre.oval:tst:16533"/>
                <criterion comment="libpam-openafs-kaserver DPKG is earlier than 1.4.2-6etch2" test_ref="oval:org.mitre.oval:tst:15661"/>
                <criterion comment="openafs-kpasswd DPKG is earlier than 1.4.2-6etch2" test_ref="oval:org.mitre.oval:tst:16275"/>
                <criterion comment="libopenafs-dev DPKG is earlier than 1.4.2-6etch2" test_ref="oval:org.mitre.oval:tst:16597"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:7684" class="patch">
      <metadata>
        <title>DSA-1925 proftpd-dfsg -- insufficient input validation</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <platform>Debian GNU/Linux 4.0</platform>
          <product>proftpd-dfsg</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2009/dsa-1925" ref_id="DSA-1925"/>
        <description>It has been discovered that proftpd-dfsg, a virtual-hosting FTP daemon, does not properly handle a "\0" character in a domain name in the Subject Alternative Name field of an X.509 client certificate, when the dNSNameRequired TLS option is enabled.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:08-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T07:56:05.200-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:01:28.194-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:01:03.268-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Platform section" operator="OR">
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Architecture independent section" operator="AND">
              <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="proftpd is earlier than 1.3.1-17lenny4" test_ref="oval:org.mitre.oval:tst:17397"/>
                <criterion comment="proftpd-doc is earlier than 1.3.1-17lenny4" test_ref="oval:org.mitre.oval:tst:17356"/>
              </criteria>
            </criteria>
            <criteria comment="Architecture dependent section" operator="AND">
              <criteria comment="Supported architectures section" operator="OR">
                <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
                <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
                <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
                <criterion comment="Installed architecture is armel" test_ref="oval:org.mitre.oval:tst:11101"/>
                <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
                <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
                <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
                <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
                <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
              </criteria>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="proftpd-mod-mysql DPKG is earlier than 1.3.1-17lenny4" test_ref="oval:org.mitre.oval:tst:16944"/>
                <criterion comment="proftpd-mod-pgsql DPKG is earlier than 1.3.1-17lenny4" test_ref="oval:org.mitre.oval:tst:17437"/>
                <criterion comment="proftpd-mod-ldap DPKG is earlier than 1.3.1-17lenny4" test_ref="oval:org.mitre.oval:tst:17331"/>
                <criterion comment="proftpd-basic DPKG is earlier than 1.3.1-17lenny4" test_ref="oval:org.mitre.oval:tst:17159"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 4.0 is installed" definition_ref="oval:org.mitre.oval:def:6461"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Architecture independent section" operator="AND">
              <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="proftpd-pgsql is earlier than 1.3.0-19etch3" test_ref="oval:org.mitre.oval:tst:17085"/>
                <criterion comment="proftpd-doc is earlier than 1.3.0-19etch3" test_ref="oval:org.mitre.oval:tst:17349"/>
                <criterion comment="proftpd-ldap is earlier than 1.3.0-19etch3" test_ref="oval:org.mitre.oval:tst:17236"/>
                <criterion comment="proftpd-mysql is earlier than 1.3.0-19etch3" test_ref="oval:org.mitre.oval:tst:17366"/>
              </criteria>
            </criteria>
            <criteria comment="Architecture dependent section" operator="AND">
              <criteria comment="Supported architectures section" operator="OR">
                <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
                <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
                <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
                <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
                <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
                <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
                <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
                <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
              </criteria>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="proftpd DPKG is earlier than 1.3.0-19etch3" test_ref="oval:org.mitre.oval:tst:17066"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:7678" class="patch">
      <metadata>
        <title>DSA-1738 curl -- arbitrary file access</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <platform>Debian GNU/Linux 4.0</platform>
          <product>curl</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2009/dsa-1738" ref_id="DSA-1738"/>
        <description>David Kierznowski discovered that libcurl, a multi-protocol file transfer library, when configured to follow URL redirects automatically, does not question the new target location. As libcurl also supports file:// and scp:// URLs - depending on the setup - an untrusted server could use that to expose local files, overwrite local files or even execute arbitrary code via a malicious URL redirect. This update introduces a new option called CURLOPT_REDIR_PROTOCOLS which by default does not include the scp and file protocol handlers.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:11-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T07:59:20.874-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:01:26.424-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:01:01.661-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Platform section" operator="OR">
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Architecture dependent section" operator="AND">
              <criteria comment="Supported architectures section" operator="OR">
                <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
                <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
                <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
                <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
                <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
                <criterion comment="Installed architecture is armel" test_ref="oval:org.mitre.oval:tst:11101"/>
                <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
                <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
                <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
                <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
                <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
              </criteria>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="libcurl4-gnutls-dev DPKG is earlier than 7.18.2-8lenny2" test_ref="oval:org.mitre.oval:tst:19186"/>
                <criterion comment="libcurl4-openssl-dev DPKG is earlier than 7.18.2-8lenny2" test_ref="oval:org.mitre.oval:tst:19470"/>
                <criterion comment="libcurl3-gnutls DPKG is earlier than 7.18.2-8lenny2" test_ref="oval:org.mitre.oval:tst:19466"/>
                <criterion comment="libcurl3-dbg DPKG is earlier than 7.18.2-8lenny2" test_ref="oval:org.mitre.oval:tst:19216"/>
                <criterion comment="libcurl3 DPKG is earlier than 7.18.2-8lenny2" test_ref="oval:org.mitre.oval:tst:18499"/>
                <criterion comment="curl DPKG is earlier than 7.18.2-8lenny2" test_ref="oval:org.mitre.oval:tst:19484"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 4.0 is installed" definition_ref="oval:org.mitre.oval:def:6461"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Architecture independent section" operator="AND">
              <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criterion comment="libcurl3-dev is earlier than 7.15.5-1etch2" test_ref="oval:org.mitre.oval:tst:19050"/>
            </criteria>
            <criteria comment="Packages section" operator="OR">
              <criterion comment="libcurl3-gnutls DPKG is earlier than 7.15.5-1etch2" test_ref="oval:org.mitre.oval:tst:19492"/>
              <criterion comment="libcurl3-dbg DPKG is earlier than 7.15.5-1etch2" test_ref="oval:org.mitre.oval:tst:18692"/>
              <criterion comment="libcurl3-gnutls-dev DPKG is earlier than 7.15.5-1etch2" test_ref="oval:org.mitre.oval:tst:19421"/>
              <criterion comment="libcurl3 DPKG is earlier than 7.15.5-1etch2" test_ref="oval:org.mitre.oval:tst:19455"/>
              <criterion comment="curl DPKG is earlier than 7.15.5-1etch2" test_ref="oval:org.mitre.oval:tst:19340"/>
              <criterion comment="libcurl3-openssl-dev DPKG is earlier than 7.15.5-1etch2" test_ref="oval:org.mitre.oval:tst:19480"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:7674" class="patch">
      <metadata>
        <title>DSA-1884 nginx -- buffer underflow</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <platform>Debian GNU/Linux 4.0</platform>
          <product>nginx</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2009/dsa-1884" ref_id="DSA-1884"/>
        <description>Chris Ries discovered that nginx, a high-performance HTTP server, reverse proxy and IMAP/POP3 proxy server, is vulnerable to a buffer underflow when processing certain HTTP requests. An attacker can use this to execute arbitrary code with the rights of the worker process (www-data on Debian) or possibly perform denial of service attacks by repeatedly crashing worker processes via a specially crafted URL in an HTTP request.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:04-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T07:51:24.641-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:01:26.109-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:01:01.391-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Platform section" operator="OR">
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Packages section" operator="OR">
              <criterion comment="nginx DPKG is earlier than 0.6.32-3+lenny2" test_ref="oval:org.mitre.oval:tst:13564"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 4.0 is installed" definition_ref="oval:org.mitre.oval:def:6461"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Packages section" operator="OR">
              <criterion comment="nginx DPKG is earlier than 0.4.13-2+etch2" test_ref="oval:org.mitre.oval:tst:13405"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:7658" class="patch">
      <metadata>
        <title>DSA-1838 pulseaudio -- privilege escalation</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <product>pulseaudio</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2009/dsa-1838" ref_id="DSA-1838"/>
        <description>Tavis Ormandy and Julien Tinnes discovered that the pulseaudio daemon does not drop privileges before re-executing itself, enabling local attackers to increase their privileges. The old stable distribution (etch) is not affected by this issue.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:05-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T07:52:49.278-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:01:24.494-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:01:00.188-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Release section" operator="AND">
        <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
        <criteria comment="Architecture section" operator="OR">
          <criteria comment="Packages section" operator="OR">
            <criterion comment="libpulse-dev DPKG is earlier than 0.9.10-3+lenny1" test_ref="oval:org.mitre.oval:tst:14723"/>
            <criterion comment="pulseaudio-utils DPKG is earlier than 0.9.10-3+lenny1" test_ref="oval:org.mitre.oval:tst:14079"/>
            <criterion comment="pulseaudio-esound-compat DPKG is earlier than 0.9.10-3+lenny1" test_ref="oval:org.mitre.oval:tst:13866"/>
            <criterion comment="libpulse-mainloop-glib0-dbg DPKG is earlier than 0.9.10-3+lenny1" test_ref="oval:org.mitre.oval:tst:14795"/>
            <criterion comment="pulseaudio-module-gconf-dbg DPKG is earlier than 0.9.10-3+lenny1" test_ref="oval:org.mitre.oval:tst:14279"/>
            <criterion comment="pulseaudio-dbg DPKG is earlier than 0.9.10-3+lenny1" test_ref="oval:org.mitre.oval:tst:14439"/>
            <criterion comment="pulseaudio-esound-compat-dbg DPKG is earlier than 0.9.10-3+lenny1" test_ref="oval:org.mitre.oval:tst:14823"/>
            <criterion comment="pulseaudio-module-hal DPKG is earlier than 0.9.10-3+lenny1" test_ref="oval:org.mitre.oval:tst:14804"/>
            <criterion comment="libpulsecore5 DPKG is earlier than 0.9.10-3+lenny1" test_ref="oval:org.mitre.oval:tst:14669"/>
            <criterion comment="libpulse-browse0 DPKG is earlier than 0.9.10-3+lenny1" test_ref="oval:org.mitre.oval:tst:14827"/>
            <criterion comment="pulseaudio-module-zeroconf DPKG is earlier than 0.9.10-3+lenny1" test_ref="oval:org.mitre.oval:tst:14861"/>
            <criterion comment="libpulse-browse0-dbg DPKG is earlier than 0.9.10-3+lenny1" test_ref="oval:org.mitre.oval:tst:14831"/>
            <criterion comment="pulseaudio-module-zeroconf-dbg DPKG is earlier than 0.9.10-3+lenny1" test_ref="oval:org.mitre.oval:tst:14580"/>
            <criterion comment="pulseaudio-module-jack-dbg DPKG is earlier than 0.9.10-3+lenny1" test_ref="oval:org.mitre.oval:tst:14678"/>
            <criterion comment="pulseaudio-module-x11 DPKG is earlier than 0.9.10-3+lenny1" test_ref="oval:org.mitre.oval:tst:14746"/>
            <criterion comment="pulseaudio-utils-dbg DPKG is earlier than 0.9.10-3+lenny1" test_ref="oval:org.mitre.oval:tst:14839"/>
            <criterion comment="pulseaudio-module-x11-dbg DPKG is earlier than 0.9.10-3+lenny1" test_ref="oval:org.mitre.oval:tst:14526"/>
            <criterion comment="libpulse-mainloop-glib0 DPKG is earlier than 0.9.10-3+lenny1" test_ref="oval:org.mitre.oval:tst:14211"/>
            <criterion comment="pulseaudio-module-gconf DPKG is earlier than 0.9.10-3+lenny1" test_ref="oval:org.mitre.oval:tst:14498"/>
            <criterion comment="pulseaudio-module-hal-dbg DPKG is earlier than 0.9.10-3+lenny1" test_ref="oval:org.mitre.oval:tst:14821"/>
            <criterion comment="pulseaudio-module-lirc-dbg DPKG is earlier than 0.9.10-3+lenny1" test_ref="oval:org.mitre.oval:tst:14239"/>
            <criterion comment="pulseaudio-module-lirc DPKG is earlier than 0.9.10-3+lenny1" test_ref="oval:org.mitre.oval:tst:14016"/>
            <criterion comment="pulseaudio-module-jack DPKG is earlier than 0.9.10-3+lenny1" test_ref="oval:org.mitre.oval:tst:14794"/>
            <criterion comment="libpulse0 DPKG is earlier than 0.9.10-3+lenny1" test_ref="oval:org.mitre.oval:tst:14722"/>
            <criterion comment="pulseaudio DPKG is earlier than 0.9.10-3+lenny1" test_ref="oval:org.mitre.oval:tst:14852"/>
            <criterion comment="libpulsecore5-dbg DPKG is earlier than 0.9.10-3+lenny1" test_ref="oval:org.mitre.oval:tst:14769"/>
            <criterion comment="libpulse0-dbg DPKG is earlier than 0.9.10-3+lenny1" test_ref="oval:org.mitre.oval:tst:14606"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:7644" class="patch">
      <metadata>
        <title>DSA-1927 linux-2.6 -- privilege escalation/denial of service/sensitive memory leak</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <product>linux-2.6</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2009/dsa-1927" ref_id="DSA-1927"/>
        <description>Notice: Debian 5.0.4, the next point release of Debian "lenny", will include a new default value for the mmap_min_addr tunable. This change will add an additional safeguard against a class of security vulnerabilities known as "NULL pointer dereference" vulnerabilities, but it will need to be overridden when using certain applications. Additional information about this change, including instructions for making this change locally in advance of 5.0.4 (recommended), can be found at: http://wiki.debian.org/mmap_min_addr. Several vulnerabilities have been discovered in the Linux kernel that may lead to a denial of service, sensitive memory leak or privilege escalation. The Common Vulnerabilities and Exposures project identifies the following problems: Eric Dumazet reported an instance of uninitialized kernel memory in the network packet scheduler. Local users may be able to exploit this issue to read the contents of sensitive kernel memory. Linus Torvalds provided a change to the get_random_int() function to increase its randomness. Earl Chew discovered a NULL pointer dereference issue in the pipe_rdwr_open function which can be used by local users to gain elevated privileges. Jiri Pirko discovered a typo in the initialization of a structure in the netlink subsystem that may allow local users to gain access to sensitive kernel memory. Ben Hutchings discovered an issue in the DRM manager for ATI Rage 128 graphics adapters. Local users may be able to exploit this vulnerability to cause a denial of service (NULL pointer dereference). Tomoki Sekiyama discovered a deadlock condition in the UNIX domain socket implementation. Local users can exploit this vulnerability to cause a denial of service (system hang). David Wagner reported an overflow in the KVM subsystem on i386 systems. This issue is exploitable by local users with access to the /dev/kvm device file.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:08-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T07:56:10.948-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:01:21.021-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:00:56.983-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Release section" operator="AND">
        <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
        <criteria comment="Architecture section" operator="OR">
          <criteria comment="Architecture independent section" operator="AND">
            <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
            <criteria comment="Packages section" operator="OR">
              <criterion comment="linux-patch-debian-2.6.26 is earlier than 2.6.26-19lenny2" test_ref="oval:org.mitre.oval:tst:17098"/>
              <criterion comment="linux-support-2.6.26-2 is earlier than 2.6.26-19lenny2" test_ref="oval:org.mitre.oval:tst:17280"/>
              <criterion comment="linux-doc-2.6.26 is earlier than 2.6.26-19lenny2" test_ref="oval:org.mitre.oval:tst:16479"/>
              <criterion comment="linux-tree-2.6.26 is earlier than 2.6.26-19lenny2" test_ref="oval:org.mitre.oval:tst:16866"/>
              <criterion comment="linux-source-2.6.26 is earlier than 2.6.26-19lenny2" test_ref="oval:org.mitre.oval:tst:17450"/>
              <criterion comment="linux-manual-2.6.26 is earlier than 2.6.26-19lenny2" test_ref="oval:org.mitre.oval:tst:17385"/>
            </criteria>
          </criteria>
          <criteria comment="Architecture dependent section" operator="AND">
            <criteria comment="Supported architectures section" operator="OR">
              <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
            </criteria>
            <criteria comment="Packages section" operator="OR">
              <criterion comment="xen-linux-system-2.6.26-2-xen-amd64 DPKG is earlier than 2.6.26-19lenny2" test_ref="oval:org.mitre.oval:tst:16851"/>
              <criterion comment="linux-headers-2.6.26-2-all DPKG is earlier than 2.6.26-19lenny2" test_ref="oval:org.mitre.oval:tst:17469"/>
              <criterion comment="linux-headers-2.6.26-2-openvz-amd64 DPKG is earlier than 2.6.26-19lenny2" test_ref="oval:org.mitre.oval:tst:17371"/>
              <criterion comment="linux-headers-2.6.26-2-common-vserver DPKG is earlier than 2.6.26-19lenny2" test_ref="oval:org.mitre.oval:tst:16969"/>
              <criterion comment="linux-image-2.6.26-2-openvz-amd64 DPKG is earlier than 2.6.26-19lenny2" test_ref="oval:org.mitre.oval:tst:17381"/>
              <criterion comment="linux-image-2.6.26-2-amd64 DPKG is earlier than 2.6.26-19lenny2" test_ref="oval:org.mitre.oval:tst:17345"/>
              <criterion comment="linux-headers-2.6.26-2-common-openvz DPKG is earlier than 2.6.26-19lenny2" test_ref="oval:org.mitre.oval:tst:16783"/>
              <criterion comment="linux-image-2.6.26-2-vserver-amd64 DPKG is earlier than 2.6.26-19lenny2" test_ref="oval:org.mitre.oval:tst:17294"/>
              <criterion comment="linux-modules-2.6.26-2-xen-amd64 DPKG is earlier than 2.6.26-19lenny2" test_ref="oval:org.mitre.oval:tst:17223"/>
              <criterion comment="linux-headers-2.6.26-2-all-amd64 DPKG is earlier than 2.6.26-19lenny2" test_ref="oval:org.mitre.oval:tst:17217"/>
              <criterion comment="linux-image-2.6.26-2-xen-amd64 DPKG is earlier than 2.6.26-19lenny2" test_ref="oval:org.mitre.oval:tst:17322"/>
              <criterion comment="linux-headers-2.6.26-2-common-xen DPKG is earlier than 2.6.26-19lenny2" test_ref="oval:org.mitre.oval:tst:17416"/>
              <criterion comment="linux-libc-dev DPKG is earlier than 2.6.26-19lenny2" test_ref="oval:org.mitre.oval:tst:16894"/>
              <criterion comment="linux-headers-2.6.26-2-xen-amd64 DPKG is earlier than 2.6.26-19lenny2" test_ref="oval:org.mitre.oval:tst:16872"/>
              <criterion comment="linux-headers-2.6.26-2-amd64 DPKG is earlier than 2.6.26-19lenny2" test_ref="oval:org.mitre.oval:tst:17132"/>
              <criterion comment="linux-headers-2.6.26-2-common DPKG is earlier than 2.6.26-19lenny2" test_ref="oval:org.mitre.oval:tst:17065"/>
              <criterion comment="linux-headers-2.6.26-2-vserver-amd64 DPKG is earlier than 2.6.26-19lenny2" test_ref="oval:org.mitre.oval:tst:17297"/>
            </criteria>
          </criteria>
          <criteria comment="Architecture dependent section" operator="AND">
            <criteria comment="Supported architectures section" operator="OR">
              <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
            </criteria>
            <criteria comment="Packages section" operator="OR">
              <criterion comment="linux-headers-2.6.26-2-all DPKG is earlier than 2.6.26-19lenny2" test_ref="oval:org.mitre.oval:tst:17396"/>
              <criterion comment="linux-headers-2.6.26-2-powerpc-smp DPKG is earlier than 2.6.26-19lenny2" test_ref="oval:org.mitre.oval:tst:17459"/>
              <criterion comment="linux-headers-2.6.26-2-powerpc64 DPKG is earlier than 2.6.26-19lenny2" test_ref="oval:org.mitre.oval:tst:17271"/>
              <criterion comment="linux-image-2.6.26-2-powerpc64 DPKG is earlier than 2.6.26-19lenny2" test_ref="oval:org.mitre.oval:tst:17390"/>
              <criterion comment="linux-headers-2.6.26-2-common-vserver DPKG is earlier than 2.6.26-19lenny2" test_ref="oval:org.mitre.oval:tst:17364"/>
              <criterion comment="linux-headers-2.6.26-2-powerpc DPKG is earlier than 2.6.26-19lenny2" test_ref="oval:org.mitre.oval:tst:17138"/>
              <criterion comment="linux-image-2.6.26-2-powerpc DPKG is earlier than 2.6.26-19lenny2" test_ref="oval:org.mitre.oval:tst:16855"/>
              <criterion comment="linux-image-2.6.26-2-vserver-powerpc64 DPKG is earlier than 2.6.26-19lenny2" test_ref="oval:org.mitre.oval:tst:17180"/>
              <criterion comment="linux-image-2.6.26-2-powerpc-smp DPKG is earlier than 2.6.26-19lenny2" test_ref="oval:org.mitre.oval:tst:17303"/>
              <criterion comment="linux-headers-2.6.26-2-all-powerpc DPKG is earlier than 2.6.26-19lenny2" test_ref="oval:org.mitre.oval:tst:17467"/>
              <criterion comment="linux-libc-dev DPKG is earlier than 2.6.26-19lenny2" test_ref="oval:org.mitre.oval:tst:17121"/>
              <criterion comment="linux-headers-2.6.26-2-vserver-powerpc64 DPKG is earlier than 2.6.26-19lenny2" test_ref="oval:org.mitre.oval:tst:17462"/>
              <criterion comment="linux-image-2.6.26-2-vserver-powerpc DPKG is earlier than 2.6.26-19lenny2" test_ref="oval:org.mitre.oval:tst:17461"/>
              <criterion comment="linux-headers-2.6.26-2-vserver-powerpc DPKG is earlier than 2.6.26-19lenny2" test_ref="oval:org.mitre.oval:tst:17177"/>
              <criterion comment="linux-headers-2.6.26-2-common DPKG is earlier than 2.6.26-19lenny2" test_ref="oval:org.mitre.oval:tst:17203"/>
            </criteria>
          </criteria>
          <criteria comment="Architecture depended section" operator="AND">
            <criteria comment="Supported platform section" operator="AND">
              <criterion comment="hppa architecture" test_ref="oval:org.mitre.oval:tst:11164"/>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="linux-headers-2.6.26-2-all DPKG is earlier than 2.6.26-19lenny2" test_ref="oval:org.mitre.oval:tst:16942"/>
                <criterion comment="linux-headers-2.6.26-2-parisc DPKG is earlier than 2.6.26-19lenny2" test_ref="oval:org.mitre.oval:tst:17379"/>
                <criterion comment="linux-image-2.6.26-2-parisc64 DPKG is earlier than 2.6.26-19lenny2" test_ref="oval:org.mitre.oval:tst:17458"/>
                <criterion comment="linux-image-2.6.26-2-parisc DPKG is earlier than 2.6.26-19lenny2" test_ref="oval:org.mitre.oval:tst:17136"/>
                <criterion comment="linux-headers-2.6.26-2-parisc-smp DPKG is earlier than 2.6.26-19lenny2" test_ref="oval:org.mitre.oval:tst:17453"/>
                <criterion comment="linux-headers-2.6.26-2-all-hppa DPKG is earlier than 2.6.26-19lenny2" test_ref="oval:org.mitre.oval:tst:16488"/>
                <criterion comment="linux-image-2.6.26-2-parisc64-smp DPKG is earlier than 2.6.26-19lenny2" test_ref="oval:org.mitre.oval:tst:16867"/>
                <criterion comment="linux-headers-2.6.26-2-parisc64 DPKG is earlier than 2.6.26-19lenny2" test_ref="oval:org.mitre.oval:tst:17376"/>
                <criterion comment="linux-headers-2.6.26-2-parisc64-smp DPKG is earlier than 2.6.26-19lenny2" test_ref="oval:org.mitre.oval:tst:17289"/>
                <criterion comment="linux-libc-dev DPKG is earlier than 2.6.26-19lenny2" test_ref="oval:org.mitre.oval:tst:17224"/>
                <criterion comment="linux-image-2.6.26-2-parisc-smp DPKG is earlier than 2.6.26-19lenny2" test_ref="oval:org.mitre.oval:tst:17422"/>
                <criterion comment="linux-headers-2.6.26-2-common DPKG is earlier than 2.6.26-19lenny2" test_ref="oval:org.mitre.oval:tst:17156"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:7639" class="patch">
      <metadata>
        <title>DSA-1915 linux-2.6 -- privilege escalation/denial of service/sensitive memory leak</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <product>linux-2.6</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2009/dsa-1915" ref_id="DSA-1915"/>
        <description>Notice: Debian 5.0.4, the next point release of Debian "lenny", will include a new default value for the mmap_min_addr tunable. This change will add an additional safeguard against a class of security vulnerabilities known as "NULL pointer dereference" vulnerabilities, but it will need to be overridden when using certain applications. Additional information about this change, including instructions for making this change locally in advance of 5.0.4 (recommended), can be found at: http://wiki.debian.org/mmap_min_addr. Several vulnerabilities have been discovered in the Linux kernel that may lead to a denial of service, sensitive memory leak or privilege escalation. The Common Vulnerabilities and Exposures project identifies the following problems: Eric Paris provided several fixes to increase the protection provided by the mmap_min_addr tunable against NULL pointer dereference vulnerabilities. Mark Smith discovered a memory leak in the appletalk implementation. When the appletalk and ipddp modules are loaded, but no ipddp "N" device is found, remote attackers can cause a denial of service by consuming large amounts of system memory. Loic Minier discovered an issue in the eCryptfs filesystem. A local user can cause a denial of service (kernel oops) by causing a dentry value to go negative. Arjan van de Ven discovered an issue in the AX.25 protocol implementation. A specially crafted call to setsockopt() can result in a denial of service (kernel oops). Jan Beulich discovered the existence of a sensitive kernel memory leak. Systems running the "amd64" kernel do not properly sanitize registers for 32-bit processes. Jiri Slaby fixed a sensitive memory leak issue in the ANSI/IEEE 802.2 LLC implementation. This is not exploitable in the Debian lenny kernel as root privileges are required to exploit this issue. Eric Dumazet fixed several sensitive memory leaks in the IrDA, X.25 PLP (Rose), NET/ROM, Acorn Econet/AUN, and Controller Area Network (CAN) implementations. Local users can exploit these issues to gain access to kernel memory. Eric Paris discovered an issue with the NFSv4 server implementation. When an O_EXCL create fails, files may be left with corrupted permissions, possibly granting unintentional privileges to other local users. Jan Kiszka noticed that the kvm_emulate_hypercall function in KVM does not prevent access to MMU hypercalls from ring 0, which allows local guest OS users to cause a denial of service (guest kernel crash) and read or write guest kernel memory. Alistair Strachan reported an issue in the r8169 driver. Remote users can cause a denial of service (IOMMU space exhaustion and system crash) by transmitting a large amount of jumbo frames.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:07-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T07:54:19.660-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:01:19.892-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:00:56.127-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Release section" operator="AND">
        <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
        <criteria comment="Architecture section" operator="OR">
          <criteria comment="Architecture independent section" operator="AND">
            <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
            <criteria comment="Packages section" operator="OR">
              <criterion comment="linux-patch-debian-2.6.26 is earlier than 2.6.26-19lenny1" test_ref="oval:org.mitre.oval:tst:16039"/>
              <criterion comment="linux-support-2.6.26-2 is earlier than 2.6.26-19lenny1" test_ref="oval:org.mitre.oval:tst:15760"/>
              <criterion comment="linux-doc-2.6.26 is earlier than 2.6.26-19lenny1" test_ref="oval:org.mitre.oval:tst:15864"/>
              <criterion comment="linux-tree-2.6.26 is earlier than 2.6.26-19lenny1" test_ref="oval:org.mitre.oval:tst:15949"/>
              <criterion comment="linux-source-2.6.26 is earlier than 2.6.26-19lenny1" test_ref="oval:org.mitre.oval:tst:16048"/>
              <criterion comment="linux-manual-2.6.26 is earlier than 2.6.26-19lenny1" test_ref="oval:org.mitre.oval:tst:15955"/>
            </criteria>
          </criteria>
          <criteria comment="Architecture dependent section" operator="AND">
            <criteria comment="Supported architectures section" operator="OR">
              <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
            </criteria>
            <criteria comment="Packages section" operator="OR">
              <criterion comment="linux-headers-2.6.26-2-all DPKG is earlier than 2.6.26-19lenny1" test_ref="oval:org.mitre.oval:tst:15625"/>
              <criterion comment="linux-image-2.6.26-2-vserver-s390x DPKG is earlier than 2.6.26-19lenny1" test_ref="oval:org.mitre.oval:tst:15250"/>
              <criterion comment="linux-image-2.6.26-2-s390 DPKG is earlier than 2.6.26-19lenny1" test_ref="oval:org.mitre.oval:tst:16141"/>
              <criterion comment="linux-headers-2.6.26-2-common-vserver DPKG is earlier than 2.6.26-19lenny1" test_ref="oval:org.mitre.oval:tst:16140"/>
              <criterion comment="linux-image-2.6.26-2-s390-tape DPKG is earlier than 2.6.26-19lenny1" test_ref="oval:org.mitre.oval:tst:16228"/>
              <criterion comment="linux-headers-2.6.26-2-all-s390 DPKG is earlier than 2.6.26-19lenny1" test_ref="oval:org.mitre.oval:tst:16085"/>
              <criterion comment="linux-headers-2.6.26-2-s390 DPKG is earlier than 2.6.26-19lenny1" test_ref="oval:org.mitre.oval:tst:15896"/>
              <criterion comment="linux-headers-2.6.26-2-vserver-s390x DPKG is earlier than 2.6.26-19lenny1" test_ref="oval:org.mitre.oval:tst:16232"/>
              <criterion comment="linux-libc-dev DPKG is earlier than 2.6.26-19lenny1" test_ref="oval:org.mitre.oval:tst:16184"/>
              <criterion comment="linux-image-2.6.26-2-s390x DPKG is earlier than 2.6.26-19lenny1" test_ref="oval:org.mitre.oval:tst:15650"/>
              <criterion comment="linux-headers-2.6.26-2-common DPKG is earlier than 2.6.26-19lenny1" test_ref="oval:org.mitre.oval:tst:16229"/>
              <criterion comment="linux-headers-2.6.26-2-s390x DPKG is earlier than 2.6.26-19lenny1" test_ref="oval:org.mitre.oval:tst:15918"/>
            </criteria>
          </criteria>
          <criteria comment="Architecture dependent section" operator="AND">
            <criteria comment="Supported architectures section" operator="OR">
              <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
            </criteria>
            <criteria comment="Packages section" operator="OR">
              <criterion comment="xen-linux-system-2.6.26-2-xen-amd64 DPKG is earlier than 2.6.26-19lenny1" test_ref="oval:org.mitre.oval:tst:16207"/>
              <criterion comment="linux-headers-2.6.26-2-all DPKG is earlier than 2.6.26-19lenny1" test_ref="oval:org.mitre.oval:tst:15832"/>
              <criterion comment="linux-modules-2.6.26-2-xen-amd64 DPKG is earlier than 2.6.26-19lenny1" test_ref="oval:org.mitre.oval:tst:15938"/>
              <criterion comment="linux-headers-2.6.26-2-openvz-amd64 DPKG is earlier than 2.6.26-19lenny1" test_ref="oval:org.mitre.oval:tst:16178"/>
              <criterion comment="linux-headers-2.6.26-2-common-vserver DPKG is earlier than 2.6.26-19lenny1" test_ref="oval:org.mitre.oval:tst:15289"/>
              <criterion comment="linux-image-2.6.26-2-openvz-amd64 DPKG is earlier than 2.6.26-19lenny1" test_ref="oval:org.mitre.oval:tst:16025"/>
              <criterion comment="linux-libc-dev DPKG is earlier than 2.6.26-19lenny1" test_ref="oval:org.mitre.oval:tst:15680"/>
              <criterion comment="linux-headers-2.6.26-2-common-openvz DPKG is earlier than 2.6.26-19lenny1" test_ref="oval:org.mitre.oval:tst:16026"/>
              <criterion comment="linux-image-2.6.26-2-vserver-amd64 DPKG is earlier than 2.6.26-19lenny1" test_ref="oval:org.mitre.oval:tst:15326"/>
              <criterion comment="linux-headers-2.6.26-2-all-amd64 DPKG is earlier than 2.6.26-19lenny1" test_ref="oval:org.mitre.oval:tst:16120"/>
              <criterion comment="linux-image-2.6.26-2-xen-amd64 DPKG is earlier than 2.6.26-19lenny1" test_ref="oval:org.mitre.oval:tst:16192"/>
              <criterion comment="linux-headers-2.6.26-2-common-xen DPKG is earlier than 2.6.26-19lenny1" test_ref="oval:org.mitre.oval:tst:16065"/>
              <criterion comment="linux-image-2.6.26-2-amd64 DPKG is earlier than 2.6.26-19lenny1" test_ref="oval:org.mitre.oval:tst:16233"/>
              <criterion comment="linux-headers-2.6.26-2-xen-amd64 DPKG is earlier than 2.6.26-19lenny1" test_ref="oval:org.mitre.oval:tst:16209"/>
              <criterion comment="linux-headers-2.6.26-2-amd64 DPKG is earlier than 2.6.26-19lenny1" test_ref="oval:org.mitre.oval:tst:16242"/>
              <criterion comment="linux-headers-2.6.26-2-common DPKG is earlier than 2.6.26-19lenny1" test_ref="oval:org.mitre.oval:tst:15959"/>
              <criterion comment="linux-headers-2.6.26-2-vserver-amd64 DPKG is earlier than 2.6.26-19lenny1" test_ref="oval:org.mitre.oval:tst:15961"/>
            </criteria>
          </criteria>
          <criteria comment="Architecture depended section" operator="AND">
            <criteria comment="Supported platform section" operator="AND">
              <criterion comment="hppa architecture" test_ref="oval:org.mitre.oval:tst:11164"/>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="linux-headers-2.6.26-2-all DPKG is earlier than 2.6.26-19lenny1" test_ref="oval:org.mitre.oval:tst:15819"/>
                <criterion comment="linux-headers-2.6.26-2-parisc DPKG is earlier than 2.6.26-19lenny1" test_ref="oval:org.mitre.oval:tst:15899"/>
                <criterion comment="linux-image-2.6.26-2-parisc64 DPKG is earlier than 2.6.26-19lenny1" test_ref="oval:org.mitre.oval:tst:15923"/>
                <criterion comment="linux-image-2.6.26-2-parisc DPKG is earlier than 2.6.26-19lenny1" test_ref="oval:org.mitre.oval:tst:16326"/>
                <criterion comment="linux-headers-2.6.26-2-common DPKG is earlier than 2.6.26-19lenny1" test_ref="oval:org.mitre.oval:tst:15897"/>
                <criterion comment="linux-headers-2.6.26-2-all-hppa DPKG is earlier than 2.6.26-19lenny1" test_ref="oval:org.mitre.oval:tst:16393"/>
                <criterion comment="linux-image-2.6.26-2-parisc-smp DPKG is earlier than 2.6.26-19lenny1" test_ref="oval:org.mitre.oval:tst:15943"/>
                <criterion comment="linux-headers-2.6.26-2-parisc64-smp DPKG is earlier than 2.6.26-19lenny1" test_ref="oval:org.mitre.oval:tst:15505"/>
                <criterion comment="linux-headers-2.6.26-2-parisc64 DPKG is earlier than 2.6.26-19lenny1" test_ref="oval:org.mitre.oval:tst:16319"/>
                <criterion comment="linux-libc-dev DPKG is earlier than 2.6.26-19lenny1" test_ref="oval:org.mitre.oval:tst:16304"/>
                <criterion comment="linux-image-2.6.26-2-parisc64-smp DPKG is earlier than 2.6.26-19lenny1" test_ref="oval:org.mitre.oval:tst:16309"/>
                <criterion comment="linux-headers-2.6.26-2-parisc-smp DPKG is earlier than 2.6.26-19lenny1" test_ref="oval:org.mitre.oval:tst:15850"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:7638" class="patch">
      <metadata>
        <title>DSA-1909 postgresql-ocaml -- missing escape function</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <platform>Debian GNU/Linux 4.0</platform>
          <product>postgresql-ocaml</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2009/dsa-1909" ref_id="DSA-1909"/>
        <description>It was discovered that postgresql-ocaml, OCaml bindings to PostgreSQL's libpq, was missing a function to call PQescapeStringConn(). This is needed, because PQescapeStringConn() honours the charset of the connection and prevents insufficient escaping, when certain multibyte character encodings are used. The added function is called escape_string_conn() and takes the established database connection as a first argument. The old escape_string() was kept for backwards compatibility. Developers using these bindings are encouraged to adjust their code to use the new function.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:03-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T07:50:40.789-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:01:19.251-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:00:55.626-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Platform section" operator="OR">
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Architecture dependent section" operator="AND">
              <criteria comment="Supported architectures section" operator="OR">
                <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
                <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
                <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
                <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
                <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
                <criterion comment="Installed architecture is armel" test_ref="oval:org.mitre.oval:tst:11101"/>
                <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
                <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
                <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
                <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
                <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
                <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
              </criteria>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="libpostgresql-ocaml-dev DPKG is earlier than 1.7.0-3+lenny1" test_ref="oval:org.mitre.oval:tst:13218"/>
                <criterion comment="libpostgresql-ocaml DPKG is earlier than 1.7.0-3+lenny1" test_ref="oval:org.mitre.oval:tst:12962"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 4.0 is installed" definition_ref="oval:org.mitre.oval:def:6461"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Packages section" operator="OR">
              <criterion comment="libpostgresql-ocaml-dev DPKG is earlier than 1.5.4-2+etch1" test_ref="oval:org.mitre.oval:tst:13046"/>
              <criterion comment="libpostgresql-ocaml DPKG is earlier than 1.5.4-2+etch1" test_ref="oval:org.mitre.oval:tst:13102"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:7635" class="patch">
      <metadata>
        <title>DSA-1848 znc -- directory traversal</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <platform>Debian GNU/Linux 4.0</platform>
          <product>znc</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2009/dsa-1848" ref_id="DSA-1848"/>
        <description>It was discovered that znc, an IRC proxy, did not properly process certain DCC requests, allowing attackers to upload arbitrary files.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:03-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T07:50:05.800-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:01:18.177-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:00:54.736-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Platform section" operator="OR">
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Architecture dependent section" operator="AND">
              <criteria comment="Supported architectures section" operator="OR">
                <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
                <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
                <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
                <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
                <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
                <criterion comment="Installed architecture is armel" test_ref="oval:org.mitre.oval:tst:11101"/>
                <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
                <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
                <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
                <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
                <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
                <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
              </criteria>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="znc DPKG is earlier than 0.058-2+lenny3" test_ref="oval:org.mitre.oval:tst:12457"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 4.0 is installed" definition_ref="oval:org.mitre.oval:def:6461"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Packages section" operator="OR">
              <criterion comment="znc DPKG is earlier than 0.045-3+etch3" test_ref="oval:org.mitre.oval:tst:12610"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7607" version="3" class="patch">
      <metadata>
        <title>DSA-2019 pango1.0 -- missing input sanitization</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <product>pango1.0</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2010/dsa-2019" ref_id="DSA-2019"/>
        <description>Marc Schoenefeld discovered an improper input sanitization in Pango, a library for layout and rendering of text, leading to array indexing error. If a local user was tricked into loading a specially-crafted font file in an application, using the Pango font rendering library, it could lead to denial of service .</description>
        <oval_repository>
          <dates>
            <submitted date="2010-05-24T18:49:49-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2010-05-26T13:27:09.356-04:00">DRAFT</status_change>
            <status_change date="2010-06-14T04:01:01.710-04:00">INTERIM</status_change>
            <status_change date="2010-06-29T11:50:04.880-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
        <criteria operator="OR" comment="Architecture section">
          <criteria operator="AND" comment="Architecture independent section">
            <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
            <criteria operator="OR" comment="Packages section">
              <criterion comment="libpango1.0-doc is earlier than 1.20.5-5+lenny1" test_ref="oval:org.mitre.oval:tst:23622"/>
              <criterion comment="libpango1.0-common is earlier than 1.20.5-5+lenny1" test_ref="oval:org.mitre.oval:tst:24415"/>
            </criteria>
          </criteria>
          <criteria operator="AND" comment="Architecture dependent section">
            <criteria operator="OR" comment="Supported architectures section">
              <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
              <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
              <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
              <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
              <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
              <criterion comment="Installed architecture is armel" test_ref="oval:org.mitre.oval:tst:11101"/>
              <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
              <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
              <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
              <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
              <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
            </criteria>
            <criteria operator="OR" comment="Packages section">
              <criterion comment="libpango1.0-0 is earlier than 1.20.5-5+lenny1" test_ref="oval:org.mitre.oval:tst:24251"/>
              <criterion comment="libpango1.0-0-dbg is earlier than 1.20.5-5+lenny1" test_ref="oval:org.mitre.oval:tst:24323"/>
              <criterion comment="libpango1.0-dev is earlier than 1.20.5-5+lenny1" test_ref="oval:org.mitre.oval:tst:24017"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:7605" class="patch">
      <metadata>
        <title>DSA-1728 dkim-milter -- improper assertion</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <product>dkim-milter</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2009/dsa-1728" ref_id="DSA-1728"/>
        <description>It was discovered that dkim-milter, an implementation of the DomainKeys Identified Mail protocol, may crash during DKIM verification if it encounters a specially-crafted or revoked public key record in DNS. The old stable distribution (etch) does not contain dkim-milter packages.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:08-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T07:56:28.617-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:01:13.592-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:00:51.010-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Release section" operator="AND">
        <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
        <criteria comment="Architecture section" operator="OR">
          <criteria comment="Architecture dependent section" operator="AND">
            <criteria comment="Supported architectures section" operator="OR">
              <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
              <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
              <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
              <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
              <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
              <criterion comment="Installed architecture is armel" test_ref="oval:org.mitre.oval:tst:11101"/>
              <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
              <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
              <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
              <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
              <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
            </criteria>
            <criteria comment="Packages section" operator="OR">
              <criterion comment="libsmdkim-dev DPKG is earlier than 2.6.0.dfsg-1+lenny1" test_ref="oval:org.mitre.oval:tst:17647"/>
              <criterion comment="libsmdkim2 DPKG is earlier than 2.6.0.dfsg-1+lenny1" test_ref="oval:org.mitre.oval:tst:17507"/>
              <criterion comment="dkim-filter DPKG is earlier than 2.6.0.dfsg-1+lenny1" test_ref="oval:org.mitre.oval:tst:17514"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:7600" class="patch">
      <metadata>
        <title>DSA-1834 apache2 -- denial of service</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <platform>Debian GNU/Linux 4.0</platform>
          <product>apache2</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2009/dsa-1834" ref_id="DSA-1834"/>
        <description>A denial of service flaw was found in the Apache mod_proxy module when it was used as a reverse proxy. A remote attacker could use this flaw to force a proxy process to consume large amounts of CPU time. This issue did not affect Debian 4.0 "etch". A denial of service flaw was found in the Apache mod_deflate module. This module continued to compress large files until compression was complete, even if the network connection that requested the content was closed before compression completed. This would cause mod_deflate to consume large amounts of CPU if mod_deflate was enabled for a large file. A similar flaw related to HEAD requests for compressed content was also fixed. The oldstable distribution (etch), these problems have been fixed in version 2.2.3-4+etch9.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:05-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T07:52:43.860-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:01:11.568-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:00:49.540-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Platform section" operator="OR">
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Architecture independent section" operator="AND">
              <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="apache2-src is earlier than 2.2.9-10+lenny4" test_ref="oval:org.mitre.oval:tst:14788"/>
                <criterion comment="apache2-doc is earlier than 2.2.9-10+lenny4" test_ref="oval:org.mitre.oval:tst:14650"/>
                <criterion comment="apache2 is earlier than 2.2.9-10+lenny4" test_ref="oval:org.mitre.oval:tst:14326"/>
              </criteria>
            </criteria>
            <criteria comment="Architecture dependent section" operator="AND">
              <criteria comment="Supported architectures section" operator="OR">
                <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
                <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
                <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
                <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
                <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
                <criterion comment="Installed architecture is armel" test_ref="oval:org.mitre.oval:tst:11101"/>
                <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
                <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
                <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
                <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
                <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
              </criteria>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="apache2-threaded-dev DPKG is earlier than 2.2.9-10+lenny4" test_ref="oval:org.mitre.oval:tst:14447"/>
                <criterion comment="apache2-utils DPKG is earlier than 2.2.9-10+lenny4" test_ref="oval:org.mitre.oval:tst:14774"/>
                <criterion comment="apache2-mpm-worker DPKG is earlier than 2.2.9-10+lenny4" test_ref="oval:org.mitre.oval:tst:14691"/>
                <criterion comment="apache2.2-common DPKG is earlier than 2.2.9-10+lenny4" test_ref="oval:org.mitre.oval:tst:14031"/>
                <criterion comment="apache2-suexec-custom DPKG is earlier than 2.2.9-10+lenny4" test_ref="oval:org.mitre.oval:tst:14613"/>
                <criterion comment="apache2-suexec DPKG is earlier than 2.2.9-10+lenny4" test_ref="oval:org.mitre.oval:tst:14697"/>
                <criterion comment="apache2-mpm-prefork DPKG is earlier than 2.2.9-10+lenny4" test_ref="oval:org.mitre.oval:tst:14334"/>
                <criterion comment="apache2-dbg DPKG is earlier than 2.2.9-10+lenny4" test_ref="oval:org.mitre.oval:tst:14133"/>
                <criterion comment="apache2-mpm-event DPKG is earlier than 2.2.9-10+lenny4" test_ref="oval:org.mitre.oval:tst:14537"/>
                <criterion comment="apache2-prefork-dev DPKG is earlier than 2.2.9-10+lenny4" test_ref="oval:org.mitre.oval:tst:14514"/>
              </criteria>
            </criteria>
            <criteria comment="Packages section" operator="OR">
              <criterion comment="apache2-mpm-itk DPKG is earlier than 2.2.6-02-1+lenny2" test_ref="oval:org.mitre.oval:tst:14791"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 4.0 is installed" definition_ref="oval:org.mitre.oval:def:6461"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Architecture independent section" operator="AND">
              <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="apache2-mpm-perchild is earlier than 2.2.3-4+etch9" test_ref="oval:org.mitre.oval:tst:14736"/>
                <criterion comment="apache2-src is earlier than 2.2.3-4+etch9" test_ref="oval:org.mitre.oval:tst:14454"/>
                <criterion comment="apache2-doc is earlier than 2.2.3-4+etch9" test_ref="oval:org.mitre.oval:tst:14683"/>
                <criterion comment="apache2 is earlier than 2.2.3-4+etch9" test_ref="oval:org.mitre.oval:tst:14707"/>
              </criteria>
            </criteria>
            <criteria comment="Architecture dependent section" operator="AND">
              <criteria comment="Supported architectures section" operator="OR">
                <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
                <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
                <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
                <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
                <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
                <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
                <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
                <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
                <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
              </criteria>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="apache2-mpm-itk DPKG is earlier than 2.2.3-01-2+etch3" test_ref="oval:org.mitre.oval:tst:14767"/>
                <criterion comment="apache2-utils DPKG is earlier than 2.2.3-4+etch9" test_ref="oval:org.mitre.oval:tst:14543"/>
                <criterion comment="apache2-mpm-worker DPKG is earlier than 2.2.3-4+etch9" test_ref="oval:org.mitre.oval:tst:14428"/>
                <criterion comment="apache2.2-common DPKG is earlier than 2.2.3-4+etch9" test_ref="oval:org.mitre.oval:tst:14104"/>
                <criterion comment="apache2-threaded-dev DPKG is earlier than 2.2.3-4+etch9" test_ref="oval:org.mitre.oval:tst:14584"/>
                <criterion comment="apache2-mpm-event DPKG is earlier than 2.2.3-4+etch9" test_ref="oval:org.mitre.oval:tst:14489"/>
                <criterion comment="apache2-mpm-prefork DPKG is earlier than 2.2.3-4+etch9" test_ref="oval:org.mitre.oval:tst:14562"/>
                <criterion comment="apache2-prefork-dev DPKG is earlier than 2.2.3-4+etch9" test_ref="oval:org.mitre.oval:tst:14778"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7590" version="3" class="patch">
      <metadata>
        <title>DSA-2033 ejabberd -- heap overflow</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <product>ejabberd</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2010/dsa-2033" ref_id="DSA-2033"/>
        <description>It was discovered that in ejabberd, a distributed XMPP/Jabber server written in Erlang, a problem in ejabberd_c2s.erl allows remote authenticated users to cause a denial of service by sending a large number of c2s  messages; that triggers an overload of the queue, which in turn causes a crash of the ejabberd daemon.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-05-24T19:10:11-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2010-05-26T13:29:14.821-04:00">DRAFT</status_change>
            <status_change date="2010-06-14T04:01:01.496-04:00">INTERIM</status_change>
            <status_change date="2010-06-29T11:50:04.428-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
        <criteria operator="OR" comment="Architecture section">
          <criteria operator="OR" comment="Packages section">
            <criterion comment="ejabberd is earlier than 2.0.1-6+lenny2" test_ref="oval:org.mitre.oval:tst:26597"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:7586" class="patch">
      <metadata>
        <title>DSA-1942 wireshark -- several vulnerabilities</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <platform>Debian GNU/Linux 4.0</platform>
          <product>wireshark</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2009/dsa-1942" ref_id="DSA-1942"/>
        <description>Several remote vulnerabilities have been discovered in the Wireshark network traffic analyzer, which may lead to the execution of arbitrary code or denial of service. The Common Vulnerabilities and Exposures project identifies the following problems: A NULL pointer dereference was found in the RADIUS dissector. A NULL pointer dereference was found in the DCERP/NT dissector. An integer overflow was discovered in the ERF parser. This update also includes fixes for three minor issues (CVE-2008-1829, CVE-2009-2562, CVE-2009-3241), which were scheduled for the next stable point update. Also CVE-2009-1268 was fixed for Etch. Since this security update was issued prior to the release of the point update, the fixes were included.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:02-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T07:48:36.074-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:01:10.242-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:00:48.403-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Platform section" operator="OR">
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Architecture dependent section" operator="AND">
              <criteria comment="Supported architectures section" operator="OR">
                <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
                <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
                <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
                <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
                <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
                <criterion comment="Installed architecture is armel" test_ref="oval:org.mitre.oval:tst:11101"/>
                <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
                <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
                <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
                <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
                <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
                <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
              </criteria>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="wireshark-dev DPKG is earlier than 1.0.2-3+lenny7" test_ref="oval:org.mitre.oval:tst:11593"/>
                <criterion comment="wireshark-common DPKG is earlier than 1.0.2-3+lenny7" test_ref="oval:org.mitre.oval:tst:11843"/>
                <criterion comment="tshark DPKG is earlier than 1.0.2-3+lenny7" test_ref="oval:org.mitre.oval:tst:11792"/>
                <criterion comment="wireshark DPKG is earlier than 1.0.2-3+lenny7" test_ref="oval:org.mitre.oval:tst:11443"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 4.0 is installed" definition_ref="oval:org.mitre.oval:def:6461"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Packages section" operator="OR">
              <criterion comment="wireshark-dev DPKG is earlier than 0.99.4-5.etch.4" test_ref="oval:org.mitre.oval:tst:11848"/>
              <criterion comment="tshark DPKG is earlier than 0.99.4-5.etch.4" test_ref="oval:org.mitre.oval:tst:11683"/>
              <criterion comment="ethereal-dev DPKG is earlier than 0.99.4-5.etch.4" test_ref="oval:org.mitre.oval:tst:11714"/>
              <criterion comment="tethereal DPKG is earlier than 0.99.4-5.etch.4" test_ref="oval:org.mitre.oval:tst:11600"/>
              <criterion comment="wireshark-common DPKG is earlier than 0.99.4-5.etch.4" test_ref="oval:org.mitre.oval:tst:11653"/>
              <criterion comment="ethereal DPKG is earlier than 0.99.4-5.etch.4" test_ref="oval:org.mitre.oval:tst:10970"/>
              <criterion comment="ethereal-common DPKG is earlier than 0.99.4-5.etch.4" test_ref="oval:org.mitre.oval:tst:11117"/>
              <criterion comment="wireshark DPKG is earlier than 0.99.4-5.etch.4" test_ref="oval:org.mitre.oval:tst:11858"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:7585" class="patch">
      <metadata>
        <title>DSA-1752 webcit -- format string vulnerability</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <product>webcit</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2009/dsa-1752" ref_id="DSA-1752"/>
        <description>Wilfried Goesgens discovered that WebCit, the web-based user interface for the Citadel groupware system, contains a format string vulnerability in the mini_calendar component, possibly allowing arbitrary code execution (CVE-2009-0364).</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:04-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T07:51:17.513-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:01:09.774-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:00:47.960-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Release section" operator="AND">
        <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
        <criteria comment="Architecture section" operator="OR">
          <criteria comment="Architecture dependent section" operator="AND">
            <criteria comment="Supported architectures section" operator="OR">
              <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
              <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
              <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
              <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
              <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
              <criterion comment="Installed architecture is armel" test_ref="oval:org.mitre.oval:tst:11101"/>
              <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
              <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
              <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
              <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
              <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
              <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
            </criteria>
            <criteria comment="Packages section" operator="OR">
              <criterion comment="citadel-webcit DPKG is earlier than 7.37-dfsg-7" test_ref="oval:org.mitre.oval:tst:13024"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:7579" class="patch">
      <metadata>
        <title>DSA-1824 phpmyadmin -- several vulnerabilities</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <platform>Debian GNU/Linux 4.0</platform>
          <product>phpmyadmin</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2009/dsa-1824" ref_id="DSA-1824"/>
        <description>Several remote vulnerabilities have been discovered in phpMyAdmin, a tool to administer MySQL over the web. The Common Vulnerabilities and Exposures project identifies the following problems: Cross site scripting vulnerability in the export page allow for an attacker that can place crafted cookies with the user to inject arbitrary web script or HTML. Static code injection allows for a remote attacker to inject arbitrary code into phpMyAdmin via the setup.php script. This script is in Debian under normal circumstances protected via Apache authentication. However, because of a recent worm based on this exploit, we are patching it regardless, to also protect installations that somehow still expose the setup.php script.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:08-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T07:55:54.675-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:01:07.132-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:00:45.749-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Platform section" operator="OR">
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Architecture independent section" operator="AND">
              <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criterion comment="phpmyadmin is earlier than 2.11.8.1-5+lenny1" test_ref="oval:org.mitre.oval:tst:17351"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 4.0 is installed" definition_ref="oval:org.mitre.oval:def:6461"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Architecture independent section" operator="AND">
              <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criterion comment="phpmyadmin is earlier than 2.9.1.1-11" test_ref="oval:org.mitre.oval:tst:17172"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7571" version="3" class="patch">
      <metadata>
        <title>DSA-1963 unbound -- cryptographic implementation error</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <product>unbound</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2009/dsa-1963" ref_id="DSA-1963"/>
        <description>It was discovered that Unbound, a DNS resolver, does not properly check cryptographic signatures on NSEC3 records. As a result, zones signed with the NSEC3 variant of DNSSEC lose their cryptographic protection.  The old stable distribution  does not contain an unbound package.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-05-24T19:09:29-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2010-05-26T13:29:08.362-04:00">DRAFT</status_change>
            <status_change date="2010-06-14T04:01:00.748-04:00">INTERIM</status_change>
            <status_change date="2010-06-29T11:50:03.447-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
        <criteria operator="OR" comment="Architecture section">
          <criteria operator="AND" comment="Architecture dependent section">
            <criteria operator="OR" comment="Supported architectures section">
              <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
              <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
              <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
              <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
              <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
              <criterion comment="Installed architecture is armel" test_ref="oval:org.mitre.oval:tst:11101"/>
              <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
              <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
              <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
              <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
              <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
              <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
            </criteria>
            <criteria operator="OR" comment="Packages section">
              <criterion comment="unbound is earlier than 1.0.2-1+lenny1" test_ref="oval:org.mitre.oval:tst:26599"/>
              <criterion comment="libunbound0 is earlier than 1.0.2-1+lenny1" test_ref="oval:org.mitre.oval:tst:26918"/>
              <criterion comment="libunbound-dev is earlier than 1.0.2-1+lenny1" test_ref="oval:org.mitre.oval:tst:26491"/>
              <criterion comment="unbound-host is earlier than 1.0.2-1+lenny1" test_ref="oval:org.mitre.oval:tst:26921"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7566" version="3" class="patch">
      <metadata>
        <title>DSA-2014 moin -- several vulnerabilities</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <product>moin</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2010/dsa-2014" ref_id="DSA-2014"/>
        <description>Several vulnerabilities have been discovered in moin, a python clone of WikiWiki. The Common Vulnerabilities and Exposures project identifies the following problems: Multiple security issues in MoinMoin related to configurations that have a non-empty superuser list, the xmlrpc action enabled, the SyncPages action enabled, or OpenID configured. MoinMoin does not properly sanitize user profiles. The default configuration of cfg.packagepages_actions_excluded in MoinMoin does not prevent unsafe package actions. In addition, this update fixes an error when processing hierarchical ACLs, which can be exploited to access restricted sub-pages.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-05-24T19:01:50-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2010-05-26T13:27:35.163-04:00">DRAFT</status_change>
            <status_change date="2010-06-14T04:01:00.512-04:00">INTERIM</status_change>
            <status_change date="2010-06-29T11:50:03.233-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
        <criteria operator="OR" comment="Architecture section">
          <criteria operator="AND" comment="Architecture independent section">
            <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
            <criterion comment="python-moinmoin is earlier than 1.7.1-3+lenny3" test_ref="oval:org.mitre.oval:tst:25445"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7548" version="3" class="patch">
      <metadata>
        <title>DSA-1955 network-manager/network-manager-applet -- information disclosure</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <platform>Debian GNU/Linux 4.0</platform>
          <product>network-manager/network-manager-applet</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2009/dsa-1955" ref_id="DSA-1955"/>
        <description>It was discovered that network-manager-applet, a network management framework, lacks some dbus restriction rules, which allows local users to obtain sensitive information. If you have locally modified the /etc/dbus-1/system.d/nm-applet.conf file, then please make sure that you merge the changes from this fix when asked during upgrade.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-05-24T19:04:04-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2010-05-26T13:27:47.648-04:00">DRAFT</status_change>
            <status_change date="2010-06-14T04:01:00.011-04:00">INTERIM</status_change>
            <status_change date="2010-06-29T11:50:02.775-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Release section">
          <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
          <criteria operator="OR" comment="Architecture section">
            <criteria operator="AND" comment="Architecture dependent section">
              <criteria operator="OR" comment="Supported architectures section">
                <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
                <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
                <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
                <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
                <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
                <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
                <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
                <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
                <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
              </criteria>
              <criteria operator="OR" comment="Packages section">
                <criterion comment="network-manager-gnome is earlier than 0.6.6-4+lenny1" test_ref="oval:org.mitre.oval:tst:25700"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Release section">
          <extend_definition comment="Debian 4.0 is installed." definition_ref="oval:org.mitre.oval:def:6461"/>
          <criteria operator="OR" comment="Architecture section">
            <criteria operator="AND" comment="Architecture dependent section">
              <criteria operator="OR" comment="Supported architectures section">
                <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
                <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
                <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
                <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
                <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
                <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
                <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
                <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
              </criteria>
              <criteria operator="OR" comment="Packages section">
                <criterion comment="network-manager-dev is earlier than 0.6.4-6+etch1" test_ref="oval:org.mitre.oval:tst:25692"/>
                <criterion comment="libnm-util0 is earlier than 0.6.4-6+etch1" test_ref="oval:org.mitre.oval:tst:25103"/>
                <criterion comment="libnm-glib-dev is earlier than 0.6.4-6+etch1" test_ref="oval:org.mitre.oval:tst:25546"/>
                <criterion comment="network-manager is earlier than 0.6.4-6+etch1" test_ref="oval:org.mitre.oval:tst:25925"/>
                <criterion comment="network-manager-gnome is earlier than 0.6.4-6+etch1" test_ref="oval:org.mitre.oval:tst:25748"/>
                <criterion comment="libnm-glib0 is earlier than 0.6.4-6+etch1" test_ref="oval:org.mitre.oval:tst:25871"/>
                <criterion comment="libnm-util-dev is earlier than 0.6.4-6+etch1" test_ref="oval:org.mitre.oval:tst:25544"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:7542" class="patch">
      <metadata>
        <title>DSA-1795 ldns -- buffer overflow</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <product>ldns</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2009/dsa-1795" ref_id="DSA-1795"/>
        <description>Stefan Kaltenbrunner discovered that ldns, a library and set of utilities to facilitate DNS programming, did not correctly implement a buffer boundary check in its RR DNS record parser. This weakness could enable overflow of a heap buffer if a maliciously-crafted record is parsed, potentially allowing the execution of arbitrary code. The scope of compromise will vary with the context in which ldns is used, and could present either a local or remote attack vector. The old stable distribution (etch) is not affected by this issue.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:03-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T07:49:07.656-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:01:04.478-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:00:43.649-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Release section" operator="AND">
        <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
        <criteria comment="Architecture section" operator="OR">
          <criteria comment="Architecture dependent section" operator="AND">
            <criteria comment="Supported architectures section" operator="OR">
              <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
              <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
              <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
              <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
              <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
              <criterion comment="Installed architecture is armel" test_ref="oval:org.mitre.oval:tst:11101"/>
              <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
              <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
              <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
              <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
              <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
              <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
            </criteria>
            <criteria comment="Packages section" operator="OR">
              <criterion comment="libldns-dev DPKG is earlier than 1.4.0-1+lenny1" test_ref="oval:org.mitre.oval:tst:11694"/>
              <criterion comment="ldnsutils DPKG is earlier than 1.4.0-1+lenny1" test_ref="oval:org.mitre.oval:tst:12081"/>
              <criterion comment="libldns1 DPKG is earlier than 1.4.0-1+lenny1" test_ref="oval:org.mitre.oval:tst:11248"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7539" version="3" class="patch">
      <metadata>
        <title>DSA-1993 otrs2 -- sql injection</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <product>otrs2</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2010/dsa-1993" ref_id="DSA-1993"/>
        <description>It was discovered that otrs2, the Open Ticket Request System, does not properly sanitise input data that is used on SQL queries, which might be used to inject arbitrary SQL to, for example, escalate privileges on a system that uses otrs2. The oldstable distribution  is not affected.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-05-24T19:06:02-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2010-05-26T13:28:13.360-04:00">DRAFT</status_change>
            <status_change date="2010-06-14T04:00:59.778-04:00">INTERIM</status_change>
            <status_change date="2010-06-29T11:50:02.562-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
        <criteria operator="OR" comment="Architecture section">
          <criteria operator="AND" comment="Architecture independent section">
            <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
            <criterion comment="otrs2 is earlier than 2.2.7-2lenny3" test_ref="oval:org.mitre.oval:tst:25876"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:7530" class="patch">
      <metadata>
        <title>DSA-1785 wireshark -- several vulnerabilities</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <product>wireshark</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2009/dsa-1785" ref_id="DSA-1785"/>
        <description>Several remote vulnerabilities have been discovered in the Wireshark network traffic analyzer, which may lead to denial of service or the execution of arbitrary code. The Common Vulnerabilities and Exposures project identifies the following problems: A format string vulnerability was discovered in the PROFINET dissector. The dissector for the Check Point High-Availability Protocol could be forced to crash. Malformed Tektronix files could lead to a crash. The old stable distribution (etch), is only affected by the CPHAP crash, which doesn't warrant an update on its own. The fix will be queued up for an upcoming security update or a point release.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:10-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T07:58:09.777-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:01:02.388-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:00:41.758-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Release section" operator="AND">
        <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
        <criteria comment="Architecture section" operator="OR">
          <criteria comment="Architecture dependent section" operator="AND">
            <criteria comment="Supported architectures section" operator="OR">
              <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
              <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
              <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
              <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
              <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
              <criterion comment="Installed architecture is armel" test_ref="oval:org.mitre.oval:tst:11101"/>
              <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
              <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
              <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
              <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
              <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
              <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
            </criteria>
            <criteria comment="Packages section" operator="OR">
              <criterion comment="wireshark-dev DPKG is earlier than 1.0.2-3+lenny5" test_ref="oval:org.mitre.oval:tst:18750"/>
              <criterion comment="wireshark-common DPKG is earlier than 1.0.2-3+lenny5" test_ref="oval:org.mitre.oval:tst:18525"/>
              <criterion comment="tshark DPKG is earlier than 1.0.2-3+lenny5" test_ref="oval:org.mitre.oval:tst:18824"/>
              <criterion comment="wireshark DPKG is earlier than 1.0.2-3+lenny5" test_ref="oval:org.mitre.oval:tst:18695"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:7524" class="patch">
      <metadata>
        <title>DSA-1868 kde4libs -- several vulnerabilities</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <product>kde4libs</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2009/dsa-1868" ref_id="DSA-1868"/>
        <description>Several security issues have been discovered in kde4libs, core libraries for all KDE 4 applications. The Common Vulnerabilities and Exposures project identifies the following problems: It was discovered that there is a use-after-free flaw in handling certain DOM event handlers. This could lead to the execution of arbitrary code, when visiting a malicious website. It was discovered that there could be an uninitialised pointer when handling a Cascading Style Sheets (CSS) attr function call. This could lead to the execution of arbitrary code, when visiting a malicious website. It was discovered that the JavaScript garbage collector does not handle allocation failures properly, which could lead to the execution of arbitrary code when visiting a malicious website. The oldstable distribution (etch) does not contain kde4libs.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:09-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T07:57:16.178-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:01:00.904-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:00:40.602-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Release section" operator="AND">
        <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
        <criteria comment="Architecture section" operator="OR">
          <criteria comment="Architecture independent section" operator="AND">
            <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
            <criterion comment="kdelibs5-data is earlier than 4.1.0-3+lenny1" test_ref="oval:org.mitre.oval:tst:18093"/>
          </criteria>
          <criteria comment="Packages section" operator="OR">
            <criterion comment="kdelibs5-dev DPKG is earlier than 4.1.0-3+lenny1" test_ref="oval:org.mitre.oval:tst:18065"/>
            <criterion comment="kdelibs-bin DPKG is earlier than 4.1.0-3+lenny1" test_ref="oval:org.mitre.oval:tst:17993"/>
            <criterion comment="kdelibs5-dbg DPKG is earlier than 4.1.0-3+lenny1" test_ref="oval:org.mitre.oval:tst:18411"/>
            <criterion comment="kdelibs5 DPKG is earlier than 4.1.0-3+lenny1" test_ref="oval:org.mitre.oval:tst:18110"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:7522" class="patch">
      <metadata>
        <title>DSA-1835 tiff -- several vulnerabilities</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <platform>Debian GNU/Linux 4.0</platform>
          <product>tiff</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2009/dsa-1835" ref_id="DSA-1835"/>
        <description>Several vulnerabilities have been discovered in the library for the Tag Image File Format (TIFF). The Common Vulnerabilities and Exposures project identifies the following problems: It was discovered that malformed TIFF images can lead to a crash in the decompression code, resulting in denial of service. Andrea Barisani discovered several integer overflows, which can lead to the execution of arbitrary code if malformed images are passed to the rgb2ycbcr or tiff2rgba tools.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:05-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T07:52:45.886-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:01:00.339-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:00:40.085-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Platform section" operator="OR">
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Architecture independent section" operator="AND">
              <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criterion comment="libtiff-doc is earlier than 3.8.2-11.2" test_ref="oval:org.mitre.oval:tst:14629"/>
            </criteria>
            <criteria comment="Architecture dependent section" operator="AND">
              <criteria comment="Supported architectures section" operator="OR">
                <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
                <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
                <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
                <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
                <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
                <criterion comment="Installed architecture is armel" test_ref="oval:org.mitre.oval:tst:11101"/>
                <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
                <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
                <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
                <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
                <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
                <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
              </criteria>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="libtiff4 DPKG is earlier than 3.8.2-11.2" test_ref="oval:org.mitre.oval:tst:14329"/>
                <criterion comment="libtiff-opengl DPKG is earlier than 3.8.2-11.2" test_ref="oval:org.mitre.oval:tst:14485"/>
                <criterion comment="libtiff-tools DPKG is earlier than 3.8.2-11.2" test_ref="oval:org.mitre.oval:tst:14420"/>
                <criterion comment="libtiffxx0c2 DPKG is earlier than 3.8.2-11.2" test_ref="oval:org.mitre.oval:tst:14310"/>
                <criterion comment="libtiff4-dev DPKG is earlier than 3.8.2-11.2" test_ref="oval:org.mitre.oval:tst:14561"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 4.0 is installed" definition_ref="oval:org.mitre.oval:def:6461"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Packages section" operator="OR">
              <criterion comment="libtiff4 DPKG is earlier than 3.8.2-7+etch3" test_ref="oval:org.mitre.oval:tst:13798"/>
              <criterion comment="libtiff-opengl DPKG is earlier than 3.8.2-7+etch3" test_ref="oval:org.mitre.oval:tst:13831"/>
              <criterion comment="libtiffxx0c2 DPKG is earlier than 3.8.2-7+etch3" test_ref="oval:org.mitre.oval:tst:14786"/>
              <criterion comment="libtiff-tools DPKG is earlier than 3.8.2-7+etch3" test_ref="oval:org.mitre.oval:tst:14670"/>
              <criterion comment="libtiff4-dev DPKG is earlier than 3.8.2-7+etch3" test_ref="oval:org.mitre.oval:tst:14346"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7521" version="1" class="patch">
      <metadata>
        <title>DSA-1945 gforge -- symlink attack</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <platform>Debian GNU/Linux 4.0</platform>
          <product>gforge</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2009/dsa-1945" ref_id="DSA-1945"/>
        <description>Sylvain Beucler discovered that gforge, a collaborative development tool, is prone to a symlink attack, which allows local users to perform a denial of service attack by overwriting arbitrary files. The oldstable distribution (etch), this problem has been fixed in version 4.5.14-22etch13.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:02-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T07:48:53.420-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:00:59.519-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:00:39.464-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Release section">
          <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
          <criteria operator="OR" comment="Architecture section">
            <criteria operator="AND" comment="Architecture independent section">
              <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criteria operator="OR" comment="Packages section">
                <criterion comment="gforge-mta-courier is earlier than 4.7~rc2-7lenny3" test_ref="oval:org.mitre.oval:tst:11884"/>
                <criterion comment="gforge-ftp-proftpd is earlier than 4.7~rc2-7lenny3" test_ref="oval:org.mitre.oval:tst:11729"/>
                <criterion comment="gforge is earlier than 4.7~rc2-7lenny3" test_ref="oval:org.mitre.oval:tst:11760"/>
                <criterion comment="gforge-common is earlier than 4.7~rc2-7lenny3" test_ref="oval:org.mitre.oval:tst:11759"/>
                <criterion comment="gforge-plugin-scmsvn is earlier than 4.7~rc2-7lenny3" test_ref="oval:org.mitre.oval:tst:41217"/>
                <criterion comment="gforge-web-apache2 is earlier than 4.7~rc2-7lenny3" test_ref="oval:org.mitre.oval:tst:11881"/>
                <criterion comment="gforge-mta-postfix is earlier than 4.7~rc2-7lenny3" test_ref="oval:org.mitre.oval:tst:11872"/>
                <criterion comment="gforge-shell-postgresql is earlier than 4.7~rc2-7lenny3" test_ref="oval:org.mitre.oval:tst:11936"/>
                <criterion comment="gforge-plugin-scmcvs is earlier than 4.7~rc2-7lenny3" test_ref="oval:org.mitre.oval:tst:12044"/>
                <criterion comment="gforge-lists-mailman is earlier than 4.7~rc2-7lenny3" test_ref="oval:org.mitre.oval:tst:11986"/>
                <criterion comment="gforge-web-apache is earlier than 4.7~rc2-7lenny3" test_ref="oval:org.mitre.oval:tst:12060"/>
                <criterion comment="gforge-db-postgresql is earlier than 4.7~rc2-7lenny3" test_ref="oval:org.mitre.oval:tst:11989"/>
                <criterion comment="gforge-mta-exim4 is earlier than 4.7~rc2-7lenny3" test_ref="oval:org.mitre.oval:tst:11402"/>
                <criterion comment="gforge-plugin-mediawiki is earlier than 4.7~rc2-7lenny3" test_ref="oval:org.mitre.oval:tst:11357"/>
                <criterion comment="gforge-dns-bind9 is earlier than 4.7~rc2-7lenny3" test_ref="oval:org.mitre.oval:tst:11958"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Release section">
          <extend_definition comment="Debian 4.0 is installed." definition_ref="oval:org.mitre.oval:def:6461"/>
          <criteria operator="OR" comment="Architecture section">
            <criteria operator="AND" comment="Architecture independent section">
              <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criteria operator="OR" comment="Packages section">
                <criterion comment="gforge-ldap-openldap is earlier than 4.5.14-22etch13" test_ref="oval:org.mitre.oval:tst:11761"/>
                <criterion comment="gforge-mta-courier is earlier than 4.5.14-22etch13" test_ref="oval:org.mitre.oval:tst:11554"/>
                <criterion comment="gforge-mta-exim is earlier than 4.5.14-22etch13" test_ref="oval:org.mitre.oval:tst:11954"/>
                <criterion comment="gforge is earlier than 4.5.14-22etch13" test_ref="oval:org.mitre.oval:tst:11998"/>
                <criterion comment="gforge-common is earlier than 4.5.14-22etch13" test_ref="oval:org.mitre.oval:tst:11748"/>
                <criterion comment="gforge-shell-postgresql is earlier than 4.5.14-22etch13" test_ref="oval:org.mitre.oval:tst:11594"/>
                <criterion comment="gforge-mta-postfix is earlier than 4.5.14-22etch13" test_ref="oval:org.mitre.oval:tst:12007"/>
                <criterion comment="gforge-mta-exim4 is earlier than 4.5.14-22etch13" test_ref="oval:org.mitre.oval:tst:11711"/>
                <criterion comment="gforge-shell-ldap is earlier than 4.5.14-22etch13" test_ref="oval:org.mitre.oval:tst:11892"/>
                <criterion comment="gforge-lists-mailman is earlier than 4.5.14-22etch13" test_ref="oval:org.mitre.oval:tst:11678"/>
                <criterion comment="gforge-web-apache is earlier than 4.5.14-22etch13" test_ref="oval:org.mitre.oval:tst:11887"/>
                <criterion comment="gforge-db-postgresql is earlier than 4.5.14-22etch13" test_ref="oval:org.mitre.oval:tst:11875"/>
                <criterion comment="gforge-ftp-proftpd is earlier than 4.5.14-22etch13" test_ref="oval:org.mitre.oval:tst:11893"/>
                <criterion comment="gforge-dns-bind9 is earlier than 4.5.14-22etch13" test_ref="oval:org.mitre.oval:tst:11679"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7518" version="3" class="patch">
      <metadata>
        <title>DSA-2037 kdebase -- race condition</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <product>kdebase</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2010/dsa-2037" ref_id="DSA-2037"/>
        <description>Sebastian Krahmer discovered that a race condition in the KDE Desktop Environment"s KDM display manager, allow a local user to elevate privileges to root.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-05-24T19:09:32-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2010-05-26T13:29:11.533-04:00">DRAFT</status_change>
            <status_change date="2010-06-14T04:00:58.264-04:00">INTERIM</status_change>
            <status_change date="2010-06-29T11:50:00.656-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
        <criteria operator="OR" comment="Architecture section">
          <criteria operator="AND" comment="Architecture independent section">
            <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
            <criteria operator="OR" comment="Packages section">
              <criterion comment="kdeeject is earlier than 3.5.9.dfsg.1-6+lenny1" test_ref="oval:org.mitre.oval:tst:26696"/>
              <criterion comment="kdebase-doc-html is earlier than 3.5.9.dfsg.1-6+lenny1" test_ref="oval:org.mitre.oval:tst:26764"/>
              <criterion comment="kdebase-data is earlier than 3.5.9.dfsg.1-6+lenny1" test_ref="oval:org.mitre.oval:tst:26314"/>
              <criterion comment="kdebase is earlier than 3.5.9.dfsg.1-6+lenny1" test_ref="oval:org.mitre.oval:tst:26058"/>
              <criterion comment="kdebase-doc is earlier than 3.5.9.dfsg.1-6+lenny1" test_ref="oval:org.mitre.oval:tst:26927"/>
            </criteria>
          </criteria>
          <criteria operator="AND" comment="Architecture dependent section">
            <criteria operator="OR" comment="Supported architectures section">
              <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
              <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
              <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
              <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
              <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
              <criterion comment="Installed architecture is armel" test_ref="oval:org.mitre.oval:tst:11101"/>
              <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
              <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
              <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
              <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
              <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
            </criteria>
            <criteria operator="OR" comment="Packages section">
              <criterion comment="kdm is earlier than 3.5.9.dfsg.1-6+lenny1" test_ref="oval:org.mitre.oval:tst:26594"/>
              <criterion comment="konqueror-nsplugins is earlier than 3.5.9.dfsg.1-6+lenny1" test_ref="oval:org.mitre.oval:tst:26895"/>
              <criterion comment="kdebase-bin is earlier than 3.5.9.dfsg.1-6+lenny1" test_ref="oval:org.mitre.oval:tst:26564"/>
              <criterion comment="kcontrol is earlier than 3.5.9.dfsg.1-6+lenny1" test_ref="oval:org.mitre.oval:tst:26983"/>
              <criterion comment="kmenuedit is earlier than 3.5.9.dfsg.1-6+lenny1" test_ref="oval:org.mitre.oval:tst:26632"/>
              <criterion comment="kwin is earlier than 3.5.9.dfsg.1-6+lenny1" test_ref="oval:org.mitre.oval:tst:26937"/>
              <criterion comment="libkonq4 is earlier than 3.5.9.dfsg.1-6+lenny1" test_ref="oval:org.mitre.oval:tst:26810"/>
              <criterion comment="kdebase-dbg is earlier than 3.5.9.dfsg.1-6+lenny1" test_ref="oval:org.mitre.oval:tst:26708"/>
              <criterion comment="kdebase-kio-plugins is earlier than 3.5.9.dfsg.1-6+lenny1" test_ref="oval:org.mitre.oval:tst:26881"/>
              <criterion comment="ktip is earlier than 3.5.9.dfsg.1-6+lenny1" test_ref="oval:org.mitre.oval:tst:26984"/>
              <criterion comment="kate is earlier than 3.5.9.dfsg.1-6+lenny1" test_ref="oval:org.mitre.oval:tst:26736"/>
              <criterion comment="kdepasswd is earlier than 3.5.9.dfsg.1-6+lenny1" test_ref="oval:org.mitre.oval:tst:26905"/>
              <criterion comment="khelpcenter is earlier than 4.0.0.really.3.5.9.dfsg.1-6+lenny1" test_ref="oval:org.mitre.oval:tst:26911"/>
              <criterion comment="kdebase-dev is earlier than 3.5.9.dfsg.1-6+lenny1" test_ref="oval:org.mitre.oval:tst:26828"/>
              <criterion comment="kappfinder is earlier than 3.5.9.dfsg.1-6+lenny1" test_ref="oval:org.mitre.oval:tst:26630"/>
              <criterion comment="kdesktop is earlier than 3.5.9.dfsg.1-6+lenny1" test_ref="oval:org.mitre.oval:tst:26544"/>
              <criterion comment="klipper is earlier than 3.5.9.dfsg.1-6+lenny1" test_ref="oval:org.mitre.oval:tst:26973"/>
              <criterion comment="ksmserver is earlier than 3.5.9.dfsg.1-6+lenny1" test_ref="oval:org.mitre.oval:tst:26930"/>
              <criterion comment="konsole is earlier than 3.5.9.dfsg.1-6+lenny1" test_ref="oval:org.mitre.oval:tst:26978"/>
              <criterion comment="kdebase-bin-kde3 is earlier than 3.5.9.dfsg.1-6+lenny1" test_ref="oval:org.mitre.oval:tst:26891"/>
              <criterion comment="kicker is earlier than 3.5.9.dfsg.1-6+lenny1" test_ref="oval:org.mitre.oval:tst:26888"/>
              <criterion comment="kpager is earlier than 3.5.9.dfsg.1-6+lenny1" test_ref="oval:org.mitre.oval:tst:26838"/>
              <criterion comment="ksysguard is earlier than 3.5.9.dfsg.1-6+lenny1" test_ref="oval:org.mitre.oval:tst:26541"/>
              <criterion comment="kfind is earlier than 3.5.9.dfsg.1-6+lenny1" test_ref="oval:org.mitre.oval:tst:26940"/>
              <criterion comment="ksysguardd is earlier than 3.5.9.dfsg.1-6+lenny1" test_ref="oval:org.mitre.oval:tst:26877"/>
              <criterion comment="konqueror is earlier than 3.5.9.dfsg.1-6+lenny1" test_ref="oval:org.mitre.oval:tst:26023"/>
              <criterion comment="ksplash is earlier than 3.5.9.dfsg.1-6+lenny1" test_ref="oval:org.mitre.oval:tst:26809"/>
              <criterion comment="kpersonalizer is earlier than 3.5.9.dfsg.1-6+lenny1" test_ref="oval:org.mitre.oval:tst:27019"/>
              <criterion comment="libkonq4-dev is earlier than 3.5.9.dfsg.1-6+lenny1" test_ref="oval:org.mitre.oval:tst:26668"/>
              <criterion comment="kdeprint is earlier than 3.5.9.dfsg.1-6+lenny1" test_ref="oval:org.mitre.oval:tst:26488"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7515" version="3" class="patch">
      <metadata>
        <title>DSA-2004 samba -- several vulnerabilities</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <product>samba</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2010/dsa-2004" ref_id="DSA-2004"/>
        <description>Two local vulnerabilities have been discovered in samba, a SMB/CIFS file, print, and login server for Unix. The Common Vulnerabilities and Exposures project identifies the following problems: Ronald Volgers discovered that a race condition in mount.cifs allows local users to mount remote filesystems over arbitrary mount points. Jeff Layton discovered that missing input sanitising in mount.cifs allows denial of service by corrupting /etc/mtab.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-05-24T19:13:01-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2010-05-26T13:29:40.539-04:00">DRAFT</status_change>
            <status_change date="2010-06-14T04:00:57.638-04:00">INTERIM</status_change>
            <status_change date="2010-06-29T11:49:58.829-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
        <criteria operator="OR" comment="Architecture section">
          <criteria operator="AND" comment="Architecture independent section">
            <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
            <criteria operator="OR" comment="Packages section">
              <criterion comment="samba-doc is earlier than 3.2.5-4lenny9" test_ref="oval:org.mitre.oval:tst:27225"/>
              <criterion comment="samba-doc-pdf is earlier than 3.2.5-4lenny9" test_ref="oval:org.mitre.oval:tst:27081"/>
            </criteria>
          </criteria>
          <criteria operator="AND" comment="Architecture dependent section">
            <criteria operator="OR" comment="Supported architectures section">
              <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
              <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
              <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
              <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
              <criterion comment="Installed architecture is armel" test_ref="oval:org.mitre.oval:tst:11101"/>
              <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
              <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
              <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
              <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
              <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
              <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
            </criteria>
            <criteria operator="OR" comment="Packages section">
              <criterion comment="smbfs is earlier than 3.2.5-4lenny9" test_ref="oval:org.mitre.oval:tst:27370"/>
              <criterion comment="samba is earlier than 3.2.5-4lenny9" test_ref="oval:org.mitre.oval:tst:27436"/>
              <criterion comment="samba-tools is earlier than 3.2.5-4lenny9" test_ref="oval:org.mitre.oval:tst:27484"/>
              <criterion comment="libsmbclient is earlier than 3.2.5-4lenny9" test_ref="oval:org.mitre.oval:tst:27199"/>
              <criterion comment="smbclient is earlier than 3.2.5-4lenny9" test_ref="oval:org.mitre.oval:tst:27383"/>
              <criterion comment="libwbclient0 is earlier than 3.2.5-4lenny9" test_ref="oval:org.mitre.oval:tst:27203"/>
              <criterion comment="swat is earlier than 3.2.5-4lenny9" test_ref="oval:org.mitre.oval:tst:27157"/>
              <criterion comment="winbind is earlier than 3.2.5-4lenny9" test_ref="oval:org.mitre.oval:tst:27449"/>
              <criterion comment="samba-dbg is earlier than 3.2.5-4lenny9" test_ref="oval:org.mitre.oval:tst:27046"/>
              <criterion comment="libsmbclient-dev is earlier than 3.2.5-4lenny9" test_ref="oval:org.mitre.oval:tst:26955"/>
              <criterion comment="samba-common is earlier than 3.2.5-4lenny9" test_ref="oval:org.mitre.oval:tst:27424"/>
              <criterion comment="libpam-smbpass is earlier than 3.2.5-4lenny9" test_ref="oval:org.mitre.oval:tst:27247"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:7510" class="patch">
      <metadata>
        <title>DSA-1888 openssl, openssl097 -- cryptographic weakness</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <platform>Debian GNU/Linux 4.0</platform>
          <product>openssl</product>
          <product>openssl097</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2009/dsa-1888" ref_id="DSA-1888"/>
        <description>Certificates with MD2 hash signatures are no longer accepted by OpenSSL, since they're no longer considered cryptographically secure.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:04-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T07:51:21.690-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:00:57.817-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:00:38.577-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Platform section" operator="OR">
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Architecture dependent section" operator="AND">
              <criteria comment="Supported architectures section" operator="OR">
                <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
                <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
                <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
                <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
                <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
                <criterion comment="Installed architecture is armel" test_ref="oval:org.mitre.oval:tst:11101"/>
                <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
                <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
                <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
                <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
                <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
              </criteria>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="libssl-dev DPKG is earlier than 0.9.8g-15+lenny5" test_ref="oval:org.mitre.oval:tst:13263"/>
                <criterion comment="libssl0.9.8-dbg DPKG is earlier than 0.9.8g-15+lenny5" test_ref="oval:org.mitre.oval:tst:13565"/>
                <criterion comment="openssl DPKG is earlier than 0.9.8g-15+lenny5" test_ref="oval:org.mitre.oval:tst:13092"/>
                <criterion comment="libssl0.9.8 DPKG is earlier than 0.9.8g-15+lenny5" test_ref="oval:org.mitre.oval:tst:13045"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 4.0 is installed" definition_ref="oval:org.mitre.oval:def:6461"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Packages section" operator="OR">
              <criterion comment="libssl0.9.7-dbg DPKG is earlier than 0.9.7k-3.1etch5" test_ref="oval:org.mitre.oval:tst:13329"/>
              <criterion comment="libssl-dev DPKG is earlier than 0.9.8c-4etch9" test_ref="oval:org.mitre.oval:tst:13395"/>
              <criterion comment="libssl0.9.8-dbg DPKG is earlier than 0.9.8c-4etch9" test_ref="oval:org.mitre.oval:tst:13330"/>
              <criterion comment="openssl DPKG is earlier than 0.9.8c-4etch9" test_ref="oval:org.mitre.oval:tst:13448"/>
              <criterion comment="libssl0.9.8 DPKG is earlier than 0.9.8c-4etch9" test_ref="oval:org.mitre.oval:tst:13558"/>
              <criterion comment="libssl0.9.7 DPKG is earlier than 0.9.7k-3.1etch5" test_ref="oval:org.mitre.oval:tst:13402"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7495" version="3" class="patch">
      <metadata>
        <title>DSA-1974 gzip -- several vulnerabilities</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <platform>Debian GNU/Linux 4.0</platform>
          <product>gzip</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2010/dsa-1974" ref_id="DSA-1974"/>
        <description>Several vulnerabilities have been found in gzip, the GNU compression utilities. The Common Vulnerabilities and Exposures project identifies the following problems: Thiemo Nagel discovered a missing input sanitation flaw in the way gzip used to decompress data blocks for dynamic Huffman codes, which could lead to the execution of arbitrary code when trying to decompress a crafted archive. This issue is a reappearance of CVE-2006-4334 and only affects the lenny version. Aki Helin discovered an integer underflow when decompressing files that are compressed using the LZW algorithm. This could lead to the execution of arbitrary code when trying to decompress a crafted LZW compressed gzip archive.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-05-24T19:10:32-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2010-05-26T13:29:23.224-04:00">DRAFT</status_change>
            <status_change date="2010-06-14T04:00:57.184-04:00">INTERIM</status_change>
            <status_change date="2010-06-29T11:49:57.741-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Release section">
          <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
          <criteria operator="OR" comment="Architecture section">
            <criteria operator="AND" comment="Architecture independent section">
              <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criterion comment="gzip-win32 is earlier than 1.3.12-6+lenny1" test_ref="oval:org.mitre.oval:tst:26883"/>
            </criteria>
            <criteria operator="AND" comment="Architecture dependent section">
              <criteria operator="OR" comment="Supported architectures section">
                <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
                <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
                <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
                <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
                <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
                <criterion comment="Installed architecture is armel" test_ref="oval:org.mitre.oval:tst:11101"/>
                <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
                <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
                <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
                <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
                <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
              </criteria>
              <criteria operator="OR" comment="Packages section">
                <criterion comment="gzip is earlier than 1.3.12-6+lenny1" test_ref="oval:org.mitre.oval:tst:27016"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Release section">
          <extend_definition comment="Debian 4.0 is installed." definition_ref="oval:org.mitre.oval:def:6461"/>
          <criteria operator="OR" comment="Architecture section">
            <criteria operator="AND" comment="Architecture dependent section">
              <criteria operator="OR" comment="Supported architectures section">
                <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
                <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
                <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
                <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
                <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
                <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
                <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
                <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
                <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
                <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
              </criteria>
              <criteria operator="OR" comment="Packages section">
                <criterion comment="gzip is earlier than 1.3.5-15+etch1" test_ref="oval:org.mitre.oval:tst:26822"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:7489" class="patch">
      <metadata>
        <title>DSA-1889 icu -- programming error</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <platform>Debian GNU/Linux 4.0</platform>
          <product>icu</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2009/dsa-1889" ref_id="DSA-1889"/>
        <description>It was discovered that the ICU unicode library performed incorrect processing of invalid multibyte sequences, resulting in potential bypass of security mechanisms.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:04-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T07:51:20.374-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:00:56.413-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:00:37.667-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Platform section" operator="OR">
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Architecture independent section" operator="AND">
              <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criterion comment="icu-doc is earlier than 3.8.1-3+lenny2" test_ref="oval:org.mitre.oval:tst:13124"/>
            </criteria>
            <criteria comment="Architecture dependent section" operator="AND">
              <criteria comment="Supported architectures section" operator="OR">
                <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
                <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
                <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
                <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
                <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
                <criterion comment="Installed architecture is armel" test_ref="oval:org.mitre.oval:tst:11101"/>
                <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
                <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
                <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
                <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
                <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
                <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
              </criteria>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="libicu38 DPKG is earlier than 3.8.1-3+lenny2" test_ref="oval:org.mitre.oval:tst:12611"/>
                <criterion comment="libicu38-dbg DPKG is earlier than 3.8.1-3+lenny2" test_ref="oval:org.mitre.oval:tst:13455"/>
                <criterion comment="libicu-dev DPKG is earlier than 3.8.1-3+lenny2" test_ref="oval:org.mitre.oval:tst:13004"/>
              </criteria>
            </criteria>
            <criteria comment="Architecture dependent section" operator="AND">
              <criteria comment="Supported architectures section" operator="OR">
                <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
              </criteria>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="lib32icu38 DPKG is earlier than 3.8.1-3+lenny2" test_ref="oval:org.mitre.oval:tst:13596"/>
                <criterion comment="lib32icu-dev DPKG is earlier than 3.8.1-3+lenny2" test_ref="oval:org.mitre.oval:tst:13167"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 4.0 is installed" definition_ref="oval:org.mitre.oval:def:6461"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Architecture independent section" operator="AND">
              <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criterion comment="icu-doc is earlier than 3.6-2etch3" test_ref="oval:org.mitre.oval:tst:12869"/>
            </criteria>
            <criteria comment="Architecture dependent section" operator="AND">
              <criteria comment="Supported architectures section" operator="OR">
                <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
                <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
                <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
                <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
                <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
                <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
                <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
                <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
                <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
                <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
              </criteria>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="libicu36-dev DPKG is earlier than 3.6-2etch3" test_ref="oval:org.mitre.oval:tst:13335"/>
                <criterion comment="libicu36 DPKG is earlier than 3.6-2etch3" test_ref="oval:org.mitre.oval:tst:13549"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:7485" class="patch">
      <metadata>
        <title>DSA-1903 graphicsmagick -- several vulnerabilities</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <platform>Debian GNU/Linux 4.0</platform>
          <product>graphicsmagick</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2009/dsa-1903" ref_id="DSA-1903"/>
        <description>Several vulnerabilities have been discovered in graphicsmagick, a collection of image processing tool, which can lead to the execution of arbitrary code, exposure of sensitive information or cause DoS. The Common Vulnerabilities and Exposures project identifies the following problems: Multiple integer overflows in XInitImage function in xwd.c for GraphicsMagick, allow user-assisted remote attackers to cause a denial of service (crash) or obtain sensitive information via crafted images with large or negative values that trigger a buffer overflow. It only affects the oldstable distribution (etch). Multiple integer overflows allow remote attackers to execute arbitrary code via a crafted DCM image, or the colors or comments field in a crafted XWD image. It only affects the oldstable distribution (etch). A crafted image file can trigger an infinite loop in the ReadDCMImage function or in the ReadXCFImage function. It only affects the oldstable distribution (etch). Multiple integer overflows allow context-dependent attackers to execute arbitrary code via a crafted .dcm, .dib, .xbm, .xcf, or .xwd image file, which triggers a heap-based buffer overflow. It only affects the oldstable distribution (etch). A sign extension error allows context-dependent attackers to execute arbitrary code via a crafted width value in an image file, which triggers an integer overflow and a heap-based buffer overflow. It affects only the oldstable distribution (etch). The load_tile function in the XCF coder allows user-assisted remote attackers to cause a denial of service or possibly execute arbitrary code via a crafted .xcf file that triggers an out-of-bounds heap write. It affects only oldstable (etch). Multiple vulnerabilities in GraphicsMagick before 1.2.4 allow remote attackers to cause a denial of service (crash, infinite loop, or memory consumption) via vectors in the AVI, AVS, DCM, EPT, FITS, MTV, PALM, RLA, and TGA decoder readers; and the GetImageCharacteristics function in magick/image.c, as reachable from a crafted PNG, JPEG, BMP, or TIFF file. Multiple heap-based buffer underflows in the ReadPALMImage function in coders/palm.c in GraphicsMagick before 1.2.3 allow remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted PALM image. Heap-based buffer overflow in the DecodeImage function in coders/pict.c in GraphicsMagick before 1.1.14, and 1.2.x before 1.2.3, allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted PICT image. Multiple vulnerabilities in GraphicsMagick allow remote attackers to cause a denial of service (crash) via vectors in XCF and CINEON images. Vulnerability in GraphicsMagick allows remote attackers to cause a denial of service (crash) via vectors in DPX images. Integer overflow allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted TIFF file, which triggers a buffer overflow.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:04-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T07:50:44.930-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:00:55.298-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:00:36.682-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Platform section" operator="OR">
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Architecture independent section" operator="AND">
              <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="graphicsmagick-libmagick-dev-compat is earlier than 1.1.11-3.2+lenny1" test_ref="oval:org.mitre.oval:tst:13084"/>
                <criterion comment="graphicsmagick-imagemagick-compat is earlier than 1.1.11-3.2+lenny1" test_ref="oval:org.mitre.oval:tst:13281"/>
              </criteria>
            </criteria>
            <criteria comment="Architecture dependent section" operator="AND">
              <criteria comment="Supported architectures section" operator="OR">
                <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
                <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
                <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
                <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
                <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
                <criterion comment="Installed architecture is armel" test_ref="oval:org.mitre.oval:tst:11101"/>
                <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
                <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
                <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
                <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
                <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
                <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
              </criteria>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="libgraphics-magick-perl DPKG is earlier than 1.1.11-3.2+lenny1" test_ref="oval:org.mitre.oval:tst:12426"/>
                <criterion comment="libgraphicsmagick++1 DPKG is earlier than 1.1.11-3.2+lenny1" test_ref="oval:org.mitre.oval:tst:13042"/>
                <criterion comment="libgraphicsmagick1-dev DPKG is earlier than 1.1.11-3.2+lenny1" test_ref="oval:org.mitre.oval:tst:12847"/>
                <criterion comment="libgraphicsmagick1 DPKG is earlier than 1.1.11-3.2+lenny1" test_ref="oval:org.mitre.oval:tst:13317"/>
                <criterion comment="graphicsmagick-dbg DPKG is earlier than 1.1.11-3.2+lenny1" test_ref="oval:org.mitre.oval:tst:12952"/>
                <criterion comment="graphicsmagick DPKG is earlier than 1.1.11-3.2+lenny1" test_ref="oval:org.mitre.oval:tst:13210"/>
                <criterion comment="libgraphicsmagick++1-dev DPKG is earlier than 1.1.11-3.2+lenny1" test_ref="oval:org.mitre.oval:tst:13309"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 4.0 is installed" definition_ref="oval:org.mitre.oval:def:6461"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Architecture independent section" operator="AND">
              <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="graphicsmagick-libmagick-dev-compat is earlier than 1.1.7-13+etch1" test_ref="oval:org.mitre.oval:tst:13057"/>
                <criterion comment="graphicsmagick-imagemagick-compat is earlier than 1.1.7-13+etch1" test_ref="oval:org.mitre.oval:tst:13308"/>
              </criteria>
            </criteria>
            <criteria comment="Packages section" operator="OR">
              <criterion comment="libgraphics-magick-perl DPKG is earlier than 1.1.7-13+etch1" test_ref="oval:org.mitre.oval:tst:13243"/>
              <criterion comment="libgraphicsmagick++1 DPKG is earlier than 1.1.7-13+etch1" test_ref="oval:org.mitre.oval:tst:13163"/>
              <criterion comment="libgraphicsmagick1-dev DPKG is earlier than 1.1.7-13+etch1" test_ref="oval:org.mitre.oval:tst:12896"/>
              <criterion comment="libgraphicsmagick1 DPKG is earlier than 1.1.7-13+etch1" test_ref="oval:org.mitre.oval:tst:13073"/>
              <criterion comment="graphicsmagick-dbg DPKG is earlier than 1.1.7-13+etch1" test_ref="oval:org.mitre.oval:tst:13279"/>
              <criterion comment="graphicsmagick DPKG is earlier than 1.1.7-13+etch1" test_ref="oval:org.mitre.oval:tst:13151"/>
              <criterion comment="libgraphicsmagick++1-dev DPKG is earlier than 1.1.7-13+etch1" test_ref="oval:org.mitre.oval:tst:13269"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7481" version="3" class="patch">
      <metadata>
        <title>DSA-1958 libtool -- privilege escalation</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <platform>Debian GNU/Linux 4.0</platform>
          <product>libtool</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2009/dsa-1958" ref_id="DSA-1958"/>
        <description>It was discovered that ltdl, a system-independent dlopen wrapper for GNU libtool, can be tricked to load and run modules from an arbitrary directory, which might be used to execute arbitrary code with the privileges of the user running an application that uses libltdl.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-05-24T19:04:31-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2010-05-26T13:27:53.638-04:00">DRAFT</status_change>
            <status_change date="2010-06-14T04:00:56.632-04:00">INTERIM</status_change>
            <status_change date="2010-06-29T11:49:56.448-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Release section">
          <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
          <criteria operator="OR" comment="Architecture section">
            <criteria operator="AND" comment="Architecture independent section">
              <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criterion comment="libtool-doc is earlier than 1.5.26-4+lenny1" test_ref="oval:org.mitre.oval:tst:25806"/>
            </criteria>
            <criteria operator="AND" comment="Architecture dependent section">
              <criteria operator="OR" comment="Supported architectures section">
                <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
                <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
                <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
                <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
                <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
                <criterion comment="Installed architecture is armel" test_ref="oval:org.mitre.oval:tst:11101"/>
                <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
                <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
                <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
                <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
                <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
                <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
              </criteria>
              <criteria operator="OR" comment="Packages section">
                <criterion comment="libltdl3 is earlier than 1.5.26-4+lenny1" test_ref="oval:org.mitre.oval:tst:25449"/>
                <criterion comment="libltdl3-dev is earlier than 1.5.26-4+lenny1" test_ref="oval:org.mitre.oval:tst:25791"/>
                <criterion comment="libtool is earlier than 1.5.26-4+lenny1" test_ref="oval:org.mitre.oval:tst:25785"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Release section">
          <extend_definition comment="Debian 4.0 is installed." definition_ref="oval:org.mitre.oval:def:6461"/>
          <criteria operator="OR" comment="Architecture section">
            <criteria operator="AND" comment="Architecture independent section">
              <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criterion comment="libtool-doc is earlier than 1.5.22-4+etch1" test_ref="oval:org.mitre.oval:tst:25757"/>
            </criteria>
            <criteria operator="OR" comment="Packages section">
              <criterion comment="libltdl3 is earlier than 1.5.22-4+etch1" test_ref="oval:org.mitre.oval:tst:25741"/>
              <criterion comment="libltdl3-dev is earlier than 1.5.22-4+etch1" test_ref="oval:org.mitre.oval:tst:25553"/>
              <criterion comment="libtool is earlier than 1.5.22-4+etch1" test_ref="oval:org.mitre.oval:tst:25770"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7480" version="3" class="patch">
      <metadata>
        <title>DSA-1996 linux-2.6 -- privilege escalation/denial of service/sensitive memory leak</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <product>linux-2.6</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2010/dsa-1996" ref_id="DSA-1996"/>
        <description>Several vulnerabilities have been discovered in the Linux kernel that may lead to a denial of service, sensitive memory leak or privilege escalation. The Common Vulnerabilities and Exposures project identifies the following problems: Joseph Malicki reported that the dbg_lvl sysfs attribute for the megaraid_sas device driver had world-writable permissions, permitting local users to modify logging settings. Lennert Buytenhek reported a race in the mac80211 subsystem that may allow remote users to cause a denial of service  on a system connected to the same wireless network. Fabian Yamaguchi reported issues in the e1000 and e1000e drivers for Intel gigabit network adapters which allow remote users to bypass packet filters using specially crafted ethernet frames. Andi Kleen reported a defect which allows local users to gain read access to memory reachable by the kernel when the print-fatal-signals option is enabled. This option is disabled by default. Florian Westphal reported a lack of capability checking in the ebtables netfilter subsystem. If the ebtables module is loaded, local users can add and modify ebtables rules. Al Viro reported several issues with the mmap/mremap system calls that allow local users to cause a denial of service  or obtain elevated privileges. Gleb Natapov discovered issues in the KVM subsystem where missing permission checks  permit a user in a guest system to denial of service a guest  or gain escalated privileges with the guest. Mathias Krause reported an issue with the load_elf_binary code on the amd64 flavor kernels that allows local users to cause a denial of service . Marcelo Tosatti fixed an issue in the PIT emulation code in the KVM subsystem that allows privileged users in a guest domain to cause a denial of service  of the host system. Sebastian Krahmer discovered an issue in the netlink connector subsystem that permits local users to allocate large amounts of system memory resulting in a denial of service . Ramon de Carvalho Valle discovered an issue in the sys_move_pages interface, limited to amd64, ia64 and powerpc64 flavors in Debian. Local users can exploit this issue to cause a denial of service  or gain access to sensitive kernel memory.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-05-24T19:08:09-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2010-05-26T13:28:47.102-04:00">DRAFT</status_change>
            <status_change date="2010-06-14T04:00:55.676-04:00">INTERIM</status_change>
            <status_change date="2010-06-29T11:49:55.562-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
        <criteria operator="OR" comment="Architecture section">
          <criteria operator="AND" comment="Architecture independent section">
            <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
            <criteria operator="OR" comment="Packages section">
              <criterion comment="linux-patch-debian-2.6.26 is earlier than 2.6.26-21lenny1" test_ref="oval:org.mitre.oval:tst:25636"/>
              <criterion comment="linux-support-2.6.26-2 is earlier than 2.6.26-21lenny3" test_ref="oval:org.mitre.oval:tst:26587"/>
              <criterion comment="linux-doc-2.6.26 is earlier than 2.6.26-21lenny1" test_ref="oval:org.mitre.oval:tst:26184"/>
              <criterion comment="linux-tree-2.6.26 is earlier than 2.6.26-21lenny1" test_ref="oval:org.mitre.oval:tst:26500"/>
              <criterion comment="linux-source-2.6.26 is earlier than 2.6.26-21lenny1" test_ref="oval:org.mitre.oval:tst:26338"/>
              <criterion comment="linux-manual-2.6.26 is earlier than 2.6.26-21lenny1" test_ref="oval:org.mitre.oval:tst:26522"/>
            </criteria>
          </criteria>
          <criteria operator="AND" comment="Architecture dependent section">
            <criteria operator="OR" comment="Supported architectures section">
              <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
            </criteria>
            <criteria operator="OR" comment="Packages section">
              <criterion comment="linux-headers-2.6.26-2-all is earlier than 2.6.26-21lenny3" test_ref="oval:org.mitre.oval:tst:26534"/>
              <criterion comment="linux-image-2.6.26-2-vserver-s390x is earlier than 2.6.26-21lenny3" test_ref="oval:org.mitre.oval:tst:26293"/>
              <criterion comment="linux-image-2.6.26-2-s390 is earlier than 2.6.26-21lenny2" test_ref="oval:org.mitre.oval:tst:26442"/>
              <criterion comment="linux-headers-2.6.26-2-s390 is earlier than 2.6.26-21lenny3" test_ref="oval:org.mitre.oval:tst:26132"/>
              <criterion comment="linux-image-2.6.26-2-s390-tape is earlier than 2.6.26-21lenny3" test_ref="oval:org.mitre.oval:tst:26165"/>
              <criterion comment="linux-headers-2.6.26-2-all-s390 is earlier than 2.6.26-21lenny1" test_ref="oval:org.mitre.oval:tst:26364"/>
              <criterion comment="linux-headers-2.6.26-2-vserver-s390x is earlier than 2.6.26-21lenny1" test_ref="oval:org.mitre.oval:tst:26540"/>
              <criterion comment="linux-headers-2.6.26-2-common-vserver is earlier than 2.6.26-21lenny1" test_ref="oval:org.mitre.oval:tst:26332"/>
              <criterion comment="linux-libc-dev is earlier than 2.6.26-21lenny2" test_ref="oval:org.mitre.oval:tst:26348"/>
              <criterion comment="linux-image-2.6.26-2-s390x is earlier than 2.6.26-21lenny2" test_ref="oval:org.mitre.oval:tst:26149"/>
              <criterion comment="linux-headers-2.6.26-2-common is earlier than 2.6.26-21lenny2" test_ref="oval:org.mitre.oval:tst:26382"/>
              <criterion comment="linux-headers-2.6.26-2-s390x is earlier than 2.6.26-21lenny2" test_ref="oval:org.mitre.oval:tst:26512"/>
            </criteria>
          </criteria>
          <criteria operator="AND" comment="Architecture dependent section">
            <criteria operator="OR" comment="Supported architectures section">
              <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
            </criteria>
            <criteria operator="OR" comment="Packages section">
              <criterion comment="xen-linux-system-2.6.26-2-xen-amd64 is earlier than 2.6.26-21lenny2" test_ref="oval:org.mitre.oval:tst:26340"/>
              <criterion comment="linux-headers-2.6.26-2-all is earlier than 2.6.26-21lenny2" test_ref="oval:org.mitre.oval:tst:26333"/>
              <criterion comment="linux-headers-2.6.26-2-openvz-amd64 is earlier than 2.6.26-21lenny3" test_ref="oval:org.mitre.oval:tst:26537"/>
              <criterion comment="linux-headers-2.6.26-2-common-vserver is earlier than 2.6.26-21lenny3" test_ref="oval:org.mitre.oval:tst:25650"/>
              <criterion comment="linux-image-2.6.26-2-openvz-amd64 is earlier than 2.6.26-21lenny3" test_ref="oval:org.mitre.oval:tst:26439"/>
              <criterion comment="linux-image-2.6.26-2-amd64 is earlier than 2.6.26-21lenny3" test_ref="oval:org.mitre.oval:tst:26440"/>
              <criterion comment="linux-headers-2.6.26-2-common-openvz is earlier than 2.6.26-21lenny3" test_ref="oval:org.mitre.oval:tst:26416"/>
              <criterion comment="linux-modules-2.6.26-2-xen-amd64 is earlier than 2.6.26-21lenny3" test_ref="oval:org.mitre.oval:tst:26373"/>
              <criterion comment="linux-headers-2.6.26-2-all-amd64 is earlier than 2.6.26-21lenny3" test_ref="oval:org.mitre.oval:tst:26645"/>
              <criterion comment="linux-image-2.6.26-2-xen-amd64 is earlier than 2.6.26-21lenny2" test_ref="oval:org.mitre.oval:tst:26635"/>
              <criterion comment="linux-headers-2.6.26-2-common-xen is earlier than 2.6.26-21lenny2" test_ref="oval:org.mitre.oval:tst:26475"/>
              <criterion comment="linux-libc-dev is earlier than 2.6.26-21lenny2" test_ref="oval:org.mitre.oval:tst:26625"/>
              <criterion comment="linux-headers-2.6.26-2-xen-amd64 is earlier than 2.6.26-21lenny3" test_ref="oval:org.mitre.oval:tst:26143"/>
              <criterion comment="linux-headers-2.6.26-2-amd64 is earlier than 2.6.26-21lenny2" test_ref="oval:org.mitre.oval:tst:26606"/>
              <criterion comment="linux-headers-2.6.26-2-common is earlier than 2.6.26-21lenny3" test_ref="oval:org.mitre.oval:tst:25820"/>
              <criterion comment="linux-image-2.6.26-2-vserver-amd64 is earlier than 2.6.26-21lenny3" test_ref="oval:org.mitre.oval:tst:26559"/>
              <criterion comment="linux-headers-2.6.26-2-vserver-amd64 is earlier than 2.6.26-21lenny3" test_ref="oval:org.mitre.oval:tst:26536"/>
            </criteria>
          </criteria>
          <criteria operator="AND" comment="Architecture depended section">
            <criteria operator="AND" comment="Supported platform section">
              <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
              <criteria operator="OR" comment="Packages section">
                <criterion comment="linux-headers-2.6.26-2-all is earlier than 2.6.26-21lenny3" test_ref="oval:org.mitre.oval:tst:26749"/>
                <criterion comment="linux-headers-2.6.26-2-parisc is earlier than 2.6.26-21lenny2" test_ref="oval:org.mitre.oval:tst:26705"/>
                <criterion comment="linux-image-2.6.26-2-parisc64 is earlier than 2.6.26-21lenny3" test_ref="oval:org.mitre.oval:tst:26582"/>
                <criterion comment="linux-image-2.6.26-2-parisc is earlier than 2.6.26-21lenny2" test_ref="oval:org.mitre.oval:tst:26782"/>
                <criterion comment="linux-headers-2.6.26-2-parisc-smp is earlier than 2.6.26-21lenny3" test_ref="oval:org.mitre.oval:tst:26704"/>
                <criterion comment="linux-headers-2.6.26-2-all-hppa is earlier than 2.6.26-21lenny2" test_ref="oval:org.mitre.oval:tst:26745"/>
                <criterion comment="linux-image-2.6.26-2-parisc-smp is earlier than 2.6.26-21lenny2" test_ref="oval:org.mitre.oval:tst:26803"/>
                <criterion comment="linux-headers-2.6.26-2-parisc64-smp is earlier than 2.6.26-21lenny2" test_ref="oval:org.mitre.oval:tst:26703"/>
                <criterion comment="linux-headers-2.6.26-2-parisc64 is earlier than 2.6.26-21lenny2" test_ref="oval:org.mitre.oval:tst:26835"/>
                <criterion comment="linux-libc-dev is earlier than 2.6.26-21lenny2" test_ref="oval:org.mitre.oval:tst:26762"/>
                <criterion comment="linux-image-2.6.26-2-parisc64-smp is earlier than 2.6.26-21lenny2" test_ref="oval:org.mitre.oval:tst:26550"/>
                <criterion comment="linux-headers-2.6.26-2-common is earlier than 2.6.26-21lenny3" test_ref="oval:org.mitre.oval:tst:26169"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:7473" class="patch">
      <metadata>
        <title>DSA-1726 python-crypto -- buffer overflow</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <product>python-crypto</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2009/dsa-1726" ref_id="DSA-1726"/>
        <description>Mike Wiacek discovered that a buffer overflow in the ARC2 implementation of Python Crypto, a collection of cryptographic algorithms and protocols for Python allows denial of service and potentially the execution of arbitrary code.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:08-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T07:56:29.613-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:00:54.769-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:00:36.405-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Release section" operator="AND">
        <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
        <criteria comment="Architecture section" operator="OR">
          <criteria comment="Packages section" operator="OR">
            <criterion comment="python-crypto DPKG is earlier than 2.0.1+dfsg1-2.3+lenny0" test_ref="oval:org.mitre.oval:tst:17409"/>
            <criterion comment="python-crypto-dbg DPKG is earlier than 2.0.1+dfsg1-2.3+lenny0" test_ref="oval:org.mitre.oval:tst:17226"/>
          </criteria>
          <criteria comment="Architecture dependent section" operator="AND">
            <criteria comment="Supported architectures section" operator="OR">
              <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
            </criteria>
            <criteria comment="Packages section" operator="OR">
              <criterion comment="python-crypto DPKG is earlier than 2.0.1+dfsg1-2.3+lenny0" test_ref="oval:org.mitre.oval:tst:17436"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7463" version="3" class="patch">
      <metadata>
        <title>DSA-1999 xulrunner -- several vulnerabilities</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <product>xulrunner</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2010/dsa-1999" ref_id="DSA-1999"/>
        <description>Several remote vulnerabilities have been discovered in Xulrunner, a runtime environment for XUL applications, such as the Iceweasel web browser. The Common Vulnerabilities and Exposures project identifies the following problems: Alin Rad Pop discovered that incorrect memory handling in the HTML parser could lead to the execution of arbitrary code. Hidetake Jo discovered that the same-origin policy can be bypassed through window.dialogArguments. Henri Sivonen, Boris Zbarsky, Zack Weinberg, Bob Clary, Martijn Wargers and Paul Nickerson reported crashes in layout engine, which might allow the execution of arbitrary code. Orlando Barrera II discovered that incorrect memory handling in the implementation of the web worker API could lead to the execution of arbitrary code. Georgi Guninski discovered that the same origin policy can be bypassed through specially crafted SVG documents.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-05-24T19:08:09-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2010-05-26T13:28:48.598-04:00">DRAFT</status_change>
            <status_change date="2010-06-14T04:00:55.150-04:00">INTERIM</status_change>
            <status_change date="2010-06-29T11:49:54.832-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
        <criteria operator="OR" comment="Architecture section">
          <criteria operator="AND" comment="Architecture independent section">
            <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
            <criterion comment="libmozillainterfaces-java is earlier than 1.9.0.18-1" test_ref="oval:org.mitre.oval:tst:26857"/>
          </criteria>
          <criteria operator="AND" comment="Architecture dependent section">
            <criteria operator="OR" comment="Supported architectures section">
              <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
              <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
              <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
              <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
              <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
              <criterion comment="Installed architecture is armel" test_ref="oval:org.mitre.oval:tst:11101"/>
              <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
              <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
              <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
              <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
              <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
              <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
            </criteria>
            <criteria operator="OR" comment="Packages section">
              <criterion comment="libmozjs-dev is earlier than 1.9.0.18-1" test_ref="oval:org.mitre.oval:tst:26323"/>
              <criterion comment="spidermonkey-bin is earlier than 1.9.0.18-1" test_ref="oval:org.mitre.oval:tst:26664"/>
              <criterion comment="xulrunner-dev is earlier than 1.9.0.18-1" test_ref="oval:org.mitre.oval:tst:26629"/>
              <criterion comment="xulrunner-1.9 is earlier than 1.9.0.18-1" test_ref="oval:org.mitre.oval:tst:26674"/>
              <criterion comment="libmozjs1d-dbg is earlier than 1.9.0.18-1" test_ref="oval:org.mitre.oval:tst:26694"/>
              <criterion comment="libmozjs1d is earlier than 1.9.0.18-1" test_ref="oval:org.mitre.oval:tst:26786"/>
              <criterion comment="python-xpcom is earlier than 1.9.0.18-1" test_ref="oval:org.mitre.oval:tst:26741"/>
              <criterion comment="xulrunner-1.9-dbg is earlier than 1.9.0.18-1" test_ref="oval:org.mitre.oval:tst:26396"/>
              <criterion comment="xulrunner-1.9-gnome-support is earlier than 1.9.0.18-1" test_ref="oval:org.mitre.oval:tst:26804"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7457" version="3" class="patch">
      <metadata>
        <title>DSA-2020 ikiwiki -- insufficient input sanitization</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <product>ikiwiki</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2010/dsa-2020" ref_id="DSA-2020"/>
        <description>Ivan Shmakov discovered that the htmlscrubber component of ikwiki, a wiki compiler, performs insufficient input sanitization on data:image/svg+xml URIs. As these can contain script code this can be used by an attacker to conduct cross-site scripting attacks.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-05-24T19:08:20-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2010-05-26T13:28:52.498-04:00">DRAFT</status_change>
            <status_change date="2010-06-14T04:00:54.547-04:00">INTERIM</status_change>
            <status_change date="2010-06-29T11:49:54.620-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
        <criteria operator="OR" comment="Architecture section">
          <criteria operator="AND" comment="Architecture independent section">
            <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
            <criterion comment="ikiwiki is earlier than 2.53.5" test_ref="oval:org.mitre.oval:tst:26319"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:7454" class="patch">
      <metadata>
        <title>DSA-1839 gst-plugins-good0.10 -- integer overflow</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <platform>Debian GNU/Linux 4.0</platform>
          <product>gst-plugins-good0.10</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2009/dsa-1839" ref_id="DSA-1839"/>
        <description>It has been discovered that gst-plugins-good0.10, the GStreamer plugins from the "good" set, are prone to an integer overflow, when processing a large PNG file. This could lead to the execution of arbitrary code.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:05-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T07:52:50.569-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:00:53.427-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:00:35.379-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Platform section" operator="OR">
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Architecture independent section" operator="AND">
              <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criterion comment="gstreamer0.10-plugins-good-doc is earlier than 0.10.8-4.1~lenny2" test_ref="oval:org.mitre.oval:tst:14690"/>
            </criteria>
            <criteria comment="Architecture dependent section" operator="AND">
              <criteria comment="Supported architectures section" operator="OR">
                <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
                <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
                <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
                <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
                <criterion comment="Installed architecture is armel" test_ref="oval:org.mitre.oval:tst:11101"/>
                <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
                <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
                <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
                <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
                <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
                <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
              </criteria>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="gstreamer0.10-plugins-good DPKG is earlier than 0.10.8-4.1~lenny2" test_ref="oval:org.mitre.oval:tst:14811"/>
                <criterion comment="gstreamer0.10-esd DPKG is earlier than 0.10.8-4.1~lenny2" test_ref="oval:org.mitre.oval:tst:14521"/>
                <criterion comment="gstreamer0.10-plugins-good-dbg DPKG is earlier than 0.10.8-4.1~lenny2" test_ref="oval:org.mitre.oval:tst:14834"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 4.0 is installed" definition_ref="oval:org.mitre.oval:def:6461"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Architecture independent section" operator="AND">
              <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criterion comment="gstreamer0.10-plugins-good-doc is earlier than 0.10.4-4+etch1" test_ref="oval:org.mitre.oval:tst:14857"/>
            </criteria>
            <criteria comment="Architecture dependent section" operator="AND">
              <criteria comment="Supported architectures section" operator="OR">
                <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
                <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
                <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
                <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
                <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
                <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
                <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
                <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
                <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
              </criteria>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="gstreamer0.10-plugins-good DPKG is earlier than 0.10.4-4+etch1" test_ref="oval:org.mitre.oval:tst:14850"/>
                <criterion comment="gstreamer0.10-esd DPKG is earlier than 0.10.4-4+etch1" test_ref="oval:org.mitre.oval:tst:14673"/>
                <criterion comment="gstreamer0.10-plugins-good-dbg DPKG is earlier than 0.10.4-4+etch1" test_ref="oval:org.mitre.oval:tst:14591"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7452" version="3" class="patch">
      <metadata>
        <title>DSA-1969 krb5 -- integer underflow</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <platform>Debian GNU/Linux 4.0</platform>
          <product>krb5</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2010/dsa-1969" ref_id="DSA-1969"/>
        <description>It was discovered that krb5, a system for authenticating users and services on a network, is prone to integer underflow in the AES and RC4 decryption operations of the crypto library. A remote attacker can cause crashes, heap corruption, or, under extraordinarily unlikely conditions, arbitrary code execution.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-05-24T19:08:31-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2010-05-26T13:28:58.263-04:00">DRAFT</status_change>
            <status_change date="2010-06-14T04:00:53.766-04:00">INTERIM</status_change>
            <status_change date="2010-06-29T11:49:53.874-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Release section">
          <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
          <criteria operator="OR" comment="Architecture section">
            <criteria operator="AND" comment="Architecture independent section">
              <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criterion comment="krb5-doc is earlier than 1.6.dfsg.4~beta1-5lenny2" test_ref="oval:org.mitre.oval:tst:26844"/>
            </criteria>
            <criteria operator="AND" comment="Architecture dependent section">
              <criteria operator="OR" comment="Supported architectures section">
                <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
                <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
                <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
                <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
                <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
                <criterion comment="Installed architecture is armel" test_ref="oval:org.mitre.oval:tst:11101"/>
                <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
                <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
                <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
                <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
                <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
                <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
              </criteria>
              <criteria operator="OR" comment="Packages section">
                <criterion comment="krb5-rsh-server is earlier than 1.6.dfsg.4~beta1-5lenny2" test_ref="oval:org.mitre.oval:tst:26548"/>
                <criterion comment="krb5-kdc-ldap is earlier than 1.6.dfsg.4~beta1-5lenny2" test_ref="oval:org.mitre.oval:tst:26623"/>
                <criterion comment="krb5-telnetd is earlier than 1.6.dfsg.4~beta1-5lenny2" test_ref="oval:org.mitre.oval:tst:26652"/>
                <criterion comment="libkrb53 is earlier than 1.6.dfsg.4~beta1-5lenny2" test_ref="oval:org.mitre.oval:tst:26785"/>
                <criterion comment="libkrb5-dev is earlier than 1.6.dfsg.4~beta1-5lenny2" test_ref="oval:org.mitre.oval:tst:26547"/>
                <criterion comment="krb5-ftpd is earlier than 1.6.dfsg.4~beta1-5lenny2" test_ref="oval:org.mitre.oval:tst:26865"/>
                <criterion comment="krb5-pkinit is earlier than 1.6.dfsg.4~beta1-5lenny2" test_ref="oval:org.mitre.oval:tst:26796"/>
                <criterion comment="krb5-admin-server is earlier than 1.6.dfsg.4~beta1-5lenny2" test_ref="oval:org.mitre.oval:tst:26428"/>
                <criterion comment="libkadm55 is earlier than 1.6.dfsg.4~beta1-5lenny2" test_ref="oval:org.mitre.oval:tst:26776"/>
                <criterion comment="libkrb5-dbg is earlier than 1.6.dfsg.4~beta1-5lenny2" test_ref="oval:org.mitre.oval:tst:26521"/>
                <criterion comment="krb5-user is earlier than 1.6.dfsg.4~beta1-5lenny2" test_ref="oval:org.mitre.oval:tst:26903"/>
                <criterion comment="krb5-clients is earlier than 1.6.dfsg.4~beta1-5lenny2" test_ref="oval:org.mitre.oval:tst:26627"/>
                <criterion comment="krb5-kdc is earlier than 1.6.dfsg.4~beta1-5lenny2" test_ref="oval:org.mitre.oval:tst:26676"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Release section">
          <extend_definition comment="Debian 4.0 is installed." definition_ref="oval:org.mitre.oval:def:6461"/>
          <criteria operator="OR" comment="Architecture section">
            <criteria operator="AND" comment="Architecture independent section">
              <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criterion comment="krb5-doc is earlier than 1.4.4-7etch8" test_ref="oval:org.mitre.oval:tst:26401"/>
            </criteria>
            <criteria operator="OR" comment="Packages section">
              <criterion comment="krb5-rsh-server is earlier than 1.4.4-7etch8" test_ref="oval:org.mitre.oval:tst:26592"/>
              <criterion comment="krb5-telnetd is earlier than 1.4.4-7etch8" test_ref="oval:org.mitre.oval:tst:26902"/>
              <criterion comment="libkrb53 is earlier than 1.4.4-7etch8" test_ref="oval:org.mitre.oval:tst:26103"/>
              <criterion comment="libkrb5-dev is earlier than 1.4.4-7etch8" test_ref="oval:org.mitre.oval:tst:26467"/>
              <criterion comment="krb5-ftpd is earlier than 1.4.4-7etch8" test_ref="oval:org.mitre.oval:tst:26879"/>
              <criterion comment="krb5-admin-server is earlier than 1.4.4-7etch8" test_ref="oval:org.mitre.oval:tst:26760"/>
              <criterion comment="libkadm55 is earlier than 1.4.4-7etch8" test_ref="oval:org.mitre.oval:tst:26757"/>
              <criterion comment="libkrb5-dbg is earlier than 1.4.4-7etch8" test_ref="oval:org.mitre.oval:tst:26665"/>
              <criterion comment="krb5-user is earlier than 1.4.4-7etch8" test_ref="oval:org.mitre.oval:tst:26405"/>
              <criterion comment="krb5-clients is earlier than 1.4.4-7etch8" test_ref="oval:org.mitre.oval:tst:26722"/>
              <criterion comment="krb5-kdc is earlier than 1.4.4-7etch8" test_ref="oval:org.mitre.oval:tst:26619"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7451" version="3" class="patch">
      <metadata>
        <title>DSA-2022 mediawiki -- several vulnerabilities</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <product>mediawiki</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2010/dsa-2022" ref_id="DSA-2022"/>
        <description>Several vulnerabilities have been discovered in mediawiki, a web-based wiki engine. The following issues have been identified: Insufficient input sanitization in the CSS validation code allows editors to display external images in wiki pages. This can be a privacy concern on public wikis as it allows attackers to gather IP addresses and other information by linking these images to a web server under their control. Insufficient permission checks have been found in thump.php which can lead to disclosure of image files that are restricted to certain users .</description>
        <oval_repository>
          <dates>
            <submitted date="2010-05-24T19:08:21-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2010-05-26T13:28:53.214-04:00">DRAFT</status_change>
            <status_change date="2010-06-14T04:00:53.262-04:00">INTERIM</status_change>
            <status_change date="2010-06-29T11:49:53.509-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
        <criteria operator="OR" comment="Architecture section">
          <criteria operator="AND" comment="Architecture independent section">
            <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
            <criterion comment="mediawiki is earlier than 1.12.0-2lenny4" test_ref="oval:org.mitre.oval:tst:26689"/>
          </criteria>
          <criteria operator="AND" comment="Architecture dependent section">
            <criteria operator="OR" comment="Supported architectures section">
              <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
              <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
              <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
              <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
              <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
              <criterion comment="Installed architecture is armel" test_ref="oval:org.mitre.oval:tst:11101"/>
              <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
              <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
              <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
              <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
              <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
            </criteria>
            <criteria operator="OR" comment="Packages section">
              <criterion comment="mediawiki-math is earlier than 1.12.0-2lenny4" test_ref="oval:org.mitre.oval:tst:26746"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7445" version="3" class="patch">
      <metadata>
        <title>DSA-2002 polipo -- denial of service</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <product>polipo</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2010/dsa-2002" ref_id="DSA-2002"/>
        <description>Several denial of service vulnerabilities have been discovered in polipo, a small, caching web proxy. The Common Vulnerabilities and Exposures project identifies the following problems: A malicous remote sever could cause polipo to crash by sending an invalid Cache-Control header. A malicous client could cause polipo to crash by sending a large Content-Length value. This upgrade also fixes some other bugs that could lead to a daemon crash or an infinite loop and may be triggerable remotely.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-05-24T19:11:05-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2010-05-26T13:29:29.101-04:00">DRAFT</status_change>
            <status_change date="2010-06-14T04:00:52.865-04:00">INTERIM</status_change>
            <status_change date="2010-06-29T11:49:53.155-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
        <criteria operator="OR" comment="Architecture section">
          <criteria operator="AND" comment="Architecture dependent section">
            <criteria operator="OR" comment="Supported architectures section">
              <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
              <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
              <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
              <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
              <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
              <criterion comment="Installed architecture is armel" test_ref="oval:org.mitre.oval:tst:11101"/>
              <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
              <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
              <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
              <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
              <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
              <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
            </criteria>
            <criteria operator="OR" comment="Packages section">
              <criterion comment="polipo is earlier than 1.0.4-1+lenny1" test_ref="oval:org.mitre.oval:tst:26922"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:7440" class="patch">
      <metadata>
        <title>DSA-1863 zope2.10/zope2.9 -- several vulnerabilities</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <platform>Debian GNU/Linux 4.0</platform>
          <product>zope2.10/zope2.9</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2009/dsa-1863" ref_id="DSA-1863"/>
        <description>Several remote vulnerabilities have been discovered in the zope, a feature-rich web application server written in python, that could lead to arbitrary code execution in the worst case. The Common Vulnerabilities and Exposures project identified the following problems: Due to a programming error an authorization method in the StorageServer component of ZEO was not used as an internal method. This allows a malicious client to bypass authentication when connecting to a ZEO server by simply calling this authorization method. The ZEO server doesn't restrict the callables when unpickling data received from a malicious client which can be used by an attacker to execute arbitrary python code on the server by sending certain exception pickles. This also allows an attacker to import any importable module as ZEO is importing the module containing a callable specified in a pickle to test for a certain flag. The update also limits the number of new object ids a client can request to 100 as it would be possible to consume huge amounts of resources by requesting a big batch of new object ids. No CVE id has been assigned to this. The oldstable distribution (etch), this problem has been fixed in version 2.9.6-4etch2 of zope2.9.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:08-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T07:56:53.728-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:00:51.449-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:00:33.943-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Platform section" operator="OR">
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Architecture independent section" operator="AND">
              <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criterion comment="zope2.10-sandbox is earlier than 2.10.6-1+lenny1" test_ref="oval:org.mitre.oval:tst:17158"/>
            </criteria>
            <criteria comment="Architecture dependent section" operator="AND">
              <criteria comment="Supported architectures section" operator="OR">
                <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
                <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
                <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
                <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
                <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
                <criterion comment="Installed architecture is armel" test_ref="oval:org.mitre.oval:tst:11101"/>
                <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
                <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
                <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
                <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
                <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
              </criteria>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="zope2.10 DPKG is earlier than 2.10.6-1+lenny1" test_ref="oval:org.mitre.oval:tst:17654"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 4.0 is installed" definition_ref="oval:org.mitre.oval:def:6461"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Architecture independent section" operator="AND">
              <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criterion comment="zope2.9-sandbox is earlier than 2.9.6-4etch2" test_ref="oval:org.mitre.oval:tst:17884"/>
            </criteria>
            <criteria comment="Packages section" operator="OR">
              <criterion comment="zope2.9 DPKG is earlier than 2.9.6-4etch2" test_ref="oval:org.mitre.oval:tst:17759"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7432" version="3" class="patch">
      <metadata>
        <title>DSA-2027 xulrunner -- several vulnerabilities</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <product>xulrunner</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2010/dsa-2027" ref_id="DSA-2027"/>
        <description>Several remote vulnerabilities have been discovered in Xulrunner, a runtime environment for XUL applications, such as the Iceweasel web browser. The Common Vulnerabilities and Exposures project identifies the following problems: Jesse Ruderman and Ehsan Akhgari discovered crashes in the layout engine, which might allow the execution of arbitrary code. It was discovered that incorrect memory handling in the XUL event handler might allow the execution of arbitrary code. It was discovered that incorrect memory handling in the XUL event handler might allow the execution of arbitrary code. It was discovered that incorrect memory handling in the plugin code might allow the execution of arbitrary code. Paul Stone discovered that forced drag-and-drop events could lead to Chrome privilege escalation. It was discovered that a programming error in the XMLHttpRequestSpy module could lead to the execution of arbitrary code.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-05-24T19:08:20-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2010-05-26T13:28:51.982-04:00">DRAFT</status_change>
            <status_change date="2010-06-14T04:00:52.416-04:00">INTERIM</status_change>
            <status_change date="2010-06-29T11:49:52.651-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
        <criteria operator="OR" comment="Architecture section">
          <criteria operator="AND" comment="Architecture independent section">
            <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
            <criterion comment="libmozillainterfaces-java is earlier than 1.9.0.19-1" test_ref="oval:org.mitre.oval:tst:26724"/>
          </criteria>
          <criteria operator="AND" comment="Architecture dependent section">
            <criteria operator="OR" comment="Supported architectures section">
              <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
              <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
              <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
              <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
              <criterion comment="Installed architecture is armel" test_ref="oval:org.mitre.oval:tst:11101"/>
              <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
              <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
              <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
              <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
            </criteria>
            <criteria operator="OR" comment="Packages section">
              <criterion comment="libmozjs-dev is earlier than 1.9.0.19-1" test_ref="oval:org.mitre.oval:tst:26795"/>
              <criterion comment="spidermonkey-bin is earlier than 1.9.0.19-1" test_ref="oval:org.mitre.oval:tst:26718"/>
              <criterion comment="xulrunner-1.9-gnome-support is earlier than 1.9.0.19-1" test_ref="oval:org.mitre.oval:tst:26858"/>
              <criterion comment="xulrunner-1.9 is earlier than 1.9.0.19-1" test_ref="oval:org.mitre.oval:tst:26825"/>
              <criterion comment="libmozjs1d-dbg is earlier than 1.9.0.19-1" test_ref="oval:org.mitre.oval:tst:26847"/>
              <criterion comment="libmozjs1d is earlier than 1.9.0.19-1" test_ref="oval:org.mitre.oval:tst:26716"/>
              <criterion comment="python-xpcom is earlier than 1.9.0.19-1" test_ref="oval:org.mitre.oval:tst:26168"/>
              <criterion comment="xulrunner-1.9-dbg is earlier than 1.9.0.19-1" test_ref="oval:org.mitre.oval:tst:26841"/>
              <criterion comment="xulrunner-dev is earlier than 1.9.0.19-1" test_ref="oval:org.mitre.oval:tst:26691"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:7414" class="patch">
      <metadata>
        <title>DSA-1788 quagga -- improper assertion</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <product>quagga</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2009/dsa-1788" ref_id="DSA-1788"/>
        <description>It was discovered that Quagga, an IP routing daemon, could no longer process the Internet routing table due to broken handling of multiple 4-byte AS numbers in an AS path. If such a prefix is received, the BGP daemon crashes with an assert failure, leading to a denial of service. The old stable distribution (etch) is not affected by this issue.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:10-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T07:57:57.307-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:00:45.414-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:00:29.428-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Release section" operator="AND">
        <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
        <criteria comment="Architecture section" operator="OR">
          <criteria comment="Architecture independent section" operator="AND">
            <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
            <criterion comment="quagga-doc is earlier than 0.99.10-1lenny2" test_ref="oval:org.mitre.oval:tst:18660"/>
          </criteria>
          <criteria comment="Architecture dependent section" operator="AND">
            <criteria comment="Supported architectures section" operator="OR">
              <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
              <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
              <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
              <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
              <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
              <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
              <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
              <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
              <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
            </criteria>
            <criteria comment="Packages section" operator="OR">
              <criterion comment="quagga DPKG is earlier than 0.99.10-1lenny2" test_ref="oval:org.mitre.oval:tst:18157"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:7412" class="patch">
      <metadata>
        <title>DSA-1745 lcms -- several vulnerabilities</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <platform>Debian GNU/Linux 4.0</platform>
          <product>lcms</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2009/dsa-1745" ref_id="DSA-1745"/>
        <description>Several security issues have been discovered in lcms, a color management library. The Common Vulnerabilities and Exposures project identifies the following problems: Chris Evans discovered that lcms is affected by a memory leak, which could result in a denial of service via specially crafted image files. Chris Evans discovered that lcms is prone to several integer overflows via specially crafted image files, which could lead to the execution of arbitrary code. Chris Evans discovered the lack of upper-bounds check on sizes leading to a buffer overflow, which could be used to execute arbitrary code.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:12-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T07:59:55.476-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:00:44.708-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:00:28.891-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Platform section" operator="OR">
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Architecture dependent section" operator="AND">
              <criteria comment="Supported architectures section" operator="OR">
                <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
                <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
                <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
                <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
                <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
                <criterion comment="Installed architecture is armel" test_ref="oval:org.mitre.oval:tst:11101"/>
                <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
                <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
                <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
                <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
                <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
                <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
              </criteria>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="liblcms1-dev DPKG is earlier than 1.17.dfsg-1+lenny1" test_ref="oval:org.mitre.oval:tst:19608"/>
                <criterion comment="liblcms1 DPKG is earlier than 1.17.dfsg-1+lenny1" test_ref="oval:org.mitre.oval:tst:20088"/>
                <criterion comment="liblcms-utils DPKG is earlier than 1.17.dfsg-1+lenny1" test_ref="oval:org.mitre.oval:tst:19915"/>
                <criterion comment="python-liblcms DPKG is earlier than 1.17.dfsg-1+lenny1" test_ref="oval:org.mitre.oval:tst:19713"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 4.0 is installed" definition_ref="oval:org.mitre.oval:def:6461"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Packages section" operator="OR">
              <criterion comment="liblcms1-dev DPKG is earlier than 1.15-1.1+etch2" test_ref="oval:org.mitre.oval:tst:19863"/>
              <criterion comment="liblcms-utils DPKG is earlier than 1.15-1.1+etch2" test_ref="oval:org.mitre.oval:tst:19413"/>
              <criterion comment="liblcms1 DPKG is earlier than 1.15-1.1+etch2" test_ref="oval:org.mitre.oval:tst:19664"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7409" version="3" class="patch">
      <metadata>
        <title>DSA-2043 vlc -- integer overflow</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <product>vlc</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2010/dsa-2043" ref_id="DSA-2043"/>
        <description>tixxDZ  discovered a vulnerability in vlc, the multimedia player and streamer. Missing data validation in vlc"s real data transport  implementation enable an integer underflow and consequently an unbounded buffer operation. A maliciously crafted stream could thus enable an attacker to execute arbitrary code. No Common Vulnerabilities and Exposures project identifier is available for this issue.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-05-24T19:04:53-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2010-05-26T13:27:58.658-04:00">DRAFT</status_change>
            <status_change date="2010-06-14T04:00:51.596-04:00">INTERIM</status_change>
            <status_change date="2010-06-29T11:49:51.283-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
        <criteria operator="OR" comment="Architecture section">
          <criteria operator="AND" comment="Architecture dependent section">
            <criteria operator="OR" comment="Supported architectures section">
              <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
              <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
              <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
              <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
              <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
              <criterion comment="Installed architecture is armel" test_ref="oval:org.mitre.oval:tst:11101"/>
              <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
              <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
              <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
              <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
              <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
            </criteria>
            <criteria operator="OR" comment="Packages section">
              <criterion comment="vlc-nox is earlier than 0.8.6.h-4+lenny2.3" test_ref="oval:org.mitre.oval:tst:24990"/>
              <criterion comment="vlc-plugin-jack is earlier than 0.8.6.h-4+lenny2.3" test_ref="oval:org.mitre.oval:tst:25975"/>
              <criterion comment="vlc-plugin-arts is earlier than 0.8.6.h-4+lenny2.3" test_ref="oval:org.mitre.oval:tst:25320"/>
              <criterion comment="vlc is earlier than 0.8.6.h-4+lenny2.3" test_ref="oval:org.mitre.oval:tst:25849"/>
              <criterion comment="mozilla-plugin-vlc is earlier than 0.8.6.h-4+lenny2.3" test_ref="oval:org.mitre.oval:tst:25825"/>
              <criterion comment="vlc-plugin-ggi is earlier than 0.8.6.h-4+lenny2.3" test_ref="oval:org.mitre.oval:tst:25262"/>
              <criterion comment="libvlc0-dev is earlier than 0.8.6.h-4+lenny2.3" test_ref="oval:org.mitre.oval:tst:25881"/>
              <criterion comment="libvlc0 is earlier than 0.8.6.h-4+lenny2.3" test_ref="oval:org.mitre.oval:tst:25725"/>
              <criterion comment="vlc-plugin-esd is earlier than 0.8.6.h-4+lenny2.3" test_ref="oval:org.mitre.oval:tst:25136"/>
              <criterion comment="vlc-plugin-sdl is earlier than 0.8.6.h-4+lenny2.3" test_ref="oval:org.mitre.oval:tst:25746"/>
            </criteria>
          </criteria>
          <criteria operator="AND" comment="Architecture dependent section">
            <criteria operator="OR" comment="Supported architectures section">
              <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
            </criteria>
            <criteria operator="OR" comment="Packages section">
              <criterion comment="vlc-plugin-glide is earlier than 0.8.6.h-4+lenny2.3" test_ref="oval:org.mitre.oval:tst:25868"/>
              <criterion comment="vlc-plugin-svgalib is earlier than 0.8.6.h-4+lenny2.3" test_ref="oval:org.mitre.oval:tst:25929"/>
            </criteria>
          </criteria>
          <criteria operator="AND" comment="Architecture depended section">
            <criteria operator="AND" comment="Supported platform section">
              <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
              <criteria operator="OR" comment="Packages section">
                <criterion comment="vlc-plugin-svgalib is earlier than 0.8.6.h-4+lenny2.3" test_ref="oval:org.mitre.oval:tst:25918"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7407" version="3" class="patch">
      <metadata>
        <title>DSA-2036 jasper -- programming error</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <product>jasper</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2010/dsa-2036" ref_id="DSA-2036"/>
        <description>It was discovered that the JasPer JPEG-2000 runtime library allowed an attacker to create a crafted input file that could lead to denial of service and heap corruption. Besides addressing this vulnerability, this updates also addresses a regression introduced in the security fix for CVE-2008-3521, applied before Debian Lenny"s release, that could cause errors when reading some JPEG input files.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-05-24T19:09:57-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2010-05-26T13:29:12.529-04:00">DRAFT</status_change>
            <status_change date="2010-06-14T04:00:51.244-04:00">INTERIM</status_change>
            <status_change date="2010-06-29T11:49:50.855-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
        <criteria operator="OR" comment="Architecture section">
          <criteria operator="AND" comment="Architecture dependent section">
            <criteria operator="OR" comment="Supported architectures section">
              <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
              <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
              <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
              <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
              <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
              <criterion comment="Installed architecture is armel" test_ref="oval:org.mitre.oval:tst:11101"/>
              <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
              <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
              <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
              <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
              <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
            </criteria>
            <criteria operator="OR" comment="Packages section">
              <criterion comment="libjasper-runtime is earlier than 1.900.1-5.1+lenny1" test_ref="oval:org.mitre.oval:tst:26740"/>
              <criterion comment="libjasper1 is earlier than 1.900.1-5.1+lenny1" test_ref="oval:org.mitre.oval:tst:26886"/>
              <criterion comment="libjasper-dev is earlier than 1.900.1-5.1+lenny1" test_ref="oval:org.mitre.oval:tst:26900"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:7391" class="patch">
      <metadata>
        <title>DSA-1730 proftpd-dfsg -- SQL injection vulnerabilites</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <product>proftpd-dfsg</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2009/dsa-1730" ref_id="DSA-1730"/>
        <description>The security update for proftpd-dfsg in DSA-1727-1 caused a regression with the postgresql backend. This update corrects the flaw. Also it was discovered that the oldstable distribution (etch) is not affected by the security issues. For reference the original advisory follows. Two SQL injection vulnerabilities have been found in proftpd, a virtual-hosting FTP daemon. The Common Vulnerabilities and Exposures project identifies the following problems: Shino discovered that proftpd is prone to an SQL injection vulnerability via the use of certain characters in the username.  TJ Saunders discovered that proftpd is prone to an SQL injection vulnerability due to insufficient escaping mechanisms, when multybite character encodings are used. The oldstable distribution (etch) is not affected by these problems.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:11-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T07:59:29.205-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:00:41.554-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:00:27.147-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Release section" operator="AND">
        <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
        <criteria comment="Architecture section" operator="OR">
          <criteria comment="Architecture independent section" operator="AND">
            <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
            <criteria comment="Packages section" operator="OR">
              <criterion comment="proftpd is earlier than 1.3.1-17lenny2" test_ref="oval:org.mitre.oval:tst:19097"/>
              <criterion comment="proftpd-doc is earlier than 1.3.1-17lenny2" test_ref="oval:org.mitre.oval:tst:19293"/>
            </criteria>
          </criteria>
          <criteria comment="Packages section" operator="OR">
            <criterion comment="proftpd-mod-mysql DPKG is earlier than 1.3.1-17lenny2" test_ref="oval:org.mitre.oval:tst:19592"/>
            <criterion comment="proftpd-mod-pgsql DPKG is earlier than 1.3.1-17lenny2" test_ref="oval:org.mitre.oval:tst:19471"/>
            <criterion comment="proftpd-mod-ldap DPKG is earlier than 1.3.1-17lenny2" test_ref="oval:org.mitre.oval:tst:19542"/>
            <criterion comment="proftpd-basic DPKG is earlier than 1.3.1-17lenny2" test_ref="oval:org.mitre.oval:tst:19493"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7379" version="3" class="patch">
      <metadata>
        <title>DSA-1948 ntp -- denial of service</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <platform>Debian GNU/Linux 4.0</platform>
          <product>ntp</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2009/dsa-1948" ref_id="DSA-1948"/>
        <description>Robin Park and Dmitri Vinokurov discovered that the daemon component of the ntp package, a reference implementation of the NTP protocol, is not properly reacting to certain incoming packets. An unexpected NTP mode 7 packet  with spoofed IP data can lead ntpd to reply with a mode 7 response to the spoofed address. This may result in the service playing packet ping-pong with other ntp servers or even itself which causes CPU usage and excessive disk use due to logging. An attacker can use this to conduct denial of service attacks.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-05-24T18:48:59-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2010-05-26T13:27:04.876-04:00">DRAFT</status_change>
            <status_change date="2010-06-14T04:00:50.552-04:00">INTERIM</status_change>
            <status_change date="2010-06-29T11:49:49.386-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Release section">
          <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
          <criteria operator="OR" comment="Architecture section">
            <criteria operator="AND" comment="Architecture independent section">
              <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criterion comment="ntp-doc is earlier than 4.2.4p4+dfsg-8lenny3" test_ref="oval:org.mitre.oval:tst:24360"/>
            </criteria>
            <criteria operator="AND" comment="Architecture dependent section">
              <criteria operator="OR" comment="Supported architectures section">
                <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
                <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
                <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
                <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
                <criterion comment="Installed architecture is armel" test_ref="oval:org.mitre.oval:tst:11101"/>
                <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
                <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
                <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
                <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
                <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
                <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
              </criteria>
              <criteria operator="OR" comment="Packages section">
                <criterion comment="ntpdate is earlier than 4.2.4p4+dfsg-8lenny3" test_ref="oval:org.mitre.oval:tst:24221"/>
                <criterion comment="ntp is earlier than 4.2.4p4+dfsg-8lenny3" test_ref="oval:org.mitre.oval:tst:24181"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Release section">
          <extend_definition comment="Debian 4.0 is installed." definition_ref="oval:org.mitre.oval:def:6461"/>
          <criteria operator="OR" comment="Architecture section">
            <criteria operator="AND" comment="Architecture independent section">
              <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criteria operator="OR" comment="Packages section">
                <criterion comment="ntp-doc is earlier than 4.2.2.p4+dfsg-2etch4" test_ref="oval:org.mitre.oval:tst:24157"/>
                <criterion comment="ntp-simple is earlier than 4.2.2.p4+dfsg-2etch4" test_ref="oval:org.mitre.oval:tst:24394"/>
                <criterion comment="ntp-refclock is earlier than 4.2.2.p4+dfsg-2etch4" test_ref="oval:org.mitre.oval:tst:24367"/>
              </criteria>
            </criteria>
            <criteria operator="OR" comment="Packages section">
              <criterion comment="ntp is earlier than 4.2.2.p4+dfsg-2etch4" test_ref="oval:org.mitre.oval:tst:24086"/>
              <criterion comment="ntpdate is earlier than 4.2.2.p4+dfsg-2etch4" test_ref="oval:org.mitre.oval:tst:23435"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7367" version="3" class="patch">
      <metadata>
        <title>DSA-2001 php5 -- multiple vulnerabilities</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <product>php5</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2010/dsa-2001" ref_id="DSA-2001"/>
        <description>Several remote vulnerabilities have been discovered in PHP 5, an hypertext preprocessor. The Common Vulnerabilities and Exposures project identifies the following problems: The htmlspecialchars function does not properly handle invalid multi-byte sequences. Memory corruption via session interruption. In the stable distribution , this update also includes bug fixes  that were to be included in a stable point release as version 5.2.6.dfsg.1-1+lenny5.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-05-24T19:12:49-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2010-05-26T13:29:36.856-04:00">DRAFT</status_change>
            <status_change date="2010-06-14T04:00:49.776-04:00">INTERIM</status_change>
            <status_change date="2010-06-29T11:49:48.202-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
        <criteria operator="OR" comment="Architecture section">
          <criteria operator="AND" comment="Architecture independent section">
            <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
            <criteria operator="OR" comment="Packages section">
              <criterion comment="php-pear is earlier than 5.2.6.dfsg.1-1+lenny6" test_ref="oval:org.mitre.oval:tst:26925"/>
              <criterion comment="php5 is earlier than 5.2.6.dfsg.1-1+lenny6" test_ref="oval:org.mitre.oval:tst:27244"/>
            </criteria>
          </criteria>
          <criteria operator="AND" comment="Architecture dependent section">
            <criteria operator="OR" comment="Supported architectures section">
              <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
              <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
              <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
              <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
              <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
              <criterion comment="Installed architecture is armel" test_ref="oval:org.mitre.oval:tst:11101"/>
              <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
              <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
              <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
              <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
              <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
              <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
            </criteria>
            <criteria operator="OR" comment="Packages section">
              <criterion comment="php5-recode is earlier than 5.2.6.dfsg.1-1+lenny6" test_ref="oval:org.mitre.oval:tst:27224"/>
              <criterion comment="php5-xmlrpc is earlier than 5.2.6.dfsg.1-1+lenny6" test_ref="oval:org.mitre.oval:tst:27364"/>
              <criterion comment="php5-curl is earlier than 5.2.6.dfsg.1-1+lenny6" test_ref="oval:org.mitre.oval:tst:27282"/>
              <criterion comment="php5-snmp is earlier than 5.2.6.dfsg.1-1+lenny6" test_ref="oval:org.mitre.oval:tst:27249"/>
              <criterion comment="php5-mysql is earlier than 5.2.6.dfsg.1-1+lenny6" test_ref="oval:org.mitre.oval:tst:27379"/>
              <criterion comment="php5-odbc is earlier than 5.2.6.dfsg.1-1+lenny6" test_ref="oval:org.mitre.oval:tst:27394"/>
              <criterion comment="php5-xsl is earlier than 5.2.6.dfsg.1-1+lenny6" test_ref="oval:org.mitre.oval:tst:27401"/>
              <criterion comment="php5-gd is earlier than 5.2.6.dfsg.1-1+lenny6" test_ref="oval:org.mitre.oval:tst:26672"/>
              <criterion comment="libapache2-mod-php5 is earlier than 5.2.6.dfsg.1-1+lenny6" test_ref="oval:org.mitre.oval:tst:26414"/>
              <criterion comment="php5-mhash is earlier than 5.2.6.dfsg.1-1+lenny6" test_ref="oval:org.mitre.oval:tst:27359"/>
              <criterion comment="php5-tidy is earlier than 5.2.6.dfsg.1-1+lenny6" test_ref="oval:org.mitre.oval:tst:27129"/>
              <criterion comment="php5-mcrypt is earlier than 5.2.6.dfsg.1-1+lenny6" test_ref="oval:org.mitre.oval:tst:26998"/>
              <criterion comment="php5-dev is earlier than 5.2.6.dfsg.1-1+lenny6" test_ref="oval:org.mitre.oval:tst:26472"/>
              <criterion comment="php5-pgsql is earlier than 5.2.6.dfsg.1-1+lenny6" test_ref="oval:org.mitre.oval:tst:27245"/>
              <criterion comment="php5-gmp is earlier than 5.2.6.dfsg.1-1+lenny6" test_ref="oval:org.mitre.oval:tst:26684"/>
              <criterion comment="php5-cgi is earlier than 5.2.6.dfsg.1-1+lenny6" test_ref="oval:org.mitre.oval:tst:27005"/>
              <criterion comment="php5-imap is earlier than 5.2.6.dfsg.1-1+lenny6" test_ref="oval:org.mitre.oval:tst:27388"/>
              <criterion comment="php5-sqlite is earlier than 5.2.6.dfsg.1-1+lenny6" test_ref="oval:org.mitre.oval:tst:26473"/>
              <criterion comment="php5-ldap is earlier than 5.2.6.dfsg.1-1+lenny6" test_ref="oval:org.mitre.oval:tst:27332"/>
              <criterion comment="php5-cli is earlier than 5.2.6.dfsg.1-1+lenny6" test_ref="oval:org.mitre.oval:tst:27411"/>
              <criterion comment="php5-sybase is earlier than 5.2.6.dfsg.1-1+lenny6" test_ref="oval:org.mitre.oval:tst:27280"/>
              <criterion comment="php5-pspell is earlier than 5.2.6.dfsg.1-1+lenny6" test_ref="oval:org.mitre.oval:tst:27241"/>
              <criterion comment="libapache2-mod-php5filter is earlier than 5.2.6.dfsg.1-1+lenny6" test_ref="oval:org.mitre.oval:tst:27336"/>
              <criterion comment="php5-common is earlier than 5.2.6.dfsg.1-1+lenny6" test_ref="oval:org.mitre.oval:tst:27470"/>
              <criterion comment="php5-dbg is earlier than 5.2.6.dfsg.1-1+lenny6" test_ref="oval:org.mitre.oval:tst:27340"/>
            </criteria>
          </criteria>
          <criteria operator="AND" comment="Architecture dependent section">
            <criteria operator="OR" comment="Supported architectures section">
              <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
              <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
              <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
              <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
            </criteria>
            <criteria operator="OR" comment="Packages section">
              <criterion comment="php5-interbase is earlier than 5.2.6.dfsg.1-1+lenny6" test_ref="oval:org.mitre.oval:tst:27263"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:7366" class="patch">
      <metadata>
        <title>DSA-1754 roundup -- insufficient access checks</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <platform>Debian GNU/Linux 4.0</platform>
          <product>roundup</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2009/dsa-1754" ref_id="DSA-1754"/>
        <description>It was discovered that roundup, an issue tracker with a command-line, web and email interface, allows users to edit resources in unauthorized ways, including granting themselves admin rights. This update introduces stricter access checks, actually enforcing the configured permissions and roles. This means that the configuration may need updating. In addition, user registration via the web interface has been disabled; use the program "roundup-admin" from the command line instead.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:04-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T07:51:17.187-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:00:39.850-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:00:25.710-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Platform section" operator="OR">
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Architecture independent section" operator="AND">
              <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criterion comment="roundup is earlier than 1.4.4-4+lenny1" test_ref="oval:org.mitre.oval:tst:13368"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 4.0 is installed" definition_ref="oval:org.mitre.oval:def:6461"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Architecture independent section" operator="AND">
              <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criterion comment="roundup is earlier than 1.2.1-10+etch1" test_ref="oval:org.mitre.oval:tst:13487"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:7365" class="patch">
      <metadata>
        <title>DSA-1941 poppler -- several vulnerabilities</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <product>poppler</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2009/dsa-1941" ref_id="DSA-1941"/>
        <description>Several integer overflows, buffer overflows and memory allocation errors were discovered in the Poppler PDF rendering library, which may lead to denial of service or the execution of arbitrary code if a user is tricked into opening a malformed PDF document. An update for the old stable distribution (etch) will be issued soon as version 0.4.5-5.1etch4.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:02-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T07:48:46.471-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:00:39.283-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:00:25.257-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Release section" operator="AND">
        <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
        <criteria comment="Architecture section" operator="OR">
          <criteria comment="Architecture dependent section" operator="AND">
            <criteria comment="Supported architectures section" operator="OR">
              <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
              <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
              <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
              <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
              <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
              <criterion comment="Installed architecture is armel" test_ref="oval:org.mitre.oval:tst:11101"/>
              <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
              <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
              <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
              <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
              <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
              <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
            </criteria>
            <criteria comment="Packages section" operator="OR">
              <criterion comment="poppler-utils DPKG is earlier than 0.8.7-3" test_ref="oval:org.mitre.oval:tst:11466"/>
              <criterion comment="libpoppler-qt4-dev DPKG is earlier than 0.8.7-3" test_ref="oval:org.mitre.oval:tst:11169"/>
              <criterion comment="libpoppler-qt4-3 DPKG is earlier than 0.8.7-3" test_ref="oval:org.mitre.oval:tst:11428"/>
              <criterion comment="libpoppler-dev DPKG is earlier than 0.8.7-3" test_ref="oval:org.mitre.oval:tst:11751"/>
              <criterion comment="libpoppler-qt-dev DPKG is earlier than 0.8.7-3" test_ref="oval:org.mitre.oval:tst:12041"/>
              <criterion comment="libpoppler3 DPKG is earlier than 0.8.7-3" test_ref="oval:org.mitre.oval:tst:11655"/>
              <criterion comment="libpoppler-qt2 DPKG is earlier than 0.8.7-3" test_ref="oval:org.mitre.oval:tst:11449"/>
              <criterion comment="libpoppler-glib-dev DPKG is earlier than 0.8.7-3" test_ref="oval:org.mitre.oval:tst:11821"/>
              <criterion comment="libpoppler-glib3 DPKG is earlier than 0.8.7-3" test_ref="oval:org.mitre.oval:tst:11854"/>
              <criterion comment="poppler-dbg DPKG is earlier than 0.8.7-3" test_ref="oval:org.mitre.oval:tst:11931"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:7349" class="patch">
      <metadata>
        <title>DSA-1939 libvorbis -- several vulnerabilities</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <platform>Debian GNU/Linux 4.0</platform>
          <product>libvorbis</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2009/dsa-1939" ref_id="DSA-1939"/>
        <description>Lucas Adamski, Matthew Gregan, David Keeler, and Dan Kaminsky discovered that libvorbis, a library for the Vorbis general-purpose compressed audio codec, did not correctly handle certain malformed ogg files. An attacher could cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via a crafted .ogg file.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:11-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T07:59:18.475-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:00:38.452-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:00:24.746-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Platform section" operator="OR">
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Architecture dependent section" operator="AND">
              <criteria comment="Supported architectures section" operator="OR">
                <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
                <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
                <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
                <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
                <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
                <criterion comment="Installed architecture is armel" test_ref="oval:org.mitre.oval:tst:11101"/>
                <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
                <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
                <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
                <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
                <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
                <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
              </criteria>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="libvorbis0a DPKG is earlier than 1.2.0.dfsg-3.1+lenny1" test_ref="oval:org.mitre.oval:tst:19313"/>
                <criterion comment="libvorbisfile3 DPKG is earlier than 1.2.0.dfsg-3.1+lenny1" test_ref="oval:org.mitre.oval:tst:19408"/>
                <criterion comment="libvorbisenc2 DPKG is earlier than 1.2.0.dfsg-3.1+lenny1" test_ref="oval:org.mitre.oval:tst:19414"/>
                <criterion comment="libvorbis-dev DPKG is earlier than 1.2.0.dfsg-3.1+lenny1" test_ref="oval:org.mitre.oval:tst:18559"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 4.0 is installed" definition_ref="oval:org.mitre.oval:def:6461"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Packages section" operator="OR">
              <criterion comment="libvorbis-dev DPKG is earlier than 1.1.2.dfsg-1.4+etch1" test_ref="oval:org.mitre.oval:tst:19306"/>
              <criterion comment="libvorbis0a DPKG is earlier than 1.1.2.dfsg-1.4+etch1" test_ref="oval:org.mitre.oval:tst:19405"/>
              <criterion comment="libvorbisfile3 DPKG is earlier than 1.1.2.dfsg-1.4+etch1" test_ref="oval:org.mitre.oval:tst:19215"/>
              <criterion comment="libvorbisenc2 DPKG is earlier than 1.1.2.dfsg-1.4+etch1" test_ref="oval:org.mitre.oval:tst:19364"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:7333" class="patch">
      <metadata>
        <title>DSA-1930 drupal6 -- several vulnerabilities</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <product>drupal6</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2009/dsa-1930" ref_id="DSA-1930"/>
        <description>Several vulnerabilities have been found in drupal6, a fully-featured content management framework. The Common Vulnerabilities and Exposures project identifies the following problems: Gerhard Killesreiter discovered a flaw in the way user signatures are handled. It is possible for a user to inject arbitrary code via a crafted user signature. (SA-CORE-2009-007) Mark Piper, Sven Herrmann and Brandon Knight discovered a cross-site scripting issue in the forum module, which could be exploited via the tid parameter. (SA-CORE-2009-007) Sumit Datta discovered that certain drupal6 pages leak sensitive information such as user credentials. (SA-CORE-2009-007) Several design flaws in the OpenID module have been fixed, which could lead to cross-site request forgeries or privilege escalations. Also, the file upload function does not process all extensions properly leading to the possible execution of arbitrary code. (SA-CORE-2009-008) The oldstable distribution (etch) does not contain drupal6.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:11-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T07:59:09.220-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:00:37.349-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:00:24.154-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Release section" operator="AND">
        <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
        <criteria comment="Architecture section" operator="OR">
          <criteria comment="Architecture independent section" operator="AND">
            <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
            <criterion comment="drupal6 is earlier than 6.6-3lenny3" test_ref="oval:org.mitre.oval:tst:19246"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7332" version="3" class="patch">
      <metadata>
        <title>DSA-1961 bind9 -- DNS cache poisoning</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <platform>Debian GNU/Linux 4.0</platform>
          <product>bind9</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2009/dsa-1961" ref_id="DSA-1961"/>
        <description>Michael Sinatra discovered that the DNS resolver component in BIND does not properly check DNS records contained in additional sections of DNS responses, leading to a cache poisoning vulnerability. This vulnerability is only present in resolvers which have been configured with DNSSEC trust anchors, which is still rare. Note that this update contains an internal ABI change, which means that all BIND-related packages  must be updated at the same time . In the unlikely event that you have compiled your own software against libdns, you must recompile this programs, too.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-05-24T19:09:15-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2010-05-26T13:29:06.898-04:00">DRAFT</status_change>
            <status_change date="2010-06-14T04:00:48.983-04:00">INTERIM</status_change>
            <status_change date="2010-06-29T11:49:46.113-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Release section">
          <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
          <criteria operator="OR" comment="Architecture section">
            <criteria operator="AND" comment="Architecture independent section">
              <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criterion comment="bind9-doc is earlier than 9.5.1.dfsg.P3-1+lenny1" test_ref="oval:org.mitre.oval:tst:26952"/>
            </criteria>
            <criteria operator="AND" comment="Architecture dependent section">
              <criteria operator="OR" comment="Supported architectures section">
                <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
                <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
                <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
                <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
                <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
                <criterion comment="Installed architecture is armel" test_ref="oval:org.mitre.oval:tst:11101"/>
                <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
                <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
                <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
                <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
                <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
                <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
              </criteria>
              <criteria operator="OR" comment="Packages section">
                <criterion comment="dnsutils is earlier than 9.5.1.dfsg.P3-1+lenny1" test_ref="oval:org.mitre.oval:tst:26752"/>
                <criterion comment="libbind9-40 is earlier than 9.5.1.dfsg.P3-1+lenny1" test_ref="oval:org.mitre.oval:tst:25983"/>
                <criterion comment="libisccc40 is earlier than 9.5.1.dfsg.P3-1+lenny1" test_ref="oval:org.mitre.oval:tst:26761"/>
                <criterion comment="libisccfg40 is earlier than 9.5.1.dfsg.P3-1+lenny1" test_ref="oval:org.mitre.oval:tst:26714"/>
                <criterion comment="bind9utils is earlier than 9.5.1.dfsg.P3-1+lenny1" test_ref="oval:org.mitre.oval:tst:26612"/>
                <criterion comment="libisc45 is earlier than 9.5.1.dfsg.P3-1+lenny1" test_ref="oval:org.mitre.oval:tst:26758"/>
                <criterion comment="liblwres40 is earlier than 9.5.1.dfsg.P3-1+lenny1" test_ref="oval:org.mitre.oval:tst:26816"/>
                <criterion comment="lwresd is earlier than 9.5.1.dfsg.P3-1+lenny1" test_ref="oval:org.mitre.oval:tst:26958"/>
                <criterion comment="libbind-dev is earlier than 9.5.1.dfsg.P3-1+lenny1" test_ref="oval:org.mitre.oval:tst:26469"/>
                <criterion comment="libdns45 is earlier than 9.5.1.dfsg.P3-1+lenny1" test_ref="oval:org.mitre.oval:tst:26765"/>
                <criterion comment="bind9 is earlier than 9.5.1.dfsg.P3-1+lenny1" test_ref="oval:org.mitre.oval:tst:26611"/>
                <criterion comment="bind9-host is earlier than 9.5.1.dfsg.P3-1+lenny1" test_ref="oval:org.mitre.oval:tst:26820"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Release section">
          <extend_definition comment="Debian 4.0 is installed." definition_ref="oval:org.mitre.oval:def:6461"/>
          <criteria operator="OR" comment="Architecture section">
            <criteria operator="AND" comment="Architecture independent section">
              <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criterion comment="bind9-doc is earlier than 9.3.4-2etch6" test_ref="oval:org.mitre.oval:tst:26966"/>
            </criteria>
            <criteria operator="AND" comment="Architecture dependent section">
              <criteria operator="OR" comment="Supported architectures section">
                <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
                <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
                <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
                <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
                <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
                <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
                <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
                <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
                <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
                <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
              </criteria>
              <criteria operator="OR" comment="Packages section">
                <criterion comment="dnsutils is earlier than 9.3.4-2etch6" test_ref="oval:org.mitre.oval:tst:26179"/>
                <criterion comment="libbind-dev is earlier than 9.3.4-2etch6" test_ref="oval:org.mitre.oval:tst:26628"/>
                <criterion comment="libdns22 is earlier than 9.3.4-2etch6" test_ref="oval:org.mitre.oval:tst:26961"/>
                <criterion comment="libisccfg1 is earlier than 9.3.4-2etch6" test_ref="oval:org.mitre.oval:tst:26243"/>
                <criterion comment="libisccc0 is earlier than 9.3.4-2etch6" test_ref="oval:org.mitre.oval:tst:26322"/>
                <criterion comment="libisc11 is earlier than 9.3.4-2etch6" test_ref="oval:org.mitre.oval:tst:26633"/>
                <criterion comment="libbind9-0 is earlier than 9.3.4-2etch6" test_ref="oval:org.mitre.oval:tst:26874"/>
                <criterion comment="bind9-host is earlier than 9.3.4-2etch6" test_ref="oval:org.mitre.oval:tst:26912"/>
                <criterion comment="bind9 is earlier than 9.3.4-2etch6" test_ref="oval:org.mitre.oval:tst:26646"/>
                <criterion comment="liblwres9 is earlier than 9.3.4-2etch6" test_ref="oval:org.mitre.oval:tst:26282"/>
                <criterion comment="lwresd is earlier than 9.3.4-2etch6" test_ref="oval:org.mitre.oval:tst:26670"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7329" version="3" class="patch">
      <metadata>
        <title>DSA-1960 acpid -- programming error</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <platform>Debian GNU/Linux 4.0</platform>
          <product>acpid</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2009/dsa-1960" ref_id="DSA-1960"/>
        <description>It was discovered that acpid, the Advanced Configuration and Power Interface event daemon, on the oldstable distribution  creates its log file with weak permissions, which might expose sensitive information or might be abused by a local user to consume all free disk space on the same partition of the file.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-05-24T19:09:14-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2010-05-26T13:29:04.752-04:00">DRAFT</status_change>
            <status_change date="2010-06-14T04:00:48.692-04:00">INTERIM</status_change>
            <status_change date="2010-06-29T11:49:45.752-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Release section">
          <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
          <criteria operator="OR" comment="Architecture section">
            <criteria operator="AND" comment="Architecture dependent section">
              <criteria operator="OR" comment="Supported architectures section">
                <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
                <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
                <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
              </criteria>
              <criteria operator="OR" comment="Packages section">
                <criterion comment="acpid is earlier than 1.0.8-1lenny2" test_ref="oval:org.mitre.oval:tst:26654"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Release section">
          <extend_definition comment="Debian 4.0 is installed." definition_ref="oval:org.mitre.oval:def:6461"/>
          <criteria operator="OR" comment="Architecture section">
            <criteria operator="AND" comment="Architecture dependent section">
              <criteria operator="OR" comment="Supported architectures section">
                <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
                <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
                <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
              </criteria>
              <criteria operator="OR" comment="Packages section">
                <criterion comment="acpid is earlier than 1.0.4-5etch2" test_ref="oval:org.mitre.oval:tst:26699"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7325" version="3" class="patch">
      <metadata>
        <title>DSA-1991 squid/squid3 -- denial of service</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <platform>Debian GNU/Linux 4.0</platform>
          <product>squid/squid3</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2010/dsa-1991" ref_id="DSA-1991"/>
        <description>Two denial of service vulnerabilities have been discovered in squid and squid3, a web proxy. The Common Vulnerabilities and Exposures project identifies the following problems: Bastian Blank discovered that it is possible to cause a denial of service via a crafted auth header with certain comma delimiters. Tomas Hoger discovered that it is possible to cause a denial of service via invalid DNS header-only packets.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-05-24T19:05:56-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2010-05-26T13:28:12.439-04:00">DRAFT</status_change>
            <status_change date="2010-06-14T04:00:48.021-04:00">INTERIM</status_change>
            <status_change date="2010-06-29T11:49:45.115-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Release section">
          <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
          <criteria operator="OR" comment="Architecture section">
            <criteria operator="AND" comment="Architecture independent section">
              <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criteria operator="OR" comment="Packages section">
                <criterion comment="squid-common is earlier than 2.7.STABLE3-4.1lenny1" test_ref="oval:org.mitre.oval:tst:25654"/>
                <criterion comment="squid3-common is earlier than 3.0.STABLE8-3+lenny3" test_ref="oval:org.mitre.oval:tst:25699"/>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Architecture dependent section">
              <criteria operator="OR" comment="Supported architectures section">
                <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
                <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
                <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
                <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
                <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
                <criterion comment="Installed architecture is armel" test_ref="oval:org.mitre.oval:tst:11101"/>
                <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
                <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
                <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
                <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
                <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
              </criteria>
              <criteria operator="OR" comment="Packages section">
                <criterion comment="squidclient is earlier than 3.0.STABLE8-3+lenny3" test_ref="oval:org.mitre.oval:tst:25939"/>
                <criterion comment="squid3 is earlier than 3.0.STABLE8-3+lenny3" test_ref="oval:org.mitre.oval:tst:26044"/>
                <criterion comment="squid3-cgi is earlier than 3.0.STABLE8-3+lenny3" test_ref="oval:org.mitre.oval:tst:25670"/>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Architecture dependent section">
              <criteria operator="OR" comment="Supported architectures section">
                <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
                <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
                <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
                <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
                <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
                <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
                <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
                <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
              </criteria>
              <criteria operator="OR" comment="Packages section">
                <criterion comment="squid is earlier than 2.7.STABLE3-4.1lenny1" test_ref="oval:org.mitre.oval:tst:25714"/>
                <criterion comment="squid-cgi is earlier than 2.7.STABLE3-4.1lenny1" test_ref="oval:org.mitre.oval:tst:25894"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Release section">
          <extend_definition comment="Debian 4.0 is installed." definition_ref="oval:org.mitre.oval:def:6461"/>
          <criteria operator="OR" comment="Architecture section">
            <criteria operator="AND" comment="Architecture independent section">
              <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criteria operator="OR" comment="Packages section">
                <criterion comment="squid-common is earlier than 2.6.5-6etch5" test_ref="oval:org.mitre.oval:tst:25570"/>
                <criterion comment="squid3-common is earlier than 3.0.PRE5-5+etch2" test_ref="oval:org.mitre.oval:tst:26004"/>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Architecture dependent section">
              <criteria operator="OR" comment="Supported architectures section">
                <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
                <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
                <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
                <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
                <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
                <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
                <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
              </criteria>
              <criteria operator="OR" comment="Packages section">
                <criterion comment="squid is earlier than 2.6.5-6etch5" test_ref="oval:org.mitre.oval:tst:26028"/>
                <criterion comment="squid-cgi is earlier than 2.6.5-6etch5" test_ref="oval:org.mitre.oval:tst:25487"/>
                <criterion comment="squid3-client is earlier than 3.0.PRE5-5+etch2" test_ref="oval:org.mitre.oval:tst:25948"/>
                <criterion comment="squidclient is earlier than 2.6.5-6etch5" test_ref="oval:org.mitre.oval:tst:25992"/>
                <criterion comment="squid3-cgi is earlier than 3.0.PRE5-5+etch2" test_ref="oval:org.mitre.oval:tst:25662"/>
                <criterion comment="squid3 is earlier than 3.0.PRE5-5+etch2" test_ref="oval:org.mitre.oval:tst:25816"/>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Architecture dependent section">
              <criteria operator="OR" comment="Supported architectures section">
                <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
              </criteria>
              <criteria operator="OR" comment="Packages section">
                <criterion comment="squidclient is earlier than 2.6.5-6etch5" test_ref="oval:org.mitre.oval:tst:26032"/>
                <criterion comment="squid is earlier than 2.6.5-6etch5" test_ref="oval:org.mitre.oval:tst:25762"/>
                <criterion comment="squid-cgi is earlier than 2.6.5-6etch5" test_ref="oval:org.mitre.oval:tst:25612"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7310" version="3" class="patch">
      <metadata>
        <title>DSA-1992 chrony -- several vulnerabilities</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <platform>Debian GNU/Linux 4.0</platform>
          <product>chrony</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2010/dsa-1992" ref_id="DSA-1992"/>
        <description>Several vulnerabilities have been discovered in chrony, a pair of programs which are used to maintain the accuracy of the system clock on a computer. This issues are similar to the NTP security flaw CVE-2009-3563. The Common Vulnerabilities and Exposures project identifies the following problems: chronyd replies to all cmdmon packets with NOHOSTACCESS messages even for unauthorized hosts. An attacker can abuse this behaviour to force two chronyd instances to play packet ping-pong by sending such a packet with spoofed source address and port. This results in high CPU and network usage and thus denial of service conditions. The client logging facility of chronyd doesn"t limit memory that is used to store client information. An attacker can cause chronyd to allocate large amounts of memory by sending NTP or cmdmon packets with spoofed source addresses resulting in memory exhaustion. chronyd lacks of a rate limit control to the syslog facility when logging received packets from unauthorized hosts. This allows an attacker to cause denial of service conditions via filling up the logs and thus disk space by repeatedly sending invalid cmdmon packets.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-05-24T19:06:03-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2010-05-26T13:28:13.689-04:00">DRAFT</status_change>
            <status_change date="2010-06-14T04:00:47.606-04:00">INTERIM</status_change>
            <status_change date="2010-06-29T11:49:43.668-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Release section">
          <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
          <criteria operator="OR" comment="Architecture section">
            <criteria operator="AND" comment="Architecture dependent section">
              <criteria operator="OR" comment="Supported architectures section">
                <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
                <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
                <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
                <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
                <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
                <criterion comment="Installed architecture is armel" test_ref="oval:org.mitre.oval:tst:11101"/>
                <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
                <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
                <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
                <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
                <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
                <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
              </criteria>
              <criteria operator="OR" comment="Packages section">
                <criterion comment="chrony is earlier than 1.23-6+lenny1" test_ref="oval:org.mitre.oval:tst:25974"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Release section">
          <extend_definition comment="Debian 4.0 is installed." definition_ref="oval:org.mitre.oval:def:6461"/>
          <criteria operator="OR" comment="Architecture section">
            <criteria operator="AND" comment="Architecture dependent section">
              <criteria operator="OR" comment="Supported architectures section">
                <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
                <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
                <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
                <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
                <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
                <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
                <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
                <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
                <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
                <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
              </criteria>
              <criteria operator="OR" comment="Packages section">
                <criterion comment="chrony is earlier than 1.21z-5+etch1" test_ref="oval:org.mitre.oval:tst:25933"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7309" version="3" class="patch">
      <metadata>
        <title>DSA-2012 linux-2.6 -- privilege escalation/denial of service</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <product>linux-2.6</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2010/dsa-2012" ref_id="DSA-2012"/>
        <description>Two vulnerabilities have been discovered in the Linux kernel that may lead to a denial of service or privilege escalation. The Common Vulnerabilities and Exposures project identifies the following problems: Philipp Reisner reported an issue in the connector subsystem which allows unprivileged users to send netlink packets. This allows local users to manipulate settings for uvesafb devices which are normally reserved for privileged users. Jermome Marchand reported an issue in the futex subsystem that allows a local user to force an invalid futex state which results in a denial of service . This update also includes fixes for regressions introduced by previous updates. See the referenced Debian bug pages for details.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-05-24T19:02:34-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2010-05-26T13:27:46.142-04:00">DRAFT</status_change>
            <status_change date="2010-06-14T04:00:46.674-04:00">INTERIM</status_change>
            <status_change date="2010-06-29T11:49:42.734-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
        <criteria operator="OR" comment="Architecture section">
          <criteria operator="AND" comment="Architecture independent section">
            <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
            <criteria operator="OR" comment="Packages section">
              <criterion comment="linux-patch-debian-2.6.26 is earlier than 2.6.26-21lenny4" test_ref="oval:org.mitre.oval:tst:25384"/>
              <criterion comment="linux-support-2.6.26-2 is earlier than 2.6.26-21lenny4" test_ref="oval:org.mitre.oval:tst:25305"/>
              <criterion comment="linux-doc-2.6.26 is earlier than 2.6.26-21lenny4" test_ref="oval:org.mitre.oval:tst:25117"/>
              <criterion comment="linux-tree-2.6.26 is earlier than 2.6.26-21lenny4" test_ref="oval:org.mitre.oval:tst:25490"/>
              <criterion comment="linux-source-2.6.26 is earlier than 2.6.26-21lenny4" test_ref="oval:org.mitre.oval:tst:25471"/>
              <criterion comment="linux-manual-2.6.26 is earlier than 2.6.26-21lenny4" test_ref="oval:org.mitre.oval:tst:25713"/>
            </criteria>
          </criteria>
          <criteria operator="AND" comment="Architecture dependent section">
            <criteria operator="OR" comment="Supported architectures section">
              <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
            </criteria>
            <criteria operator="OR" comment="Packages section">
              <criterion comment="linux-headers-2.6.26-2-all is earlier than 2.6.26-21lenny4" test_ref="oval:org.mitre.oval:tst:25091"/>
              <criterion comment="linux-image-2.6.26-2-vserver-s390x is earlier than 2.6.26-21lenny4" test_ref="oval:org.mitre.oval:tst:25394"/>
              <criterion comment="linux-image-2.6.26-2-s390 is earlier than 2.6.26-21lenny4" test_ref="oval:org.mitre.oval:tst:25608"/>
              <criterion comment="linux-headers-2.6.26-2-s390 is earlier than 2.6.26-21lenny4" test_ref="oval:org.mitre.oval:tst:25589"/>
              <criterion comment="linux-image-2.6.26-2-s390-tape is earlier than 2.6.26-21lenny4" test_ref="oval:org.mitre.oval:tst:25666"/>
              <criterion comment="linux-headers-2.6.26-2-all-s390 is earlier than 2.6.26-21lenny4" test_ref="oval:org.mitre.oval:tst:25370"/>
              <criterion comment="linux-headers-2.6.26-2-vserver-s390x is earlier than 2.6.26-21lenny4" test_ref="oval:org.mitre.oval:tst:25432"/>
              <criterion comment="linux-headers-2.6.26-2-common-vserver is earlier than 2.6.26-21lenny4" test_ref="oval:org.mitre.oval:tst:25754"/>
              <criterion comment="linux-libc-dev is earlier than 2.6.26-21lenny4" test_ref="oval:org.mitre.oval:tst:25301"/>
              <criterion comment="linux-image-2.6.26-2-s390x is earlier than 2.6.26-21lenny4" test_ref="oval:org.mitre.oval:tst:25607"/>
              <criterion comment="linux-headers-2.6.26-2-common is earlier than 2.6.26-21lenny4" test_ref="oval:org.mitre.oval:tst:25764"/>
              <criterion comment="linux-headers-2.6.26-2-s390x is earlier than 2.6.26-21lenny4" test_ref="oval:org.mitre.oval:tst:25465"/>
            </criteria>
          </criteria>
          <criteria operator="AND" comment="Architecture dependent section">
            <criteria operator="OR" comment="Supported architectures section">
              <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
            </criteria>
            <criteria operator="OR" comment="Packages section">
              <criterion comment="xen-linux-system-2.6.26-2-xen-amd64 is earlier than 2.6.26-21lenny4" test_ref="oval:org.mitre.oval:tst:24905"/>
              <criterion comment="linux-headers-2.6.26-2-all is earlier than 2.6.26-21lenny4" test_ref="oval:org.mitre.oval:tst:25684"/>
              <criterion comment="linux-modules-2.6.26-2-xen-amd64 is earlier than 2.6.26-21lenny4" test_ref="oval:org.mitre.oval:tst:25405"/>
              <criterion comment="linux-headers-2.6.26-2-openvz-amd64 is earlier than 2.6.26-21lenny4" test_ref="oval:org.mitre.oval:tst:25625"/>
              <criterion comment="linux-headers-2.6.26-2-common-vserver is earlier than 2.6.26-21lenny4" test_ref="oval:org.mitre.oval:tst:25751"/>
              <criterion comment="linux-image-2.6.26-2-openvz-amd64 is earlier than 2.6.26-21lenny4" test_ref="oval:org.mitre.oval:tst:24867"/>
              <criterion comment="linux-libc-dev is earlier than 2.6.26-21lenny4" test_ref="oval:org.mitre.oval:tst:25331"/>
              <criterion comment="linux-headers-2.6.26-2-common-openvz is earlier than 2.6.26-21lenny4" test_ref="oval:org.mitre.oval:tst:25172"/>
              <criterion comment="linux-image-2.6.26-2-vserver-amd64 is earlier than 2.6.26-21lenny4" test_ref="oval:org.mitre.oval:tst:25300"/>
              <criterion comment="linux-headers-2.6.26-2-all-amd64 is earlier than 2.6.26-21lenny4" test_ref="oval:org.mitre.oval:tst:25609"/>
              <criterion comment="linux-image-2.6.26-2-xen-amd64 is earlier than 2.6.26-21lenny4" test_ref="oval:org.mitre.oval:tst:25701"/>
              <criterion comment="linux-headers-2.6.26-2-common-xen is earlier than 2.6.26-21lenny4" test_ref="oval:org.mitre.oval:tst:25527"/>
              <criterion comment="linux-image-2.6.26-2-amd64 is earlier than 2.6.26-21lenny4" test_ref="oval:org.mitre.oval:tst:25661"/>
              <criterion comment="linux-headers-2.6.26-2-xen-amd64 is earlier than 2.6.26-21lenny4" test_ref="oval:org.mitre.oval:tst:25357"/>
              <criterion comment="linux-headers-2.6.26-2-amd64 is earlier than 2.6.26-21lenny4" test_ref="oval:org.mitre.oval:tst:25724"/>
              <criterion comment="linux-headers-2.6.26-2-common is earlier than 2.6.26-21lenny4" test_ref="oval:org.mitre.oval:tst:25360"/>
              <criterion comment="linux-headers-2.6.26-2-vserver-amd64 is earlier than 2.6.26-21lenny4" test_ref="oval:org.mitre.oval:tst:25010"/>
            </criteria>
          </criteria>
          <criteria operator="AND" comment="Architecture depended section">
            <criteria operator="AND" comment="Supported platform section">
              <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
              <criteria operator="OR" comment="Packages section">
                <criterion comment="linux-headers-2.6.26-2-all is earlier than 2.6.26-21lenny4" test_ref="oval:org.mitre.oval:tst:25742"/>
                <criterion comment="linux-headers-2.6.26-2-parisc is earlier than 2.6.26-21lenny4" test_ref="oval:org.mitre.oval:tst:25799"/>
                <criterion comment="linux-image-2.6.26-2-parisc64 is earlier than 2.6.26-21lenny4" test_ref="oval:org.mitre.oval:tst:25395"/>
                <criterion comment="linux-image-2.6.26-2-parisc is earlier than 2.6.26-21lenny4" test_ref="oval:org.mitre.oval:tst:25729"/>
                <criterion comment="linux-headers-2.6.26-2-parisc-smp is earlier than 2.6.26-21lenny4" test_ref="oval:org.mitre.oval:tst:25566"/>
                <criterion comment="linux-headers-2.6.26-2-all-hppa is earlier than 2.6.26-21lenny4" test_ref="oval:org.mitre.oval:tst:25387"/>
                <criterion comment="linux-headers-2.6.26-2-parisc64 is earlier than 2.6.26-21lenny4" test_ref="oval:org.mitre.oval:tst:25440"/>
                <criterion comment="linux-headers-2.6.26-2-parisc64-smp is earlier than 2.6.26-21lenny4" test_ref="oval:org.mitre.oval:tst:25858"/>
                <criterion comment="linux-libc-dev is earlier than 2.6.26-21lenny4" test_ref="oval:org.mitre.oval:tst:25687"/>
                <criterion comment="linux-image-2.6.26-2-parisc64-smp is earlier than 2.6.26-21lenny4" test_ref="oval:org.mitre.oval:tst:25847"/>
                <criterion comment="linux-headers-2.6.26-2-common is earlier than 2.6.26-21lenny4" test_ref="oval:org.mitre.oval:tst:25797"/>
                <criterion comment="linux-image-2.6.26-2-parisc-smp is earlier than 2.6.26-21lenny4" test_ref="oval:org.mitre.oval:tst:25857"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7306" version="3" class="patch">
      <metadata>
        <title>DSA-1984 libxerces2-java -- denial of service</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <platform>Debian GNU/Linux 4.0</platform>
          <product>libxerces2-java</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2010/dsa-1984" ref_id="DSA-1984"/>
        <description>It was discovered that libxerces2-java, a validating XML parser for Java, does not properly process malformed XML files. This vulnerability could allow an attacker to cause a denial of service while parsing a malformed XML file.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-05-24T19:05:10-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2010-05-26T13:28:02.127-04:00">DRAFT</status_change>
            <status_change date="2010-06-14T04:00:46.257-04:00">INTERIM</status_change>
            <status_change date="2010-06-29T11:49:42.288-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Release section">
          <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
          <criteria operator="OR" comment="Architecture section">
            <criteria operator="AND" comment="Architecture independent section">
              <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criteria operator="OR" comment="Packages section">
                <criterion comment="libxerces2-java-doc is earlier than 2.9.1-2+lenny1" test_ref="oval:org.mitre.oval:tst:25602"/>
                <criterion comment="libxerces2-java is earlier than 2.9.1-2+lenny1" test_ref="oval:org.mitre.oval:tst:25740"/>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Architecture dependent section">
              <criteria operator="OR" comment="Supported architectures section">
                <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
                <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
                <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
                <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
                <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
                <criterion comment="Installed architecture is armel" test_ref="oval:org.mitre.oval:tst:11101"/>
                <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
                <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
                <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
              </criteria>
              <criteria operator="OR" comment="Packages section">
                <criterion comment="libxerces2-java-gcj is earlier than 2.9.1-2+lenny1" test_ref="oval:org.mitre.oval:tst:25586"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Release section">
          <extend_definition comment="Debian 4.0 is installed." definition_ref="oval:org.mitre.oval:def:6461"/>
          <criteria operator="OR" comment="Architecture section">
            <criteria operator="AND" comment="Architecture independent section">
              <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criterion comment="libxerces2-java is earlier than 2.8.1-1+etch1" test_ref="oval:org.mitre.oval:tst:25784"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:7296" class="patch">
      <metadata>
        <title>DSA-1778 mahara -- insufficient input sanitization</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <product>mahara</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2009/dsa-1778" ref_id="DSA-1778"/>
        <description>It was discovered that mahara, an electronic portfolio, weblog, and resume builder, is prone to cross-site scripting (XSS) attacks because of missing input sanitization of the introduction text field in user profiles and any text field in a user view. The oldstable distribution (etch) does not contain mahara.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:10-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T07:58:26.868-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:00:35.932-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:00:23.213-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Release section" operator="AND">
        <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
        <criteria comment="Architecture section" operator="OR">
          <criteria comment="Architecture independent section" operator="AND">
            <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
            <criteria comment="Packages section" operator="OR">
              <criterion comment="mahara-apache2 is earlier than 1.0.4-4+lenny2" test_ref="oval:org.mitre.oval:tst:19035"/>
              <criterion comment="mahara is earlier than 1.0.4-4+lenny2" test_ref="oval:org.mitre.oval:tst:19131"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7293" version="3" class="patch">
      <metadata>
        <title>DSA-2015 drbd8 -- privilege escalation</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <product>drbd8</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2010/dsa-2015" ref_id="DSA-2015"/>
        <description>A local vulnerability has been discovered in drbd8. Philipp Reisner fixed an issue in the drbd kernel module that allows local users to send netlink packets to perform actions that should be restricted to users with CAP_SYS_ADMIN privileges. This is a similar issue to those described by CVE-2009-3725. This update also fixes an ABI compatibility issue which was introduced by linux-2.6 . The prebuilt drbd module packages listed in this advisory require a linux-image package version 2.6.26-21lenny3 or greater.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-05-24T18:50:13-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2010-05-26T13:27:31.804-04:00">DRAFT</status_change>
            <status_change date="2010-06-14T04:00:42.744-04:00">INTERIM</status_change>
            <status_change date="2010-06-29T11:49:38.207-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
        <criteria operator="OR" comment="Architecture section">
          <criteria operator="AND" comment="Architecture independent section">
            <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
            <criterion comment="drbd8-source is earlier than 8.0.14-2+lenny1" test_ref="oval:org.mitre.oval:tst:24337"/>
          </criteria>
          <criteria operator="AND" comment="Architecture dependent section">
            <criteria operator="OR" comment="Supported architectures section">
              <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
            </criteria>
            <criteria operator="OR" comment="Packages section">
              <criterion comment="redhat-cluster-modules-2.6-s390x is earlier than 2.6.26-6+lenny3" test_ref="oval:org.mitre.oval:tst:23806"/>
              <criterion comment="nilfs2-modules-2.6.26-2-s390 is earlier than 2.6.26+2.0.4-6+lenny3" test_ref="oval:org.mitre.oval:tst:24476"/>
              <criterion comment="iscsitarget-modules-2.6.26-2-s390 is earlier than 2.6.26+0.4.16+svn162-6+lenny3" test_ref="oval:org.mitre.oval:tst:24414"/>
              <criterion comment="iscsitarget-modules-2.6-vserver-s390x is earlier than 2.6.26-6+lenny3" test_ref="oval:org.mitre.oval:tst:23593"/>
              <criterion comment="redhat-cluster-modules-2.6.26-2-vserver-s390x is earlier than 2.6.26+2.20081102-6+lenny3" test_ref="oval:org.mitre.oval:tst:24171"/>
              <criterion comment="lzma-modules-2.6-s390 is earlier than 2.6.26-6+lenny3" test_ref="oval:org.mitre.oval:tst:24362"/>
              <criterion comment="redhat-cluster-modules-2.6-s390 is earlier than 2.6.26-6+lenny3" test_ref="oval:org.mitre.oval:tst:24462"/>
              <criterion comment="iscsitarget-modules-2.6.26-2-vserver-s390x is earlier than 2.6.26+0.4.16+svn162-6+lenny3" test_ref="oval:org.mitre.oval:tst:24358"/>
              <criterion comment="redhat-cluster-modules-2.6.26-2-s390 is earlier than 2.6.26+2.20081102-6+lenny3" test_ref="oval:org.mitre.oval:tst:24433"/>
              <criterion comment="aufs-modules-2.6.26-2-s390x is earlier than 2.6.26+0+20080719-6+lenny3" test_ref="oval:org.mitre.oval:tst:23555"/>
              <criterion comment="redhat-cluster-modules-2.6-vserver-s390x is earlier than 2.6.26-6+lenny3" test_ref="oval:org.mitre.oval:tst:23948"/>
              <criterion comment="aufs-modules-2.6.26-2-vserver-s390x is earlier than 2.6.26+0+20080719-6+lenny3" test_ref="oval:org.mitre.oval:tst:23991"/>
              <criterion comment="nilfs2-modules-2.6.26-2-vserver-s390x is earlier than 2.6.26+2.0.4-6+lenny3" test_ref="oval:org.mitre.oval:tst:24387"/>
              <criterion comment="aufs-modules-2.6.26-2-s390 is earlier than 2.6.26+0+20080719-6+lenny3" test_ref="oval:org.mitre.oval:tst:24472"/>
              <criterion comment="lzma-modules-2.6.26-2-vserver-s390x is earlier than 2.6.26+4.43-6+lenny3" test_ref="oval:org.mitre.oval:tst:24283"/>
              <criterion comment="nilfs2-modules-2.6-s390x is earlier than 2.6.26-6+lenny3" test_ref="oval:org.mitre.oval:tst:24426"/>
              <criterion comment="loop-aes-modules-2.6-s390x is earlier than 2.6.26-6+lenny3" test_ref="oval:org.mitre.oval:tst:24540"/>
              <criterion comment="redhat-cluster-modules-2.6.26-2-s390x is earlier than 2.6.26+2.20081102-6+lenny3" test_ref="oval:org.mitre.oval:tst:24104"/>
              <criterion comment="aufs-modules-2.6-s390 is earlier than 2.6.26-6+lenny3" test_ref="oval:org.mitre.oval:tst:24198"/>
              <criterion comment="iscsitarget-modules-2.6.26-2-s390x is earlier than 2.6.26+0.4.16+svn162-6+lenny3" test_ref="oval:org.mitre.oval:tst:24220"/>
              <criterion comment="nilfs2-modules-2.6.26-2-s390x is earlier than 2.6.26+2.0.4-6+lenny3" test_ref="oval:org.mitre.oval:tst:24195"/>
              <criterion comment="iscsitarget-modules-2.6-s390x is earlier than 2.6.26-6+lenny3" test_ref="oval:org.mitre.oval:tst:24203"/>
              <criterion comment="loop-aes-modules-2.6-s390 is earlier than 2.6.26-6+lenny3" test_ref="oval:org.mitre.oval:tst:24525"/>
              <criterion comment="aufs-modules-2.6-vserver-s390x is earlier than 2.6.26-6+lenny3" test_ref="oval:org.mitre.oval:tst:23941"/>
              <criterion comment="squashfs-modules-2.6.26-2-vserver-s390x is earlier than 2.6.26+3.3-6+lenny3" test_ref="oval:org.mitre.oval:tst:24536"/>
              <criterion comment="drbd8-modules-2.6.26-2-s390 is earlier than 2.6.26+8.0.14-6+lenny3" test_ref="oval:org.mitre.oval:tst:24208"/>
              <criterion comment="loop-aes-modules-2.6.26-2-s390x is earlier than 2.6.26+3.2c-6+lenny3" test_ref="oval:org.mitre.oval:tst:24145"/>
              <criterion comment="nilfs2-modules-2.6-s390 is earlier than 2.6.26-6+lenny3" test_ref="oval:org.mitre.oval:tst:23578"/>
              <criterion comment="lzma-modules-2.6.26-2-s390x is earlier than 2.6.26+4.43-6+lenny3" test_ref="oval:org.mitre.oval:tst:24391"/>
              <criterion comment="loop-aes-modules-2.6.26-2-vserver-s390x is earlier than 2.6.26+3.2c-6+lenny3" test_ref="oval:org.mitre.oval:tst:24547"/>
              <criterion comment="drbd8-modules-2.6-s390 is earlier than 2.6.26-6+lenny3" test_ref="oval:org.mitre.oval:tst:24122"/>
              <criterion comment="aufs-modules-2.6-s390x is earlier than 2.6.26-6+lenny3" test_ref="oval:org.mitre.oval:tst:24459"/>
              <criterion comment="squashfs-modules-2.6.26-2-s390x is earlier than 2.6.26+3.3-6+lenny3" test_ref="oval:org.mitre.oval:tst:24067"/>
              <criterion comment="drbd8-modules-2.6-vserver-s390x is earlier than 2.6.26-6+lenny3" test_ref="oval:org.mitre.oval:tst:23936"/>
              <criterion comment="squashfs-modules-2.6-vserver-s390x is earlier than 2.6.26-6+lenny3" test_ref="oval:org.mitre.oval:tst:24325"/>
              <criterion comment="nilfs2-modules-2.6-vserver-s390x is earlier than 2.6.26-6+lenny3" test_ref="oval:org.mitre.oval:tst:24402"/>
              <criterion comment="drbd8-modules-2.6-s390x is earlier than 2.6.26-6+lenny3" test_ref="oval:org.mitre.oval:tst:24040"/>
              <criterion comment="drbd8-modules-2.6.26-2-vserver-s390x is earlier than 2.6.26+8.0.14-6+lenny3" test_ref="oval:org.mitre.oval:tst:24383"/>
              <criterion comment="iscsitarget-modules-2.6-s390 is earlier than 2.6.26-6+lenny3" test_ref="oval:org.mitre.oval:tst:24035"/>
              <criterion comment="squashfs-modules-2.6-s390 is earlier than 2.6.26-6+lenny3" test_ref="oval:org.mitre.oval:tst:24507"/>
              <criterion comment="loop-aes-modules-2.6-vserver-s390x is earlier than 2.6.26-6+lenny3" test_ref="oval:org.mitre.oval:tst:24329"/>
              <criterion comment="drbd8-modules-2.6.26-2-s390x is earlier than 2.6.26+8.0.14-6+lenny3" test_ref="oval:org.mitre.oval:tst:24447"/>
              <criterion comment="lzma-modules-2.6-vserver-s390x is earlier than 2.6.26-6+lenny3" test_ref="oval:org.mitre.oval:tst:24496"/>
              <criterion comment="squashfs-modules-2.6.26-2-s390 is earlier than 2.6.26+3.3-6+lenny3" test_ref="oval:org.mitre.oval:tst:24482"/>
              <criterion comment="drbd8-utils is earlier than 8.0.14-2+lenny1" test_ref="oval:org.mitre.oval:tst:24163"/>
              <criterion comment="loop-aes-modules-2.6.26-2-s390 is earlier than 2.6.26+3.2c-6+lenny3" test_ref="oval:org.mitre.oval:tst:24099"/>
              <criterion comment="lzma-modules-2.6-s390x is earlier than 2.6.26-6+lenny3" test_ref="oval:org.mitre.oval:tst:23989"/>
              <criterion comment="squashfs-modules-2.6-s390x is earlier than 2.6.26-6+lenny3" test_ref="oval:org.mitre.oval:tst:24374"/>
              <criterion comment="lzma-modules-2.6.26-2-s390 is earlier than 2.6.26+4.43-6+lenny3" test_ref="oval:org.mitre.oval:tst:23558"/>
            </criteria>
          </criteria>
          <criteria operator="AND" comment="Architecture dependent section">
            <criteria operator="OR" comment="Supported architectures section">
              <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
            </criteria>
            <criteria operator="OR" comment="Packages section">
              <criterion comment="atl2-modules-2.6.26-2-amd64 is earlier than 2.6.26+2.0.5-6+lenny3" test_ref="oval:org.mitre.oval:tst:24428"/>
              <criterion comment="tp-smapi-modules-2.6.26-2-amd64 is earlier than 2.6.26+0.37-6+lenny3" test_ref="oval:org.mitre.oval:tst:24273"/>
              <criterion comment="et131x-modules-2.6.26-2-openvz-amd64 is earlier than 2.6.26+1.2.3-2-6+lenny3" test_ref="oval:org.mitre.oval:tst:24464"/>
              <criterion comment="gspca-modules-2.6-openvz-amd64 is earlier than 2.6.26-6+lenny3" test_ref="oval:org.mitre.oval:tst:24118"/>
              <criterion comment="iscsitarget-modules-2.6.26-2-amd64 is earlier than 2.6.26+0.4.16+svn162-6+lenny3" test_ref="oval:org.mitre.oval:tst:24453"/>
              <criterion comment="squashfs-modules-2.6.26-2-vserver-amd64 is earlier than 2.6.26+3.3-6+lenny3" test_ref="oval:org.mitre.oval:tst:24543"/>
              <criterion comment="atl2-modules-2.6.26-2-openvz-amd64 is earlier than 2.6.26+2.0.5-6+lenny3" test_ref="oval:org.mitre.oval:tst:24139"/>
              <criterion comment="atl2-modules-2.6.26-2-vserver-amd64 is earlier than 2.6.26+2.0.5-6+lenny3" test_ref="oval:org.mitre.oval:tst:24404"/>
              <criterion comment="iscsitarget-modules-2.6-xen-amd64 is earlier than 2.6.26-6+lenny3" test_ref="oval:org.mitre.oval:tst:24515"/>
              <criterion comment="nilfs2-modules-2.6-openvz-amd64 is earlier than 2.6.26-6+lenny3" test_ref="oval:org.mitre.oval:tst:23962"/>
              <criterion comment="drbd8-modules-2.6-openvz-amd64 is earlier than 2.6.26-6+lenny3" test_ref="oval:org.mitre.oval:tst:24477"/>
              <criterion comment="virtualbox-ose-modules-2.6-amd64 is earlier than 2.6.26-6+lenny3" test_ref="oval:org.mitre.oval:tst:23910"/>
              <criterion comment="speakup-modules-2.6.26-2-vserver-amd64 is earlier than 2.6.26+3.0.3+git20080724.dfsg.1-6+lenny3" test_ref="oval:org.mitre.oval:tst:24108"/>
              <criterion comment="iscsitarget-modules-2.6-vserver-amd64 is earlier than 2.6.26-6+lenny3" test_ref="oval:org.mitre.oval:tst:24155"/>
              <criterion comment="nilfs2-modules-2.6-vserver-amd64 is earlier than 2.6.26-6+lenny3" test_ref="oval:org.mitre.oval:tst:24366"/>
              <criterion comment="lzma-modules-2.6.26-2-openvz-amd64 is earlier than 2.6.26+4.43-6+lenny3" test_ref="oval:org.mitre.oval:tst:24024"/>
              <criterion comment="tp-smapi-modules-2.6.26-2-openvz-amd64 is earlier than 2.6.26+0.37-6+lenny3" test_ref="oval:org.mitre.oval:tst:24548"/>
              <criterion comment="atl2-modules-2.6-openvz-amd64 is earlier than 2.6.26-6+lenny3" test_ref="oval:org.mitre.oval:tst:24235"/>
              <criterion comment="loop-aes-modules-2.6.26-2-xen-amd64 is earlier than 2.6.26+3.2c-6+lenny3" test_ref="oval:org.mitre.oval:tst:23890"/>
              <criterion comment="tp-smapi-modules-2.6-vserver-amd64 is earlier than 2.6.26-6+lenny3" test_ref="oval:org.mitre.oval:tst:23604"/>
              <criterion comment="aufs-modules-2.6-xen-amd64 is earlier than 2.6.26-6+lenny3" test_ref="oval:org.mitre.oval:tst:24057"/>
              <criterion comment="virtualbox-ose-modules-2.6-openvz-amd64 is earlier than 2.6.26-6+lenny3" test_ref="oval:org.mitre.oval:tst:24213"/>
              <criterion comment="speakup-modules-2.6-xen-amd64 is earlier than 2.6.26-6+lenny3" test_ref="oval:org.mitre.oval:tst:23637"/>
              <criterion comment="iscsitarget-modules-2.6.26-2-openvz-amd64 is earlier than 2.6.26+0.4.16+svn162-6+lenny3" test_ref="oval:org.mitre.oval:tst:24439"/>
              <criterion comment="aufs-modules-2.6.26-2-openvz-amd64 is earlier than 2.6.26+0+20080719-6+lenny3" test_ref="oval:org.mitre.oval:tst:23992"/>
              <criterion comment="speakup-modules-2.6-vserver-amd64 is earlier than 2.6.26-6+lenny3" test_ref="oval:org.mitre.oval:tst:24452"/>
              <criterion comment="nilfs2-modules-2.6-amd64 is earlier than 2.6.26-6+lenny3" test_ref="oval:org.mitre.oval:tst:24276"/>
              <criterion comment="et131x-modules-2.6-amd64 is earlier than 2.6.26-6+lenny3" test_ref="oval:org.mitre.oval:tst:24489"/>
              <criterion comment="redhat-cluster-modules-2.6-xen-amd64 is earlier than 2.6.26-6+lenny3" test_ref="oval:org.mitre.oval:tst:24224"/>
              <criterion comment="speakup-modules-2.6.26-2-openvz-amd64 is earlier than 2.6.26+3.0.3+git20080724.dfsg.1-6+lenny3" test_ref="oval:org.mitre.oval:tst:24468"/>
              <criterion comment="drbd8-modules-2.6.26-2-amd64 is earlier than 2.6.26+8.0.14-6+lenny3" test_ref="oval:org.mitre.oval:tst:24527"/>
              <criterion comment="nilfs2-modules-2.6.26-2-vserver-amd64 is earlier than 2.6.26+2.0.4-6+lenny3" test_ref="oval:org.mitre.oval:tst:23873"/>
              <criterion comment="drbd8-modules-2.6.26-2-vserver-amd64 is earlier than 2.6.26+8.0.14-6+lenny3" test_ref="oval:org.mitre.oval:tst:24578"/>
              <criterion comment="lzma-modules-2.6.26-2-vserver-amd64 is earlier than 2.6.26+4.43-6+lenny3" test_ref="oval:org.mitre.oval:tst:24498"/>
              <criterion comment="iscsitarget-modules-2.6-openvz-amd64 is earlier than 2.6.26-6+lenny3" test_ref="oval:org.mitre.oval:tst:24234"/>
              <criterion comment="nilfs2-modules-2.6.26-2-amd64 is earlier than 2.6.26+2.0.4-6+lenny3" test_ref="oval:org.mitre.oval:tst:24170"/>
              <criterion comment="redhat-cluster-modules-2.6.26-2-xen-amd64 is earlier than 2.6.26+2.20081102-6+lenny3" test_ref="oval:org.mitre.oval:tst:24475"/>
              <criterion comment="iscsitarget-modules-2.6.26-2-xen-amd64 is earlier than 2.6.26+0.4.16+svn162-6+lenny3" test_ref="oval:org.mitre.oval:tst:24438"/>
              <criterion comment="loop-aes-modules-2.6-amd64 is earlier than 2.6.26-6+lenny3" test_ref="oval:org.mitre.oval:tst:24522"/>
              <criterion comment="nilfs2-modules-2.6.26-2-xen-amd64 is earlier than 2.6.26+2.0.4-6+lenny3" test_ref="oval:org.mitre.oval:tst:24227"/>
              <criterion comment="gspca-modules-2.6-vserver-amd64 is earlier than 2.6.26-6+lenny3" test_ref="oval:org.mitre.oval:tst:24306"/>
              <criterion comment="redhat-cluster-modules-2.6.26-2-vserver-amd64 is earlier than 2.6.26+2.20081102-6+lenny3" test_ref="oval:org.mitre.oval:tst:24469"/>
              <criterion comment="atl2-modules-2.6-vserver-amd64 is earlier than 2.6.26-6+lenny3" test_ref="oval:org.mitre.oval:tst:24281"/>
              <criterion comment="redhat-cluster-modules-2.6-amd64 is earlier than 2.6.26-6+lenny3" test_ref="oval:org.mitre.oval:tst:24408"/>
              <criterion comment="speakup-modules-2.6.26-2-amd64 is earlier than 2.6.26+3.0.3+git20080724.dfsg.1-6+lenny3" test_ref="oval:org.mitre.oval:tst:24423"/>
              <criterion comment="squashfs-modules-2.6-amd64 is earlier than 2.6.26-6+lenny3" test_ref="oval:org.mitre.oval:tst:24513"/>
              <criterion comment="nilfs2-modules-2.6-xen-amd64 is earlier than 2.6.26-6+lenny3" test_ref="oval:org.mitre.oval:tst:24269"/>
              <criterion comment="lzma-modules-2.6.26-2-amd64 is earlier than 2.6.26+4.43-6+lenny3" test_ref="oval:org.mitre.oval:tst:24488"/>
              <criterion comment="gspca-modules-2.6.26-2-amd64 is earlier than 2.6.26+01.00.20-6+lenny3" test_ref="oval:org.mitre.oval:tst:24029"/>
              <criterion comment="virtualbox-ose-modules-2.6-vserver-amd64 is earlier than 2.6.26-6+lenny3" test_ref="oval:org.mitre.oval:tst:24158"/>
              <criterion comment="virtualbox-ose-modules-2.6.26-2-amd64 is earlier than 2.6.26+1.6.6-dfsg-6+lenny3" test_ref="oval:org.mitre.oval:tst:24478"/>
              <criterion comment="loop-aes-modules-2.6-vserver-amd64 is earlier than 2.6.26-6+lenny3" test_ref="oval:org.mitre.oval:tst:24451"/>
              <criterion comment="et131x-modules-2.6-openvz-amd64 is earlier than 2.6.26-6+lenny3" test_ref="oval:org.mitre.oval:tst:24308"/>
              <criterion comment="iscsitarget-modules-2.6-amd64 is earlier than 2.6.26-6+lenny3" test_ref="oval:org.mitre.oval:tst:24427"/>
              <criterion comment="lzma-modules-2.6-openvz-amd64 is earlier than 2.6.26-6+lenny3" test_ref="oval:org.mitre.oval:tst:24392"/>
              <criterion comment="squashfs-modules-2.6-openvz-amd64 is earlier than 2.6.26-6+lenny3" test_ref="oval:org.mitre.oval:tst:24176"/>
              <criterion comment="aufs-modules-2.6-openvz-amd64 is earlier than 2.6.26-6+lenny3" test_ref="oval:org.mitre.oval:tst:24569"/>
              <criterion comment="speakup-modules-2.6-openvz-amd64 is earlier than 2.6.26-6+lenny3" test_ref="oval:org.mitre.oval:tst:24531"/>
              <criterion comment="loop-aes-modules-2.6.26-2-vserver-amd64 is earlier than 2.6.26+3.2c-6+lenny3" test_ref="oval:org.mitre.oval:tst:24193"/>
              <criterion comment="aufs-modules-2.6-amd64 is earlier than 2.6.26-6+lenny3" test_ref="oval:org.mitre.oval:tst:24153"/>
              <criterion comment="drbd8-modules-2.6-amd64 is earlier than 2.6.26-6+lenny3" test_ref="oval:org.mitre.oval:tst:24440"/>
              <criterion comment="speakup-modules-2.6-amd64 is earlier than 2.6.26-6+lenny3" test_ref="oval:org.mitre.oval:tst:24572"/>
              <criterion comment="nilfs2-modules-2.6.26-2-openvz-amd64 is earlier than 2.6.26+2.0.4-6+lenny3" test_ref="oval:org.mitre.oval:tst:24185"/>
              <criterion comment="squashfs-modules-2.6-xen-amd64 is earlier than 2.6.26-6+lenny3" test_ref="oval:org.mitre.oval:tst:24553"/>
              <criterion comment="aufs-modules-2.6.26-2-amd64 is earlier than 2.6.26+0+20080719-6+lenny3" test_ref="oval:org.mitre.oval:tst:24526"/>
              <criterion comment="et131x-modules-2.6.26-2-amd64 is earlier than 2.6.26+1.2.3-2-6+lenny3" test_ref="oval:org.mitre.oval:tst:23681"/>
              <criterion comment="drbd8-modules-2.6.26-2-xen-amd64 is earlier than 2.6.26+8.0.14-6+lenny3" test_ref="oval:org.mitre.oval:tst:24328"/>
              <criterion comment="speakup-modules-2.6.26-2-xen-amd64 is earlier than 2.6.26+3.0.3+git20080724.dfsg.1-6+lenny3" test_ref="oval:org.mitre.oval:tst:24633"/>
              <criterion comment="tp-smapi-modules-2.6-amd64 is earlier than 2.6.26-6+lenny3" test_ref="oval:org.mitre.oval:tst:23698"/>
              <criterion comment="squashfs-modules-2.6-vserver-amd64 is earlier than 2.6.26-6+lenny3" test_ref="oval:org.mitre.oval:tst:24351"/>
              <criterion comment="loop-aes-modules-2.6-xen-amd64 is earlier than 2.6.26-6+lenny3" test_ref="oval:org.mitre.oval:tst:24434"/>
              <criterion comment="tp-smapi-modules-2.6.26-2-xen-amd64 is earlier than 2.6.26+0.37-6+lenny3" test_ref="oval:org.mitre.oval:tst:24626"/>
              <criterion comment="lzma-modules-2.6-amd64 is earlier than 2.6.26-6+lenny3" test_ref="oval:org.mitre.oval:tst:24425"/>
              <criterion comment="tp-smapi-modules-2.6-openvz-amd64 is earlier than 2.6.26-6+lenny3" test_ref="oval:org.mitre.oval:tst:24293"/>
              <criterion comment="drbd8-modules-2.6-xen-amd64 is earlier than 2.6.26-6+lenny3" test_ref="oval:org.mitre.oval:tst:24296"/>
              <criterion comment="atl2-modules-2.6-amd64 is earlier than 2.6.26-6+lenny3" test_ref="oval:org.mitre.oval:tst:24403"/>
              <criterion comment="squashfs-modules-2.6.26-2-openvz-amd64 is earlier than 2.6.26+3.3-6+lenny3" test_ref="oval:org.mitre.oval:tst:24563"/>
              <criterion comment="aufs-modules-2.6-vserver-amd64 is earlier than 2.6.26-6+lenny3" test_ref="oval:org.mitre.oval:tst:24580"/>
              <criterion comment="loop-aes-modules-2.6-openvz-amd64 is earlier than 2.6.26-6+lenny3" test_ref="oval:org.mitre.oval:tst:24356"/>
              <criterion comment="gspca-modules-2.6-amd64 is earlier than 2.6.26-6+lenny3" test_ref="oval:org.mitre.oval:tst:24589"/>
              <criterion comment="redhat-cluster-modules-2.6.26-2-openvz-amd64 is earlier than 2.6.26+2.20081102-6+lenny3" test_ref="oval:org.mitre.oval:tst:24270"/>
              <criterion comment="loop-aes-modules-2.6.26-2-amd64 is earlier than 2.6.26+3.2c-6+lenny3" test_ref="oval:org.mitre.oval:tst:24278"/>
              <criterion comment="drbd8-modules-2.6-vserver-amd64 is earlier than 2.6.26-6+lenny3" test_ref="oval:org.mitre.oval:tst:24609"/>
              <criterion comment="lzma-modules-2.6-vserver-amd64 is earlier than 2.6.26-6+lenny3" test_ref="oval:org.mitre.oval:tst:24343"/>
              <criterion comment="gspca-modules-2.6.26-2-openvz-amd64 is earlier than 2.6.26+01.00.20-6+lenny3" test_ref="oval:org.mitre.oval:tst:24500"/>
              <criterion comment="iscsitarget-modules-2.6.26-2-vserver-amd64 is earlier than 2.6.26+0.4.16+svn162-6+lenny3" test_ref="oval:org.mitre.oval:tst:24628"/>
              <criterion comment="lzma-modules-2.6.26-2-xen-amd64 is earlier than 2.6.26+4.43-6+lenny3" test_ref="oval:org.mitre.oval:tst:23747"/>
              <criterion comment="redhat-cluster-modules-2.6.26-2-amd64 is earlier than 2.6.26+2.20081102-6+lenny3" test_ref="oval:org.mitre.oval:tst:24517"/>
              <criterion comment="virtualbox-ose-modules-2.6.26-2-openvz-amd64 is earlier than 2.6.26+1.6.6-dfsg-6+lenny3" test_ref="oval:org.mitre.oval:tst:24172"/>
              <criterion comment="squashfs-modules-2.6.26-2-amd64 is earlier than 2.6.26+3.3-6+lenny3" test_ref="oval:org.mitre.oval:tst:24541"/>
              <criterion comment="tp-smapi-modules-2.6.26-2-vserver-amd64 is earlier than 2.6.26+0.37-6+lenny3" test_ref="oval:org.mitre.oval:tst:24241"/>
              <criterion comment="drbd8-modules-2.6.26-2-openvz-amd64 is earlier than 2.6.26+8.0.14-6+lenny3" test_ref="oval:org.mitre.oval:tst:24076"/>
              <criterion comment="lzma-modules-2.6-xen-amd64 is earlier than 2.6.26-6+lenny3" test_ref="oval:org.mitre.oval:tst:24664"/>
              <criterion comment="redhat-cluster-modules-2.6-openvz-amd64 is earlier than 2.6.26-6+lenny3" test_ref="oval:org.mitre.oval:tst:24614"/>
              <criterion comment="loop-aes-modules-2.6.26-2-openvz-amd64 is earlier than 2.6.26+3.2c-6+lenny3" test_ref="oval:org.mitre.oval:tst:24638"/>
              <criterion comment="aufs-modules-2.6.26-2-vserver-amd64 is earlier than 2.6.26+0+20080719-6+lenny3" test_ref="oval:org.mitre.oval:tst:24483"/>
              <criterion comment="gspca-modules-2.6.26-2-vserver-amd64 is earlier than 2.6.26+01.00.20-6+lenny3" test_ref="oval:org.mitre.oval:tst:24018"/>
              <criterion comment="virtualbox-ose-modules-2.6.26-2-vserver-amd64 is earlier than 2.6.26+1.6.6-dfsg-6+lenny3" test_ref="oval:org.mitre.oval:tst:24519"/>
              <criterion comment="redhat-cluster-modules-2.6-vserver-amd64 is earlier than 2.6.26-6+lenny3" test_ref="oval:org.mitre.oval:tst:23920"/>
              <criterion comment="squashfs-modules-2.6.26-2-xen-amd64 is earlier than 2.6.26+3.3-6+lenny3" test_ref="oval:org.mitre.oval:tst:24590"/>
              <criterion comment="tp-smapi-modules-2.6-xen-amd64 is earlier than 2.6.26-6+lenny3" test_ref="oval:org.mitre.oval:tst:24359"/>
              <criterion comment="aufs-modules-2.6.26-2-xen-amd64 is earlier than 2.6.26+0+20080719-6+lenny3" test_ref="oval:org.mitre.oval:tst:24673"/>
            </criteria>
          </criteria>
          <criteria operator="AND" comment="Architecture depended section">
            <criteria operator="AND" comment="Supported platform section">
              <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
              <criteria operator="OR" comment="Packages section">
                <criterion comment="et131x-modules-2.6.26-2-parisc-smp is earlier than 2.6.26+1.2.3-2-6+lenny3" test_ref="oval:org.mitre.oval:tst:25213"/>
                <criterion comment="atl2-modules-2.6-parisc64 is earlier than 2.6.26-6+lenny3" test_ref="oval:org.mitre.oval:tst:25498"/>
                <criterion comment="redhat-cluster-modules-2.6-parisc64-smp is earlier than 2.6.26-6+lenny3" test_ref="oval:org.mitre.oval:tst:25506"/>
                <criterion comment="atl2-modules-2.6.26-2-parisc is earlier than 2.6.26+2.0.5-6+lenny3" test_ref="oval:org.mitre.oval:tst:25346"/>
                <criterion comment="lzma-modules-2.6.26-2-parisc is earlier than 2.6.26+4.43-6+lenny3" test_ref="oval:org.mitre.oval:tst:25424"/>
                <criterion comment="nilfs2-modules-2.6.26-2-parisc64-smp is earlier than 2.6.26+2.0.4-6+lenny3" test_ref="oval:org.mitre.oval:tst:24969"/>
                <criterion comment="atl2-modules-2.6.26-2-parisc64-smp is earlier than 2.6.26+2.0.5-6+lenny3" test_ref="oval:org.mitre.oval:tst:24559"/>
                <criterion comment="loop-aes-modules-2.6.26-2-parisc64 is earlier than 2.6.26+3.2c-6+lenny3" test_ref="oval:org.mitre.oval:tst:24714"/>
                <criterion comment="et131x-modules-2.6-parisc64 is earlier than 2.6.26-6+lenny3" test_ref="oval:org.mitre.oval:tst:25500"/>
                <criterion comment="redhat-cluster-modules-2.6.26-2-parisc-smp is earlier than 2.6.26+2.20081102-6+lenny3" test_ref="oval:org.mitre.oval:tst:25529"/>
                <criterion comment="atl2-modules-2.6-parisc is earlier than 2.6.26-6+lenny3" test_ref="oval:org.mitre.oval:tst:24812"/>
                <criterion comment="aufs-modules-2.6-parisc64-smp is earlier than 2.6.26-6+lenny3" test_ref="oval:org.mitre.oval:tst:25541"/>
                <criterion comment="aufs-modules-2.6-parisc64 is earlier than 2.6.26-6+lenny3" test_ref="oval:org.mitre.oval:tst:25560"/>
                <criterion comment="nilfs2-modules-2.6-parisc64 is earlier than 2.6.26-6+lenny3" test_ref="oval:org.mitre.oval:tst:24983"/>
                <criterion comment="loop-aes-modules-2.6-parisc64-smp is earlier than 2.6.26-6+lenny3" test_ref="oval:org.mitre.oval:tst:25524"/>
                <criterion comment="aufs-modules-2.6-parisc-smp is earlier than 2.6.26-6+lenny3" test_ref="oval:org.mitre.oval:tst:25201"/>
                <criterion comment="drbd8-modules-2.6-parisc64-smp is earlier than 2.6.26-6+lenny3" test_ref="oval:org.mitre.oval:tst:25250"/>
                <criterion comment="redhat-cluster-modules-2.6.26-2-parisc is earlier than 2.6.26+2.20081102-6+lenny3" test_ref="oval:org.mitre.oval:tst:25096"/>
                <criterion comment="aufs-modules-2.6-parisc is earlier than 2.6.26-6+lenny3" test_ref="oval:org.mitre.oval:tst:25413"/>
                <criterion comment="lzma-modules-2.6-parisc64 is earlier than 2.6.26-6+lenny3" test_ref="oval:org.mitre.oval:tst:24575"/>
                <criterion comment="speakup-modules-2.6.26-2-parisc64-smp is earlier than 2.6.26+3.0.3+git20080724.dfsg.1-6+lenny3" test_ref="oval:org.mitre.oval:tst:25299"/>
                <criterion comment="nilfs2-modules-2.6-parisc-smp is earlier than 2.6.26-6+lenny3" test_ref="oval:org.mitre.oval:tst:25559"/>
                <criterion comment="lzma-modules-2.6-parisc64-smp is earlier than 2.6.26-6+lenny3" test_ref="oval:org.mitre.oval:tst:25165"/>
                <criterion comment="lzma-modules-2.6.26-2-parisc64 is earlier than 2.6.26+4.43-6+lenny3" test_ref="oval:org.mitre.oval:tst:24762"/>
                <criterion comment="loop-aes-modules-2.6.26-2-parisc64-smp is earlier than 2.6.26+3.2c-6+lenny3" test_ref="oval:org.mitre.oval:tst:25198"/>
                <criterion comment="et131x-modules-2.6.26-2-parisc64 is earlier than 2.6.26+1.2.3-2-6+lenny3" test_ref="oval:org.mitre.oval:tst:24704"/>
                <criterion comment="et131x-modules-2.6-parisc-smp is earlier than 2.6.26-6+lenny3" test_ref="oval:org.mitre.oval:tst:25392"/>
                <criterion comment="aufs-modules-2.6.26-2-parisc64 is earlier than 2.6.26+0+20080719-6+lenny3" test_ref="oval:org.mitre.oval:tst:25404"/>
                <criterion comment="lzma-modules-2.6.26-2-parisc64-smp is earlier than 2.6.26+4.43-6+lenny3" test_ref="oval:org.mitre.oval:tst:25267"/>
                <criterion comment="atl2-modules-2.6-parisc-smp is earlier than 2.6.26-6+lenny3" test_ref="oval:org.mitre.oval:tst:25349"/>
                <criterion comment="drbd8-modules-2.6-parisc-smp is earlier than 2.6.26-6+lenny3" test_ref="oval:org.mitre.oval:tst:25179"/>
                <criterion comment="loop-aes-modules-2.6.26-2-parisc-smp is earlier than 2.6.26+3.2c-6+lenny3" test_ref="oval:org.mitre.oval:tst:24699"/>
                <criterion comment="atl2-modules-2.6.26-2-parisc64 is earlier than 2.6.26+2.0.5-6+lenny3" test_ref="oval:org.mitre.oval:tst:25522"/>
                <criterion comment="loop-aes-modules-2.6.26-2-parisc is earlier than 2.6.26+3.2c-6+lenny3" test_ref="oval:org.mitre.oval:tst:24769"/>
                <criterion comment="aufs-modules-2.6.26-2-parisc is earlier than 2.6.26+0+20080719-6+lenny3" test_ref="oval:org.mitre.oval:tst:25406"/>
                <criterion comment="aufs-modules-2.6.26-2-parisc-smp is earlier than 2.6.26+0+20080719-6+lenny3" test_ref="oval:org.mitre.oval:tst:25552"/>
                <criterion comment="redhat-cluster-modules-2.6-parisc is earlier than 2.6.26-6+lenny3" test_ref="oval:org.mitre.oval:tst:25407"/>
                <criterion comment="nilfs2-modules-2.6.26-2-parisc64 is earlier than 2.6.26+2.0.4-6+lenny3" test_ref="oval:org.mitre.oval:tst:25532"/>
                <criterion comment="drbd8-modules-2.6-parisc64 is earlier than 2.6.26-6+lenny3" test_ref="oval:org.mitre.oval:tst:25467"/>
                <criterion comment="redhat-cluster-modules-2.6-parisc-smp is earlier than 2.6.26-6+lenny3" test_ref="oval:org.mitre.oval:tst:25363"/>
                <criterion comment="nilfs2-modules-2.6-parisc is earlier than 2.6.26-6+lenny3" test_ref="oval:org.mitre.oval:tst:25391"/>
                <criterion comment="speakup-modules-2.6-parisc64-smp is earlier than 2.6.26-6+lenny3" test_ref="oval:org.mitre.oval:tst:25545"/>
                <criterion comment="lzma-modules-2.6.26-2-parisc-smp is earlier than 2.6.26+4.43-6+lenny3" test_ref="oval:org.mitre.oval:tst:25561"/>
                <criterion comment="redhat-cluster-modules-2.6.26-2-parisc64 is earlier than 2.6.26+2.20081102-6+lenny3" test_ref="oval:org.mitre.oval:tst:25502"/>
                <criterion comment="redhat-cluster-modules-2.6.26-2-parisc64-smp is earlier than 2.6.26+2.20081102-6+lenny3" test_ref="oval:org.mitre.oval:tst:25531"/>
                <criterion comment="atl2-modules-2.6.26-2-parisc-smp is earlier than 2.6.26+2.0.5-6+lenny3" test_ref="oval:org.mitre.oval:tst:25428"/>
                <criterion comment="speakup-modules-2.6-parisc is earlier than 2.6.26-6+lenny3" test_ref="oval:org.mitre.oval:tst:25568"/>
                <criterion comment="aufs-modules-2.6.26-2-parisc64-smp is earlier than 2.6.26+0+20080719-6+lenny3" test_ref="oval:org.mitre.oval:tst:25272"/>
                <criterion comment="nilfs2-modules-2.6.26-2-parisc is earlier than 2.6.26+2.0.4-6+lenny3" test_ref="oval:org.mitre.oval:tst:25355"/>
                <criterion comment="drbd8-modules-2.6.26-2-parisc is earlier than 2.6.26+8.0.14-6+lenny3" test_ref="oval:org.mitre.oval:tst:25398"/>
                <criterion comment="nilfs2-modules-2.6.26-2-parisc-smp is earlier than 2.6.26+2.0.4-6+lenny3" test_ref="oval:org.mitre.oval:tst:25376"/>
                <criterion comment="speakup-modules-2.6.26-2-parisc is earlier than 2.6.26+3.0.3+git20080724.dfsg.1-6+lenny3" test_ref="oval:org.mitre.oval:tst:24980"/>
                <criterion comment="drbd8-modules-2.6-parisc is earlier than 2.6.26-6+lenny3" test_ref="oval:org.mitre.oval:tst:25356"/>
                <criterion comment="speakup-modules-2.6.26-2-parisc-smp is earlier than 2.6.26+3.0.3+git20080724.dfsg.1-6+lenny3" test_ref="oval:org.mitre.oval:tst:25543"/>
                <criterion comment="drbd8-modules-2.6.26-2-parisc64 is earlier than 2.6.26+8.0.14-6+lenny3" test_ref="oval:org.mitre.oval:tst:25478"/>
                <criterion comment="loop-aes-modules-2.6-parisc-smp is earlier than 2.6.26-6+lenny3" test_ref="oval:org.mitre.oval:tst:25466"/>
                <criterion comment="lzma-modules-2.6-parisc-smp is earlier than 2.6.26-6+lenny3" test_ref="oval:org.mitre.oval:tst:25549"/>
                <criterion comment="loop-aes-modules-2.6-parisc64 is earlier than 2.6.26-6+lenny3" test_ref="oval:org.mitre.oval:tst:25448"/>
                <criterion comment="redhat-cluster-modules-2.6-parisc64 is earlier than 2.6.26-6+lenny3" test_ref="oval:org.mitre.oval:tst:24882"/>
                <criterion comment="atl2-modules-2.6-parisc64-smp is earlier than 2.6.26-6+lenny3" test_ref="oval:org.mitre.oval:tst:25037"/>
                <criterion comment="speakup-modules-2.6.26-2-parisc64 is earlier than 2.6.26+3.0.3+git20080724.dfsg.1-6+lenny3" test_ref="oval:org.mitre.oval:tst:25508"/>
                <criterion comment="drbd8-modules-2.6.26-2-parisc64-smp is earlier than 2.6.26+8.0.14-6+lenny3" test_ref="oval:org.mitre.oval:tst:25383"/>
                <criterion comment="et131x-modules-2.6-parisc64-smp is earlier than 2.6.26-6+lenny3" test_ref="oval:org.mitre.oval:tst:25464"/>
                <criterion comment="et131x-modules-2.6-parisc is earlier than 2.6.26-6+lenny3" test_ref="oval:org.mitre.oval:tst:25345"/>
                <criterion comment="et131x-modules-2.6.26-2-parisc64-smp is earlier than 2.6.26+1.2.3-2-6+lenny3" test_ref="oval:org.mitre.oval:tst:25118"/>
                <criterion comment="drbd8-modules-2.6.26-2-parisc-smp is earlier than 2.6.26+8.0.14-6+lenny3" test_ref="oval:org.mitre.oval:tst:25225"/>
                <criterion comment="speakup-modules-2.6-parisc-smp is earlier than 2.6.26-6+lenny3" test_ref="oval:org.mitre.oval:tst:25518"/>
                <criterion comment="lzma-modules-2.6-parisc is earlier than 2.6.26-6+lenny3" test_ref="oval:org.mitre.oval:tst:25557"/>
                <criterion comment="nilfs2-modules-2.6-parisc64-smp is earlier than 2.6.26-6+lenny3" test_ref="oval:org.mitre.oval:tst:25235"/>
                <criterion comment="drbd8-utils is earlier than 8.0.14-2+lenny1" test_ref="oval:org.mitre.oval:tst:25576"/>
                <criterion comment="speakup-modules-2.6-parisc64 is earlier than 2.6.26-6+lenny3" test_ref="oval:org.mitre.oval:tst:25569"/>
                <criterion comment="loop-aes-modules-2.6-parisc is earlier than 2.6.26-6+lenny3" test_ref="oval:org.mitre.oval:tst:24583"/>
                <criterion comment="et131x-modules-2.6.26-2-parisc is earlier than 2.6.26+1.2.3-2-6+lenny3" test_ref="oval:org.mitre.oval:tst:25563"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7290" version="3" class="patch">
      <metadata>
        <title>DSA-2034 phpmyadmin -- several vulnerabilities</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <product>phpmyadmin</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2010/dsa-2034" ref_id="DSA-2034"/>
        <description>Several vulnerabilities have been discovered in phpMyAdmin, a tool to administer MySQL over the web. The Common Vulnerabilities and Exposures project identifies the following problems: phpMyAdmin may create a temporary directory, if the configured directory does not exist yet, with insecure filesystem permissions. phpMyAdmin uses predictable filenames for temporary files, which may lead to a local denial of service attack or privilege escalation. The setup.php script shipped with phpMyAdmin may unserialize untrusted data, allowing for cross site request forgery.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-05-24T19:10:10-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2010-05-26T13:29:14.593-04:00">DRAFT</status_change>
            <status_change date="2010-06-14T04:00:42.461-04:00">INTERIM</status_change>
            <status_change date="2010-06-29T11:49:37.878-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
        <criteria operator="OR" comment="Architecture section">
          <criteria operator="AND" comment="Architecture independent section">
            <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
            <criterion comment="phpmyadmin is earlier than 2.11.8.1-5+lenny4" test_ref="oval:org.mitre.oval:tst:26989"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:7282" class="patch">
      <metadata>
        <title>DSA-1869 curl -- insufficient input validation</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <platform>Debian GNU/Linux 4.0</platform>
          <product>curl</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2009/dsa-1869" ref_id="DSA-1869"/>
        <description>It was discovered that curl, a client and library to get files from servers using HTTP, HTTPS or FTP, is vulnerable to the "Null Prefix Attacks Against SSL/TLS Certificates" recently published at the Blackhat conference. This allows an attacker to perform undetected man-in-the-middle attacks via a crafted ITU-T X.509 certificate with an injected null byte in the Common Name field.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:09-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T07:57:15.196-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:00:34.681-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:00:22.328-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Platform section" operator="OR">
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Architecture dependent section" operator="AND">
              <criteria comment="Supported architectures section" operator="OR">
                <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
                <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
                <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
                <criterion comment="Installed architecture is armel" test_ref="oval:org.mitre.oval:tst:11101"/>
                <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
                <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
                <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
                <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
                <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
              </criteria>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="libcurl4-gnutls-dev DPKG is earlier than 7.18.2-8lenny3" test_ref="oval:org.mitre.oval:tst:17761"/>
                <criterion comment="libcurl4-openssl-dev DPKG is earlier than 7.18.2-8lenny3" test_ref="oval:org.mitre.oval:tst:18407"/>
                <criterion comment="libcurl3-gnutls DPKG is earlier than 7.18.2-8lenny3" test_ref="oval:org.mitre.oval:tst:17941"/>
                <criterion comment="libcurl3-dbg DPKG is earlier than 7.18.2-8lenny3" test_ref="oval:org.mitre.oval:tst:18119"/>
                <criterion comment="libcurl3 DPKG is earlier than 7.18.2-8lenny3" test_ref="oval:org.mitre.oval:tst:17645"/>
                <criterion comment="curl DPKG is earlier than 7.18.2-8lenny3" test_ref="oval:org.mitre.oval:tst:18344"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 4.0 is installed" definition_ref="oval:org.mitre.oval:def:6461"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Architecture independent section" operator="AND">
              <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criterion comment="libcurl3-dev is earlier than 7.15.5-1etch3" test_ref="oval:org.mitre.oval:tst:18307"/>
            </criteria>
            <criteria comment="Architecture dependent section" operator="AND">
              <criteria comment="Supported architectures section" operator="OR">
                <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
                <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
                <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
                <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
                <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
                <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
                <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
                <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
                <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
              </criteria>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="libcurl3-gnutls DPKG is earlier than 7.15.5-1etch3" test_ref="oval:org.mitre.oval:tst:18356"/>
                <criterion comment="libcurl3-dbg DPKG is earlier than 7.15.5-1etch3" test_ref="oval:org.mitre.oval:tst:18400"/>
                <criterion comment="libcurl3-gnutls-dev DPKG is earlier than 7.15.5-1etch3" test_ref="oval:org.mitre.oval:tst:17725"/>
                <criterion comment="libcurl3 DPKG is earlier than 7.15.5-1etch3" test_ref="oval:org.mitre.oval:tst:18452"/>
                <criterion comment="curl DPKG is earlier than 7.15.5-1etch3" test_ref="oval:org.mitre.oval:tst:18124"/>
                <criterion comment="libcurl3-openssl-dev DPKG is earlier than 7.15.5-1etch3" test_ref="oval:org.mitre.oval:tst:18322"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:7270" class="patch">
      <metadata>
        <title>DSA-1816 apache2 -- insufficient security check</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <platform>Debian GNU/Linux 4.0</platform>
          <product>apache2</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2009/dsa-1816" ref_id="DSA-1816"/>
        <description>It was discovered that the Apache web server did not properly handle the "Options=" parameter to the AllowOverride directive: In the stable distribution (lenny), local users could (via .htaccess) enable script execution in Server Side Includes even in configurations where the AllowOverride directive contained only Options=IncludesNoEXEC. In the oldstable distribution (etch), local users could (via .htaccess) enable script execution in Server Side Includes and CGI script execution in configurations where the AllowOverride directive contained any "Options=" value. The oldstable distribution (etch), this problem has been fixed in version 2.2.3-4+etch8.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:09-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T07:57:34.797-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:00:33.863-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:00:21.391-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Platform section" operator="OR">
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Architecture independent section" operator="AND">
              <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="apache2-src is earlier than 2.2.9-10+lenny3" test_ref="oval:org.mitre.oval:tst:18462"/>
                <criterion comment="apache2-doc is earlier than 2.2.9-10+lenny3" test_ref="oval:org.mitre.oval:tst:18244"/>
                <criterion comment="apache2 is earlier than 2.2.9-10+lenny3" test_ref="oval:org.mitre.oval:tst:18541"/>
              </criteria>
            </criteria>
            <criteria comment="Architecture dependent section" operator="AND">
              <criteria comment="Supported architectures section" operator="OR">
                <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
                <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
                <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
                <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
                <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
                <criterion comment="Installed architecture is armel" test_ref="oval:org.mitre.oval:tst:11101"/>
                <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
                <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
                <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
                <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
                <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
                <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
              </criteria>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="apache2-utils DPKG is earlier than 2.2.9-10+lenny3" test_ref="oval:org.mitre.oval:tst:18296"/>
                <criterion comment="apache2-mpm-worker DPKG is earlier than 2.2.9-10+lenny3" test_ref="oval:org.mitre.oval:tst:18522"/>
                <criterion comment="apache2.2-common DPKG is earlier than 2.2.9-10+lenny3" test_ref="oval:org.mitre.oval:tst:18500"/>
                <criterion comment="apache2-suexec-custom DPKG is earlier than 2.2.9-10+lenny3" test_ref="oval:org.mitre.oval:tst:18376"/>
                <criterion comment="apache2-suexec DPKG is earlier than 2.2.9-10+lenny3" test_ref="oval:org.mitre.oval:tst:18437"/>
                <criterion comment="apache2-threaded-dev DPKG is earlier than 2.2.9-10+lenny3" test_ref="oval:org.mitre.oval:tst:18085"/>
                <criterion comment="apache2-dbg DPKG is earlier than 2.2.9-10+lenny3" test_ref="oval:org.mitre.oval:tst:18551"/>
                <criterion comment="apache2-mpm-event DPKG is earlier than 2.2.9-10+lenny3" test_ref="oval:org.mitre.oval:tst:18481"/>
                <criterion comment="apache2-mpm-prefork DPKG is earlier than 2.2.9-10+lenny3" test_ref="oval:org.mitre.oval:tst:18325"/>
                <criterion comment="apache2-prefork-dev DPKG is earlier than 2.2.9-10+lenny3" test_ref="oval:org.mitre.oval:tst:17611"/>
              </criteria>
            </criteria>
            <criteria comment="Architecture dependent section" operator="AND">
              <criteria comment="Supported architectures section" operator="OR">
                <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
                <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
                <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
                <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
                <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
                <criterion comment="Installed architecture is armel" test_ref="oval:org.mitre.oval:tst:11101"/>
                <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
                <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
                <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
                <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
                <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
              </criteria>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="apache2-mpm-itk DPKG is earlier than 2.2.6-02-1+lenny1" test_ref="oval:org.mitre.oval:tst:17839"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 4.0 is installed" definition_ref="oval:org.mitre.oval:def:6461"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Architecture independent section" operator="AND">
              <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="apache2-mpm-perchild is earlier than 2.2.3-4+etch8" test_ref="oval:org.mitre.oval:tst:18282"/>
                <criterion comment="apache2-src is earlier than 2.2.3-4+etch8" test_ref="oval:org.mitre.oval:tst:17957"/>
                <criterion comment="apache2-doc is earlier than 2.2.3-4+etch8" test_ref="oval:org.mitre.oval:tst:18568"/>
                <criterion comment="apache2 is earlier than 2.2.3-4+etch8" test_ref="oval:org.mitre.oval:tst:18502"/>
              </criteria>
            </criteria>
            <criteria comment="Packages section" operator="OR">
              <criterion comment="apache2-utils DPKG is earlier than 2.2.3-4+etch8" test_ref="oval:org.mitre.oval:tst:18365"/>
              <criterion comment="apache2-mpm-worker DPKG is earlier than 2.2.3-4+etch8" test_ref="oval:org.mitre.oval:tst:18593"/>
              <criterion comment="apache2.2-common DPKG is earlier than 2.2.3-4+etch8" test_ref="oval:org.mitre.oval:tst:18596"/>
              <criterion comment="apache2-threaded-dev DPKG is earlier than 2.2.3-4+etch8" test_ref="oval:org.mitre.oval:tst:18449"/>
              <criterion comment="apache2-mpm-event DPKG is earlier than 2.2.3-4+etch8" test_ref="oval:org.mitre.oval:tst:18250"/>
              <criterion comment="apache2-mpm-prefork DPKG is earlier than 2.2.3-4+etch8" test_ref="oval:org.mitre.oval:tst:18253"/>
              <criterion comment="apache2-prefork-dev DPKG is earlier than 2.2.3-4+etch8" test_ref="oval:org.mitre.oval:tst:18515"/>
            </criteria>
            <criteria comment="Architecture dependent section" operator="AND">
              <criteria comment="Supported architectures section" operator="OR">
                <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
                <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
                <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
                <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
                <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
                <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
                <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
                <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
                <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
                <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
              </criteria>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="apache2-mpm-itk DPKG is earlier than 2.2.3-01-2+etch2" test_ref="oval:org.mitre.oval:tst:18587"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7264" version="3" class="patch">
      <metadata>
        <title>DSA-2041 mediawiki -- Cross-Site Request Forgery</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <product>mediawiki</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2010/dsa-2041" ref_id="DSA-2041"/>
        <description>It was discovered that mediawiki, a website engine for collaborative work, is vulnerable to a Cross-Site Request Forgery login attack, which could be used to conduct phishing or similar attacks to users via affected mediawiki installations. Note that the fix used breaks the login API and may require clients using it to be updated.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-05-24T19:05:02-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2010-05-26T13:27:59.677-04:00">DRAFT</status_change>
            <status_change date="2010-06-14T04:00:41.721-04:00">INTERIM</status_change>
            <status_change date="2010-06-29T11:49:34.792-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
        <criteria operator="OR" comment="Architecture section">
          <criteria operator="AND" comment="Architecture independent section">
            <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
            <criterion comment="mediawiki is earlier than 1.12.0-2lenny5" test_ref="oval:org.mitre.oval:tst:25897"/>
          </criteria>
          <criteria operator="AND" comment="Architecture dependent section">
            <criteria operator="OR" comment="Supported architectures section">
              <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
              <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
              <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
              <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
              <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
              <criterion comment="Installed architecture is armel" test_ref="oval:org.mitre.oval:tst:11101"/>
              <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
              <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
              <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
              <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
              <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
              <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
            </criteria>
            <criteria operator="OR" comment="Packages section">
              <criterion comment="mediawikimath is earlier than 1.12.0-2lenny5" test_ref="oval:org.mitre.oval:tst:25972"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:7263" class="patch">
      <metadata>
        <title>DSA-1846 kvm -- denial of service</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <product>kvm</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2009/dsa-1846" ref_id="DSA-1846"/>
        <description>Matt T. Yourst discovered an issue in the kvm subsystem. Local users with permission to manipulate /dev/kvm can cause a denial of service (hang) by providing an invalid cr3 value to the KVM_SET_SREGS call.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:03-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T07:50:15.502-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:00:33.555-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:00:21.103-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Release section" operator="AND">
        <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
        <criteria comment="Architecture section" operator="OR">
          <criteria comment="Architecture independent section" operator="AND">
            <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
            <criterion comment="kvm-source is earlier than 72+dfsg-5~lenny2" test_ref="oval:org.mitre.oval:tst:12674"/>
          </criteria>
          <criteria comment="Architecture dependent section" operator="AND">
            <criteria comment="Supported architectures section" operator="OR">
              <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
              <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
            </criteria>
            <criteria comment="Packages section" operator="OR">
              <criterion comment="kvm DPKG is earlier than 72+dfsg-5~lenny2" test_ref="oval:org.mitre.oval:tst:12799"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7259" version="3" class="patch">
      <metadata>
        <title>DSA-1982 hybserv -- denial of service</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <product>hybserv</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2010/dsa-1982" ref_id="DSA-1982"/>
        <description>Julien Cristau discovered that hybserv, a daemon running IRC services for IRCD-Hybrid, is prone to a denial of service attack via the commands option.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-05-24T19:05:20-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2010-05-26T13:28:04.542-04:00">DRAFT</status_change>
            <status_change date="2010-06-14T04:00:41.396-04:00">INTERIM</status_change>
            <status_change date="2010-06-29T11:49:34.449-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
        <criteria operator="OR" comment="Architecture section">
          <criteria operator="AND" comment="Architecture dependent section">
            <criteria operator="OR" comment="Supported architectures section">
              <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
              <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
              <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
              <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
              <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
              <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
              <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
              <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
              <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
            </criteria>
            <criteria operator="OR" comment="Packages section">
              <criterion comment="hybserv is earlier than 1.9.2-4+lenny2" test_ref="oval:org.mitre.oval:tst:25678"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:7250" class="patch">
      <metadata>
        <title>DSA-1878 devscripts -- missing input sanitation</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <platform>Debian GNU/Linux 4.0</platform>
          <product>devscripts</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2009/dsa-1878" ref_id="DSA-1878"/>
        <description>Raphael Geissert discovered that uscan, a program to check for availability of new source code versions which is part of the devscripts package, runs Perl code downloaded from potentially untrusted sources to implement its URL and version mangling functionality. This update addresses this issue by reimplementing the relevant Perl operators without relying on the Perl interpreter, trying to preserve backwards compatibility as much as possible.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:06-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T07:53:50.812-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:00:33.132-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:00:20.655-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Platform section" operator="OR">
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Architecture dependent section" operator="AND">
              <criteria comment="Supported architectures section" operator="OR">
                <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
                <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
                <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
                <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
                <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
                <criterion comment="Installed architecture is armel" test_ref="oval:org.mitre.oval:tst:11101"/>
                <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
                <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
                <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
                <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
                <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
                <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
              </criteria>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="devscripts DPKG is earlier than 2.10.35lenny6" test_ref="oval:org.mitre.oval:tst:15703"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 4.0 is installed" definition_ref="oval:org.mitre.oval:def:6461"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Packages section" operator="OR">
              <criterion comment="devscripts DPKG is earlier than 2.9.26etch4" test_ref="oval:org.mitre.oval:tst:15233"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7248" version="1" class="patch">
      <metadata>
        <title>DSA-1798 pango1.0 -- integer overflow</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <platform>Debian GNU/Linux 4.0</platform>
          <product>pango1.0</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2009/dsa-1798" ref_id="DSA-1798"/>
        <description>Will Drewry discovered that pango, a system for layout and rendering of internationalized text, is prone to an integer overflow via long glyphstrings. This could cause the execution of arbitrary code when displaying crafted data through an application using the pango library.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:02-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T07:48:55.534-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:00:32.419-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:00:20.117-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Release section">
          <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
          <criteria operator="OR" comment="Architecture section">
            <criteria operator="AND" comment="Architecture independent section">
              <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criteria operator="OR" comment="Packages section">
                <criterion comment="libpango1.0-doc is earlier than 1.20.5-3+lenny1" test_ref="oval:org.mitre.oval:tst:11844"/>
                <criterion comment="libpango1.0-common is earlier than 1.20.5-3+lenny1" test_ref="oval:org.mitre.oval:tst:11945"/>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Architecture dependent section">
              <criteria operator="OR" comment="Supported architectures section">
                <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
                <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
                <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
                <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
                <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
                <criterion comment="Installed architecture is armel" test_ref="oval:org.mitre.oval:tst:11101"/>
                <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
                <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
                <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
                <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
                <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
                <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
              </criteria>
              <criteria operator="OR" comment="Packages section">
                <criterion comment="libpango1.0-0 is earlier than 1.20.5-3+lenny1" test_ref="oval:org.mitre.oval:tst:12028"/>
                <criterion comment="libpango1.0-0-dbg is earlier than 1.20.5-3+lenny1" test_ref="oval:org.mitre.oval:tst:12039"/>
                <criterion comment="libpango1.0-dev is earlier than 1.20.5-3+lenny1" test_ref="oval:org.mitre.oval:tst:12019"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Release section">
          <extend_definition comment="Debian 4.0 is installed." definition_ref="oval:org.mitre.oval:def:6461"/>
          <criteria operator="OR" comment="Architecture section">
            <criteria operator="AND" comment="Architecture independent section">
              <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criteria operator="OR" comment="Packages section">
                <criterion comment="libpango1.0-doc is earlier than 1.14.8-5+etch1" test_ref="oval:org.mitre.oval:tst:11726"/>
                <criterion comment="libpango1.0-common is earlier than 1.14.8-5+etch1" test_ref="oval:org.mitre.oval:tst:11800"/>
              </criteria>
            </criteria>
            <criteria operator="OR" comment="Packages section">
              <criterion comment="libpango1.0-0 is earlier than 1.14.8-5+etch1" test_ref="oval:org.mitre.oval:tst:11587"/>
              <criterion comment="libpango1.0-0-dbg is earlier than 1.14.8-5+etch1" test_ref="oval:org.mitre.oval:tst:41755"/>
              <criterion comment="libpango1.0-dev is earlier than 1.14.8-5+etch1" test_ref="oval:org.mitre.oval:tst:11934"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7247" version="3" class="patch">
      <metadata>
        <title>DSA-1950 webkit -- several vulnerabilities</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <product>webkit</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2009/dsa-1950" ref_id="DSA-1950"/>
        <description>Several vulnerabilities have been discovered in WebKit, a Web content engine library for Gtk+. The Common Vulnerabilities and Exposures project identifies the following problems: Array index error in the insertItemBefore method in WebKit, allows remote attackers to execute arbitrary code via a document with a SVGPathList data structure containing a negative index in the SVGTransformList, SVGStringList, SVGNumberList, SVGPathSegList, SVGPointList, or SVGLengthList SVGList object, which triggers memory corruption. The JavaScript garbage collector in WebKit does not properly handle allocation failures, which allows remote attackers to execute arbitrary code or cause a denial of service  via a crafted HTML document that triggers write access to an "offset of a NULL pointer." Use-after-free vulnerability in WebKit, allows remote attackers to execute arbitrary code or cause a denial of service  by setting an unspecified property of an HTML tag that causes child elements to be freed and later accessed when an HTML error occurs, related to "recursion in certain DOM event handlers." WebKit does not initialize a pointer during handling of a Cascading Style Sheets  attr function call with a large numerical argument, which allows remote attackers to execute arbitrary code or cause a denial of service  via a crafted HTML document. WebKit does not properly initialize memory for Attr DOM objects, which allows remote attackers to execute arbitrary code or cause a denial of service  via a crafted HTML document. WebKit does not prevent remote loading of local Java applets, which allows remote attackers to execute arbitrary code, gain privileges, or obtain sensitive information via an APPLET or OBJECT element. WebKit do not properly handle numeric character references, which allows remote attackers to execute arbitrary code or cause a denial of service  via a crafted HTML document. Cross-site scripting  vulnerability in Web Inspector in WebKit allows user-assisted remote attackers to inject arbitrary web script or HTML, and read local files, via vectors related to the improper escaping of HTML attributes. WebKit allows remote attackers to spoof the browser"s display of the host name, security indicators, and unspecified other UI elements via a custom cursor in conjunction with a modified CSS3 hotspot property. CRLF injection vulnerability in WebKit allows remote attackers to inject HTTP headers and bypass the Same Origin Policy via a crafted HTML document, related to cross-site scripting  attacks that depend on communication with arbitrary web sites on the same server through use of XMLHttpRequest without a Host header. Cross-site scripting  vulnerability in WebKit allows remote attackers to inject arbitrary web script or HTML via vectors involving access to frame contents after completion of a page transition. WebKit allows remote attackers to read images from arbitrary web sites via a CANVAS element with an SVG image, related to a "cross-site image capture issue." WebKit does not properly handle redirects, which allows remote attackers to read images from arbitrary web sites via vectors involving a CANVAS element and redirection, related to a "cross-site image capture issue." WebKit does not prevent web sites from loading third-party content into a subframe, which allows remote attackers to bypass the Same Origin Policy and conduct "clickjacking" attacks via a crafted HTML document. Cross-site scripting  vulnerability in WebKit allows remote attackers to inject arbitrary web script or HTML via an event handler that triggers script execution in the context of the next loaded document. WebKit allows remote attackers to cause a denial of service  via a web page containing an HTMLSelectElement object with a large length attribute, related to the length property of a Select object.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-05-24T19:04:19-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2010-05-26T13:27:50.462-04:00">DRAFT</status_change>
            <status_change date="2010-06-14T04:00:40.705-04:00">INTERIM</status_change>
            <status_change date="2010-06-29T11:49:33.542-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
        <criteria operator="OR" comment="Architecture section">
          <criteria operator="AND" comment="Architecture independent section">
            <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
            <criterion comment="libwebkit-dev is earlier than 1.0.1-4+lenny2" test_ref="oval:org.mitre.oval:tst:25253"/>
          </criteria>
          <criteria operator="AND" comment="Architecture dependent section">
            <criteria operator="OR" comment="Supported architectures section">
              <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
              <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
              <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
              <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
              <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
              <criterion comment="Installed architecture is armel" test_ref="oval:org.mitre.oval:tst:11101"/>
              <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
              <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
              <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
              <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
              <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
            </criteria>
            <criteria operator="OR" comment="Packages section">
              <criterion comment="libwebkit-1.0-1-dbg is earlier than 1.0.1-4+lenny2" test_ref="oval:org.mitre.oval:tst:25542"/>
              <criterion comment="libwebkit-1.0-1 is earlier than 1.0.1-4+lenny2" test_ref="oval:org.mitre.oval:tst:25497"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7239" version="3" class="patch">
      <metadata>
        <title>DSA-2009 tdiary -- insufficient input sanitising</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <product>tdiary</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2010/dsa-2009" ref_id="DSA-2009"/>
        <description>It was discovered that tdiary, a communication-friendly weblog system, is prone to a cross-site scripting vulnerability due to insufficient input sanitising in the TrackBack transmission plugin.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-05-24T19:14:12-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2010-05-26T13:29:44.648-04:00">DRAFT</status_change>
            <status_change date="2010-06-14T04:00:40.421-04:00">INTERIM</status_change>
            <status_change date="2010-06-29T11:49:32.510-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
        <criteria operator="OR" comment="Architecture section">
          <criteria operator="AND" comment="Architecture independent section">
            <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
            <criteria operator="OR" comment="Packages section">
              <criterion comment="tdiary-theme is earlier than 2.2.1-1+lenny1" test_ref="oval:org.mitre.oval:tst:27480"/>
              <criterion comment="tdiary is earlier than 2.2.1-1+lenny1" test_ref="oval:org.mitre.oval:tst:27186"/>
              <criterion comment="tdiary-mode is earlier than 2.2.1-1+lenny1" test_ref="oval:org.mitre.oval:tst:27661"/>
              <criterion comment="tdiary-plugin is earlier than 2.2.1-1+lenny1" test_ref="oval:org.mitre.oval:tst:27625"/>
              <criterion comment="tdiary-contrib is earlier than 2.2.1-1+lenny1" test_ref="oval:org.mitre.oval:tst:27560"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7234" version="3" class="patch">
      <metadata>
        <title>DSA-2007 cups -- format string vulnerability</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <product>cups</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2010/dsa-2007" ref_id="DSA-2007"/>
        <description>Ronald Volgers discovered that the lppasswd component of the cups suite, the Common UNIX Printing System, is vulnerable to format string attacks due to insecure use of the LOCALEDIR environment variable. An attacker can abuse this behaviour to execute arbitrary code via crafted localization files and triggering calls to _cupsLangprintf. This works as the lppasswd binary happens to be installed with setuid 0 permissions.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-05-24T19:12:49-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2010-05-26T13:29:38.882-04:00">DRAFT</status_change>
            <status_change date="2010-06-14T04:00:39.774-04:00">INTERIM</status_change>
            <status_change date="2010-06-29T11:49:31.901-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
        <criteria operator="OR" comment="Architecture section">
          <criteria operator="AND" comment="Architecture independent section">
            <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
            <criteria operator="OR" comment="Packages section">
              <criterion comment="cupsys-bsd is earlier than 1.3.8-1+lenny8" test_ref="oval:org.mitre.oval:tst:27316"/>
              <criterion comment="cups-common is earlier than 1.3.8-1+lenny8" test_ref="oval:org.mitre.oval:tst:26876"/>
              <criterion comment="libcupsys2-dev is earlier than 1.3.8-1+lenny8" test_ref="oval:org.mitre.oval:tst:27084"/>
              <criterion comment="cupsys-common is earlier than 1.3.8-1+lenny8" test_ref="oval:org.mitre.oval:tst:27350"/>
              <criterion comment="cupsys-client is earlier than 1.3.8-1+lenny8" test_ref="oval:org.mitre.oval:tst:26487"/>
              <criterion comment="cupsys-dbg is earlier than 1.3.8-1+lenny8" test_ref="oval:org.mitre.oval:tst:27371"/>
              <criterion comment="cupsys is earlier than 1.3.8-1+lenny8" test_ref="oval:org.mitre.oval:tst:27486"/>
              <criterion comment="libcupsys2 is earlier than 1.3.8-1+lenny8" test_ref="oval:org.mitre.oval:tst:27269"/>
            </criteria>
          </criteria>
          <criteria operator="AND" comment="Architecture dependent section">
            <criteria operator="OR" comment="Supported architectures section">
              <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
              <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
              <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
              <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
              <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
              <criterion comment="Installed architecture is armel" test_ref="oval:org.mitre.oval:tst:11101"/>
              <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
              <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
              <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
              <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
              <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
            </criteria>
            <criteria operator="OR" comment="Packages section">
              <criterion comment="libcups2-dev is earlier than 1.3.8-1+lenny8" test_ref="oval:org.mitre.oval:tst:27409"/>
              <criterion comment="cups-bsd is earlier than 1.3.8-1+lenny8" test_ref="oval:org.mitre.oval:tst:27304"/>
              <criterion comment="libcupsimage2-dev is earlier than 1.3.8-1+lenny8" test_ref="oval:org.mitre.oval:tst:27270"/>
              <criterion comment="libcupsimage2 is earlier than 1.3.8-1+lenny8" test_ref="oval:org.mitre.oval:tst:27465"/>
              <criterion comment="cups-client is earlier than 1.3.8-1+lenny8" test_ref="oval:org.mitre.oval:tst:27434"/>
              <criterion comment="libcups2 is earlier than 1.3.8-1+lenny8" test_ref="oval:org.mitre.oval:tst:27442"/>
              <criterion comment="cups-dbg is earlier than 1.3.8-1+lenny8" test_ref="oval:org.mitre.oval:tst:27240"/>
              <criterion comment="cups is earlier than 1.3.8-1+lenny8" test_ref="oval:org.mitre.oval:tst:27488"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:7226" class="patch">
      <metadata>
        <title>DSA-1881 cyrus-imapd-2.2 -- buffer overflow</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <platform>Debian GNU/Linux 4.0</platform>
          <product>cyrus-imapd-2.2</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2009/dsa-1881" ref_id="DSA-1881"/>
        <description>It was discovered that the SIEVE component of cyrus-imapd, a highly scalable enterprise mail system, is vulnerable to a buffer overflow when processing SIEVE scripts. Due to incorrect use of the sizeof() operator an attacker is able to pass a negative length to snprintf() calls resulting in large positive values due to integer conversion. This causes a buffer overflow which can be used to elevate privileges to the cyrus system user. An attacker who is able to install SIEVE scripts executed by the server is therefore able to read and modify arbitrary email messages on the system.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:04-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T07:51:28.309-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:00:29.634-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:00:18.181-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Platform section" operator="OR">
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Architecture independent section" operator="AND">
              <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="cyrus-doc-2.2 is earlier than 2.2.13-14+lenny1" test_ref="oval:org.mitre.oval:tst:13485"/>
                <criterion comment="cyrus-admin-2.2 is earlier than 2.2.13-14+lenny1" test_ref="oval:org.mitre.oval:tst:13603"/>
              </criteria>
            </criteria>
            <criteria comment="Architecture dependent section" operator="AND">
              <criteria comment="Supported architectures section" operator="OR">
                <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
                <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
                <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
                <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
                <criterion comment="Installed architecture is armel" test_ref="oval:org.mitre.oval:tst:11101"/>
                <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
                <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
                <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
                <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
                <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
                <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
              </criteria>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="cyrus-clients-2.2 DPKG is earlier than 2.2.13-14+lenny1" test_ref="oval:org.mitre.oval:tst:13278"/>
                <criterion comment="cyrus-nntpd-2.2 DPKG is earlier than 2.2.13-14+lenny1" test_ref="oval:org.mitre.oval:tst:13519"/>
                <criterion comment="cyrus-imapd-2.2 DPKG is earlier than 2.2.13-14+lenny1" test_ref="oval:org.mitre.oval:tst:13586"/>
                <criterion comment="cyrus-dev-2.2 DPKG is earlier than 2.2.13-14+lenny1" test_ref="oval:org.mitre.oval:tst:13509"/>
                <criterion comment="cyrus-pop3d-2.2 DPKG is earlier than 2.2.13-14+lenny1" test_ref="oval:org.mitre.oval:tst:13172"/>
                <criterion comment="cyrus-common-2.2 DPKG is earlier than 2.2.13-14+lenny1" test_ref="oval:org.mitre.oval:tst:12832"/>
                <criterion comment="libcyrus-imap-perl22 DPKG is earlier than 2.2.13-14+lenny1" test_ref="oval:org.mitre.oval:tst:13382"/>
                <criterion comment="cyrus-murder-2.2 DPKG is earlier than 2.2.13-14+lenny1" test_ref="oval:org.mitre.oval:tst:13394"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria comment="Release section" operator="AND">
          <extend_definition comment="Debian 4.0 is installed" definition_ref="oval:org.mitre.oval:def:6461"/>
          <criteria comment="Architecture section" operator="OR">
            <criteria comment="Architecture independent section" operator="AND">
              <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="cyrus-doc-2.2 is earlier than 2.2.13-10+etch2" test_ref="oval:org.mitre.oval:tst:12868"/>
                <criterion comment="cyrus-admin-2.2 is earlier than 2.2.13-10+etch2" test_ref="oval:org.mitre.oval:tst:13573"/>
              </criteria>
            </criteria>
            <criteria comment="Packages section" operator="OR">
              <criterion comment="cyrus-clients-2.2 DPKG is earlier than 2.2.13-10+etch2" test_ref="oval:org.mitre.oval:tst:13070"/>
              <criterion comment="cyrus-nntpd-2.2 DPKG is earlier than 2.2.13-10+etch2" test_ref="oval:org.mitre.oval:tst:12935"/>
              <criterion comment="cyrus-imapd-2.2 DPKG is earlier than 2.2.13-10+etch2" test_ref="oval:org.mitre.oval:tst:13542"/>
              <criterion comment="cyrus-dev-2.2 DPKG is earlier than 2.2.13-10+etch2" test_ref="oval:org.mitre.oval:tst:13231"/>
              <criterion comment="cyrus-pop3d-2.2 DPKG is earlier than 2.2.13-10+etch2" test_ref="oval:org.mitre.oval:tst:13380"/>
              <criterion comment="cyrus-common-2.2 DPKG is earlier than 2.2.13-10+etch2" test_ref="oval:org.mitre.oval:tst:12885"/>
              <criterion comment="libcyrus-imap-perl22 DPKG is earlier than 2.2.13-10+etch2" test_ref="oval:org.mitre.oval:tst:13526"/>
              <criterion comment="cyrus-murder-2.2 DPKG is earlier than 2.2.13-10+etch2" test_ref="oval:org.mitre.oval:tst:13192"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7213" version="3" class="patch">
      <metadata>
        <title>DSA-1947 shibboleth-sp, shibboleth-sp2, opensaml2 -- missing input sanitising</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <platform>Debian GNU/Linux 4.0</platform>
          <product>shibboleth-sp</product>
          <product>shibboleth-sp2</product>
          <product>opensaml2</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2009/dsa-1947" ref_id="DSA-1947"/>
        <description>Matt Elder discovered that Shibboleth, a federated web single sign-on system is vulnerable to script injection through redirection URLs</description>
        <oval_repository>
          <dates>
            <submitted date="2010-05-24T18:49:37-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2010-05-26T13:27:08.222-04:00">DRAFT</status_change>
            <status_change date="2010-06-14T04:00:38.921-04:00">INTERIM</status_change>
            <status_change date="2010-06-29T11:49:30.740-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Release section">
          <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
          <criteria operator="OR" comment="Architecture section">
            <criteria operator="AND" comment="Architecture independent section">
              <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criteria operator="OR" comment="Packages section">
                <criterion comment="libshibsp-doc is earlier than 2.0.dfsg1-4+lenny2" test_ref="oval:org.mitre.oval:tst:23919"/>
                <criterion comment="libsaml2-doc is earlier than 2.0-2+lenny2" test_ref="oval:org.mitre.oval:tst:24252"/>
                <criterion comment="shibboleth-sp2-schemas is earlier than 2.0.dfsg1-4+lenny2" test_ref="oval:org.mitre.oval:tst:24229"/>
                <criterion comment="opensaml2-schemas is earlier than 2.0-2+lenny2" test_ref="oval:org.mitre.oval:tst:24352"/>
              </criteria>
            </criteria>
            <criteria operator="OR" comment="Packages section">
              <criterion comment="libshib6 is earlier than 1.3.1.dfsg1-3+lenny2" test_ref="oval:org.mitre.oval:tst:24370"/>
              <criterion comment="libsaml2-dev is earlier than 2.0-2+lenny2" test_ref="oval:org.mitre.oval:tst:24205"/>
              <criterion comment="libshib-dev is earlier than 1.3.1.dfsg1-3+lenny2" test_ref="oval:org.mitre.oval:tst:24317"/>
              <criterion comment="libshibsp1 is earlier than 2.0.dfsg1-4+lenny2" test_ref="oval:org.mitre.oval:tst:24431"/>
              <criterion comment="libapache2-mod-shib2 is earlier than 2.0.dfsg1-4+lenny2" test_ref="oval:org.mitre.oval:tst:24401"/>
              <criterion comment="libsaml2 is earlier than 2.0-2+lenny2" test_ref="oval:org.mitre.oval:tst:24046"/>
              <criterion comment="libapache2-mod-shib is earlier than 1.3.1.dfsg1-3+lenny2" test_ref="oval:org.mitre.oval:tst:24031"/>
              <criterion comment="opensaml2-tools is earlier than 2.0-2+lenny2" test_ref="oval:org.mitre.oval:tst:24405"/>
              <criterion comment="libshibsp-dev is earlier than 2.0.dfsg1-4+lenny2" test_ref="oval:org.mitre.oval:tst:24231"/>
              <criterion comment="libshib-target5 is earlier than 1.3.1.dfsg1-3+lenny2" test_ref="oval:org.mitre.oval:tst:23721"/>
            </criteria>
            <criteria operator="AND" comment="Architecture dependent section">
              <criteria operator="OR" comment="Supported architectures section">
                <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
              </criteria>
              <criteria operator="OR" comment="Packages section">
                <criterion comment="libshib6 is earlier than 1.3.1.dfsg1-3+lenny2" test_ref="oval:org.mitre.oval:tst:24245"/>
                <criterion comment="libshib-dev is earlier than 1.3.1.dfsg1-3+lenny2" test_ref="oval:org.mitre.oval:tst:24199"/>
                <criterion comment="libshibsp1 is earlier than 2.0.dfsg1-4+lenny2" test_ref="oval:org.mitre.oval:tst:23973"/>
                <criterion comment="libapache2-mod-shib2 is earlier than 2.0.dfsg1-4+lenny2" test_ref="oval:org.mitre.oval:tst:24289"/>
                <criterion comment="libapache2-mod-shib is earlier than 1.3.1.dfsg1-3+lenny2" test_ref="oval:org.mitre.oval:tst:23844"/>
                <criterion comment="libshibsp-dev is earlier than 2.0.dfsg1-4+lenny2" test_ref="oval:org.mitre.oval:tst:24418"/>
                <criterion comment="libshib-target5 is earlier than 1.3.1.dfsg1-3+lenny2" test_ref="oval:org.mitre.oval:tst:23858"/>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Architecture depended section">
              <criteria operator="AND" comment="Supported platform section">
                <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
                <criteria operator="OR" comment="Packages section">
                  <criterion comment="libshib6 is earlier than 1.3.1.dfsg1-3+lenny2" test_ref="oval:org.mitre.oval:tst:24244"/>
                  <criterion comment="libshib-dev is earlier than 1.3.1.dfsg1-3+lenny2" test_ref="oval:org.mitre.oval:tst:23801"/>
                  <criterion comment="libshib-target5 is earlier than 1.3.1.dfsg1-3+lenny2" test_ref="oval:org.mitre.oval:tst:24350"/>
                  <criterion comment="libapache2-mod-shib is earlier than 1.3.1.dfsg1-3+lenny2" test_ref="oval:org.mitre.oval:tst:24020"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Release section">
          <extend_definition comment="Debian 4.0 is installed." definition_ref="oval:org.mitre.oval:def:6461"/>
          <criteria operator="OR" comment="Architecture section">
            <criteria operator="AND" comment="Architecture dependent section">
              <criteria operator="OR" comment="Supported architectures section">
                <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
                <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
                <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
                <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
                <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
                <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
                <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
                <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
                <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
              </criteria>
              <criteria operator="OR" comment="Packages section">
                <criterion comment="libshib6 is earlier than 1.3f.dfsg1-2+etch2" test_ref="oval:org.mitre.oval:tst:24191"/>
                <criterion comment="libshib-dev is earlier than 1.3f.dfsg1-2+etch2" test_ref="oval:org.mitre.oval:tst:23619"/>
                <criterion comment="libshib-target5 is earlier than 1.3f.dfsg1-2+etch2" test_ref="oval:org.mitre.oval:tst:23828"/>
                <criterion comment="libapache2-mod-shib is earlier than 1.3f.dfsg1-2+etch2" test_ref="oval:org.mitre.oval:tst:24248"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7189" version="3" class="patch">
      <metadata>
        <title>DSA-1990 trac-git -- shell command injection</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <product>trac-git</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2010/dsa-1990" ref_id="DSA-1990"/>
        <description>Stefan Goebel discovered that the Debian version of trac-git, the Git add-on for the Trac issue tracking system, contains a flaw which enables attackers to execute code on the web server running trac-git by sending crafted HTTP queries. The old stable distribution  does not contain a trac-git package.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-05-24T19:06:01-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2010-05-26T13:28:13.107-04:00">DRAFT</status_change>
            <status_change date="2010-06-14T04:00:38.678-04:00">INTERIM</status_change>
            <status_change date="2010-06-29T11:49:30.226-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
        <criteria operator="OR" comment="Architecture section">
          <criteria operator="AND" comment="Architecture independent section">
            <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
            <criterion comment="trac-git is earlier than 0.0.20080710-3+lenny1" test_ref="oval:org.mitre.oval:tst:26045"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7185" version="3" class="patch">
      <metadata>
        <title>DSA-1949 php-net-ping -- programming error</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <platform>Debian GNU/Linux 4.0</platform>
          <product>php-net-ping</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2009/dsa-1949" ref_id="DSA-1949"/>
        <description>It was discovered that php-net-ping, a PHP PEAR module to execute ping independently of the Operating System, performs insufficient input sanitising, which might be used to inject arguments  or execute arbitrary commands  on a system that uses php-net-ping.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-05-24T18:49:36-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2010-05-26T13:27:05.611-04:00">DRAFT</status_change>
            <status_change date="2010-06-14T04:00:38.421-04:00">INTERIM</status_change>
            <status_change date="2010-06-29T11:49:29.649-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Release section">
          <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
          <criteria operator="OR" comment="Architecture section">
            <criteria operator="AND" comment="Architecture independent section">
              <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criterion comment="php-net-ping is earlier than 2.4.2-1+lenny1" test_ref="oval:org.mitre.oval:tst:24303"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Release section">
          <extend_definition comment="Debian 4.0 is installed." definition_ref="oval:org.mitre.oval:def:6461"/>
          <criteria operator="OR" comment="Architecture section">
            <criteria operator="AND" comment="Architecture independent section">
              <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criterion comment="php-net-ping is earlier than 2.4.2-1+etch1" test_ref="oval:org.mitre.oval:tst:24135"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7161" version="3" class="patch">
      <metadata>
        <title>DSA-2035 apache2 -- multiple issues</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <product>apache2</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2010/dsa-2035" ref_id="DSA-2035"/>
        <description>Two issues have been found in the Apache HTTPD web server: mod_proxy_ajp would return the wrong status code if it encountered an error, causing a backend server to be put into an error state until the retry timeout expired. A remote attacker could send malicious requests to trigger this issue, resulting in denial of service. A flaw in the core subrequest process code was found, which could lead to a daemon crash  or disclosure of sensitive information if the headers of a subrequest were modified by modules such as mod_headers.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-05-24T19:10:00-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2010-05-26T13:29:13.987-04:00">DRAFT</status_change>
            <status_change date="2010-06-14T04:00:37.789-04:00">INTERIM</status_change>
            <status_change date="2010-06-29T11:49:28.758-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
        <criteria operator="OR" comment="Architecture section">
          <criteria operator="AND" comment="Architecture independent section">
            <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
            <criteria operator="OR" comment="Packages section">
              <criterion comment="apache2-doc is earlier than 2.2.9-10+lenny7" test_ref="oval:org.mitre.oval:tst:26870"/>
              <criterion comment="apache2-src is earlier than 2.2.9-10+lenny7" test_ref="oval:org.mitre.oval:tst:26862"/>
              <criterion comment="apache2 is earlier than 2.2.9-10+lenny7" test_ref="oval:org.mitre.oval:tst:26981"/>
            </criteria>
          </criteria>
          <criteria operator="AND" comment="Architecture dependent section">
            <criteria operator="OR" comment="Supported architectures section">
              <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
              <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
              <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
              <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
              <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
              <criterion comment="Installed architecture is armel" test_ref="oval:org.mitre.oval:tst:11101"/>
              <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
              <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
              <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
              <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
              <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
              <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
            </criteria>
            <criteria operator="OR" comment="Packages section">
              <criterion comment="apache2-utils is earlier than 2.2.9-10+lenny7" test_ref="oval:org.mitre.oval:tst:26649"/>
              <criterion comment="apache2-mpm-worker is earlier than 2.2.9-10+lenny7" test_ref="oval:org.mitre.oval:tst:26929"/>
              <criterion comment="apache2.2-common is earlier than 2.2.9-10+lenny7" test_ref="oval:org.mitre.oval:tst:27000"/>
              <criterion comment="apache2-suexec-custom is earlier than 2.2.9-10+lenny7" test_ref="oval:org.mitre.oval:tst:26622"/>
              <criterion comment="apache2-suexec is earlier than 2.2.9-10+lenny7" test_ref="oval:org.mitre.oval:tst:27003"/>
              <criterion comment="apache2-mpm-prefork is earlier than 2.2.9-10+lenny7" test_ref="oval:org.mitre.oval:tst:27013"/>
              <criterion comment="apache2-dbg is earlier than 2.2.9-10+lenny7" test_ref="oval:org.mitre.oval:tst:26567"/>
              <criterion comment="apache2-mpm-event is earlier than 2.2.9-10+lenny7" test_ref="oval:org.mitre.oval:tst:26887"/>
              <criterion comment="apache2-threaded-dev is earlier than 2.2.9-10+lenny7" test_ref="oval:org.mitre.oval:tst:26601"/>
              <criterion comment="apache2-prefork-dev is earlier than 2.2.9-10+lenny7" test_ref="oval:org.mitre.oval:tst:26122"/>
            </criteria>
          </criteria>
          <criteria operator="AND" comment="Architecture dependent section">
            <criteria operator="OR" comment="Supported architectures section">
              <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
              <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
              <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
              <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
              <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
              <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
              <criterion comment="Installed architecture is armel" test_ref="oval:org.mitre.oval:tst:11101"/>
              <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
              <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
              <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
              <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
            </criteria>
            <criteria operator="OR" comment="Packages section">
              <criterion comment="apache2-mpm-itk is earlier than 2.2.6-02-1+lenny2+b3" test_ref="oval:org.mitre.oval:tst:26866"/>
            </criteria>
          </criteria>
          <criteria operator="AND" comment="Architecture depended section">
            <criteria operator="AND" comment="Supported platform section">
              <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
              <criteria operator="OR" comment="Packages section">
                <criterion comment="apache2-mpm-itk is earlier than 2.2.6-02-1+lenny2+b4" test_ref="oval:org.mitre.oval:tst:26806"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7153" version="3" class="patch">
      <metadata>
        <title>DSA-1968 pdns-recursor -- several vulnerabilities</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <product>pdns-recursor</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2010/dsa-1968" ref_id="DSA-1968"/>
        <description>It was discovered that pdns-recursor, the PowerDNS recursive name server, contains several vulnerabilities: A buffer overflow can be exploited to crash the daemon, or potentially execute arbitrary code. A cache poisoning vulnerability may allow attackers to trick the server into serving incorrect DNS data.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-05-24T19:08:31-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2010-05-26T13:28:55.440-04:00">DRAFT</status_change>
            <status_change date="2010-06-14T04:00:37.506-04:00">INTERIM</status_change>
            <status_change date="2010-06-29T11:49:27.751-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
        <criteria operator="OR" comment="Architecture section">
          <criteria operator="AND" comment="Architecture dependent section">
            <criteria operator="OR" comment="Supported architectures section">
              <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
              <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
              <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
              <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
              <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
              <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
            </criteria>
            <criteria operator="OR" comment="Packages section">
              <criterion comment="pdns-recursor is earlier than 3.1.7-1+lenny1" test_ref="oval:org.mitre.oval:tst:25911"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7152" version="3" class="patch">
      <metadata>
        <title>DSA-1977 python2.4 python2.5 -- several vulnerabilities</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <platform>Debian GNU/Linux 4.0</platform>
          <product>python2.4 python2.5</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2010/dsa-1977" ref_id="DSA-1977"/>
        <description>Jukka Taimisto, Tero Rontti and Rauli Kaksonen discovered that the embedded Expat copy in the interpreter for the Python language, does not properly process malformed or crafted XML files.  This vulnerability could allow an attacker to cause a denial of service while parsing a malformed XML file. In addition, this update fixes an integer overflow in the hashlib module in python2.5. This vulnerability could allow an attacker to defeat cryptographic digests.  It only affects the oldstable distribution .</description>
        <oval_repository>
          <dates>
            <submitted date="2010-05-24T19:10:22-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2010-05-26T13:29:22.099-04:00">DRAFT</status_change>
            <status_change date="2010-06-14T04:00:36.773-04:00">INTERIM</status_change>
            <status_change date="2010-06-29T11:49:26.985-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Release section">
          <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
          <criteria operator="OR" comment="Architecture section">
            <criteria operator="AND" comment="Architecture independent section">
              <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criteria operator="OR" comment="Packages section">
                <criterion comment="python2.4-examples is earlier than 2.4.6-1+lenny1" test_ref="oval:org.mitre.oval:tst:26908"/>
                <criterion comment="idle-python2.4 is earlier than 2.4.6-1+lenny1" test_ref="oval:org.mitre.oval:tst:27061"/>
                <criterion comment="idle-python2.5 is earlier than 2.5.2-15+lenny1" test_ref="oval:org.mitre.oval:tst:26553"/>
                <criterion comment="python2.5-examples is earlier than 2.5.2-15+lenny1" test_ref="oval:org.mitre.oval:tst:27069"/>
              </criteria>
            </criteria>
            <criteria operator="OR" comment="Packages section">
              <criterion comment="python2.4-dev is earlier than 2.4.6-1+lenny1" test_ref="oval:org.mitre.oval:tst:26819"/>
              <criterion comment="python2.4-minimal is earlier than 2.4.6-1+lenny1" test_ref="oval:org.mitre.oval:tst:27052"/>
              <criterion comment="python2.5 is earlier than 2.5.2-15+lenny1" test_ref="oval:org.mitre.oval:tst:26915"/>
              <criterion comment="python2.4 is earlier than 2.4.6-1+lenny1" test_ref="oval:org.mitre.oval:tst:27112"/>
              <criterion comment="python2.5-minimal is earlier than 2.5.2-15+lenny1" test_ref="oval:org.mitre.oval:tst:27113"/>
              <criterion comment="python2.4-dbg is earlier than 2.4.6-1+lenny1" test_ref="oval:org.mitre.oval:tst:27045"/>
              <criterion comment="python2.5-dbg is earlier than 2.5.2-15+lenny1" test_ref="oval:org.mitre.oval:tst:26680"/>
              <criterion comment="python2.5-dev is earlier than 2.5.2-15+lenny1" test_ref="oval:org.mitre.oval:tst:27127"/>
            </criteria>
            <criteria operator="AND" comment="Architecture dependent section">
              <criteria operator="OR" comment="Supported architectures section">
                <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
              </criteria>
              <criteria operator="OR" comment="Packages section">
                <criterion comment="python2.4-dev is earlier than 2.4.6-1+lenny1" test_ref="oval:org.mitre.oval:tst:27020"/>
                <criterion comment="python2.4 is earlier than 2.4.6-1+lenny1" test_ref="oval:org.mitre.oval:tst:27009"/>
                <criterion comment="python2.4-dbg is earlier than 2.4.6-1+lenny1" test_ref="oval:org.mitre.oval:tst:26991"/>
                <criterion comment="python2.4-minimal is earlier than 2.4.6-1+lenny1" test_ref="oval:org.mitre.oval:tst:26308"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Release section">
          <extend_definition comment="Debian 4.0 is installed." definition_ref="oval:org.mitre.oval:def:6461"/>
          <criteria operator="OR" comment="Architecture section">
            <criteria operator="AND" comment="Architecture independent section">
              <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criteria operator="OR" comment="Packages section">
                <criterion comment="idle-python2.5 is earlier than 2.5-5+etch2" test_ref="oval:org.mitre.oval:tst:26688"/>
                <criterion comment="python2.4-examples is earlier than 2.4.4-3+etch3" test_ref="oval:org.mitre.oval:tst:27074"/>
                <criterion comment="idle-python2.4 is earlier than 2.4.4-3+etch3" test_ref="oval:org.mitre.oval:tst:26720"/>
                <criterion comment="python2.5-examples is earlier than 2.5-5+etch2" test_ref="oval:org.mitre.oval:tst:26721"/>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Architecture dependent section">
              <criteria operator="OR" comment="Supported architectures section">
                <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
                <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
                <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
                <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
                <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
                <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
                <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
                <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
                <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
                <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
              </criteria>
              <criteria operator="OR" comment="Packages section">
                <criterion comment="python2.4-dev is earlier than 2.4.4-3+etch3" test_ref="oval:org.mitre.oval:tst:27106"/>
                <criterion comment="python2.4-minimal is earlier than 2.4.4-3+etch3" test_ref="oval:org.mitre.oval:tst:27015"/>
                <criterion comment="python2.5 is earlier than 2.5-5+etch2" test_ref="oval:org.mitre.oval:tst:26695"/>
                <criterion comment="python2.4 is earlier than 2.4.4-3+etch3" test_ref="oval:org.mitre.oval:tst:27041"/>
                <criterion comment="python2.5-minimal is earlier than 2.5-5+etch2" test_ref="oval:org.mitre.oval:tst:26493"/>
                <criterion comment="python2.4-dbg is earlier than 2.4.4-3+etch3" test_ref="oval:org.mitre.oval:tst:27042"/>
                <criterion comment="python2.5-dev is earlier than 2.5-5+etch2" test_ref="oval:org.mitre.oval:tst:26897"/>
                <criterion comment="python2.5-dbg is earlier than 2.5-5+etch2" test_ref="oval:org.mitre.oval:tst:26157"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7147" version="3" class="patch">
      <metadata>
        <title>DSA-2010 kvm -- privilege escalation/denial of service</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <product>kvm</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2010/dsa-2010" ref_id="DSA-2010"/>
        <description>Several local vulnerabilities have been discovered in kvm, a full virtualization system. The Common Vulnerabilities and Exposures project identifies the following problems: Gleb Natapov discovered issues in the KVM subsystem where missing permission checks  permit a user in a guest system to denial of service a guest  or gain escalated privileges with the guest. Marcelo Tosatti fixed an issue in the PIT emulation code in the KVM subsystem that allows privileged users in a guest domain to cause a denial of service  of the host system. Paolo Bonzini found a bug in KVM that can be used to bypass proper permission checking while loading segment selectors. This potentially allows privileged guest users to execute privileged instructions on the host system.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-05-24T19:02:14-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2010-05-26T13:27:39.535-04:00">DRAFT</status_change>
            <status_change date="2010-06-14T04:00:36.506-04:00">INTERIM</status_change>
            <status_change date="2010-06-29T11:49:25.985-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
        <criteria operator="OR" comment="Architecture section">
          <criteria operator="AND" comment="Architecture independent section">
            <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
            <criterion comment="kvm-source is earlier than 72+dfsg-5~lenny5" test_ref="oval:org.mitre.oval:tst:24786"/>
          </criteria>
          <criteria operator="AND" comment="Architecture dependent section">
            <criteria operator="OR" comment="Supported architectures section">
              <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
              <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
            </criteria>
            <criteria operator="OR" comment="Packages section">
              <criterion comment="kvm is earlier than 72+dfsg-5~lenny5" test_ref="oval:org.mitre.oval:tst:25412"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7142" version="3" class="patch">
      <metadata>
        <title>DSA-1987 lighttpd -- denial of service</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <platform>Debian GNU/Linux 4.0</platform>
          <product>lighttpd</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2010/dsa-1987" ref_id="DSA-1987"/>
        <description>Li Ming discovered that lighttpd, a small and fast webserver with minimal memory footprint, is vulnerable to a denial of service attack due to bad memory handling. Slowly sending very small chunks of request data causes lighttpd to allocate new buffers for each read instead of appending to old ones. An attacker can abuse this behaviour to cause denial of service conditions due to memory exhaustion.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-05-24T19:05:05-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2010-05-26T13:28:01.304-04:00">DRAFT</status_change>
            <status_change date="2010-06-14T04:00:35.893-04:00">INTERIM</status_change>
            <status_change date="2010-06-29T11:49:24.513-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Release section">
          <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
          <criteria operator="OR" comment="Architecture section">
            <criteria operator="AND" comment="Architecture independent section">
              <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criterion comment="lighttpd-doc is earlier than 1.4.19-5+lenny1" test_ref="oval:org.mitre.oval:tst:25962"/>
            </criteria>
            <criteria operator="AND" comment="Architecture dependent section">
              <criteria operator="OR" comment="Supported architectures section">
                <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
                <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
                <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
                <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
                <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
                <criterion comment="Installed architecture is armel" test_ref="oval:org.mitre.oval:tst:11101"/>
                <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
                <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
                <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
                <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
                <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
              </criteria>
              <criteria operator="OR" comment="Packages section">
                <criterion comment="lighttpd-mod-mysql-vhost is earlier than 1.4.19-5+lenny1" test_ref="oval:org.mitre.oval:tst:25908"/>
                <criterion comment="lighttpd-mod-magnet is earlier than 1.4.19-5+lenny1" test_ref="oval:org.mitre.oval:tst:25795"/>
                <criterion comment="lighttpd is earlier than 1.4.19-5+lenny1" test_ref="oval:org.mitre.oval:tst:25601"/>
                <criterion comment="lighttpd-mod-cml is earlier than 1.4.19-5+lenny1" test_ref="oval:org.mitre.oval:tst:25535"/>
                <criterion comment="lighttpd-mod-webdav is earlier than 1.4.19-5+lenny1" test_ref="oval:org.mitre.oval:tst:25966"/>
                <criterion comment="lighttpd-mod-trigger-b4-dl is earlier than 1.4.19-5+lenny1" test_ref="oval:org.mitre.oval:tst:25115"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Release section">
          <extend_definition comment="Debian 4.0 is installed." definition_ref="oval:org.mitre.oval:def:6461"/>
          <criteria operator="OR" comment="Architecture section">
            <criteria operator="AND" comment="Architecture independent section">
              <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criterion comment="lighttpd-doc is earlier than 1.4.13-4etch12" test_ref="oval:org.mitre.oval:tst:25338"/>
            </criteria>
            <criteria operator="AND" comment="Architecture dependent section">
              <criteria operator="OR" comment="Supported architectures section">
                <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
                <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
                <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
                <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
                <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
                <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
                <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
                <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
                <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
                <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
              </criteria>
              <criteria operator="OR" comment="Packages section">
                <criterion comment="lighttpd-mod-mysql-vhost is earlier than 1.4.13-4etch12" test_ref="oval:org.mitre.oval:tst:25292"/>
                <criterion comment="lighttpd-mod-magnet is earlier than 1.4.13-4etch12" test_ref="oval:org.mitre.oval:tst:25970"/>
                <criterion comment="lighttpd is earlier than 1.4.13-4etch12" test_ref="oval:org.mitre.oval:tst:25893"/>
                <criterion comment="lighttpd-mod-cml is earlier than 1.4.13-4etch12" test_ref="oval:org.mitre.oval:tst:25882"/>
                <criterion comment="lighttpd-mod-webdav is earlier than 1.4.13-4etch12" test_ref="oval:org.mitre.oval:tst:25571"/>
                <criterion comment="lighttpd-mod-trigger-b4-dl is earlier than 1.4.13-4etch12" test_ref="oval:org.mitre.oval:tst:25853"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7137" version="3" class="patch">
      <metadata>
        <title>DSA-2008 typo3-src -- several vulnerabilities</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <product>typo3-src</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2010/dsa-2008" ref_id="DSA-2008"/>
        <description>Several remote vulnerabilities have been discovered in the TYPO3 web content management framework: Cross-site scripting vulnerabilities have been discovered in both the frontend and the backend. Also, user data could be leaked. More details can be found in the Typo3 security advisory.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-05-24T19:14:11-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2010-05-26T13:29:44.083-04:00">DRAFT</status_change>
            <status_change date="2010-06-14T04:00:35.662-04:00">INTERIM</status_change>
            <status_change date="2010-06-29T11:49:24.261-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
        <criteria operator="OR" comment="Architecture section">
          <criteria operator="AND" comment="Architecture independent section">
            <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
            <criteria operator="OR" comment="Packages section">
              <criterion comment="typo3 is earlier than 4.2.5-1+lenny3" test_ref="oval:org.mitre.oval:tst:27561"/>
              <criterion comment="typo3-src-4.2 is earlier than 4.2.5-1+lenny3" test_ref="oval:org.mitre.oval:tst:27613"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7111" version="3" class="patch">
      <metadata>
        <title>DSA-1965 phpldapadmin -- missing input sanitising</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <product>phpldapadmin</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2010/dsa-1965" ref_id="DSA-1965"/>
        <description>It was discovered that phpLDAPadmin, a web based interface for administering LDAP servers, doesn"t sanitize an internal variable, which allows remote attackers to include and execute arbitrary local files. The oldstable distribution  is not affected by this problem.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-05-24T19:09:10-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2010-05-26T13:29:03.369-04:00">DRAFT</status_change>
            <status_change date="2010-06-14T04:00:35.451-04:00">INTERIM</status_change>
            <status_change date="2010-06-29T11:49:22.706-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
        <criteria operator="OR" comment="Architecture section">
          <criteria operator="AND" comment="Architecture independent section">
            <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
            <criterion comment="phpldapadmin is earlier than 1.1.0.5-6+lenny1" test_ref="oval:org.mitre.oval:tst:26869"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7105" version="3" class="patch">
      <metadata>
        <title>DSA-1980 ircd-hybrid/ircd-ratbox -- integer underflow/denial of service</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <product>ircd-hybrid/ircd-ratbox</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2010/dsa-1980" ref_id="DSA-1980"/>
        <description>David Leadbeater discovered an integer underflow that could be triggered via the LINKS command and can lead to a denial of service or the execution of arbitrary code . This issue affects both, ircd-hybrid and ircd-ratbox. It was discovered that the ratbox IRC server is prone to a denial of service attack via the HELP command. The ircd-hybrid package is not vulnerable to this issue .</description>
        <oval_repository>
          <dates>
            <submitted date="2010-05-24T19:05:24-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2010-05-26T13:28:05.666-04:00">DRAFT</status_change>
            <status_change date="2010-06-14T04:00:34.997-04:00">INTERIM</status_change>
            <status_change date="2010-06-29T11:49:22.270-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
        <criteria operator="OR" comment="Architecture section">
          <criteria operator="AND" comment="Architecture independent section">
            <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
            <criterion comment="hybrid-dev is earlier than 7.2.2.dfsg.2-4+lenny1" test_ref="oval:org.mitre.oval:tst:25660"/>
          </criteria>
          <criteria operator="AND" comment="Architecture dependent section">
            <criteria operator="OR" comment="Supported architectures section">
              <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
              <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
              <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
              <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
              <criterion comment="Installed architecture is armel" test_ref="oval:org.mitre.oval:tst:11101"/>
              <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
              <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
              <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
              <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
              <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
              <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
            </criteria>
            <criteria operator="OR" comment="Packages section">
              <criterion comment="ircd-ratbox-dbg is earlier than 2.2.8.dfsg-2+lenny1" test_ref="oval:org.mitre.oval:tst:25694"/>
              <criterion comment="ircd-hybrid is earlier than 7.2.2.dfsg.2-4+lenny1" test_ref="oval:org.mitre.oval:tst:25150"/>
              <criterion comment="ircd-ratbox is earlier than 2.2.8.dfsg-2+lenny1" test_ref="oval:org.mitre.oval:tst:25961"/>
            </criteria>
          </criteria>
          <criteria operator="AND" comment="Architecture dependent section">
            <criteria operator="OR" comment="Supported architectures section">
              <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
            </criteria>
            <criteria operator="OR" comment="Packages section">
              <criterion comment="ircd-hybrid is earlier than 7.2.2.dfsg.2-4+lenny1" test_ref="oval:org.mitre.oval:tst:25943"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7103" version="3" class="patch">
      <metadata>
        <title>DSA-2032 libpng -- several vulnerabilities</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <product>libpng</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2010/dsa-2032" ref_id="DSA-2032"/>
        <description>Several vulnerabilities have been discovered in libpng, a library for reading and writing PNG files. The Common Vulnerabilities and Exposures project identifies the following problems: libpng does not properly parse 1-bit interlaced images with width values that are not divisible by 8, which causes libpng to include uninitialized bits in certain rows of a PNG file and might allow remote attackers to read portions of sensitive memory via "out-of-bounds pixels" in the file. libpng does not properly handle compressed ancillary-chunk data that has a disproportionately large uncompressed representation, which allows remote attackers to cause a denial of service  via a crafted PNG file</description>
        <oval_repository>
          <dates>
            <submitted date="2010-05-24T19:10:12-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2010-05-26T13:29:15.220-04:00">DRAFT</status_change>
            <status_change date="2010-06-14T04:00:34.623-04:00">INTERIM</status_change>
            <status_change date="2010-06-29T11:49:21.799-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
        <criteria operator="OR" comment="Architecture section">
          <criteria operator="AND" comment="Architecture independent section">
            <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
            <criterion comment="libpng3 is earlier than 1.2.27-2+lenny3" test_ref="oval:org.mitre.oval:tst:26889"/>
          </criteria>
          <criteria operator="AND" comment="Architecture dependent section">
            <criteria operator="OR" comment="Supported architectures section">
              <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
              <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
              <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
              <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
              <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
              <criterion comment="Installed architecture is armel" test_ref="oval:org.mitre.oval:tst:11101"/>
              <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
              <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
              <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
              <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
              <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
            </criteria>
            <criteria operator="OR" comment="Packages section">
              <criterion comment="libpng12-dev is earlier than 1.2.27-2+lenny3" test_ref="oval:org.mitre.oval:tst:26982"/>
              <criterion comment="libpng12-0 is earlier than 1.2.27-2+lenny3" test_ref="oval:org.mitre.oval:tst:26975"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7097" version="3" class="patch">
      <metadata>
        <title>DSA-2030 mahara -- sql injection</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <product>mahara</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2010/dsa-2030" ref_id="DSA-2030"/>
        <description>It was discovered that mahara, an electronic portfolio, weblog, and resume builder is not properly escaping input when generating a unique username based on a remote user name from a single sign-on application. An attacker can use this to compromise the mahara database via crafted user names.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-05-24T19:10:14-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2010-05-26T13:29:16.966-04:00">DRAFT</status_change>
            <status_change date="2010-06-14T04:00:34.397-04:00">INTERIM</status_change>
            <status_change date="2010-06-29T11:49:21.553-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
        <criteria operator="OR" comment="Architecture section">
          <criteria operator="AND" comment="Architecture independent section">
            <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
            <criteria operator="OR" comment="Packages section">
              <criterion comment="mahara-apache2 is earlier than 1.0.4-4+lenny5" test_ref="oval:org.mitre.oval:tst:26530"/>
              <criterion comment="mahara is earlier than 1.0.4-4+lenny5" test_ref="oval:org.mitre.oval:tst:26817"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7093" version="3" class="patch">
      <metadata>
        <title>DSA-2024 moin -- insufficient input sanitising</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <product>moin</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2010/dsa-2024" ref_id="DSA-2024"/>
        <description>Jamie Strandboge discovered that moin, a python clone of WikiWiki, does not sufficiently sanitize the page name in "Despam" action, allowing remote attackers to perform cross-site scripting  attacks. In addition, this update fixes a minor issue in the "textcha" protection, it could be trivially bypassed by blanking the "textcha-question" and "textcha-answer" form fields.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-05-24T19:08:14-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2010-05-26T13:28:49.927-04:00">DRAFT</status_change>
            <status_change date="2010-06-14T04:00:34.185-04:00">INTERIM</status_change>
            <status_change date="2010-06-29T11:49:20.856-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
        <criteria operator="OR" comment="Architecture section">
          <criteria operator="AND" comment="Architecture independent section">
            <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
            <criterion comment="python-moinmoin is earlier than 1.7.1-3+lenny4" test_ref="oval:org.mitre.oval:tst:26723"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7089" version="3" class="patch">
      <metadata>
        <title>DSA-2016 drupal6 -- several vulnerabilities</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <product>drupal6</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2010/dsa-2016" ref_id="DSA-2016"/>
        <description>Several vulnerabilities  have been discovered in drupal6, a fully-featured content management framework. A user-supplied value is directly output during installation allowing a malicious user to craft a URL and perform a cross-site scripting attack. The exploit can only be conducted on sites not yet installed. The API function drupal_goto is susceptible to a phishing attack. An attacker could formulate a redirect in a way that gets the Drupal site to send the user to an arbitrarily provided URL. No user submitted data will be sent to that URL. Locale module and dependent contributed modules do not sanitize the display of language codes, native and English language names properly. While these usually come from a preselected list, arbitrary administrator input is allowed. This vulnerability is mitigated by the fact that the attacker must have a role with the "administer languages" permission. Under certain circumstances, a user with an open session that is blocked can maintain his/her session on the Drupal site, despite being blocked.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-05-24T19:02:11-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2010-05-26T13:27:38.556-04:00">DRAFT</status_change>
            <status_change date="2010-06-14T04:00:33.927-04:00">INTERIM</status_change>
            <status_change date="2010-06-29T11:49:20.621-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
        <criteria operator="OR" comment="Architecture section">
          <criteria operator="AND" comment="Architecture independent section">
            <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
            <criterion comment="drupal6 is earlier than 6.6-3lenny5" test_ref="oval:org.mitre.oval:tst:25579"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7075" version="3" class="patch">
      <metadata>
        <title>DSA-1983 wireshark -- several vulnerabilities</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <product>wireshark</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2010/dsa-1983" ref_id="DSA-1983"/>
        <description>Several remote vulnerabilities have been discovered in the Wireshark network traffic analyzer, which may lead to the execution of arbitrary code or denial of service. The Common Vulnerabilities and Exposures project identifies the following problems: A NULL pointer dereference was found in the SMB/SMB2 dissectors. Several buffer overflows were found in the LWRES dissector.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-05-24T19:05:21-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2010-05-26T13:28:05.129-04:00">DRAFT</status_change>
            <status_change date="2010-06-14T04:00:33.701-04:00">INTERIM</status_change>
            <status_change date="2010-06-29T11:49:20.370-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
        <criteria operator="OR" comment="Architecture section">
          <criteria operator="OR" comment="Packages section">
            <criterion comment="wireshark-dev is earlier than 1.0.2-3+lenny8" test_ref="oval:org.mitre.oval:tst:25942"/>
            <criterion comment="wireshark-common is earlier than 1.0.2-3+lenny8" test_ref="oval:org.mitre.oval:tst:25805"/>
            <criterion comment="tshark is earlier than 1.0.2-3+lenny8" test_ref="oval:org.mitre.oval:tst:25872"/>
            <criterion comment="wireshark is earlier than 1.0.2-3+lenny8" test_ref="oval:org.mitre.oval:tst:25921"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7069" version="3" class="patch">
      <metadata>
        <title>DSA-1966 horde3 -- insufficient input sanitising</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <platform>Debian GNU/Linux 4.0</platform>
          <product>horde3</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2010/dsa-1966" ref_id="DSA-1966"/>
        <description>Several vulnerabilities have been found in horde3, the horde web application framework. The Common Vulnerabilities and Exposures project identifies the following problems: It has been discovered that horde3 is prone to cross-site scripting attacks via crafted number preferences or inline MIME text parts when using text/plain as MIME type. For lenny this issue was already fixed, but as an additional security precaution, the display of inline text was disabled in the configuration file. It has been discovered that the horde3 administration interface is prone to cross-site scripting attacks due to the use of the PHP_SELF variable. This issue can only be exploited by authenticated administrators. It has been discovered that horde3 is prone to several cross-site scripting attacks via crafted data:text/html values in HTML messages.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-05-24T19:09:11-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2010-05-26T13:29:03.688-04:00">DRAFT</status_change>
            <status_change date="2010-06-14T04:00:33.462-04:00">INTERIM</status_change>
            <status_change date="2010-06-29T11:49:19.475-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Release section">
          <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
          <criteria operator="OR" comment="Architecture section">
            <criteria operator="AND" comment="Architecture independent section">
              <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criterion comment="horde3 is earlier than 3.2.2+debian0-2+lenny2" test_ref="oval:org.mitre.oval:tst:26370"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Release section">
          <extend_definition comment="Debian 4.0 is installed." definition_ref="oval:org.mitre.oval:def:6461"/>
          <criteria operator="OR" comment="Architecture section">
            <criteria operator="AND" comment="Architecture independent section">
              <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criterion comment="horde3 is earlier than 3.1.3-4etch7" test_ref="oval:org.mitre.oval:tst:26484"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7068" version="3" class="patch">
      <metadata>
        <title>DSA-1967 transmission -- directory traversal</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <product>transmission</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2010/dsa-1967" ref_id="DSA-1967"/>
        <description>Dan Rosenberg discovered that Transmission, a lightwight client for the Bittorrent filesharing protocol, performs insufficient sanitising of file names specified in .torrent files. This could lead to the overwrite of local files with the privileges of the user running Transmission if the user is tricked into opening a malicious torrent file.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-05-24T19:09:11-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2010-05-26T13:29:04.249-04:00">DRAFT</status_change>
            <status_change date="2010-06-14T04:00:32.993-04:00">INTERIM</status_change>
            <status_change date="2010-06-29T11:49:18.934-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
        <criteria operator="OR" comment="Architecture section">
          <criteria operator="AND" comment="Architecture independent section">
            <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
            <criteria operator="OR" comment="Packages section">
              <criterion comment="transmission is earlier than 1.22-1+lenny2" test_ref="oval:org.mitre.oval:tst:26939"/>
              <criterion comment="transmission-common is earlier than 1.22-1+lenny2" test_ref="oval:org.mitre.oval:tst:26650"/>
            </criteria>
          </criteria>
          <criteria operator="AND" comment="Architecture dependent section">
            <criteria operator="OR" comment="Supported architectures section">
              <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
              <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
              <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
              <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
              <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
              <criterion comment="Installed architecture is armel" test_ref="oval:org.mitre.oval:tst:11101"/>
              <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
              <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
              <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
              <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
              <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
            </criteria>
            <criteria operator="OR" comment="Packages section">
              <criterion comment="transmission-gtk is earlier than 1.22-1+lenny2" test_ref="oval:org.mitre.oval:tst:26451"/>
              <criterion comment="transmission-cli is earlier than 1.22-1+lenny2" test_ref="oval:org.mitre.oval:tst:26733"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:7065" class="patch">
      <metadata>
        <title>DSA-1905 python-django -- insufficient input validation</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <product>python-django</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2009/dsa-1905" ref_id="DSA-1905"/>
        <description>The forms library of python-django, a high-level Python web development framework, is using a badly chosen regular expression when validating email addresses and URLs. An attacker can use this to perform denial of service attacks (100% CPU consumption) due to bad backtracking via a specially crafted email address or URL which is validated by the django forms library. python-django in the oldstable distribution (etch), is not affected by this problem.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:04-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T07:50:42.300-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:00:25.756-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:00:15.356-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Release section" operator="AND">
        <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
        <criteria comment="Architecture section" operator="OR">
          <criteria comment="Architecture independent section" operator="AND">
            <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
            <criterion comment="python-django is earlier than 1.0.2-1+lenny2" test_ref="oval:org.mitre.oval:tst:12934"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7038" version="3" class="patch">
      <metadata>
        <title>DSA-1956 xulrunner -- several vulnerabilities</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <product>xulrunner</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2009/dsa-1956" ref_id="DSA-1956"/>
        <description>Several remote vulnerabilities have been discovered in Xulrunner, a runtime environment for XUL applications, such as the Iceweasel web browser. The Common Vulnerabilities and Exposures project identifies the following problems: David James discovered that the window.opener property allows Chrome privilege escalation. Jordi Chanel discovered a spoofing vulnerability of the URL location bar using the document.location property. Jonathan Morgan discovered that the icon indicating a secure connection could be spoofed through the document.location property. Takehiro Takahashi discovered that the NTLM implementaion is vulnerable to reflection attacks. Jesse Ruderman discovered a crash in the layout engine, which might allow the execution of arbitrary code. Jesse Ruderman, Josh Soref, Martijn Wargers, Jose Angel and Olli Pettay discovered crashes in the layout engine, which might allow the execution of arbitrary code.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-05-24T19:04:11-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2010-05-26T13:27:49.557-04:00">DRAFT</status_change>
            <status_change date="2010-06-14T04:00:32.430-04:00">INTERIM</status_change>
            <status_change date="2010-06-29T11:49:18.584-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
        <criteria operator="OR" comment="Architecture section">
          <criteria operator="AND" comment="Architecture independent section">
            <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
            <criterion comment="libmozillainterfaces-java is earlier than 1.9.0.16-1" test_ref="oval:org.mitre.oval:tst:25706"/>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="libmozjs-dev is earlier than 1.9.0.16-1" test_ref="oval:org.mitre.oval:tst:25386"/>
            <criterion comment="spidermonkey-bin is earlier than 1.9.0.16-1" test_ref="oval:org.mitre.oval:tst:25915"/>
            <criterion comment="xulrunner-1.9-gnome-support is earlier than 1.9.0.16-1" test_ref="oval:org.mitre.oval:tst:25477"/>
            <criterion comment="xulrunner-1.9 is earlier than 1.9.0.16-1" test_ref="oval:org.mitre.oval:tst:25731"/>
            <criterion comment="libmozjs1d-dbg is earlier than 1.9.0.16-1" test_ref="oval:org.mitre.oval:tst:25704"/>
            <criterion comment="libmozjs1d is earlier than 1.9.0.16-1" test_ref="oval:org.mitre.oval:tst:25627"/>
            <criterion comment="python-xpcom is earlier than 1.9.0.16-1" test_ref="oval:org.mitre.oval:tst:25914"/>
            <criterion comment="xulrunner-1.9-dbg is earlier than 1.9.0.16-1" test_ref="oval:org.mitre.oval:tst:25889"/>
            <criterion comment="xulrunner-dev is earlier than 1.9.0.16-1" test_ref="oval:org.mitre.oval:tst:25667"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition version="1" id="oval:org.mitre.oval:def:7036" class="patch">
      <metadata>
        <title>DSA-1845 linux-2.6 -- denial of service, privilege escalation</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <product>linux-2.6</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2009/dsa-1845" ref_id="DSA-1845"/>
        <description>Several vulnerabilities have been discovered in the Linux kernel that may lead to a denial of service, or privilege escalation. The Common Vulnerabilities and Exposures project identifies the following problems: Julien Tinnes and Tavis Ormandy reported an issue in the Linux personality code. Local users can take advantage of a setuid binary that can either be made to dereference a NULL pointer or drop privileges and return control to the user. This allows a user to bypass mmap_min_addr restrictions which can be exploited to execute arbitrary code. Matt T. Yourst discovered an issue in the kvm subsystem. Local users with permission to manipulate /dev/kvm can cause a denial of service (hang) by providing an invalid cr3 value to the KVM_SET_SREGS call. Ramon de Carvalho Valle discovered two issues with the eCryptfs layered filesystem using the fsfuzzer utility. A local user with permissions to perform an eCryptfs mount may modify the contents of a eCryptfs file, overflowing the stack and potentially gaining elevated privileges.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:03-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T07:50:21.122-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:00:24.464-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:00:14.409-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Release section" operator="AND">
        <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
        <criteria comment="Architecture section" operator="OR">
          <criteria comment="Architecture independent section" operator="AND">
            <criterion comment="all architecture" test_ref="oval:org.mitre.oval:tst:10881"/>
            <criteria comment="Packages section" operator="OR">
              <criterion comment="linux-patch-debian-2.6.26 is earlier than 2.6.26-17lenny1" test_ref="oval:org.mitre.oval:tst:11820"/>
              <criterion comment="linux-support-2.6.26-2 is earlier than 2.6.26-17lenny1" test_ref="oval:org.mitre.oval:tst:12450"/>
              <criterion comment="linux-doc-2.6.26 is earlier than 2.6.26-17lenny1" test_ref="oval:org.mitre.oval:tst:11834"/>
              <criterion comment="linux-tree-2.6.26 is earlier than 2.6.26-17lenny1" test_ref="oval:org.mitre.oval:tst:12408"/>
              <criterion comment="linux-source-2.6.26 is earlier than 2.6.26-17lenny1" test_ref="oval:org.mitre.oval:tst:12597"/>
              <criterion comment="linux-manual-2.6.26 is earlier than 2.6.26-17lenny1" test_ref="oval:org.mitre.oval:tst:12339"/>
            </criteria>
          </criteria>
          <criteria comment="Architecture dependent section" operator="AND">
            <criteria comment="Supported architectures section" operator="OR">
              <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
            </criteria>
            <criteria comment="Packages section" operator="OR">
              <criterion comment="linux-headers-2.6.26-2-all DPKG is earlier than 2.6.26-17lenny1" test_ref="oval:org.mitre.oval:tst:12723"/>
              <criterion comment="linux-image-2.6.26-2-vserver-s390x DPKG is earlier than 2.6.26-17lenny1" test_ref="oval:org.mitre.oval:tst:12811"/>
              <criterion comment="linux-image-2.6.26-2-s390 DPKG is earlier than 2.6.26-17lenny1" test_ref="oval:org.mitre.oval:tst:12785"/>
              <criterion comment="linux-headers-2.6.26-2-s390 DPKG is earlier than 2.6.26-17lenny1" test_ref="oval:org.mitre.oval:tst:12759"/>
              <criterion comment="linux-image-2.6.26-2-s390-tape DPKG is earlier than 2.6.26-17lenny1" test_ref="oval:org.mitre.oval:tst:12749"/>
              <criterion comment="linux-headers-2.6.26-2-all-s390 DPKG is earlier than 2.6.26-17lenny1" test_ref="oval:org.mitre.oval:tst:12797"/>
              <criterion comment="linux-headers-2.6.26-2-vserver-s390x DPKG is earlier than 2.6.26-17lenny1" test_ref="oval:org.mitre.oval:tst:12420"/>
              <criterion comment="linux-headers-2.6.26-2-common-vserver DPKG is earlier than 2.6.26-17lenny1" test_ref="oval:org.mitre.oval:tst:12591"/>
              <criterion comment="linux-libc-dev DPKG is earlier than 2.6.26-17lenny1" test_ref="oval:org.mitre.oval:tst:11859"/>
              <criterion comment="linux-image-2.6.26-2-s390x DPKG is earlier than 2.6.26-17lenny1" test_ref="oval:org.mitre.oval:tst:12186"/>
              <criterion comment="linux-headers-2.6.26-2-common DPKG is earlier than 2.6.26-17lenny1" test_ref="oval:org.mitre.oval:tst:12743"/>
              <criterion comment="linux-headers-2.6.26-2-s390x DPKG is earlier than 2.6.26-17lenny1" test_ref="oval:org.mitre.oval:tst:12850"/>
            </criteria>
          </criteria>
          <criteria comment="Architecture dependent section" operator="AND">
            <criteria comment="Supported architectures section" operator="OR">
              <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
            </criteria>
            <criteria comment="Packages section" operator="OR">
              <criterion comment="xen-linux-system-2.6.26-2-xen-amd64 DPKG is earlier than 2.6.26-17lenny1" test_ref="oval:org.mitre.oval:tst:12793"/>
              <criterion comment="linux-headers-2.6.26-2-all DPKG is earlier than 2.6.26-17lenny1" test_ref="oval:org.mitre.oval:tst:12407"/>
              <criterion comment="linux-modules-2.6.26-2-xen-amd64 DPKG is earlier than 2.6.26-17lenny1" test_ref="oval:org.mitre.oval:tst:12673"/>
              <criterion comment="linux-headers-2.6.26-2-openvz-amd64 DPKG is earlier than 2.6.26-17lenny1" test_ref="oval:org.mitre.oval:tst:12766"/>
              <criterion comment="linux-headers-2.6.26-2-common-vserver DPKG is earlier than 2.6.26-17lenny1" test_ref="oval:org.mitre.oval:tst:12802"/>
              <criterion comment="linux-image-2.6.26-2-openvz-amd64 DPKG is earlier than 2.6.26-17lenny1" test_ref="oval:org.mitre.oval:tst:12246"/>
              <criterion comment="linux-libc-dev DPKG is earlier than 2.6.26-17lenny1" test_ref="oval:org.mitre.oval:tst:12621"/>
              <criterion comment="linux-headers-2.6.26-2-common-openvz DPKG is earlier than 2.6.26-17lenny1" test_ref="oval:org.mitre.oval:tst:12732"/>
              <criterion comment="linux-image-2.6.26-2-vserver-amd64 DPKG is earlier than 2.6.26-17lenny1" test_ref="oval:org.mitre.oval:tst:12843"/>
              <criterion comment="linux-headers-2.6.26-2-all-amd64 DPKG is earlier than 2.6.26-17lenny1" test_ref="oval:org.mitre.oval:tst:12760"/>
              <criterion comment="linux-image-2.6.26-2-xen-amd64 DPKG is earlier than 2.6.26-17lenny1" test_ref="oval:org.mitre.oval:tst:12546"/>
              <criterion comment="linux-headers-2.6.26-2-common-xen DPKG is earlier than 2.6.26-17lenny1" test_ref="oval:org.mitre.oval:tst:12609"/>
              <criterion comment="linux-image-2.6.26-2-amd64 DPKG is earlier than 2.6.26-17lenny1" test_ref="oval:org.mitre.oval:tst:12687"/>
              <criterion comment="linux-headers-2.6.26-2-xen-amd64 DPKG is earlier than 2.6.26-17lenny1" test_ref="oval:org.mitre.oval:tst:12630"/>
              <criterion comment="linux-headers-2.6.26-2-amd64 DPKG is earlier than 2.6.26-17lenny1" test_ref="oval:org.mitre.oval:tst:12507"/>
              <criterion comment="linux-headers-2.6.26-2-common DPKG is earlier than 2.6.26-17lenny1" test_ref="oval:org.mitre.oval:tst:11984"/>
              <criterion comment="linux-headers-2.6.26-2-vserver-amd64 DPKG is earlier than 2.6.26-17lenny1" test_ref="oval:org.mitre.oval:tst:11878"/>
            </criteria>
          </criteria>
          <criteria comment="Architecture depended section" operator="AND">
            <criteria comment="Supported platform section" operator="AND">
              <criterion comment="hppa architecture" test_ref="oval:org.mitre.oval:tst:11164"/>
              <criteria comment="Packages section" operator="OR">
                <criterion comment="linux-headers-2.6.26-2-all DPKG is earlier than 2.6.26-17lenny1" test_ref="oval:org.mitre.oval:tst:12789"/>
                <criterion comment="linux-headers-2.6.26-2-parisc DPKG is earlier than 2.6.26-17lenny1" test_ref="oval:org.mitre.oval:tst:12763"/>
                <criterion comment="linux-image-2.6.26-2-parisc64 DPKG is earlier than 2.6.26-17lenny1" test_ref="oval:org.mitre.oval:tst:12774"/>
                <criterion comment="linux-image-2.6.26-2-parisc DPKG is earlier than 2.6.26-17lenny1" test_ref="oval:org.mitre.oval:tst:12750"/>
                <criterion comment="linux-headers-2.6.26-2-common DPKG is earlier than 2.6.26-17lenny1" test_ref="oval:org.mitre.oval:tst:12782"/>
                <criterion comment="linux-headers-2.6.26-2-all-hppa DPKG is earlier than 2.6.26-17lenny1" test_ref="oval:org.mitre.oval:tst:12069"/>
                <criterion comment="linux-headers-2.6.26-2-parisc64 DPKG is earlier than 2.6.26-17lenny1" test_ref="oval:org.mitre.oval:tst:12910"/>
                <criterion comment="linux-headers-2.6.26-2-parisc64-smp DPKG is earlier than 2.6.26-17lenny1" test_ref="oval:org.mitre.oval:tst:12902"/>
                <criterion comment="linux-libc-dev DPKG is earlier than 2.6.26-17lenny1" test_ref="oval:org.mitre.oval:tst:12860"/>
                <criterion comment="linux-image-2.6.26-2-parisc64-smp DPKG is earlier than 2.6.26-17lenny1" test_ref="oval:org.mitre.oval:tst:12977"/>
                <criterion comment="linux-headers-2.6.26-2-parisc-smp DPKG is earlier than 2.6.26-17lenny1" test_ref="oval:org.mitre.oval:tst:12815"/>
                <criterion comment="linux-image-2.6.26-2-parisc-smp DPKG is earlier than 2.6.26-17lenny1" test_ref="oval:org.mitre.oval:tst:12535"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7022" version="3" class="patch">
      <metadata>
        <title>DSA-1957 aria2 -- buffer overflow</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <product>aria2</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2009/dsa-1957" ref_id="DSA-1957"/>
        <description>It was discovered that aria2, a high speed download utility, is prone to a buffer overflow in the DHT routing code, which might lead to the execution of arbitrary code. The oldstable distribution  is not affected by this problem.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-05-24T19:04:10-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2010-05-26T13:27:48.482-04:00">DRAFT</status_change>
            <status_change date="2010-06-14T04:00:32.105-04:00">INTERIM</status_change>
            <status_change date="2010-06-29T11:49:18.263-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
        <criteria operator="OR" comment="Architecture section">
          <criteria operator="AND" comment="Architecture dependent section">
            <criteria operator="OR" comment="Supported architectures section">
              <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
              <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
              <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
              <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
              <criterion comment="Installed architecture is armel" test_ref="oval:org.mitre.oval:tst:11101"/>
              <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
              <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
              <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
            </criteria>
            <criteria operator="OR" comment="Packages section">
              <criterion comment="aria2 is earlier than 0.14.0-1+lenny1" test_ref="oval:org.mitre.oval:tst:25585"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7021" version="3" class="patch">
      <metadata>
        <title>DSA-2000 ffmpeg-debian -- several vulnerabilities</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <product>ffmpeg-debian</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2010/dsa-2000" ref_id="DSA-2000"/>
        <description>Several vulnerabilities have been discovered in ffmpeg, a multimedia player, server and encoder, which also provides a range of multimedia libraries used in applications like MPlayer: Various programming errors in container and codec implementations may lead to denial of service or the execution of arbitrary code if the user is tricked into opening a malformed media file or stream. The implementations of the following affected codecs and container formats have been updated:</description>
        <oval_repository>
          <dates>
            <submitted date="2010-05-24T19:12:38-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2010-05-26T13:29:34.690-04:00">DRAFT</status_change>
            <status_change date="2010-06-14T04:00:31.484-04:00">INTERIM</status_change>
            <status_change date="2010-06-29T11:49:17.622-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
        <criteria operator="OR" comment="Architecture section">
          <criteria operator="AND" comment="Architecture independent section">
            <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
            <criterion comment="ffmpeg-doc is earlier than 0.svn20080206-18+lenny1" test_ref="oval:org.mitre.oval:tst:26398"/>
          </criteria>
          <criteria operator="AND" comment="Architecture dependent section">
            <criteria operator="OR" comment="Supported architectures section">
              <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
              <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
              <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
              <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
              <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
              <criterion comment="Installed architecture is armel" test_ref="oval:org.mitre.oval:tst:11101"/>
              <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
              <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
              <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
              <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
              <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
              <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
            </criteria>
            <criteria operator="OR" comment="Packages section">
              <criterion comment="ffmpeg-dbg is earlier than 0.svn20080206-18+lenny1" test_ref="oval:org.mitre.oval:tst:26972"/>
              <criterion comment="libavcodec51 is earlier than 0.svn20080206-18+lenny1" test_ref="oval:org.mitre.oval:tst:27274"/>
              <criterion comment="ffmpeg is earlier than 0.svn20080206-18+lenny1" test_ref="oval:org.mitre.oval:tst:26831"/>
              <criterion comment="libswscale0 is earlier than 0.svn20080206-18+lenny1" test_ref="oval:org.mitre.oval:tst:27059"/>
              <criterion comment="libavutil-dev is earlier than 0.svn20080206-18+lenny1" test_ref="oval:org.mitre.oval:tst:27390"/>
              <criterion comment="libavformat52 is earlier than 0.svn20080206-18+lenny1" test_ref="oval:org.mitre.oval:tst:27348"/>
              <criterion comment="libpostproc-dev is earlier than 0.svn20080206-18+lenny1" test_ref="oval:org.mitre.oval:tst:26404"/>
              <criterion comment="libpostproc51 is earlier than 0.svn20080206-18+lenny1" test_ref="oval:org.mitre.oval:tst:26659"/>
              <criterion comment="libavdevice52 is earlier than 0.svn20080206-18+lenny1" test_ref="oval:org.mitre.oval:tst:27268"/>
              <criterion comment="libavcodec-dev is earlier than 0.svn20080206-18+lenny1" test_ref="oval:org.mitre.oval:tst:27400"/>
              <criterion comment="libswscale-dev is earlier than 0.svn20080206-18+lenny1" test_ref="oval:org.mitre.oval:tst:27296"/>
              <criterion comment="libavutil49 is earlier than 0.svn20080206-18+lenny1" test_ref="oval:org.mitre.oval:tst:26849"/>
              <criterion comment="libavformat-dev is earlier than 0.svn20080206-18+lenny1" test_ref="oval:org.mitre.oval:tst:27384"/>
              <criterion comment="libavdevice-dev is earlier than 0.svn20080206-18+lenny1" test_ref="oval:org.mitre.oval:tst:26572"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7013" version="3" class="patch">
      <metadata>
        <title>DSA-1979 lintian -- multiple vulnerabilities</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <platform>Debian GNU/Linux 4.0</platform>
          <product>lintian</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2010/dsa-1979" ref_id="DSA-1979"/>
        <description>Multiple vulnerabilities have been discovered in lintian, a Debian package checker. The following Common Vulnerabilities and Exposures project ids have been assigned to identify them: Control field names and values were not sanitised before using them in certain operations that could lead to directory traversals. Patch systems" control files were not sanitised before using them in certain operations that could lead to directory traversals. An attacker could exploit these vulnerabilities to overwrite arbitrary files or disclose system information. Multiple check scripts and the Lintian::Schedule module were using user-provided input as part of the sprintf/printf format string. File names were not properly escaped when passing them as arguments to certain commands, allowing the execution of other commands as pipes or as a set of shell commands.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-05-24T19:10:22-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2010-05-26T13:29:18.725-04:00">DRAFT</status_change>
            <status_change date="2010-06-14T04:00:30.848-04:00">INTERIM</status_change>
            <status_change date="2010-06-29T11:49:16.683-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Release section">
          <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
          <criteria operator="OR" comment="Architecture section">
            <criteria operator="AND" comment="Architecture independent section">
              <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criterion comment="lintian is earlier than 1.24.2.1+lenny1" test_ref="oval:org.mitre.oval:tst:26663"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Release section">
          <extend_definition comment="Debian 4.0 is installed." definition_ref="oval:org.mitre.oval:def:6461"/>
          <criteria operator="OR" comment="Architecture section">
            <criteria operator="AND" comment="Architecture independent section">
              <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criterion comment="lintian is earlier than 1.23.28+etch1" test_ref="oval:org.mitre.oval:tst:26735"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7004" version="3" class="patch">
      <metadata>
        <title>DSA-1972 audiofile -- buffer overflow</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <product>audiofile</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2010/dsa-1972" ref_id="DSA-1972"/>
        <description>Max Kellermann discovered a heap-based buffer overflow in the handling of ADPCM WAV files in libaudiofile. This flaw could result in a denial of service  or possibly execution of arbitrary code via a crafted WAV file. The old stable distribution , this problem will be fixed in version 0.2.6-6+etch1. The packages for the oldstable distribution are not included in this advisory. An update will be released soon.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-05-24T19:10:57-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2010-05-26T13:29:26.925-04:00">DRAFT</status_change>
            <status_change date="2010-06-14T04:00:30.448-04:00">INTERIM</status_change>
            <status_change date="2010-06-29T11:49:16.267-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
        <criteria operator="OR" comment="Architecture section">
          <criteria operator="AND" comment="Architecture dependent section">
            <criteria operator="OR" comment="Supported architectures section">
              <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
              <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
              <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
              <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
              <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
              <criterion comment="Installed architecture is armel" test_ref="oval:org.mitre.oval:tst:11101"/>
              <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
              <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
              <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
              <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
              <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
              <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
            </criteria>
            <criteria operator="OR" comment="Packages section">
              <criterion comment="libaudiofile0 is earlier than 0.2.6-7+lenny1" test_ref="oval:org.mitre.oval:tst:26233"/>
              <criterion comment="libaudiofile0-dbg is earlier than 0.2.6-7+lenny1" test_ref="oval:org.mitre.oval:tst:26963"/>
              <criterion comment="libaudiofile-dev is earlier than 0.2.6-7+lenny1" test_ref="oval:org.mitre.oval:tst:26767"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6994" version="3" class="patch">
      <metadata>
        <title>DSA-2018 php5 -- DoS (crash)</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <product>php5</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2010/dsa-2018" ref_id="DSA-2018"/>
        <description>Auke van Slooten discovered that PHP 5, an hypertext preprocessor, crashes  when processing invalid XML-RPC requests.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-05-24T18:49:53-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2010-05-26T13:27:12.185-04:00">DRAFT</status_change>
            <status_change date="2010-06-14T04:00:29.643-04:00">INTERIM</status_change>
            <status_change date="2010-06-29T11:49:15.141-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
        <criteria operator="OR" comment="Architecture section">
          <criteria operator="AND" comment="Architecture independent section">
            <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
            <criteria operator="OR" comment="Packages section">
              <criterion comment="php-pear is earlier than 5.2.6.dfsg.1-1+lenny8" test_ref="oval:org.mitre.oval:tst:24380"/>
              <criterion comment="php5 is earlier than 5.2.6.dfsg.1-1+lenny8" test_ref="oval:org.mitre.oval:tst:24285"/>
            </criteria>
          </criteria>
          <criteria operator="AND" comment="Architecture dependent section">
            <criteria operator="OR" comment="Supported architectures section">
              <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
              <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
              <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
              <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
              <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
              <criterion comment="Installed architecture is armel" test_ref="oval:org.mitre.oval:tst:11101"/>
              <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
              <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
              <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
              <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
              <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
              <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
            </criteria>
            <criteria operator="OR" comment="Packages section">
              <criterion comment="php5-recode is earlier than 5.2.6.dfsg.1-1+lenny8" test_ref="oval:org.mitre.oval:tst:23443"/>
              <criterion comment="php5-cgi is earlier than 5.2.6.dfsg.1-1+lenny8" test_ref="oval:org.mitre.oval:tst:24240"/>
              <criterion comment="php5-curl is earlier than 5.2.6.dfsg.1-1+lenny8" test_ref="oval:org.mitre.oval:tst:24316"/>
              <criterion comment="php5-snmp is earlier than 5.2.6.dfsg.1-1+lenny8" test_ref="oval:org.mitre.oval:tst:24123"/>
              <criterion comment="php5-mysql is earlier than 5.2.6.dfsg.1-1+lenny8" test_ref="oval:org.mitre.oval:tst:24330"/>
              <criterion comment="php5-odbc is earlier than 5.2.6.dfsg.1-1+lenny8" test_ref="oval:org.mitre.oval:tst:24363"/>
              <criterion comment="php5-xsl is earlier than 5.2.6.dfsg.1-1+lenny8" test_ref="oval:org.mitre.oval:tst:24132"/>
              <criterion comment="php5-gd is earlier than 5.2.6.dfsg.1-1+lenny8" test_ref="oval:org.mitre.oval:tst:23498"/>
              <criterion comment="libapache2-mod-php5 is earlier than 5.2.6.dfsg.1-1+lenny8" test_ref="oval:org.mitre.oval:tst:24422"/>
              <criterion comment="php5-mhash is earlier than 5.2.6.dfsg.1-1+lenny8" test_ref="oval:org.mitre.oval:tst:23830"/>
              <criterion comment="php5-tidy is earlier than 5.2.6.dfsg.1-1+lenny8" test_ref="oval:org.mitre.oval:tst:24242"/>
              <criterion comment="php5-mcrypt is earlier than 5.2.6.dfsg.1-1+lenny8" test_ref="oval:org.mitre.oval:tst:24127"/>
              <criterion comment="php5-dev is earlier than 5.2.6.dfsg.1-1+lenny8" test_ref="oval:org.mitre.oval:tst:24416"/>
              <criterion comment="php5-pgsql is earlier than 5.2.6.dfsg.1-1+lenny8" test_ref="oval:org.mitre.oval:tst:24419"/>
              <criterion comment="php5-gmp is earlier than 5.2.6.dfsg.1-1+lenny8" test_ref="oval:org.mitre.oval:tst:24393"/>
              <criterion comment="php5-xmlrpc is earlier than 5.2.6.dfsg.1-1+lenny8" test_ref="oval:org.mitre.oval:tst:24299"/>
              <criterion comment="php5-imap is earlier than 5.2.6.dfsg.1-1+lenny8" test_ref="oval:org.mitre.oval:tst:24444"/>
              <criterion comment="php5-sqlite is earlier than 5.2.6.dfsg.1-1+lenny8" test_ref="oval:org.mitre.oval:tst:24457"/>
              <criterion comment="php5-ldap is earlier than 5.2.6.dfsg.1-1+lenny8" test_ref="oval:org.mitre.oval:tst:24184"/>
              <criterion comment="php5-cli is earlier than 5.2.6.dfsg.1-1+lenny8" test_ref="oval:org.mitre.oval:tst:24178"/>
              <criterion comment="php5-sybase is earlier than 5.2.6.dfsg.1-1+lenny8" test_ref="oval:org.mitre.oval:tst:24119"/>
              <criterion comment="php5-pspell is earlier than 5.2.6.dfsg.1-1+lenny8" test_ref="oval:org.mitre.oval:tst:24232"/>
              <criterion comment="libapache2-mod-php5filter is earlier than 5.2.6.dfsg.1-1+lenny8" test_ref="oval:org.mitre.oval:tst:24021"/>
              <criterion comment="php5-common is earlier than 5.2.6.dfsg.1-1+lenny8" test_ref="oval:org.mitre.oval:tst:24413"/>
              <criterion comment="php5-dbg is earlier than 5.2.6.dfsg.1-1+lenny8" test_ref="oval:org.mitre.oval:tst:24182"/>
            </criteria>
          </criteria>
          <criteria operator="AND" comment="Architecture dependent section">
            <criteria operator="OR" comment="Supported architectures section">
              <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
              <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
              <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
              <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
            </criteria>
            <criteria operator="OR" comment="Packages section">
              <criterion comment="php5-interbase is earlier than 5.2.6.dfsg.1-1+lenny8" test_ref="oval:org.mitre.oval:tst:24154"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6990" version="3" class="patch">
      <metadata>
        <title>DSA-2028 xpdf -- multiple vulnerabilities</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <product>xpdf</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2010/dsa-2028" ref_id="DSA-2028"/>
        <description>Several vulnerabilities have been identified in xpdf, a suite of tools for viewing and converting Portable Document Format  files. The Common Vulnerabilities and Exposures project identifies the following problems: Integer overflow in SplashBitmap::SplashBitmap which might allow remote attackers to execute arbitrary code or an application crash via a crafted PDF document. NULL pointer dereference or heap-based buffer overflow in Splash::drawImage which might allow remote attackers to cause a denial of service  or possibly execute arbitrary code via a crafted PDF document. Integer overflow in the PSOutputDev::doImageL1Sep which might allow remote attackers to execute arbitrary code via a crafted PDF document. Integer overflow in the ObjectStream::ObjectStream which might allow remote attackers to execute arbitrary code via a crafted PDF document. Integer overflow in the ImageStream::ImageStream which might allow remote attackers to cause a denial of service via a crafted PDF document.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-05-24T19:08:26-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2010-05-26T13:28:54.667-04:00">DRAFT</status_change>
            <status_change date="2010-06-14T04:00:29.372-04:00">INTERIM</status_change>
            <status_change date="2010-06-29T11:49:14.467-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
        <criteria operator="OR" comment="Architecture section">
          <criteria operator="AND" comment="Architecture independent section">
            <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
            <criteria operator="OR" comment="Packages section">
              <criterion comment="xpdf-common is earlier than 3.02-1.4+lenny2" test_ref="oval:org.mitre.oval:tst:26779"/>
              <criterion comment="xpdf is earlier than 3.02-1.4+lenny2" test_ref="oval:org.mitre.oval:tst:26743"/>
            </criteria>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="xpdf-utils is earlier than 3.02-1.4+lenny2" test_ref="oval:org.mitre.oval:tst:26853"/>
            <criterion comment="xpdf-reader is earlier than 3.02-1.4+lenny2" test_ref="oval:org.mitre.oval:tst:26626"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6983" version="3" class="patch">
      <metadata>
        <title>DSA-1954 cacti -- insufficient input sanitising</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <platform>Debian GNU/Linux 4.0</platform>
          <product>cacti</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2009/dsa-1954" ref_id="DSA-1954"/>
        <description>Several vulnerabilities have been found in cacti, a frontend to rrdtool for monitoring systems and services. The Common Vulnerabilities and Exposures project identifies the following problems: It was discovered that cacti is prone to a denial of service via the graph_height, graph_width, graph_start and graph_end parameters. This issue only affects the oldstable  version of cacti. It was discovered that cacti is prone to several cross-site scripting attacks via different vectors. It has been discovered that cacti allows authenticated administrator users to gain access to the host system by executing arbitrary commands via the "Data Input Method" for the "Linux - Get Memory Usage" setting. There is no fix for this issue at this stage. Upstream will implement a whitelist policy to only allow certain "safe" commands. For the moment, we recommend that such access is only given to trusted users and that the options "Data Input" and "User Administration" are otherwise deactivated.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-05-24T19:04:09-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2010-05-26T13:27:48.205-04:00">DRAFT</status_change>
            <status_change date="2010-06-14T04:00:29.108-04:00">INTERIM</status_change>
            <status_change date="2010-06-29T11:49:14.197-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Release section">
          <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
          <criteria operator="OR" comment="Architecture section">
            <criteria operator="AND" comment="Architecture independent section">
              <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criterion comment="cacti is earlier than 0.8.7b-2.1+lenny1" test_ref="oval:org.mitre.oval:tst:25676"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Release section">
          <extend_definition comment="Debian 4.0 is installed." definition_ref="oval:org.mitre.oval:def:6461"/>
          <criteria operator="OR" comment="Architecture section">
            <criteria operator="AND" comment="Architecture independent section">
              <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criterion comment="cacti is earlier than 0.8.6i-3.6" test_ref="oval:org.mitre.oval:tst:25904"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6977" version="3" class="patch">
      <metadata>
        <title>DSA-1962 kvm -- several vulnerabilities</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <product>kvm</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2009/dsa-1962" ref_id="DSA-1962"/>
        <description>Several vulnerabilities have been discovered in kvm, a full virtualization system. The Common Vulnerabilities and Exposures project identifies the following problems: It was discovered an Integer overflow in the kvm_dev_ioctl_get_supported_cpuid function. This allows local users to have an unspecified impact via a KVM_GET_SUPPORTED_CPUID request to the kvm_arch_dev_ioctl function. It was discovered that the handle_dr function in the KVM subsystem does not properly verify the Current Privilege Level  before accessing a debug register, which allows guest OS users to cause a denial of service  on the host OS via a crafted application. It was discovered that the do_insn_fetch function in the x86 emulator in the KVM subsystem tries to interpret instructions that contain too many bytes to be valid, which allows guest OS users to cause a denial of service  on the host OS via unspecified manipulations related to SMP support.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-05-24T19:09:29-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2010-05-26T13:29:07.717-04:00">DRAFT</status_change>
            <status_change date="2010-06-14T04:00:28.794-04:00">INTERIM</status_change>
            <status_change date="2010-06-29T11:49:13.782-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
        <criteria operator="OR" comment="Architecture section">
          <criteria operator="AND" comment="Architecture independent section">
            <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
            <criterion comment="kvm-source is earlier than 72+dfsg-5~lenny4" test_ref="oval:org.mitre.oval:tst:26943"/>
          </criteria>
          <criteria operator="AND" comment="Architecture dependent section">
            <criteria operator="OR" comment="Supported architectures section">
              <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
              <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
            </criteria>
            <criteria operator="OR" comment="Packages section">
              <criterion comment="kvm is earlier than 72+dfsg-5~lenny4" test_ref="oval:org.mitre.oval:tst:26938"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6966" version="3" class="patch">
      <metadata>
        <title>DSA-1951 firefox-sage -- insufficient input sanitising</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <platform>Debian GNU/Linux 4.0</platform>
          <product>firefox-sage</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2009/dsa-1951" ref_id="DSA-1951"/>
        <description>It was discovered that firefox-sage, a lightweight RSS and Atom feed reader for Firefox, does not sanitise the RSS feed information correctly, which makes it prone to a cross-site scripting and a cross-domain scripting attack.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-05-24T19:04:19-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2010-05-26T13:27:49.964-04:00">DRAFT</status_change>
            <status_change date="2010-06-14T04:00:28.531-04:00">INTERIM</status_change>
            <status_change date="2010-06-29T11:49:13.524-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Release section">
          <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
          <criteria operator="OR" comment="Architecture section">
            <criteria operator="AND" comment="Architecture independent section">
              <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criterion comment="firefox-sage is earlier than 1.4.2-0.1+lenny1" test_ref="oval:org.mitre.oval:tst:25348"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Release section">
          <extend_definition comment="Debian 4.0 is installed." definition_ref="oval:org.mitre.oval:def:6461"/>
          <criteria operator="OR" comment="Architecture section">
            <criteria operator="AND" comment="Architecture independent section">
              <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criterion comment="firefox-sage is earlier than 1.3.6-4etch1" test_ref="oval:org.mitre.oval:tst:25727"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6965" version="3" class="patch">
      <metadata>
        <title>DSA-2040 squidguard -- buffer overflow</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <product>squidguard</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2010/dsa-2040" ref_id="DSA-2040"/>
        <description>It was discovered that in squidguard, a URL redirector/filter/ACL plugin for squid, several problems in src/sgLog.c and src/sgDiv.c allow remote users to either:</description>
        <oval_repository>
          <dates>
            <submitted date="2010-05-24T19:05:02-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2010-05-26T13:27:59.220-04:00">DRAFT</status_change>
            <status_change date="2010-06-14T04:00:28.157-04:00">INTERIM</status_change>
            <status_change date="2010-06-29T11:49:13.168-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
        <criteria operator="OR" comment="Architecture section">
          <criteria operator="AND" comment="Architecture dependent section">
            <criteria operator="OR" comment="Supported architectures section">
              <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
              <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
              <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
              <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
              <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
              <criterion comment="Installed architecture is armel" test_ref="oval:org.mitre.oval:tst:11101"/>
              <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
              <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
              <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
              <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
              <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
              <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
            </criteria>
            <criteria operator="OR" comment="Packages section">
              <criterion comment="squidguard is earlier than 1.2.0-8.4+lenny1" test_ref="oval:org.mitre.oval:tst:25059"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6964" version="3" class="patch">
      <metadata>
        <title>DSA-1970 openssl -- denial of service</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <product>openssl</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2010/dsa-1970" ref_id="DSA-1970"/>
        <description>It was discovered that a significant memory leak could occur in OpenSSL, related to the reinitialization of zlib. This could result in a remotely exploitable denial of service vulnerability when using the Apache httpd server in a configuration where mod_ssl, mod_php5, and the php5-curl extension are loaded. The old stable distribution  is not affected by this issue.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-05-24T19:11:02-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2010-05-26T13:29:28.663-04:00">DRAFT</status_change>
            <status_change date="2010-06-14T04:00:27.688-04:00">INTERIM</status_change>
            <status_change date="2010-06-29T11:49:12.733-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
        <criteria operator="OR" comment="Architecture section">
          <criteria operator="AND" comment="Architecture dependent section">
            <criteria operator="OR" comment="Supported architectures section">
              <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
              <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
              <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
              <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
              <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
              <criterion comment="Installed architecture is armel" test_ref="oval:org.mitre.oval:tst:11101"/>
              <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
              <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
              <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
              <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
              <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
            </criteria>
            <criteria operator="OR" comment="Packages section">
              <criterion comment="libssl-dev is earlier than 0.9.8g-15+lenny6" test_ref="oval:org.mitre.oval:tst:26221"/>
              <criterion comment="libssl0.9.8-dbg is earlier than 0.9.8g-15+lenny6" test_ref="oval:org.mitre.oval:tst:26285"/>
              <criterion comment="openssl is earlier than 0.9.8g-15+lenny6" test_ref="oval:org.mitre.oval:tst:27100"/>
              <criterion comment="libssl0.9.8 is earlier than 0.9.8g-15+lenny6" test_ref="oval:org.mitre.oval:tst:27243"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6950" version="3" class="patch">
      <metadata>
        <title>DSA-1952 asterisk -- several vulnerabilities, end-of-life announcement in oldstable</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <product>asterisk</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2009/dsa-1952" ref_id="DSA-1952"/>
        <description>Several vulnerabilities have been discovered in asterisk, an Open Source PBX and telephony toolkit. The Common Vulnerabilities and Exposures project identifies the following problems: It is possible to determine valid login names via probing, due to the IAX2 response from asterisk . It is possible to determine a valid SIP username, when Digest authentication and authalwaysreject are enabled . It is possible to determine a valid SIP username via multiple crafted REGISTER messages . It was discovered that asterisk contains an obsolete copy of the Prototype JavaScript framework, which is vulnerable to several security issues. This copy is unused and now removed from asterisk . It was discovered that it is possible to perform a denial of service attack via RTP comfort noise payload with a long data length . The current version in oldstable is not supported by upstream anymore and is affected by several security issues. Backporting fixes for these and any future issues has become unfeasible and therefore we need to drop our security support for the version in oldstable. We recommend that all asterisk users upgrade to the stable distribution .</description>
        <oval_repository>
          <dates>
            <submitted date="2010-05-24T19:04:25-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2010-05-26T13:27:52.565-04:00">DRAFT</status_change>
            <status_change date="2010-06-14T04:00:26.959-04:00">INTERIM</status_change>
            <status_change date="2010-06-29T11:49:12.441-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
        <criteria operator="OR" comment="Architecture section">
          <criteria operator="AND" comment="Architecture independent section">
            <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
            <criteria operator="OR" comment="Packages section">
              <criterion comment="asterisk-doc is earlier than 1.4.21.2~dfsg-3+lenny1" test_ref="oval:org.mitre.oval:tst:25433"/>
              <criterion comment="asterisk-dev is earlier than 1.4.21.2~dfsg-3+lenny1" test_ref="oval:org.mitre.oval:tst:25629"/>
              <criterion comment="asterisk-config is earlier than 1.4.21.2~dfsg-3+lenny1" test_ref="oval:org.mitre.oval:tst:25245"/>
              <criterion comment="asterisk-sounds-main is earlier than 1.4.21.2~dfsg-3+lenny1" test_ref="oval:org.mitre.oval:tst:25616"/>
            </criteria>
          </criteria>
          <criteria operator="OR" comment="Packages section">
            <criterion comment="asterisk-h323 is earlier than 1.4.21.2~dfsg-3+lenny1" test_ref="oval:org.mitre.oval:tst:25539"/>
            <criterion comment="asterisk is earlier than 1.4.21.2~dfsg-3+lenny1" test_ref="oval:org.mitre.oval:tst:25873"/>
            <criterion comment="asterisk-dbg is earlier than 1.4.21.2~dfsg-3+lenny1" test_ref="oval:org.mitre.oval:tst:25771"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6923" version="3" class="patch">
      <metadata>
        <title>DSA-1988 qt4-x11 -- several vulnerabilities</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <product>qt4-x11</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2010/dsa-1988" ref_id="DSA-1988"/>
        <description>Several vulnerabilities have been discovered in qt4-x11, a cross-platform C++ application framework. The Common Vulnerabilities and Exposures project identifies the following problems: Array index error in the insertItemBefore method in WebKit, as used in qt4-x11, allows remote attackers to execute arbitrary code. The JavaScript garbage collector in WebKit, as used in qt4-x11 does not properly handle allocation failures, which allows remote attackers to execute arbitrary code or cause a denial of service  via a crafted HTML document that triggers write access to an "offset of a NULL pointer. Use-after-free vulnerability in WebKit, as used in qt4-x11, allows remote attackers to execute arbitrary code or cause a denial of service  by setting an unspecified property of an HTML tag that causes child elements to be freed and later accessed when an HTML error occurs. WebKit in qt4-x11 does not initialize a pointer during handling of a Cascading Style Sheets  attr function call with a large numerical argument, which allows remote attackers to execute arbitrary code or cause a denial of service  via a crafted HTML document. The XSL stylesheet implementation in WebKit, as used in qt4-x11 does not properly handle XML external entities, which allows remote attackers to read arbitrary files via a crafted DTD. WebKit in qt4-x11 does not properly initialize memory for Attr DOM objects, which allows remote attackers to execute arbitrary code or cause a denial of service  via a crafted HTML document. WebKit in qt4-x11 does not prevent remote loading of local Java applets, which allows remote attackers to execute arbitrary code, gain privileges, or obtain sensitive information via an APPLET or OBJECT element. The XSLT functionality in WebKit, as used in qt4-x11 does not properly implement the document function, which allows remote attackers to read arbitrary local files and files from different security zones. WebKit in qt4-x11 does not properly handle numeric character references, which allows remote attackers to execute arbitrary code or cause a denial of service  via a crafted HTML document. qt4-x11 does not properly handle a "\0" character in a domain name in the Subject Alternative Name field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority. The oldstable distribution  is not affected by these problems.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-05-24T19:05:28-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2010-05-26T13:28:09.478-04:00">DRAFT</status_change>
            <status_change date="2010-06-14T04:00:26.134-04:00">INTERIM</status_change>
            <status_change date="2010-06-29T11:49:10.173-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
        <criteria operator="OR" comment="Architecture section">
          <criteria operator="AND" comment="Architecture independent section">
            <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
            <criteria operator="OR" comment="Packages section">
              <criterion comment="qt4-doc is earlier than 4.4.3-1+lenny1" test_ref="oval:org.mitre.oval:tst:25809"/>
              <criterion comment="qt4-doc-html is earlier than 4.4.3-1+lenny1" test_ref="oval:org.mitre.oval:tst:25899"/>
            </criteria>
          </criteria>
          <criteria operator="AND" comment="Architecture dependent section">
            <criteria operator="OR" comment="Supported architectures section">
              <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
              <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
              <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
              <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
              <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
              <criterion comment="Installed architecture is armel" test_ref="oval:org.mitre.oval:tst:11101"/>
              <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
              <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
              <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
              <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
              <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
            </criteria>
            <criteria operator="OR" comment="Packages section">
              <criterion comment="libqtgui4 is earlier than 4.4.3-1+lenny1" test_ref="oval:org.mitre.oval:tst:25955"/>
              <criterion comment="qt4-dev-tools is earlier than 4.4.3-1+lenny1" test_ref="oval:org.mitre.oval:tst:25778"/>
              <criterion comment="libqt4-designer is earlier than 4.4.3-1+lenny1" test_ref="oval:org.mitre.oval:tst:25957"/>
              <criterion comment="libqt4-core is earlier than 4.4.3-1+lenny1" test_ref="oval:org.mitre.oval:tst:25875"/>
              <criterion comment="libqt4-webkit is earlier than 4.4.3-1+lenny1" test_ref="oval:org.mitre.oval:tst:25436"/>
              <criterion comment="libqt4-sql-sqlite2 is earlier than 4.4.3-1+lenny1" test_ref="oval:org.mitre.oval:tst:25883"/>
              <criterion comment="libqt4-svg is earlier than 4.4.3-1+lenny1" test_ref="oval:org.mitre.oval:tst:25864"/>
              <criterion comment="libqtcore4 is earlier than 4.4.3-1+lenny1" test_ref="oval:org.mitre.oval:tst:25930"/>
              <criterion comment="qt4-designer is earlier than 4.4.3-1+lenny1" test_ref="oval:org.mitre.oval:tst:25845"/>
              <criterion comment="qt4-demos is earlier than 4.4.3-1+lenny1" test_ref="oval:org.mitre.oval:tst:25895"/>
              <criterion comment="libqt4-gui is earlier than 4.4.3-1+lenny1" test_ref="oval:org.mitre.oval:tst:25680"/>
              <criterion comment="libqt4-help is earlier than 4.4.3-1+lenny1" test_ref="oval:org.mitre.oval:tst:25819"/>
              <criterion comment="libqt4-dbus is earlier than 4.4.3-1+lenny1" test_ref="oval:org.mitre.oval:tst:25683"/>
              <criterion comment="libqt4-sql-odbc is earlier than 4.4.3-1+lenny1" test_ref="oval:org.mitre.oval:tst:25954"/>
              <criterion comment="libqt4-script is earlier than 4.4.3-1+lenny1" test_ref="oval:org.mitre.oval:tst:25688"/>
              <criterion comment="libqt4-xml is earlier than 4.4.3-1+lenny1" test_ref="oval:org.mitre.oval:tst:25756"/>
              <criterion comment="libqt4-network is earlier than 4.4.3-1+lenny1" test_ref="oval:org.mitre.oval:tst:25672"/>
              <criterion comment="libqt4-opengl is earlier than 4.4.3-1+lenny1" test_ref="oval:org.mitre.oval:tst:25963"/>
              <criterion comment="libqt4-assistant is earlier than 4.4.3-1+lenny1" test_ref="oval:org.mitre.oval:tst:25682"/>
              <criterion comment="libqt4-dev is earlier than 4.4.3-1+lenny1" test_ref="oval:org.mitre.oval:tst:25671"/>
              <criterion comment="qt4-qmake is earlier than 4.4.3-1+lenny1" test_ref="oval:org.mitre.oval:tst:25652"/>
              <criterion comment="libqt4-xmlpatterns-dbg is earlier than 4.4.3-1+lenny1" test_ref="oval:org.mitre.oval:tst:24995"/>
              <criterion comment="libqt4-qt3support is earlier than 4.4.3-1+lenny1" test_ref="oval:org.mitre.oval:tst:25852"/>
              <criterion comment="libqt4-sql-mysql is earlier than 4.4.3-1+lenny1" test_ref="oval:org.mitre.oval:tst:25848"/>
              <criterion comment="libqt4-test is earlier than 4.4.3-1+lenny1" test_ref="oval:org.mitre.oval:tst:25768"/>
              <criterion comment="libqt4-opengl-dev is earlier than 4.4.3-1+lenny1" test_ref="oval:org.mitre.oval:tst:25050"/>
              <criterion comment="libqt4-webkit-dbg is earlier than 4.4.3-1+lenny1" test_ref="oval:org.mitre.oval:tst:26022"/>
              <criterion comment="libqt4-sql-sqlite is earlier than 4.4.3-1+lenny1" test_ref="oval:org.mitre.oval:tst:25822"/>
              <criterion comment="libqt4-sql is earlier than 4.4.3-1+lenny1" test_ref="oval:org.mitre.oval:tst:25927"/>
              <criterion comment="libqt4-xmlpatterns is earlier than 4.4.3-1+lenny1" test_ref="oval:org.mitre.oval:tst:25458"/>
              <criterion comment="libqt4-dbg is earlier than 4.4.3-1+lenny1" test_ref="oval:org.mitre.oval:tst:25995"/>
              <criterion comment="qt4-qtconfig is earlier than 4.4.3-1+lenny1" test_ref="oval:org.mitre.oval:tst:25528"/>
              <criterion comment="libqt4-sql-psql is earlier than 4.4.3-1+lenny1" test_ref="oval:org.mitre.oval:tst:26036"/>
            </criteria>
          </criteria>
          <criteria operator="AND" comment="Architecture dependent section">
            <criteria operator="OR" comment="Supported architectures section">
              <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
              <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
              <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
              <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
            </criteria>
            <criteria operator="OR" comment="Packages section">
              <criterion comment="libqt4-sql-ibase is earlier than 4.4.3-1+lenny1" test_ref="oval:org.mitre.oval:tst:25865"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6920" version="1" class="patch">
      <metadata>
        <title>DSA-1797 xulrunner -- several vulnerabilities</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <product>xulrunner</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2009/dsa-1797" ref_id="DSA-1797"/>
        <description>Several remote vulnerabilities have been discovered in Xulrunner, a runtime environment for XUL applications, such as the Iceweasel web browser. The Common Vulnerabilities and Exposures project identifies the following problems: Moxie Marlinspike discovered that Unicode box drawing characters inside of internationalised domain names could be used for phishing attacks. Olli Pettay, Martijn Wargers, Mats Palmgren, Oleg Romashin, Jesse Ruderman and Gary Kwong reported crashes in the layout engine, which might allow the execution of arbitrary code. Olli Pettay, Martijn Wargers, Mats Palmgren, Oleg Romashin, Jesse Ruderman and Gary Kwong reported crashes in the layout engine, which might allow the execution of arbitrary code. Igor Bukanov and Bob Clary discovered crashes in the Javascript engine, which might allow the execution of arbitrary code. Igor Bukanov and Bob Clary discovered crashes in the Javascript engine, which might allow the execution of arbitrary code. Daniel Veditz discovered that the Content-Disposition: header is ignored within the jar: URI scheme. Gregory Fleischer discovered that the same-origin policy for Flash files is inproperly enforced for files loaded through the view-source scheme, which may result in bypass of cross-domain policy restrictions. Cefn Hoile discovered that sites, which allow the embedding of third-party stylesheets are vulnerable to cross-site scripting attacks through XBL bindings. "moz_bug_r_a4" discovered bypasses of the same-origin policy in the XMLHttpRequest Javascript API and the XPCNativeWrapper. Paolo Amadini discovered that incorrect handling of POST data when saving a web site with an embedded frame may lead to information disclosure. It was discovered that Iceweasel allows Refresh: headers to redirect to Javascript URIs, resulting in cross-site scripting.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-15T20:12:03-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-28T07:49:05.605-05:00">DRAFT</status_change>
            <status_change date="2010-01-18T04:00:21.304-05:00">INTERIM</status_change>
            <status_change date="2010-02-08T04:00:11.289-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
        <criteria operator="OR" comment="Architecture section">
          <criteria operator="AND" comment="Architecture independent section">
            <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
            <criterion comment="libmozillainterfaces-java is earlier than 1.9.0.9-0lenny2" test_ref="oval:org.mitre.oval:tst:11771"/>
          </criteria>
          <criteria operator="AND" comment="Architecture dependent section">
            <criteria operator="OR" comment="Supported architectures section">
              <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
              <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
              <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
              <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
              <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
              <criterion comment="Installed architecture is armel" test_ref="oval:org.mitre.oval:tst:11101"/>
              <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
              <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
              <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
              <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
              <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
              <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
            </criteria>
            <criteria operator="OR" comment="Packages section">
              <criterion comment="libmozjs-dev is earlier than 1.9.0.9-0lenny2" test_ref="oval:org.mitre.oval:tst:12013"/>
              <criterion comment="spidermonkey-bin is earlier than 1.9.0.9-0lenny2" test_ref="oval:org.mitre.oval:tst:11817"/>
              <criterion comment="xulrunner-1.9-gnome-support is earlier than 1.9.0.9-0lenny2" test_ref="oval:org.mitre.oval:tst:40979"/>
              <criterion comment="xulrunner-1.9 is earlier than 1.9.0.9-0lenny2" test_ref="oval:org.mitre.oval:tst:12047"/>
              <criterion comment="libmozjs1d-dbg is earlier than 1.9.0.9-0lenny2" test_ref="oval:org.mitre.oval:tst:11136"/>
              <criterion comment="libmozjs1d is earlier than 1.9.0.9-0lenny2" test_ref="oval:org.mitre.oval:tst:11828"/>
              <criterion comment="python-xpcom is earlier than 1.9.0.9-0lenny2" test_ref="oval:org.mitre.oval:tst:11845"/>
              <criterion comment="xulrunner-1.9-dbg is earlier than 1.9.0.9-0lenny2" test_ref="oval:org.mitre.oval:tst:12064"/>
              <criterion comment="xulrunner-dev is earlier than 1.9.0.9-0lenny2" test_ref="oval:org.mitre.oval:tst:12083"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6917" version="3" class="patch">
      <metadata>
        <title>DSA-2011 dpkg -- path traversal</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <product>dpkg</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2010/dsa-2011" ref_id="DSA-2011"/>
        <description>William Grant discovered that the dpkg-source component of dpkg, the low-level infrastructure for handling the installation and removal of Debian software packages, is vulnerable to path traversal attacks. A specially crafted Debian source package can lead to file modification outside of the destination directory when extracting the package content.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-05-24T19:02:12-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2010-05-26T13:27:38.976-04:00">DRAFT</status_change>
            <status_change date="2010-06-14T04:00:25.646-04:00">INTERIM</status_change>
            <status_change date="2010-06-29T11:49:09.638-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
        <criteria operator="OR" comment="Architecture section">
          <criteria operator="AND" comment="Architecture independent section">
            <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
            <criterion comment="dpkg-dev is earlier than 1.14.29" test_ref="oval:org.mitre.oval:tst:25343"/>
          </criteria>
          <criteria operator="AND" comment="Architecture dependent section">
            <criteria operator="OR" comment="Supported architectures section">
              <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
              <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
              <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
              <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
              <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
              <criterion comment="Installed architecture is armel" test_ref="oval:org.mitre.oval:tst:11101"/>
              <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
              <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
              <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
              <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
              <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
              <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
            </criteria>
            <criteria operator="OR" comment="Packages section">
              <criterion comment="dselect is earlier than 1.14.29" test_ref="oval:org.mitre.oval:tst:25439"/>
              <criterion comment="dpkg is earlier than 1.14.29" test_ref="oval:org.mitre.oval:tst:25442"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6910" version="3" class="patch">
      <metadata>
        <title>DSA-1995 openoffice.org -- several vulnerabilities</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <platform>Debian GNU/Linux 4.0</platform>
          <product>openoffice.org</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2010/dsa-1995" ref_id="DSA-1995"/>
        <description>Several vulnerabilities have been discovered in the OpenOffice.org office suite. The Common Vulnerabilities and Exposures project identifies the following problems: It was discovered that macro security settings were insufficiently enforced for VBA macros. It was discovered that the W3C XML Signature recommendation contains a protocol-level vulnerability related to HMAC output truncation. This also affects the integrated libxmlsec library. Sebastian Apelt discovered that an integer overflow in the XPM import code may lead to the execution of arbitrary code. Sebastian Apelt and Frank Reissner discovered that a buffer overflow in the GIF import code may lead to the execution of arbitrary code. Nicolas Joly discovered multiple vulnerabilities in the parser for Word document files, which may lead to the execution of arbitrary code.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-05-24T19:06:04-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2010-05-26T13:28:37.698-04:00">DRAFT</status_change>
            <status_change date="2010-06-14T04:00:20.301-04:00">INTERIM</status_change>
            <status_change date="2010-06-29T11:49:04.363-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Release section">
          <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
          <criteria operator="OR" comment="Architecture section">
            <criteria operator="AND" comment="Architecture independent section">
              <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criteria operator="OR" comment="Packages section">
                <criterion comment="openoffice.org-dtd-officedocument1.0 is earlier than 2.4.1+dfsg-1+lenny6" test_ref="oval:org.mitre.oval:tst:25880"/>
                <criterion comment="openoffice.org-l10n-cy is earlier than 2.4.1+dfsg-1+lenny6" test_ref="oval:org.mitre.oval:tst:25932"/>
                <criterion comment="openoffice.org-l10n-cs is earlier than 2.4.1+dfsg-1+lenny6" test_ref="oval:org.mitre.oval:tst:25278"/>
                <criterion comment="openoffice.org-help-hu is earlier than 2.4.1+dfsg-1+lenny6" test_ref="oval:org.mitre.oval:tst:25347"/>
                <criterion comment="openoffice.org-l10n-vi is earlier than 2.4.1+dfsg-1+lenny6" test_ref="oval:org.mitre.oval:tst:25803"/>
                <criterion comment="openoffice.org-l10n-ca is earlier than 2.4.1+dfsg-1+lenny5" test_ref="oval:org.mitre.oval:tst:25888"/>
                <criterion comment="openoffice.org-style-industrial is earlier than 2.4.1+dfsg-1+lenny6" test_ref="oval:org.mitre.oval:tst:26001"/>
                <criterion comment="openoffice.org-help-en-us is earlier than 2.4.1+dfsg-1+lenny6" test_ref="oval:org.mitre.oval:tst:25088"/>
                <criterion comment="ttf-opensymbol is earlier than 2.4.1+dfsg-1+lenny4" test_ref="oval:org.mitre.oval:tst:26002"/>
                <criterion comment="openoffice.org-l10n-ka is earlier than 2.4.1+dfsg-1+lenny4" test_ref="oval:org.mitre.oval:tst:26038"/>
                <criterion comment="openoffice.org-l10n-km is earlier than 2.4.1+dfsg-1+lenny4" test_ref="oval:org.mitre.oval:tst:25935"/>
                <criterion comment="openoffice.org-l10n-ko is earlier than 2.4.1+dfsg-1+lenny6" test_ref="oval:org.mitre.oval:tst:26074"/>
                <criterion comment="openoffice.org-l10n-pl is earlier than 2.4.1+dfsg-1+lenny4" test_ref="oval:org.mitre.oval:tst:25846"/>
                <criterion comment="broffice.org is earlier than 2.4.1+dfsg-1+lenny4" test_ref="oval:org.mitre.oval:tst:25993"/>
                <criterion comment="openoffice.org-l10n-ku is earlier than 2.4.1+dfsg-1+lenny4" test_ref="oval:org.mitre.oval:tst:25814"/>
                <criterion comment="openoffice.org-l10n-pt is earlier than 2.4.1+dfsg-1+lenny4" test_ref="oval:org.mitre.oval:tst:25728"/>
                <criterion comment="openoffice.org-l10n-xh is earlier than 2.4.1+dfsg-1+lenny4" test_ref="oval:org.mitre.oval:tst:26060"/>
                <criterion comment="openoffice.org-help-pt is earlier than 2.4.1+dfsg-1+lenny4" test_ref="oval:org.mitre.oval:tst:25644"/>
                <criterion comment="openoffice.org-help-it is earlier than 2.4.1+dfsg-1+lenny6" test_ref="oval:org.mitre.oval:tst:25108"/>
                <criterion comment="openoffice.org-l10n-te-in is earlier than 2.4.1+dfsg-1+lenny4" test_ref="oval:org.mitre.oval:tst:26009"/>
                <criterion comment="openoffice.org-l10n-be-by is earlier than 2.4.1+dfsg-1+lenny5" test_ref="oval:org.mitre.oval:tst:26054"/>
                <criterion comment="openoffice.org-l10n-eu is earlier than 2.4.1+dfsg-1+lenny4" test_ref="oval:org.mitre.oval:tst:25951"/>
                <criterion comment="openoffice.org-l10n-hr is earlier than 2.4.1+dfsg-1+lenny6" test_ref="oval:org.mitre.oval:tst:26080"/>
                <criterion comment="openoffice.org-l10n-hu is earlier than 2.4.1+dfsg-1+lenny5" test_ref="oval:org.mitre.oval:tst:25981"/>
                <criterion comment="openoffice.org-l10n-mk is earlier than 2.4.1+dfsg-1+lenny6" test_ref="oval:org.mitre.oval:tst:25374"/>
                <criterion comment="openoffice.org-l10n-ru is earlier than 2.4.1+dfsg-1+lenny4" test_ref="oval:org.mitre.oval:tst:25737"/>
                <criterion comment="openoffice.org-l10n-he is earlier than 2.4.1+dfsg-1+lenny5" test_ref="oval:org.mitre.oval:tst:25924"/>
                <criterion comment="openoffice.org-l10n-en-za is earlier than 2.4.1+dfsg-1+lenny6" test_ref="oval:org.mitre.oval:tst:26042"/>
                <criterion comment="libuno-cli-types1.1-cil is earlier than 1.1.13.0+OOo2.4.1+dfsg-1+lenny5" test_ref="oval:org.mitre.oval:tst:25917"/>
                <criterion comment="openoffice.org-l10n-as-in is earlier than 2.4.1+dfsg-1+lenny4" test_ref="oval:org.mitre.oval:tst:25999"/>
                <criterion comment="openoffice.org-l10n-ta-in is earlier than 2.4.1+dfsg-1+lenny4" test_ref="oval:org.mitre.oval:tst:25985"/>
                <criterion comment="openoffice.org-help-nl is earlier than 2.4.1+dfsg-1+lenny4" test_ref="oval:org.mitre.oval:tst:26021"/>
                <criterion comment="openoffice.org-l10n-eo is earlier than 2.4.1+dfsg-1+lenny6" test_ref="oval:org.mitre.oval:tst:26084"/>
                <criterion comment="openoffice.org-l10n-el is earlier than 2.4.1+dfsg-1+lenny5" test_ref="oval:org.mitre.oval:tst:25976"/>
                <criterion comment="openoffice.org-l10n-ro is earlier than 2.4.1+dfsg-1+lenny4" test_ref="oval:org.mitre.oval:tst:26012"/>
                <criterion comment="openoffice.org-l10n-zu is earlier than 2.4.1+dfsg-1+lenny4" test_ref="oval:org.mitre.oval:tst:25631"/>
                <criterion comment="openoffice.org-l10n-hi-in is earlier than 2.4.1+dfsg-1+lenny6" test_ref="oval:org.mitre.oval:tst:25659"/>
                <criterion comment="openoffice.org-l10n-zh-tw is earlier than 2.4.1+dfsg-1+lenny6" test_ref="oval:org.mitre.oval:tst:26027"/>
                <criterion comment="openoffice.org-l10n-za is earlier than 2.4.1+dfsg-1+lenny6" test_ref="oval:org.mitre.oval:tst:26076"/>
                <criterion comment="openoffice.org-l10n-et is earlier than 2.4.1+dfsg-1+lenny6" test_ref="oval:org.mitre.oval:tst:26065"/>
                <criterion comment="openoffice.org-help-fr is earlier than 2.4.1+dfsg-1+lenny4" test_ref="oval:org.mitre.oval:tst:25703"/>
                <criterion comment="openoffice.org-l10n-rw is earlier than 2.4.1+dfsg-1+lenny6" test_ref="oval:org.mitre.oval:tst:25739"/>
                <criterion comment="openoffice.org-l10n-es is earlier than 2.4.1+dfsg-1+lenny4" test_ref="oval:org.mitre.oval:tst:26020"/>
                <criterion comment="openoffice.org-l10n-sr-cs is earlier than 2.4.1+dfsg-1+lenny5" test_ref="oval:org.mitre.oval:tst:25455"/>
                <criterion comment="openoffice.org-l10n-bs is earlier than 2.4.1+dfsg-1+lenny6" test_ref="oval:org.mitre.oval:tst:25787"/>
                <criterion comment="openoffice.org-l10n-br is earlier than 2.4.1+dfsg-1+lenny5" test_ref="oval:org.mitre.oval:tst:25879"/>
                <criterion comment="openoffice.org-style-tango is earlier than 2.4.1+dfsg-1+lenny5" test_ref="oval:org.mitre.oval:tst:26094"/>
                <criterion comment="openoffice.org-style-andromeda is earlier than 2.4.1+dfsg-1+lenny4" test_ref="oval:org.mitre.oval:tst:26033"/>
                <criterion comment="openoffice.org-l10n-bn is earlier than 2.4.1+dfsg-1+lenny4" test_ref="oval:org.mitre.oval:tst:25804"/>
                <criterion comment="openoffice.org-emailmerge is earlier than 2.4.1+dfsg-1+lenny4" test_ref="oval:org.mitre.oval:tst:25128"/>
                <criterion comment="openoffice.org-l10n-sl is earlier than 2.4.1+dfsg-1+lenny4" test_ref="oval:org.mitre.oval:tst:26005"/>
                <criterion comment="openoffice.org-l10n-ja is earlier than 2.4.1+dfsg-1+lenny4" test_ref="oval:org.mitre.oval:tst:26051"/>
                <criterion comment="openoffice.org-l10n-en-gb is earlier than 2.4.1+dfsg-1+lenny4" test_ref="oval:org.mitre.oval:tst:26107"/>
                <criterion comment="openoffice.org-help-gl is earlier than 2.4.1+dfsg-1+lenny5" test_ref="oval:org.mitre.oval:tst:25774"/>
                <criterion comment="openoffice.org-l10n-sk is earlier than 2.4.1+dfsg-1+lenny4" test_ref="oval:org.mitre.oval:tst:25944"/>
                <criterion comment="openoffice.org-l10n-ga is earlier than 2.4.1+dfsg-1+lenny4" test_ref="oval:org.mitre.oval:tst:26072"/>
                <criterion comment="openoffice.org-l10n-st is earlier than 2.4.1+dfsg-1+lenny5" test_ref="oval:org.mitre.oval:tst:25283"/>
                <criterion comment="openoffice.org-l10n-sv is earlier than 2.4.1+dfsg-1+lenny5" test_ref="oval:org.mitre.oval:tst:25920"/>
                <criterion comment="openoffice.org-l10n-sr is earlier than 2.4.1+dfsg-1+lenny5" test_ref="oval:org.mitre.oval:tst:25734"/>
                <criterion comment="openoffice.org-l10n-ss is earlier than 2.4.1+dfsg-1+lenny4" test_ref="oval:org.mitre.oval:tst:26093"/>
                <criterion comment="openoffice.org-help-sv is earlier than 2.4.1+dfsg-1+lenny6" test_ref="oval:org.mitre.oval:tst:26096"/>
                <criterion comment="openoffice.org-style-hicontrast is earlier than 2.4.1+dfsg-1+lenny5" test_ref="oval:org.mitre.oval:tst:26047"/>
                <criterion comment="openoffice.org-help-dz is earlier than 2.4.1+dfsg-1+lenny6" test_ref="oval:org.mitre.oval:tst:25984"/>
                <criterion comment="openoffice.org-help-da is earlier than 2.4.1+dfsg-1+lenny4" test_ref="oval:org.mitre.oval:tst:25614"/>
                <criterion comment="openoffice.org-help-de is earlier than 2.4.1+dfsg-1+lenny6" test_ref="oval:org.mitre.oval:tst:26030"/>
                <criterion comment="openoffice.org-help-sl is earlier than 2.4.1+dfsg-1+lenny6" test_ref="oval:org.mitre.oval:tst:25132"/>
                <criterion comment="openoffice.org-l10n-gl is earlier than 2.4.1+dfsg-1+lenny4" test_ref="oval:org.mitre.oval:tst:25945"/>
                <criterion comment="openoffice.org-java-common is earlier than 2.4.1+dfsg-1+lenny5" test_ref="oval:org.mitre.oval:tst:25709"/>
                <criterion comment="openoffice.org-l10n-bg is earlier than 2.4.1+dfsg-1+lenny6" test_ref="oval:org.mitre.oval:tst:25533"/>
                <criterion comment="openoffice.org-l10n-ts is earlier than 2.4.1+dfsg-1+lenny4" test_ref="oval:org.mitre.oval:tst:25941"/>
                <criterion comment="openoffice.org-l10n-tr is earlier than 2.4.1+dfsg-1+lenny5" test_ref="oval:org.mitre.oval:tst:26104"/>
                <criterion comment="openoffice.org-l10n-tn is earlier than 2.4.1+dfsg-1+lenny6" test_ref="oval:org.mitre.oval:tst:25655"/>
                <criterion comment="openoffice.org-l10n-th is earlier than 2.4.1+dfsg-1+lenny4" test_ref="oval:org.mitre.oval:tst:26100"/>
                <criterion comment="openoffice.org-l10n-tg is earlier than 2.4.1+dfsg-1+lenny4" test_ref="oval:org.mitre.oval:tst:25794"/>
                <criterion comment="openoffice.org-help-et is earlier than 2.4.1+dfsg-1+lenny4" test_ref="oval:org.mitre.oval:tst:25390"/>
                <criterion comment="openoffice.org-help-eu is earlier than 2.4.1+dfsg-1+lenny5" test_ref="oval:org.mitre.oval:tst:26000"/>
                <criterion comment="libuno-cli-basetypes1.0-cil is earlier than 1.0.10.0+OOo2.4.1+dfsg-1+lenny5" test_ref="oval:org.mitre.oval:tst:25808"/>
                <criterion comment="openoffice.org-help-es is earlier than 2.4.1+dfsg-1+lenny5" test_ref="oval:org.mitre.oval:tst:25112"/>
                <criterion comment="openoffice.org-filter-mobiledev is earlier than 2.4.1+dfsg-1+lenny4" test_ref="oval:org.mitre.oval:tst:25596"/>
                <criterion comment="openoffice.org-l10n-or-in is earlier than 2.4.1+dfsg-1+lenny6" test_ref="oval:org.mitre.oval:tst:26061"/>
                <criterion comment="openoffice.org-l10n-lt is earlier than 2.4.1+dfsg-1+lenny6" test_ref="oval:org.mitre.oval:tst:25744"/>
                <criterion comment="openoffice.org-l10n-lv is earlier than 2.4.1+dfsg-1+lenny5" test_ref="oval:org.mitre.oval:tst:26073"/>
                <criterion comment="openoffice.org-l10n-uz is earlier than 2.4.1+dfsg-1+lenny4" test_ref="oval:org.mitre.oval:tst:25517"/>
                <criterion comment="openoffice.org-l10n-de is earlier than 2.4.1+dfsg-1+lenny4" test_ref="oval:org.mitre.oval:tst:25994"/>
                <criterion comment="openoffice.org-l10n-da is earlier than 2.4.1+dfsg-1+lenny5" test_ref="oval:org.mitre.oval:tst:25761"/>
                <criterion comment="openoffice.org-l10n-uk is earlier than 2.4.1+dfsg-1+lenny5" test_ref="oval:org.mitre.oval:tst:25779"/>
                <criterion comment="openoffice.org-l10n-dz is earlier than 2.4.1+dfsg-1+lenny5" test_ref="oval:org.mitre.oval:tst:25114"/>
                <criterion comment="libuno-cli-cppuhelper1.0-cil is earlier than 1.0.13.0+OOo2.4.1+dfsg-1+lenny6" test_ref="oval:org.mitre.oval:tst:25129"/>
                <criterion comment="openoffice.org-l10n-lo is earlier than 2.4.1+dfsg-1+lenny4" test_ref="oval:org.mitre.oval:tst:25890"/>
                <criterion comment="libuno-cli-ure1.0-cil is earlier than 1.0.13.0+OOo2.4.1+dfsg-1+lenny4" test_ref="oval:org.mitre.oval:tst:25843"/>
                <criterion comment="openoffice.org-l10n-ar is earlier than 2.4.1+dfsg-1+lenny6" test_ref="oval:org.mitre.oval:tst:26079"/>
                <criterion comment="openoffice.org-l10n-ml-in is earlier than 2.4.1+dfsg-1+lenny6" test_ref="oval:org.mitre.oval:tst:25673"/>
                <criterion comment="openoffice.org-help-en-gb is earlier than 2.4.1+dfsg-1+lenny4" test_ref="oval:org.mitre.oval:tst:25979"/>
                <criterion comment="openoffice.org-l10n-af is earlier than 2.4.1+dfsg-1+lenny6" test_ref="oval:org.mitre.oval:tst:26085"/>
                <criterion comment="openoffice.org-common is earlier than 2.4.1+dfsg-1+lenny4" test_ref="oval:org.mitre.oval:tst:25605"/>
                <criterion comment="openoffice.org-help-ja is earlier than 2.4.1+dfsg-1+lenny5" test_ref="oval:org.mitre.oval:tst:26114"/>
                <criterion comment="openoffice.org-l10n-zh-cn is earlier than 2.4.1+dfsg-1+lenny5" test_ref="oval:org.mitre.oval:tst:25782"/>
                <criterion comment="openoffice.org-l10n-ve is earlier than 2.4.1+dfsg-1+lenny6" test_ref="oval:org.mitre.oval:tst:25669"/>
                <criterion comment="openoffice.org-help-zh-cn is earlier than 2.4.1+dfsg-1+lenny6" test_ref="oval:org.mitre.oval:tst:25653"/>
                <criterion comment="openoffice.org-l10n-it is earlier than 2.4.1+dfsg-1+lenny4" test_ref="oval:org.mitre.oval:tst:25965"/>
                <criterion comment="openoffice.org-l10n-gu-in is earlier than 2.4.1+dfsg-1+lenny6" test_ref="oval:org.mitre.oval:tst:26069"/>
                <criterion comment="openoffice.org-l10n-nl is earlier than 2.4.1+dfsg-1+lenny6" test_ref="oval:org.mitre.oval:tst:26064"/>
                <criterion comment="openoffice.org-l10n-in is earlier than 2.4.1+dfsg-1+lenny6" test_ref="oval:org.mitre.oval:tst:25733"/>
                <criterion comment="openoffice.org-help-zh-tw is earlier than 2.4.1+dfsg-1+lenny4" test_ref="oval:org.mitre.oval:tst:25711"/>
                <criterion comment="openoffice.org-style-crystal is earlier than 2.4.1+dfsg-1+lenny5" test_ref="oval:org.mitre.oval:tst:25359"/>
                <criterion comment="openoffice.org-l10n-mr-in is earlier than 2.4.1+dfsg-1+lenny5" test_ref="oval:org.mitre.oval:tst:26025"/>
                <criterion comment="openoffice.org-help-ru is earlier than 2.4.1+dfsg-1+lenny5" test_ref="oval:org.mitre.oval:tst:26024"/>
                <criterion comment="openoffice.org-l10n-fr is earlier than 2.4.1+dfsg-1+lenny6" test_ref="oval:org.mitre.oval:tst:25953"/>
                <criterion comment="openoffice.org-l10n-pt-br is earlier than 2.4.1+dfsg-1+lenny6" test_ref="oval:org.mitre.oval:tst:25891"/>
                <criterion comment="openoffice.org-report-builder is earlier than 1.0.2+OOo2.4.1+dfsg-1+lenny4" test_ref="oval:org.mitre.oval:tst:25166"/>
                <criterion comment="openoffice.org-help-pt-br is earlier than 2.4.1+dfsg-1+lenny6" test_ref="oval:org.mitre.oval:tst:26006"/>
                <criterion comment="openoffice.org-help-ko is earlier than 2.4.1+dfsg-1+lenny4" test_ref="oval:org.mitre.oval:tst:25730"/>
                <criterion comment="openoffice.org-help-km is earlier than 2.4.1+dfsg-1+lenny5" test_ref="oval:org.mitre.oval:tst:25998"/>
                <criterion comment="openoffice.org-l10n-fa is earlier than 2.4.1+dfsg-1+lenny6" test_ref="oval:org.mitre.oval:tst:26148"/>
                <criterion comment="openoffice.org-l10n-fi is earlier than 2.4.1+dfsg-1+lenny6" test_ref="oval:org.mitre.oval:tst:26099"/>
                <criterion comment="openoffice.org-qa-api-tests is earlier than 2.4.1+dfsg-1+lenny4" test_ref="oval:org.mitre.oval:tst:26102"/>
                <criterion comment="openoffice.org-help-hi-in is earlier than 2.4.1+dfsg-1+lenny6" test_ref="oval:org.mitre.oval:tst:26046"/>
                <criterion comment="openoffice.org-l10n-ns is earlier than 2.4.1+dfsg-1+lenny6" test_ref="oval:org.mitre.oval:tst:26144"/>
                <criterion comment="openoffice.org-l10n-nr is earlier than 2.4.1+dfsg-1+lenny4" test_ref="oval:org.mitre.oval:tst:26016"/>
                <criterion comment="openoffice.org-dev-doc is earlier than 2.4.1+dfsg-1+lenny4" test_ref="oval:org.mitre.oval:tst:25738"/>
                <criterion comment="openoffice.org-l10n-nn is earlier than 2.4.1+dfsg-1+lenny4" test_ref="oval:org.mitre.oval:tst:25191"/>
                <criterion comment="openoffice.org-help-pl is earlier than 2.4.1+dfsg-1+lenny5" test_ref="oval:org.mitre.oval:tst:25277"/>
                <criterion comment="openoffice.org-help-cs is earlier than 2.4.1+dfsg-1+lenny4" test_ref="oval:org.mitre.oval:tst:26098"/>
                <criterion comment="openoffice.org-l10n-ne is earlier than 2.4.1+dfsg-1+lenny5" test_ref="oval:org.mitre.oval:tst:26049"/>
                <criterion comment="openoffice.org-l10n-pa-in is earlier than 2.4.1+dfsg-1+lenny4" test_ref="oval:org.mitre.oval:tst:25991"/>
                <criterion comment="openoffice.org-l10n-nb is earlier than 2.4.1+dfsg-1+lenny5" test_ref="oval:org.mitre.oval:tst:26245"/>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Architecture dependent section">
              <criteria operator="OR" comment="Supported architectures section">
                <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
              </criteria>
              <criteria operator="OR" comment="Packages section">
                <criterion comment="openoffice.org is earlier than 2.4.1+dfsg-1+lenny5" test_ref="oval:org.mitre.oval:tst:26056"/>
                <criterion comment="openoffice.org-ogltrans is earlier than 2.4.1+dfsg-1+lenny6" test_ref="oval:org.mitre.oval:tst:25380"/>
                <criterion comment="openoffice.org-dbg is earlier than 2.4.1+dfsg-1+lenny4" test_ref="oval:org.mitre.oval:tst:26266"/>
                <criterion comment="python-uno is earlier than 2.4.1+dfsg-1+lenny6" test_ref="oval:org.mitre.oval:tst:26166"/>
                <criterion comment="openoffice.org-draw is earlier than 2.4.1+dfsg-1+lenny6" test_ref="oval:org.mitre.oval:tst:26204"/>
                <criterion comment="openoffice.org-kde is earlier than 2.4.1+dfsg-1+lenny6" test_ref="oval:org.mitre.oval:tst:26235"/>
                <criterion comment="openoffice.org-filter-binfilter is earlier than 2.4.1+dfsg-1+lenny4" test_ref="oval:org.mitre.oval:tst:26217"/>
                <criterion comment="openoffice.org-base is earlier than 2.4.1+dfsg-1+lenny5" test_ref="oval:org.mitre.oval:tst:26126"/>
                <criterion comment="mozilla-openoffice.org is earlier than 2.4.1+dfsg-1+lenny6" test_ref="oval:org.mitre.oval:tst:26224"/>
                <criterion comment="openoffice.org-headless is earlier than 2.4.1+dfsg-1+lenny4" test_ref="oval:org.mitre.oval:tst:26147"/>
                <criterion comment="openoffice.org-impress is earlier than 2.4.1+dfsg-1+lenny5" test_ref="oval:org.mitre.oval:tst:26274"/>
                <criterion comment="libmythes-dev is earlier than 2.4.1+dfsg-1+lenny5" test_ref="oval:org.mitre.oval:tst:26167"/>
                <criterion comment="openoffice.org-gnome is earlier than 2.4.1+dfsg-1+lenny6" test_ref="oval:org.mitre.oval:tst:26145"/>
                <criterion comment="openoffice.org-evolution is earlier than 2.4.1+dfsg-1+lenny5" test_ref="oval:org.mitre.oval:tst:26242"/>
                <criterion comment="openoffice.org-math is earlier than 2.4.1+dfsg-1+lenny4" test_ref="oval:org.mitre.oval:tst:25884"/>
                <criterion comment="openoffice.org-calc is earlier than 2.4.1+dfsg-1+lenny5" test_ref="oval:org.mitre.oval:tst:26214"/>
                <criterion comment="openoffice.org-base-core is earlier than 2.4.1+dfsg-1+lenny5" test_ref="oval:org.mitre.oval:tst:25759"/>
                <criterion comment="openoffice.org-report-builder-bin is earlier than 2.4.1+dfsg-1+lenny5" test_ref="oval:org.mitre.oval:tst:26109"/>
                <criterion comment="openoffice.org-sdbc-postgresql is earlier than 0.7.6+OOo2.4.1+dfsg-1+lenny4" test_ref="oval:org.mitre.oval:tst:25385"/>
                <criterion comment="openoffice.org-dev is earlier than 2.4.1+dfsg-1+lenny5" test_ref="oval:org.mitre.oval:tst:26083"/>
                <criterion comment="openoffice.org-gcj is earlier than 2.4.1+dfsg-1+lenny5" test_ref="oval:org.mitre.oval:tst:26119"/>
                <criterion comment="openoffice.org-core is earlier than 2.4.1+dfsg-1+lenny6" test_ref="oval:org.mitre.oval:tst:26092"/>
                <criterion comment="ure is earlier than 1.4+OOo2.4.1+dfsg-1+lenny5" test_ref="oval:org.mitre.oval:tst:26267"/>
                <criterion comment="openoffice.org-writer is earlier than 2.4.1+dfsg-1+lenny4" test_ref="oval:org.mitre.oval:tst:25986"/>
                <criterion comment="openoffice.org-qa-tools is earlier than 2.4.1+dfsg-1+lenny4" test_ref="oval:org.mitre.oval:tst:26150"/>
                <criterion comment="ure-dbg is earlier than 1.4+OOo2.4.1+dfsg-1+lenny5" test_ref="oval:org.mitre.oval:tst:25767"/>
                <criterion comment="openoffice.org-gtk is earlier than 2.4.1+dfsg-1+lenny5" test_ref="oval:org.mitre.oval:tst:26007"/>
                <criterion comment="openoffice.org-officebean is earlier than 2.4.1+dfsg-1+lenny6" test_ref="oval:org.mitre.oval:tst:26247"/>
                <criterion comment="openoffice.org-presentation-minimizer is earlier than 1.0+OOo2.4.1+dfsg-1+lenny5" test_ref="oval:org.mitre.oval:tst:26196"/>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Architecture dependent section">
              <criteria operator="OR" comment="Supported architectures section">
                <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
              </criteria>
              <criteria operator="OR" comment="Packages section">
                <criterion comment="openoffice.org is earlier than 2.4.1+dfsg-1+lenny4" test_ref="oval:org.mitre.oval:tst:26183"/>
                <criterion comment="openoffice.org-dbg is earlier than 2.4.1+dfsg-1+lenny6" test_ref="oval:org.mitre.oval:tst:26138"/>
                <criterion comment="python-uno is earlier than 2.4.1+dfsg-1+lenny4" test_ref="oval:org.mitre.oval:tst:26040"/>
                <criterion comment="openoffice.org-draw is earlier than 2.4.1+dfsg-1+lenny4" test_ref="oval:org.mitre.oval:tst:25863"/>
                <criterion comment="openoffice.org-kde is earlier than 2.4.1+dfsg-1+lenny4" test_ref="oval:org.mitre.oval:tst:26124"/>
                <criterion comment="openoffice.org-filter-binfilter is earlier than 2.4.1+dfsg-1+lenny6" test_ref="oval:org.mitre.oval:tst:25874"/>
                <criterion comment="openoffice.org-base is earlier than 2.4.1+dfsg-1+lenny5" test_ref="oval:org.mitre.oval:tst:25681"/>
                <criterion comment="ure-dbg is earlier than 1.4+OOo2.4.1+dfsg-1+lenny4" test_ref="oval:org.mitre.oval:tst:25870"/>
                <criterion comment="openoffice.org-headless is earlier than 2.4.1+dfsg-1+lenny5" test_ref="oval:org.mitre.oval:tst:25937"/>
                <criterion comment="openoffice.org-impress is earlier than 2.4.1+dfsg-1+lenny6" test_ref="oval:org.mitre.oval:tst:26106"/>
                <criterion comment="libmythes-dev is earlier than 2.4.1+dfsg-1+lenny5" test_ref="oval:org.mitre.oval:tst:25907"/>
                <criterion comment="openoffice.org-gnome is earlier than 2.4.1+dfsg-1+lenny4" test_ref="oval:org.mitre.oval:tst:26048"/>
                <criterion comment="cli-uno-bridge is earlier than 2.4.1+dfsg-1+lenny6" test_ref="oval:org.mitre.oval:tst:25989"/>
                <criterion comment="openoffice.org-evolution is earlier than 2.4.1+dfsg-1+lenny6" test_ref="oval:org.mitre.oval:tst:25949"/>
                <criterion comment="openoffice.org-math is earlier than 2.4.1+dfsg-1+lenny4" test_ref="oval:org.mitre.oval:tst:25973"/>
                <criterion comment="openoffice.org-calc is earlier than 2.4.1+dfsg-1+lenny5" test_ref="oval:org.mitre.oval:tst:26017"/>
                <criterion comment="openoffice.org-base-core is earlier than 2.4.1+dfsg-1+lenny5" test_ref="oval:org.mitre.oval:tst:26112"/>
                <criterion comment="openoffice.org-report-builder-bin is earlier than 2.4.1+dfsg-1+lenny6" test_ref="oval:org.mitre.oval:tst:26176"/>
                <criterion comment="openoffice.org-sdbc-postgresql is earlier than 0.7.6+OOo2.4.1+dfsg-1+lenny4" test_ref="oval:org.mitre.oval:tst:25892"/>
                <criterion comment="openoffice.org-dev is earlier than 2.4.1+dfsg-1+lenny4" test_ref="oval:org.mitre.oval:tst:26063"/>
                <criterion comment="openoffice.org-gcj is earlier than 2.4.1+dfsg-1+lenny4" test_ref="oval:org.mitre.oval:tst:26239"/>
                <criterion comment="openoffice.org-core is earlier than 2.4.1+dfsg-1+lenny5" test_ref="oval:org.mitre.oval:tst:25815"/>
                <criterion comment="ure is earlier than 1.4+OOo2.4.1+dfsg-1+lenny5" test_ref="oval:org.mitre.oval:tst:26088"/>
                <criterion comment="openoffice.org-writer is earlier than 2.4.1+dfsg-1+lenny4" test_ref="oval:org.mitre.oval:tst:26078"/>
                <criterion comment="openoffice.org-qa-tools is earlier than 2.4.1+dfsg-1+lenny6" test_ref="oval:org.mitre.oval:tst:26125"/>
                <criterion comment="mozilla-openoffice.org is earlier than 2.4.1+dfsg-1+lenny4" test_ref="oval:org.mitre.oval:tst:26202"/>
                <criterion comment="openoffice.org-gtk is earlier than 2.4.1+dfsg-1+lenny6" test_ref="oval:org.mitre.oval:tst:25588"/>
                <criterion comment="openoffice.org-officebean is earlier than 2.4.1+dfsg-1+lenny5" test_ref="oval:org.mitre.oval:tst:25577"/>
                <criterion comment="openoffice.org-presentation-minimizer is earlier than 1.0+OOo2.4.1+dfsg-1+lenny4" test_ref="oval:org.mitre.oval:tst:26151"/>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Architecture depended section">
              <criteria operator="AND" comment="Supported platform section">
                <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
                <criteria operator="OR" comment="Packages section">
                  <criterion comment="openoffice.org is earlier than 2.4.1+dfsg-1+lenny4" test_ref="oval:org.mitre.oval:tst:26389"/>
                  <criterion comment="openoffice.org-dbg is earlier than 2.4.1+dfsg-1+lenny6" test_ref="oval:org.mitre.oval:tst:26219"/>
                  <criterion comment="python-uno is earlier than 2.4.1+dfsg-1+lenny6" test_ref="oval:org.mitre.oval:tst:26427"/>
                  <criterion comment="openoffice.org-gtk is earlier than 2.4.1+dfsg-1+lenny6" test_ref="oval:org.mitre.oval:tst:26425"/>
                  <criterion comment="openoffice.org-draw is earlier than 2.4.1+dfsg-1+lenny6" test_ref="oval:org.mitre.oval:tst:25481"/>
                  <criterion comment="openoffice.org-kde is earlier than 2.4.1+dfsg-1+lenny6" test_ref="oval:org.mitre.oval:tst:26089"/>
                  <criterion comment="openoffice.org-sdbc-postgresql is earlier than 0.7.6+OOo2.4.1+dfsg-1+lenny4" test_ref="oval:org.mitre.oval:tst:25997"/>
                  <criterion comment="openoffice.org-base is earlier than 2.4.1+dfsg-1+lenny4" test_ref="oval:org.mitre.oval:tst:26441"/>
                  <criterion comment="mozilla-openoffice.org is earlier than 2.4.1+dfsg-1+lenny4" test_ref="oval:org.mitre.oval:tst:26284"/>
                  <criterion comment="openoffice.org-headless is earlier than 2.4.1+dfsg-1+lenny6" test_ref="oval:org.mitre.oval:tst:26295"/>
                  <criterion comment="libmythes-dev is earlier than 2.4.1+dfsg-1+lenny4" test_ref="oval:org.mitre.oval:tst:25807"/>
                  <criterion comment="openoffice.org-gnome is earlier than 2.4.1+dfsg-1+lenny6" test_ref="oval:org.mitre.oval:tst:26066"/>
                  <criterion comment="openoffice.org-evolution is earlier than 2.4.1+dfsg-1+lenny4" test_ref="oval:org.mitre.oval:tst:26129"/>
                  <criterion comment="openoffice.org-math is earlier than 2.4.1+dfsg-1+lenny4" test_ref="oval:org.mitre.oval:tst:26261"/>
                  <criterion comment="openoffice.org-calc is earlier than 2.4.1+dfsg-1+lenny6" test_ref="oval:org.mitre.oval:tst:26387"/>
                  <criterion comment="openoffice.org-base-core is earlier than 2.4.1+dfsg-1+lenny4" test_ref="oval:org.mitre.oval:tst:26465"/>
                  <criterion comment="openoffice.org-report-builder-bin is earlier than 2.4.1+dfsg-1+lenny6" test_ref="oval:org.mitre.oval:tst:26417"/>
                  <criterion comment="openoffice.org-impress is earlier than 2.4.1+dfsg-1+lenny6" test_ref="oval:org.mitre.oval:tst:26177"/>
                  <criterion comment="openoffice.org-dev is earlier than 2.4.1+dfsg-1+lenny4" test_ref="oval:org.mitre.oval:tst:26366"/>
                  <criterion comment="openoffice.org-gcj is earlier than 2.4.1+dfsg-1+lenny4" test_ref="oval:org.mitre.oval:tst:26330"/>
                  <criterion comment="openoffice.org-core is earlier than 2.4.1+dfsg-1+lenny6" test_ref="oval:org.mitre.oval:tst:26162"/>
                  <criterion comment="ure is earlier than 1.4+OOo2.4.1+dfsg-1+lenny4" test_ref="oval:org.mitre.oval:tst:26421"/>
                  <criterion comment="openoffice.org-writer is earlier than 2.4.1+dfsg-1+lenny4" test_ref="oval:org.mitre.oval:tst:26277"/>
                  <criterion comment="openoffice.org-qa-tools is earlier than 2.4.1+dfsg-1+lenny6" test_ref="oval:org.mitre.oval:tst:26455"/>
                  <criterion comment="ure-dbg is earlier than 1.4+OOo2.4.1+dfsg-1+lenny6" test_ref="oval:org.mitre.oval:tst:26307"/>
                  <criterion comment="openoffice.org-filter-binfilter is earlier than 2.4.1+dfsg-1+lenny4" test_ref="oval:org.mitre.oval:tst:26459"/>
                  <criterion comment="openoffice.org-officebean is earlier than 2.4.1+dfsg-1+lenny4" test_ref="oval:org.mitre.oval:tst:26218"/>
                  <criterion comment="openoffice.org-presentation-minimizer is earlier than 1.0+OOo2.4.1+dfsg-1+lenny4" test_ref="oval:org.mitre.oval:tst:26354"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Release section">
          <extend_definition comment="Debian 4.0 is installed." definition_ref="oval:org.mitre.oval:def:6461"/>
          <criteria operator="OR" comment="Architecture section">
            <criteria operator="AND" comment="Architecture independent section">
              <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criteria operator="OR" comment="Packages section">
                <criterion comment="openoffice.org-dtd-officedocument1.0 is earlier than 2.0.4.dfsg.2-7etch9" test_ref="oval:org.mitre.oval:tst:26347"/>
                <criterion comment="openoffice.org-l10n-cy is earlier than 2.0.4.dfsg.2-7etch8" test_ref="oval:org.mitre.oval:tst:26300"/>
                <criterion comment="openoffice.org-l10n-cs is earlier than 2.0.4.dfsg.2-7etch9" test_ref="oval:org.mitre.oval:tst:25548"/>
                <criterion comment="openoffice.org-help-hu is earlier than 2.0.4.dfsg.2-7etch9" test_ref="oval:org.mitre.oval:tst:26359"/>
                <criterion comment="openoffice.org-l10n-vi is earlier than 2.0.4.dfsg.2-7etch8" test_ref="oval:org.mitre.oval:tst:26482"/>
                <criterion comment="openoffice.org-l10n-ca is earlier than 2.0.4.dfsg.2-7etch8" test_ref="oval:org.mitre.oval:tst:25934"/>
                <criterion comment="openoffice.org-help-en-us is earlier than 2.0.4.dfsg.2-7etch9" test_ref="oval:org.mitre.oval:tst:26008"/>
                <criterion comment="ttf-opensymbol is earlier than 2.0.4.dfsg.2-7etch8" test_ref="oval:org.mitre.oval:tst:26155"/>
                <criterion comment="openoffice.org-l10n-ka is earlier than 2.0.4.dfsg.2-7etch9" test_ref="oval:org.mitre.oval:tst:25827"/>
                <criterion comment="openoffice.org-l10n-km is earlier than 2.0.4.dfsg.2-7etch8" test_ref="oval:org.mitre.oval:tst:26172"/>
                <criterion comment="openoffice.org-l10n-ko is earlier than 2.0.4.dfsg.2-7etch9" test_ref="oval:org.mitre.oval:tst:26290"/>
                <criterion comment="openoffice.org-l10n-pl is earlier than 2.0.4.dfsg.2-7etch8" test_ref="oval:org.mitre.oval:tst:26197"/>
                <criterion comment="broffice.org is earlier than 2.0.4.dfsg.2-7etch9" test_ref="oval:org.mitre.oval:tst:26052"/>
                <criterion comment="openoffice.org-l10n-ku is earlier than 2.0.4.dfsg.2-7etch9" test_ref="oval:org.mitre.oval:tst:26460"/>
                <criterion comment="openoffice.org-l10n-pt is earlier than 2.0.4.dfsg.2-7etch9" test_ref="oval:org.mitre.oval:tst:26437"/>
                <criterion comment="openoffice.org-l10n-xh is earlier than 2.0.4.dfsg.2-7etch9" test_ref="oval:org.mitre.oval:tst:25978"/>
                <criterion comment="openoffice.org-help-it is earlier than 2.0.4.dfsg.2-7etch8" test_ref="oval:org.mitre.oval:tst:25919"/>
                <criterion comment="openoffice.org-help-pl is earlier than 2.0.4.dfsg.2-7etch9" test_ref="oval:org.mitre.oval:tst:26241"/>
                <criterion comment="openoffice.org-l10n-be-by is earlier than 2.0.4.dfsg.2-7etch9" test_ref="oval:org.mitre.oval:tst:25503"/>
                <criterion comment="openoffice.org-l10n-hr is earlier than 2.0.4.dfsg.2-7etch8" test_ref="oval:org.mitre.oval:tst:26207"/>
                <criterion comment="openoffice.org-l10n-hu is earlier than 2.0.4.dfsg.2-7etch9" test_ref="oval:org.mitre.oval:tst:26272"/>
                <criterion comment="openoffice.org-l10n-mk is earlier than 2.0.4.dfsg.2-7etch9" test_ref="oval:org.mitre.oval:tst:26384"/>
                <criterion comment="openoffice.org-l10n-hi is earlier than 2.0.4.dfsg.2-7etch8" test_ref="oval:org.mitre.oval:tst:26343"/>
                <criterion comment="openoffice.org-l10n-sr-cs is earlier than 2.0.4.dfsg.2-7etch8" test_ref="oval:org.mitre.oval:tst:26466"/>
                <criterion comment="openoffice.org-l10n-he is earlier than 2.0.4.dfsg.2-7etch8" test_ref="oval:org.mitre.oval:tst:26355"/>
                <criterion comment="openoffice.org-l10n-en-za is earlier than 2.0.4.dfsg.2-7etch9" test_ref="oval:org.mitre.oval:tst:26178"/>
                <criterion comment="openoffice.org-l10n-as-in is earlier than 2.0.4.dfsg.2-7etch8" test_ref="oval:org.mitre.oval:tst:26419"/>
                <criterion comment="openoffice.org-l10n-ta-in is earlier than 2.0.4.dfsg.2-7etch8" test_ref="oval:org.mitre.oval:tst:26344"/>
                <criterion comment="openoffice.org-help-nl is earlier than 2.0.4.dfsg.2-7etch8" test_ref="oval:org.mitre.oval:tst:26424"/>
                <criterion comment="openoffice.org-l10n-eo is earlier than 2.0.4.dfsg.2-7etch8" test_ref="oval:org.mitre.oval:tst:26485"/>
                <criterion comment="openoffice.org-l10n-el is earlier than 2.0.4.dfsg.2-7etch9" test_ref="oval:org.mitre.oval:tst:26292"/>
                <criterion comment="openoffice.org-l10n-zu is earlier than 2.0.4.dfsg.2-7etch8" test_ref="oval:org.mitre.oval:tst:26397"/>
                <criterion comment="openoffice.org-l10n-hi-in is earlier than 2.0.4.dfsg.2-7etch9" test_ref="oval:org.mitre.oval:tst:26203"/>
                <criterion comment="openoffice.org-l10n-zh-tw is earlier than 2.0.4.dfsg.2-7etch9" test_ref="oval:org.mitre.oval:tst:26367"/>
                <criterion comment="openoffice.org-l10n-za is earlier than 2.0.4.dfsg.2-7etch9" test_ref="oval:org.mitre.oval:tst:26321"/>
                <criterion comment="openoffice.org-l10n-et is earlier than 2.0.4.dfsg.2-7etch8" test_ref="oval:org.mitre.oval:tst:26131"/>
                <criterion comment="openoffice.org-help-fr is earlier than 2.0.4.dfsg.2-7etch9" test_ref="oval:org.mitre.oval:tst:26259"/>
                <criterion comment="openoffice.org-l10n-rw is earlier than 2.0.4.dfsg.2-7etch9" test_ref="oval:org.mitre.oval:tst:26127"/>
                <criterion comment="openoffice.org-l10n-es is earlier than 2.0.4.dfsg.2-7etch8" test_ref="oval:org.mitre.oval:tst:26222"/>
                <criterion comment="openoffice.org-l10n-ru is earlier than 2.0.4.dfsg.2-7etch8" test_ref="oval:org.mitre.oval:tst:26358"/>
                <criterion comment="openoffice.org-l10n-bs is earlier than 2.0.4.dfsg.2-7etch9" test_ref="oval:org.mitre.oval:tst:26411"/>
                <criterion comment="openoffice.org-l10n-br is earlier than 2.0.4.dfsg.2-7etch9" test_ref="oval:org.mitre.oval:tst:25902"/>
                <criterion comment="openoffice.org-l10n-bn is earlier than 2.0.4.dfsg.2-7etch8" test_ref="oval:org.mitre.oval:tst:26195"/>
                <criterion comment="openoffice.org-l10n-bg is earlier than 2.0.4.dfsg.2-7etch9" test_ref="oval:org.mitre.oval:tst:26250"/>
                <criterion comment="openoffice.org-l10n-sl is earlier than 2.0.4.dfsg.2-7etch8" test_ref="oval:org.mitre.oval:tst:26407"/>
                <criterion comment="openoffice.org-l10n-ja is earlier than 2.0.4.dfsg.2-7etch9" test_ref="oval:org.mitre.oval:tst:25828"/>
                <criterion comment="openoffice.org-l10n-en-gb is earlier than 2.0.4.dfsg.2-7etch8" test_ref="oval:org.mitre.oval:tst:26075"/>
                <criterion comment="openoffice.org-l10n-sk is earlier than 2.0.4.dfsg.2-7etch9" test_ref="oval:org.mitre.oval:tst:25958"/>
                <criterion comment="openoffice.org-l10n-st is earlier than 2.0.4.dfsg.2-7etch8" test_ref="oval:org.mitre.oval:tst:26403"/>
                <criterion comment="openoffice.org-l10n-sv is earlier than 2.0.4.dfsg.2-7etch8" test_ref="oval:org.mitre.oval:tst:26305"/>
                <criterion comment="openoffice.org-l10n-ss is earlier than 2.0.4.dfsg.2-7etch9" test_ref="oval:org.mitre.oval:tst:26302"/>
                <criterion comment="openoffice.org-help-sv is earlier than 2.0.4.dfsg.2-7etch9" test_ref="oval:org.mitre.oval:tst:26392"/>
                <criterion comment="openoffice.org-help-dz is earlier than 2.0.4.dfsg.2-7etch9" test_ref="oval:org.mitre.oval:tst:25574"/>
                <criterion comment="openoffice.org-help-da is earlier than 2.0.4.dfsg.2-7etch9" test_ref="oval:org.mitre.oval:tst:26481"/>
                <criterion comment="openoffice.org-help-de is earlier than 2.0.4.dfsg.2-7etch8" test_ref="oval:org.mitre.oval:tst:26523"/>
                <criterion comment="openoffice.org-help-sl is earlier than 2.0.4.dfsg.2-7etch8" test_ref="oval:org.mitre.oval:tst:26543"/>
                <criterion comment="openoffice.org-java-common is earlier than 2.0.4.dfsg.2-7etch9" test_ref="oval:org.mitre.oval:tst:26489"/>
                <criterion comment="openoffice.org-l10n-ga is earlier than 2.0.4.dfsg.2-7etch8" test_ref="oval:org.mitre.oval:tst:26458"/>
                <criterion comment="openoffice.org-l10n-lv is earlier than 2.0.4.dfsg.2-7etch8" test_ref="oval:org.mitre.oval:tst:25960"/>
                <criterion comment="openoffice.org-l10n-ts is earlier than 2.0.4.dfsg.2-7etch9" test_ref="oval:org.mitre.oval:tst:26254"/>
                <criterion comment="openoffice.org-l10n-tr is earlier than 2.0.4.dfsg.2-7etch9" test_ref="oval:org.mitre.oval:tst:25829"/>
                <criterion comment="openoffice.org-l10n-tn is earlier than 2.0.4.dfsg.2-7etch8" test_ref="oval:org.mitre.oval:tst:26342"/>
                <criterion comment="openoffice.org-l10n-th is earlier than 2.0.4.dfsg.2-7etch9" test_ref="oval:org.mitre.oval:tst:26043"/>
                <criterion comment="openoffice.org-l10n-tg is earlier than 2.0.4.dfsg.2-7etch9" test_ref="oval:org.mitre.oval:tst:26377"/>
                <criterion comment="openoffice.org-help-et is earlier than 2.0.4.dfsg.2-7etch8" test_ref="oval:org.mitre.oval:tst:26420"/>
                <criterion comment="openoffice.org-help-es is earlier than 2.0.4.dfsg.2-7etch9" test_ref="oval:org.mitre.oval:tst:26123"/>
                <criterion comment="openoffice.org-filter-mobiledev is earlier than 2.0.4.dfsg.2-7etch8" test_ref="oval:org.mitre.oval:tst:25878"/>
                <criterion comment="openoffice.org-l10n-or-in is earlier than 2.0.4.dfsg.2-7etch9" test_ref="oval:org.mitre.oval:tst:25665"/>
                <criterion comment="openoffice.org-help-en is earlier than 2.0.4.dfsg.2-7etch8" test_ref="oval:org.mitre.oval:tst:26337"/>
                <criterion comment="openoffice.org-l10n-lt is earlier than 2.0.4.dfsg.2-7etch8" test_ref="oval:org.mitre.oval:tst:26297"/>
                <criterion comment="openoffice.org-l10n-te-in is earlier than 2.0.4.dfsg.2-7etch9" test_ref="oval:org.mitre.oval:tst:26503"/>
                <criterion comment="openoffice.org-l10n-de is earlier than 2.0.4.dfsg.2-7etch8" test_ref="oval:org.mitre.oval:tst:26517"/>
                <criterion comment="openoffice.org-l10n-da is earlier than 2.0.4.dfsg.2-7etch8" test_ref="oval:org.mitre.oval:tst:26527"/>
                <criterion comment="openoffice.org-l10n-uk is earlier than 2.0.4.dfsg.2-7etch8" test_ref="oval:org.mitre.oval:tst:26142"/>
                <criterion comment="openoffice.org-l10n-dz is earlier than 2.0.4.dfsg.2-7etch8" test_ref="oval:org.mitre.oval:tst:26453"/>
                <criterion comment="openoffice.org-l10n-lo is earlier than 2.0.4.dfsg.2-7etch8" test_ref="oval:org.mitre.oval:tst:26502"/>
                <criterion comment="openoffice.org-l10n-ml-in is earlier than 2.0.4.dfsg.2-7etch9" test_ref="oval:org.mitre.oval:tst:26529"/>
                <criterion comment="openoffice.org-help-en-gb is earlier than 2.0.4.dfsg.2-7etch8" test_ref="oval:org.mitre.oval:tst:26539"/>
                <criterion comment="openoffice.org-l10n-af is earlier than 2.0.4.dfsg.2-7etch8" test_ref="oval:org.mitre.oval:tst:26538"/>
                <criterion comment="openoffice.org-common is earlier than 2.0.4.dfsg.2-7etch8" test_ref="oval:org.mitre.oval:tst:26185"/>
                <criterion comment="openoffice.org-help-ja is earlier than 2.0.4.dfsg.2-7etch9" test_ref="oval:org.mitre.oval:tst:25639"/>
                <criterion comment="openoffice.org-l10n-zh-cn is earlier than 2.0.4.dfsg.2-7etch9" test_ref="oval:org.mitre.oval:tst:26264"/>
                <criterion comment="openoffice.org-l10n-ve is earlier than 2.0.4.dfsg.2-7etch8" test_ref="oval:org.mitre.oval:tst:26034"/>
                <criterion comment="openoffice.org-help-zh-cn is earlier than 2.0.4.dfsg.2-7etch9" test_ref="oval:org.mitre.oval:tst:26574"/>
                <criterion comment="openoffice.org-l10n-it is earlier than 2.0.4.dfsg.2-7etch8" test_ref="oval:org.mitre.oval:tst:26546"/>
                <criterion comment="openoffice.org-l10n-gu-in is earlier than 2.0.4.dfsg.2-7etch9" test_ref="oval:org.mitre.oval:tst:26191"/>
                <criterion comment="openoffice.org-l10n-in is earlier than 2.0.4.dfsg.2-7etch8" test_ref="oval:org.mitre.oval:tst:25750"/>
                <criterion comment="openoffice.org-help-zh-tw is earlier than 2.0.4.dfsg.2-7etch8" test_ref="oval:org.mitre.oval:tst:26276"/>
                <criterion comment="openoffice.org-help-ru is earlier than 2.0.4.dfsg.2-7etch8" test_ref="oval:org.mitre.oval:tst:26545"/>
                <criterion comment="openoffice.org-l10n-fr is earlier than 2.0.4.dfsg.2-7etch8" test_ref="oval:org.mitre.oval:tst:26363"/>
                <criterion comment="openoffice.org-l10n-pt-br is earlier than 2.0.4.dfsg.2-7etch8" test_ref="oval:org.mitre.oval:tst:26448"/>
                <criterion comment="openoffice.org-help-pt-br is earlier than 2.0.4.dfsg.2-7etch9" test_ref="oval:org.mitre.oval:tst:26435"/>
                <criterion comment="openoffice.org-help-ko is earlier than 2.0.4.dfsg.2-7etch8" test_ref="oval:org.mitre.oval:tst:26402"/>
                <criterion comment="openoffice.org-help-km is earlier than 2.0.4.dfsg.2-7etch9" test_ref="oval:org.mitre.oval:tst:25987"/>
                <criterion comment="openoffice.org-l10n-fa is earlier than 2.0.4.dfsg.2-7etch9" test_ref="oval:org.mitre.oval:tst:26483"/>
                <criterion comment="openoffice.org-l10n-fi is earlier than 2.0.4.dfsg.2-7etch9" test_ref="oval:org.mitre.oval:tst:26533"/>
                <criterion comment="openoffice.org-qa-api-tests is earlier than 2.0.4.dfsg.2-7etch9" test_ref="oval:org.mitre.oval:tst:26371"/>
                <criterion comment="openoffice.org-help-hi-in is earlier than 2.0.4.dfsg.2-7etch9" test_ref="oval:org.mitre.oval:tst:26423"/>
                <criterion comment="openoffice.org-l10n-ns is earlier than 2.0.4.dfsg.2-7etch8" test_ref="oval:org.mitre.oval:tst:26570"/>
                <criterion comment="openoffice.org-l10n-nr is earlier than 2.0.4.dfsg.2-7etch9" test_ref="oval:org.mitre.oval:tst:26146"/>
                <criterion comment="openoffice.org-dev-doc is earlier than 2.0.4.dfsg.2-7etch8" test_ref="oval:org.mitre.oval:tst:26309"/>
                <criterion comment="openoffice.org-l10n-nn is earlier than 2.0.4.dfsg.2-7etch9" test_ref="oval:org.mitre.oval:tst:26329"/>
                <criterion comment="openoffice.org-l10n-nl is earlier than 2.0.4.dfsg.2-7etch9" test_ref="oval:org.mitre.oval:tst:26324"/>
                <criterion comment="openoffice.org-help-cs is earlier than 2.0.4.dfsg.2-7etch8" test_ref="oval:org.mitre.oval:tst:26139"/>
                <criterion comment="openoffice.org-l10n-ne is earlier than 2.0.4.dfsg.2-7etch8" test_ref="oval:org.mitre.oval:tst:25581"/>
                <criterion comment="openoffice.org-l10n-pa-in is earlier than 2.0.4.dfsg.2-7etch9" test_ref="oval:org.mitre.oval:tst:26161"/>
                <criterion comment="openoffice.org-l10n-nb is earlier than 2.0.4.dfsg.2-7etch8" test_ref="oval:org.mitre.oval:tst:26565"/>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Architecture dependent section">
              <criteria operator="OR" comment="Supported architectures section">
                <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
                <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
                <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
                <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
                <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
                <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
                <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
                <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
                <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
              </criteria>
              <criteria operator="OR" comment="Packages section">
                <criterion comment="libmythes-dev is earlier than 2.0.4.dfsg.2-7etch9" test_ref="oval:org.mitre.oval:tst:26438"/>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Architecture dependent section">
              <criteria operator="OR" comment="Supported architectures section">
                <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
                <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
              </criteria>
              <criteria operator="OR" comment="Packages section">
                <criterion comment="libmythes-dev is earlier than 2.0.4.dfsg.2-7etch8" test_ref="oval:org.mitre.oval:tst:26029"/>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Architecture depended section">
              <criteria operator="AND" comment="Supported platform section">
                <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
                <criteria operator="OR" comment="Packages section">
                  <criterion comment="openoffice.org-filter-so52 is earlier than 2.0.4.dfsg.2-7etch9" test_ref="oval:org.mitre.oval:tst:26607"/>
                  <criterion comment="openoffice.org-impress is earlier than 2.0.4.dfsg.2-7etch9" test_ref="oval:org.mitre.oval:tst:26014"/>
                  <criterion comment="openoffice.org-evolution is earlier than 2.0.4.dfsg.2-7etch9" test_ref="oval:org.mitre.oval:tst:26311"/>
                  <criterion comment="openoffice.org-base is earlier than 2.0.4.dfsg.2-7etch9" test_ref="oval:org.mitre.oval:tst:25675"/>
                  <criterion comment="openoffice.org is earlier than 2.0.4.dfsg.2-7etch9" test_ref="oval:org.mitre.oval:tst:26552"/>
                  <criterion comment="openoffice.org-gtk-gnome is earlier than 2.0.4.dfsg.2-7etch9" test_ref="oval:org.mitre.oval:tst:26413"/>
                  <criterion comment="openoffice.org-calc is earlier than 2.0.4.dfsg.2-7etch9" test_ref="oval:org.mitre.oval:tst:26562"/>
                  <criterion comment="openoffice.org-qa-tools is earlier than 2.0.4.dfsg.2-7etch9" test_ref="oval:org.mitre.oval:tst:26301"/>
                  <criterion comment="openoffice.org-dbg is earlier than 2.0.4.dfsg.2-7etch9" test_ref="oval:org.mitre.oval:tst:26194"/>
                  <criterion comment="openoffice.org-gtk is earlier than 2.0.4.dfsg.2-7etch9" test_ref="oval:org.mitre.oval:tst:26310"/>
                  <criterion comment="openoffice.org-officebean is earlier than 2.0.4.dfsg.2-7etch9" test_ref="oval:org.mitre.oval:tst:26560"/>
                  <criterion comment="python-uno is earlier than 2.0.4.dfsg.2-7etch9" test_ref="oval:org.mitre.oval:tst:25913"/>
                  <criterion comment="openoffice.org-math is earlier than 2.0.4.dfsg.2-7etch9" test_ref="oval:org.mitre.oval:tst:26101"/>
                  <criterion comment="openoffice.org-writer is earlier than 2.0.4.dfsg.2-7etch9" test_ref="oval:org.mitre.oval:tst:26549"/>
                  <criterion comment="openoffice.org-dev is earlier than 2.0.4.dfsg.2-7etch9" test_ref="oval:org.mitre.oval:tst:26406"/>
                  <criterion comment="openoffice.org-gcj is earlier than 2.0.4.dfsg.2-7etch9" test_ref="oval:org.mitre.oval:tst:26598"/>
                  <criterion comment="openoffice.org-kde is earlier than 2.0.4.dfsg.2-7etch9" test_ref="oval:org.mitre.oval:tst:26616"/>
                  <criterion comment="openoffice.org-draw is earlier than 2.0.4.dfsg.2-7etch9" test_ref="oval:org.mitre.oval:tst:26352"/>
                  <criterion comment="openoffice.org-gnome is earlier than 2.0.4.dfsg.2-7etch9" test_ref="oval:org.mitre.oval:tst:26275"/>
                  <criterion comment="openoffice.org-core is earlier than 2.0.4.dfsg.2-7etch9" test_ref="oval:org.mitre.oval:tst:26508"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6898" version="3" class="patch">
      <metadata>
        <title>DSA-2017 pulseaudio -- insecure temporary directory</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <product>pulseaudio</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2010/dsa-2017" ref_id="DSA-2017"/>
        <description>Dan Rosenberg discovered that the PulseAudio sound server creates a temporary directory with a predictable name. This allows a local attacker to create a Denial of Service condition or possibly disclose sensitive information to unprivileged users.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-05-24T19:01:51-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2010-05-26T13:27:37.806-04:00">DRAFT</status_change>
            <status_change date="2010-06-14T04:00:19.375-04:00">INTERIM</status_change>
            <status_change date="2010-06-29T11:49:03.182-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
        <criteria operator="OR" comment="Architecture section">
          <criteria operator="AND" comment="Architecture dependent section">
            <criteria operator="OR" comment="Supported architectures section">
              <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
              <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
              <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
              <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
              <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
              <criterion comment="Installed architecture is armel" test_ref="oval:org.mitre.oval:tst:11101"/>
              <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
              <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
              <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
              <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
              <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
              <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
            </criteria>
            <criteria operator="OR" comment="Packages section">
              <criterion comment="libpulse-dev is earlier than 0.9.10-3+lenny2" test_ref="oval:org.mitre.oval:tst:25537"/>
              <criterion comment="pulseaudio-utils is earlier than 0.9.10-3+lenny2" test_ref="oval:org.mitre.oval:tst:25556"/>
              <criterion comment="pulseaudio-esound-compat is earlier than 0.9.10-3+lenny2" test_ref="oval:org.mitre.oval:tst:25113"/>
              <criterion comment="libpulse-mainloop-glib0-dbg is earlier than 0.9.10-3+lenny2" test_ref="oval:org.mitre.oval:tst:25099"/>
              <criterion comment="pulseaudio-dbg is earlier than 0.9.10-3+lenny2" test_ref="oval:org.mitre.oval:tst:25425"/>
              <criterion comment="pulseaudio-module-gconf-dbg is earlier than 0.9.10-3+lenny2" test_ref="oval:org.mitre.oval:tst:25168"/>
              <criterion comment="pulseaudio-esound-compat-dbg is earlier than 0.9.10-3+lenny2" test_ref="oval:org.mitre.oval:tst:25340"/>
              <criterion comment="pulseaudio-module-hal is earlier than 0.9.10-3+lenny2" test_ref="oval:org.mitre.oval:tst:25452"/>
              <criterion comment="libpulsecore5 is earlier than 0.9.10-3+lenny2" test_ref="oval:org.mitre.oval:tst:25429"/>
              <criterion comment="libpulse-browse0 is earlier than 0.9.10-3+lenny2" test_ref="oval:org.mitre.oval:tst:25322"/>
              <criterion comment="pulseaudio-module-zeroconf is earlier than 0.9.10-3+lenny2" test_ref="oval:org.mitre.oval:tst:25327"/>
              <criterion comment="libpulse-browse0-dbg is earlier than 0.9.10-3+lenny2" test_ref="oval:org.mitre.oval:tst:24794"/>
              <criterion comment="pulseaudio-module-zeroconf-dbg is earlier than 0.9.10-3+lenny2" test_ref="oval:org.mitre.oval:tst:25282"/>
              <criterion comment="pulseaudio-module-jack-dbg is earlier than 0.9.10-3+lenny2" test_ref="oval:org.mitre.oval:tst:25450"/>
              <criterion comment="pulseaudio-module-x11 is earlier than 0.9.10-3+lenny2" test_ref="oval:org.mitre.oval:tst:25420"/>
              <criterion comment="pulseaudio-utils-dbg is earlier than 0.9.10-3+lenny2" test_ref="oval:org.mitre.oval:tst:25495"/>
              <criterion comment="pulseaudio-module-x11-dbg is earlier than 0.9.10-3+lenny2" test_ref="oval:org.mitre.oval:tst:25316"/>
              <criterion comment="libpulse-mainloop-glib0 is earlier than 0.9.10-3+lenny2" test_ref="oval:org.mitre.oval:tst:24623"/>
              <criterion comment="pulseaudio-module-gconf is earlier than 0.9.10-3+lenny2" test_ref="oval:org.mitre.oval:tst:25217"/>
              <criterion comment="pulseaudio-module-hal-dbg is earlier than 0.9.10-3+lenny2" test_ref="oval:org.mitre.oval:tst:25155"/>
              <criterion comment="pulseaudio-module-lirc-dbg is earlier than 0.9.10-3+lenny2" test_ref="oval:org.mitre.oval:tst:24669"/>
              <criterion comment="pulseaudio-module-lirc is earlier than 0.9.10-3+lenny2" test_ref="oval:org.mitre.oval:tst:25565"/>
              <criterion comment="pulseaudio-module-jack is earlier than 0.9.10-3+lenny2" test_ref="oval:org.mitre.oval:tst:25525"/>
              <criterion comment="libpulse0 is earlier than 0.9.10-3+lenny2" test_ref="oval:org.mitre.oval:tst:25022"/>
              <criterion comment="pulseaudio is earlier than 0.9.10-3+lenny2" test_ref="oval:org.mitre.oval:tst:25597"/>
              <criterion comment="libpulsecore5-dbg is earlier than 0.9.10-3+lenny2" test_ref="oval:org.mitre.oval:tst:25279"/>
              <criterion comment="libpulse0-dbg is earlier than 0.9.10-3+lenny2" test_ref="oval:org.mitre.oval:tst:25558"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6884" version="3" class="patch">
      <metadata>
        <title>DSA-2039 cacti -- missing input sanitising</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <product>cacti</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2010/dsa-2039" ref_id="DSA-2039"/>
        <description>It was discovered that Cacti, a frontend to rrdtool for monitoring systems and services missed input sanitising, making an SQL injection attack possible.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-05-24T19:10:15-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2010-05-26T13:29:17.248-04:00">DRAFT</status_change>
            <status_change date="2010-06-14T04:00:19.156-04:00">INTERIM</status_change>
            <status_change date="2010-06-29T11:49:02.909-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
        <criteria operator="OR" comment="Architecture section">
          <criteria operator="AND" comment="Architecture independent section">
            <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
            <criterion comment="cacti is earlier than 0.8.7b-2.1+lenny2" test_ref="oval:org.mitre.oval:tst:26941"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6875" version="3" class="patch">
      <metadata>
        <title>DSA-1981 maildrop -- privilege escalation</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <platform>Debian GNU/Linux 4.0</platform>
          <product>maildrop</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2010/dsa-1981" ref_id="DSA-1981"/>
        <description>Christoph Anton Mitterer discovered that maildrop, a mail delivery agent with filtering abilities, is prone to a privilege escalation issue that grants a user root group privileges.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-05-24T19:05:27-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2010-05-26T13:28:06.238-04:00">DRAFT</status_change>
            <status_change date="2010-06-14T04:00:18.736-04:00">INTERIM</status_change>
            <status_change date="2010-06-29T11:49:02.286-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Release section">
          <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
          <criteria operator="OR" comment="Architecture section">
            <criteria operator="AND" comment="Architecture dependent section">
              <criteria operator="OR" comment="Supported architectures section">
                <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
                <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
                <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
                <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
                <criterion comment="Installed architecture is armel" test_ref="oval:org.mitre.oval:tst:11101"/>
                <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
                <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
                <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
                <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
                <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
                <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
              </criteria>
              <criteria operator="OR" comment="Packages section">
                <criterion comment="maildrop is earlier than 2.0.4-3+lenny1" test_ref="oval:org.mitre.oval:tst:25869"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Release section">
          <extend_definition comment="Debian 4.0 is installed." definition_ref="oval:org.mitre.oval:def:6461"/>
          <criteria operator="OR" comment="Architecture section">
            <criteria operator="AND" comment="Architecture dependent section">
              <criteria operator="OR" comment="Supported architectures section">
                <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
                <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
                <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
                <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
                <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
                <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
                <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
                <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
                <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
              </criteria>
              <criteria operator="OR" comment="Packages section">
                <criterion comment="maildrop is earlier than 2.0.2-11+etch1" test_ref="oval:org.mitre.oval:tst:25702"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6873" version="3" class="patch">
      <metadata>
        <title>DSA-2013 egroupware -- several vulnerabilities</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <product>egroupware</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2010/dsa-2013" ref_id="DSA-2013"/>
        <description>Nahuel Grisolia discovered two vulnerabilities in Egroupware, a web-based groupware suite: Missing input sanitising in the spellchecker integration may lead to the execution of arbitrary commands and a cross-site scripting vulnerability was discovered in the login page.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-05-24T19:02:15-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2010-05-26T13:27:41.841-04:00">DRAFT</status_change>
            <status_change date="2010-06-14T04:00:18.224-04:00">INTERIM</status_change>
            <status_change date="2010-06-29T11:49:01.681-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
        <criteria operator="OR" comment="Architecture section">
          <criteria operator="AND" comment="Architecture independent section">
            <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
            <criteria operator="OR" comment="Packages section">
              <criterion comment="egroupware-sambaadmin is earlier than 1.4.004-2.dfsg-4.2" test_ref="oval:org.mitre.oval:tst:25323"/>
              <criterion comment="egroupware-addressbook is earlier than 1.4.004-2.dfsg-4.2" test_ref="oval:org.mitre.oval:tst:25296"/>
              <criterion comment="egroupware-bookmarks is earlier than 1.4.004-2.dfsg-4.2" test_ref="oval:org.mitre.oval:tst:25621"/>
              <criterion comment="egroupware-projectmanager is earlier than 1.4.004-2.dfsg-4.2" test_ref="oval:org.mitre.oval:tst:25451"/>
              <criterion comment="egroupware-calendar is earlier than 1.4.004-2.dfsg-4.2" test_ref="oval:org.mitre.oval:tst:25483"/>
              <criterion comment="egroupware-infolog is earlier than 1.4.004-2.dfsg-4.2" test_ref="oval:org.mitre.oval:tst:25402"/>
              <criterion comment="egroupware is earlier than 1.4.004-2.dfsg-4.2" test_ref="oval:org.mitre.oval:tst:25486"/>
              <criterion comment="egroupware-core is earlier than 1.4.004-2.dfsg-4.2" test_ref="oval:org.mitre.oval:tst:24661"/>
              <criterion comment="egroupware-mydms is earlier than 1.4.004-2.dfsg-4.2" test_ref="oval:org.mitre.oval:tst:25656"/>
              <criterion comment="egroupware-phpbrain is earlier than 1.4.004-2.dfsg-4.2" test_ref="oval:org.mitre.oval:tst:25632"/>
              <criterion comment="egroupware-registration is earlier than 1.4.004-2.dfsg-4.2" test_ref="oval:org.mitre.oval:tst:24763"/>
              <criterion comment="egroupware-felamimail is earlier than 1.4.004-2.dfsg-4.2" test_ref="oval:org.mitre.oval:tst:25611"/>
              <criterion comment="egroupware-manual is earlier than 1.4.004-2.dfsg-4.2" test_ref="oval:org.mitre.oval:tst:25555"/>
              <criterion comment="egroupware-polls is earlier than 1.4.004-2.dfsg-4.2" test_ref="oval:org.mitre.oval:tst:25274"/>
              <criterion comment="egroupware-sitemgr is earlier than 1.4.004-2.dfsg-4.2" test_ref="oval:org.mitre.oval:tst:25461"/>
              <criterion comment="egroupware-developer-tools is earlier than 1.4.004-2.dfsg-4.2" test_ref="oval:org.mitre.oval:tst:25371"/>
              <criterion comment="egroupware-etemplate is earlier than 1.4.004-2.dfsg-4.2" test_ref="oval:org.mitre.oval:tst:25663"/>
              <criterion comment="egroupware-phpsysinfo is earlier than 1.4.004-2.dfsg-4.2" test_ref="oval:org.mitre.oval:tst:25120"/>
              <criterion comment="egroupware-emailadmin is earlier than 1.4.004-2.dfsg-4.2" test_ref="oval:org.mitre.oval:tst:25598"/>
              <criterion comment="egroupware-filemanager is earlier than 1.4.004-2.dfsg-4.2" test_ref="oval:org.mitre.oval:tst:25401"/>
              <criterion comment="egroupware-timesheet is earlier than 1.4.004-2.dfsg-4.2" test_ref="oval:org.mitre.oval:tst:25419"/>
              <criterion comment="egroupware-resources is earlier than 1.4.004-2.dfsg-4.2" test_ref="oval:org.mitre.oval:tst:25634"/>
              <criterion comment="egroupware-news-admin is earlier than 1.4.004-2.dfsg-4.2" test_ref="oval:org.mitre.oval:tst:25594"/>
              <criterion comment="egroupware-tracker is earlier than 1.4.004-2.dfsg-4.2" test_ref="oval:org.mitre.oval:tst:25664"/>
              <criterion comment="egroupware-wiki is earlier than 1.4.004-2.dfsg-4.2" test_ref="oval:org.mitre.oval:tst:25686"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6870" version="3" class="patch">
      <metadata>
        <title>DSA-1989 fuse -- denial of service</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <platform>Debian GNU/Linux 4.0</platform>
          <product>fuse</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2010/dsa-1989" ref_id="DSA-1989"/>
        <description>Dan Rosenberg discovered a race condition in FUSE, a Filesystem in USErspace. A local attacker, with access to use FUSE, could unmount arbitrary locations, leading to a denial of service.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-05-24T19:05:54-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2010-05-26T13:28:10.668-04:00">DRAFT</status_change>
            <status_change date="2010-06-14T04:00:17.681-04:00">INTERIM</status_change>
            <status_change date="2010-06-29T11:49:01.237-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Release section">
          <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
          <criteria operator="OR" comment="Architecture section">
            <criteria operator="AND" comment="Architecture dependent section">
              <criteria operator="OR" comment="Supported architectures section">
                <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
                <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
                <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
                <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
                <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
                <criterion comment="Installed architecture is armel" test_ref="oval:org.mitre.oval:tst:11101"/>
                <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
                <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
                <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
                <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
                <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
                <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
              </criteria>
              <criteria operator="OR" comment="Packages section">
                <criterion comment="libfuse2 is earlier than 2.7.4-1.1+lenny1" test_ref="oval:org.mitre.oval:tst:25841"/>
                <criterion comment="fuse-utils is earlier than 2.7.4-1.1+lenny1" test_ref="oval:org.mitre.oval:tst:25753"/>
                <criterion comment="libfuse-dev is earlier than 2.7.4-1.1+lenny1" test_ref="oval:org.mitre.oval:tst:25969"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Release section">
          <extend_definition comment="Debian 4.0 is installed." definition_ref="oval:org.mitre.oval:def:6461"/>
          <criteria operator="OR" comment="Architecture section">
            <criteria operator="AND" comment="Architecture dependent section">
              <criteria operator="OR" comment="Supported architectures section">
                <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
                <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
                <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
                <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
                <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
                <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
                <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
                <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
                <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
                <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
              </criteria>
              <criteria operator="OR" comment="Packages section">
                <criterion comment="libfuse2 is earlier than 2.5.3-4.4+etch1" test_ref="oval:org.mitre.oval:tst:25647"/>
                <criterion comment="fuse-utils is earlier than 2.5.3-4.4+etch1" test_ref="oval:org.mitre.oval:tst:25776"/>
                <criterion comment="libfuse-dev is earlier than 2.5.3-4.4+etch1" test_ref="oval:org.mitre.oval:tst:25677"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6869" version="3" class="patch">
      <metadata>
        <title>DSA-1964 postgresql-7.4, postgresql-8.1, postgresql-8.3 -- several vulnerabilities</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <platform>Debian GNU/Linux 4.0</platform>
          <product>postgresql-7.4</product>
          <product>postgresql-8.1</product>
          <product>postgresql-8.3</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2009/dsa-1964" ref_id="DSA-1964"/>
        <description>Several vulnerabilities have been discovered in PostgreSQL, a database server. The Common Vulnerabilities and Exposures project identifies the following problems: It was discovered that PostgreSQL did not properly verify the Common Name attribute in X.509 certificates, enabling attackers to bypass the  TLS protection on client-server connections, by relying on a certificate from a trusted CA which contains an embedded NUL byte in the Common Name . Authenticated database users could elevate their privileges by creating specially-crafted index functions . The following matrix shows fixed source package versions for the respective distributions. In addition to these security fixes, the updates contain reliability improvements and fix other defects. We recommend that you upgrade your PostgreSQL packages.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-05-24T19:08:41-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2010-05-26T13:29:02.373-04:00">DRAFT</status_change>
            <status_change date="2010-06-14T04:00:16.728-04:00">INTERIM</status_change>
            <status_change date="2010-06-29T11:48:59.994-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Release section">
          <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
          <criteria operator="OR" comment="Architecture section">
            <criteria operator="AND" comment="Architecture independent section">
              <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criteria operator="OR" comment="Packages section">
                <criterion comment="postgresql-doc-8.3 is earlier than 8.3.9-0lenny1" test_ref="oval:org.mitre.oval:tst:26450"/>
                <criterion comment="postgresql-doc is earlier than 8.3.9-0lenny1" test_ref="oval:org.mitre.oval:tst:26115"/>
                <criterion comment="postgresql-client is earlier than 8.3.9-0lenny1" test_ref="oval:org.mitre.oval:tst:26778"/>
                <criterion comment="postgresql is earlier than 8.3.9-0lenny1" test_ref="oval:org.mitre.oval:tst:26824"/>
                <criterion comment="postgresql-contrib is earlier than 8.3.9-0lenny1" test_ref="oval:org.mitre.oval:tst:26639"/>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Architecture dependent section">
              <criteria operator="OR" comment="Supported architectures section">
                <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
                <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
                <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
                <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
                <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
                <criterion comment="Installed architecture is armel" test_ref="oval:org.mitre.oval:tst:11101"/>
                <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
                <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
                <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
                <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
                <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
                <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
              </criteria>
              <criteria operator="OR" comment="Packages section">
                <criterion comment="postgresql-client-8.3 is earlier than 8.3.9-0lenny1" test_ref="oval:org.mitre.oval:tst:26003"/>
                <criterion comment="postgresql-plperl-8.3 is earlier than 8.3.9-0lenny1" test_ref="oval:org.mitre.oval:tst:26826"/>
                <criterion comment="postgresql-8.3 is earlier than 8.3.9-0lenny1" test_ref="oval:org.mitre.oval:tst:26852"/>
                <criterion comment="libecpg6 is earlier than 8.3.9-0lenny1" test_ref="oval:org.mitre.oval:tst:26640"/>
                <criterion comment="libpq-dev is earlier than 8.3.9-0lenny1" test_ref="oval:org.mitre.oval:tst:26556"/>
                <criterion comment="postgresql-plpython-8.3 is earlier than 8.3.9-0lenny1" test_ref="oval:org.mitre.oval:tst:26839"/>
                <criterion comment="postgresql-contrib-8.3 is earlier than 8.3.9-0lenny1" test_ref="oval:org.mitre.oval:tst:26856"/>
                <criterion comment="postgresql-server-dev-8.3 is earlier than 8.3.9-0lenny1" test_ref="oval:org.mitre.oval:tst:26901"/>
                <criterion comment="libecpg-dev is earlier than 8.3.9-0lenny1" test_ref="oval:org.mitre.oval:tst:26700"/>
                <criterion comment="postgresql-pltcl-8.3 is earlier than 8.3.9-0lenny1" test_ref="oval:org.mitre.oval:tst:26687"/>
                <criterion comment="libpq5 is earlier than 8.3.9-0lenny1" test_ref="oval:org.mitre.oval:tst:26426"/>
                <criterion comment="libpgtypes3 is earlier than 8.3.9-0lenny1" test_ref="oval:org.mitre.oval:tst:26834"/>
                <criterion comment="libecpg-compat3 is earlier than 8.3.9-0lenny1" test_ref="oval:org.mitre.oval:tst:26647"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Release section">
          <extend_definition comment="Debian 4.0 is installed." definition_ref="oval:org.mitre.oval:def:6461"/>
          <criteria operator="OR" comment="Architecture section">
            <criteria operator="AND" comment="Architecture independent section">
              <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criteria operator="OR" comment="Packages section">
                <criterion comment="postgresql-doc-8.1 is earlier than 8.1.19-0etch1" test_ref="oval:org.mitre.oval:tst:26829"/>
                <criterion comment="postgresql-server-dev-7.4 is earlier than 7.4.27-0etch1" test_ref="oval:org.mitre.oval:tst:26790"/>
                <criterion comment="postgresql-doc-7.4 is earlier than 7.4.27-0etch1" test_ref="oval:org.mitre.oval:tst:26823"/>
              </criteria>
            </criteria>
            <criteria operator="OR" comment="Packages section">
              <criterion comment="postgresql-7.4 is earlier than 7.4.27-0etch1" test_ref="oval:org.mitre.oval:tst:26851"/>
              <criterion comment="postgresql-client-8.1 is earlier than 8.1.19-0etch1" test_ref="oval:org.mitre.oval:tst:25923"/>
              <criterion comment="postgresql-8.1 is earlier than 8.1.19-0etch1" test_ref="oval:org.mitre.oval:tst:26709"/>
              <criterion comment="libpq-dev is earlier than 8.1.19-0etch1" test_ref="oval:org.mitre.oval:tst:26894"/>
              <criterion comment="postgresql-plpython-7.4 is earlier than 7.4.27-0etch1" test_ref="oval:org.mitre.oval:tst:26878"/>
              <criterion comment="postgresql-contrib-8.1 is earlier than 8.1.19-0etch1" test_ref="oval:org.mitre.oval:tst:26737"/>
              <criterion comment="postgresql-contrib-7.4 is earlier than 7.4.27-0etch1" test_ref="oval:org.mitre.oval:tst:26840"/>
              <criterion comment="libecpg5 is earlier than 8.1.19-0etch1" test_ref="oval:org.mitre.oval:tst:26880"/>
              <criterion comment="postgresql-pltcl-8.1 is earlier than 8.1.19-0etch1" test_ref="oval:org.mitre.oval:tst:26641"/>
              <criterion comment="postgresql-client-7.4 is earlier than 7.4.27-0etch1" test_ref="oval:org.mitre.oval:tst:26801"/>
              <criterion comment="libpgtypes2 is earlier than 8.1.19-0etch1" test_ref="oval:org.mitre.oval:tst:25968"/>
              <criterion comment="postgresql-server-dev-8.1 is earlier than 8.1.19-0etch1" test_ref="oval:org.mitre.oval:tst:26951"/>
              <criterion comment="libecpg-dev is earlier than 8.1.19-0etch1" test_ref="oval:org.mitre.oval:tst:26949"/>
              <criterion comment="postgresql-plpython-8.1 is earlier than 8.1.19-0etch1" test_ref="oval:org.mitre.oval:tst:26673"/>
              <criterion comment="libpq4 is earlier than 8.1.19-0etch1" test_ref="oval:org.mitre.oval:tst:26777"/>
              <criterion comment="postgresql-plperl-7.4 is earlier than 7.4.27-0etch1" test_ref="oval:org.mitre.oval:tst:26890"/>
              <criterion comment="postgresql-plperl-8.1 is earlier than 8.1.19-0etch1" test_ref="oval:org.mitre.oval:tst:26957"/>
              <criterion comment="postgresql-pltcl-7.4 is earlier than 7.4.27-0etch1" test_ref="oval:org.mitre.oval:tst:26656"/>
              <criterion comment="libecpg-compat2 is earlier than 8.1.19-0etch1" test_ref="oval:org.mitre.oval:tst:26960"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6868" version="3" class="patch">
      <metadata>
        <title>DSA-1959 ganeti -- missing input sanitation</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <product>ganeti</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2009/dsa-1959" ref_id="DSA-1959"/>
        <description>It was discovered that ganeti, a virtual server cluster manager, does not validate the path of scripts passed as arguments to certain commands, which allows local or remote users  to execute arbitrary commands on a host acting as a cluster master. The oldstable distribution  does not include ganeti.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-05-24T19:04:30-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2010-05-26T13:27:52.876-04:00">DRAFT</status_change>
            <status_change date="2010-06-14T04:00:16.493-04:00">INTERIM</status_change>
            <status_change date="2010-06-29T11:48:59.738-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
        <criteria operator="OR" comment="Architecture section">
          <criteria operator="AND" comment="Architecture independent section">
            <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
            <criterion comment="ganeti is earlier than 1.2.6-3+lenny2" test_ref="oval:org.mitre.oval:tst:25887"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6850" version="3" class="patch">
      <metadata>
        <title>DSA-2026 netpbm-free -- stack-based buffer overflow</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <product>netpbm-free</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2010/dsa-2026" ref_id="DSA-2026"/>
        <description>Marc Schoenefeld discovered a stack-based buffer overflow in the XPM reader implementation in netpbm-free, a suite of image manipulation utilities. An attacker could cause a denial of service  or possibly execute arbitrary code via an XPM image file that contains a crafted header field associated with a large color index value.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-05-24T19:08:16-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2010-05-26T13:28:51.136-04:00">DRAFT</status_change>
            <status_change date="2010-06-14T04:00:15.749-04:00">INTERIM</status_change>
            <status_change date="2010-06-29T11:48:58.885-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
        <criteria operator="OR" comment="Architecture section">
          <criteria operator="AND" comment="Architecture dependent section">
            <criteria operator="OR" comment="Supported architectures section">
              <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
              <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
              <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
              <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
              <criterion comment="Installed architecture is armel" test_ref="oval:org.mitre.oval:tst:11101"/>
              <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
              <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
              <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
              <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
            </criteria>
            <criteria operator="OR" comment="Packages section">
              <criterion comment="libnetpbm9 is earlier than 10.0-12+lenny1" test_ref="oval:org.mitre.oval:tst:26380"/>
              <criterion comment="netpbm is earlier than 10.0-12+lenny1" test_ref="oval:org.mitre.oval:tst:26578"/>
              <criterion comment="libnetpbm10-dev is earlier than 10.0-12+lenny1" test_ref="oval:org.mitre.oval:tst:26726"/>
              <criterion comment="libnetpbm10 is earlier than 10.0-12+lenny1" test_ref="oval:org.mitre.oval:tst:25903"/>
              <criterion comment="libnetpbm9-dev is earlier than 10.0-12+lenny1" test_ref="oval:org.mitre.oval:tst:26535"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6827" version="3" class="patch">
      <metadata>
        <title>DSA-1994 ajaxterm -- weak session IDs</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <platform>Debian GNU/Linux 4.0</platform>
          <product>ajaxterm</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2010/dsa-1994" ref_id="DSA-1994"/>
        <description>It was discovered that ajaxterm, a web-based terminal, generates weak and predictable session IDs, which might be used to hijack a session or cause a denial of service attack on a system that uses ajaxterm.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-05-24T19:08:03-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2010-05-26T13:28:42.751-04:00">DRAFT</status_change>
            <status_change date="2010-06-14T04:00:14.568-04:00">INTERIM</status_change>
            <status_change date="2010-06-29T11:48:56.858-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Release section">
          <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
          <criteria operator="OR" comment="Architecture section">
            <criteria operator="AND" comment="Architecture independent section">
              <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criterion comment="ajaxterm is earlier than 0.10-2+lenny1" test_ref="oval:org.mitre.oval:tst:26620"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Release section">
          <extend_definition comment="Debian 4.0 is installed." definition_ref="oval:org.mitre.oval:def:6461"/>
          <criteria operator="OR" comment="Architecture section">
            <criteria operator="AND" comment="Architecture independent section">
              <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criterion comment="ajaxterm is earlier than 0.9-2+etch1" test_ref="oval:org.mitre.oval:tst:26077"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6826" version="3" class="patch">
      <metadata>
        <title>DSA-1998 kdelibs -- buffer overflow</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <product>kdelibs</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2010/dsa-1998" ref_id="DSA-1998"/>
        <description>Maksymilian Arciemowicz discovered a buffer overflow in the internal string routines of the KDE core libraries, which could lead to the execution of arbitrary code.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-05-24T19:08:09-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2010-05-26T13:28:49.491-04:00">DRAFT</status_change>
            <status_change date="2010-06-14T04:00:14.110-04:00">INTERIM</status_change>
            <status_change date="2010-06-29T11:48:56.394-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
        <criteria operator="OR" comment="Architecture section">
          <criteria operator="AND" comment="Architecture independent section">
            <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
            <criteria operator="OR" comment="Packages section">
              <criterion comment="kdelibs4-doc is earlier than 3.5.10.dfsg.1-0lenny4" test_ref="oval:org.mitre.oval:tst:26706"/>
              <criterion comment="kdelibs is earlier than 3.5.10.dfsg.1-0lenny4" test_ref="oval:org.mitre.oval:tst:25901"/>
              <criterion comment="kdelibs-data is earlier than 3.5.10.dfsg.1-0lenny4" test_ref="oval:org.mitre.oval:tst:26815"/>
            </criteria>
          </criteria>
          <criteria operator="AND" comment="Architecture dependent section">
            <criteria operator="OR" comment="Supported architectures section">
              <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
              <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
              <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
              <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
              <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
              <criterion comment="Installed architecture is armel" test_ref="oval:org.mitre.oval:tst:11101"/>
              <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
              <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
              <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
              <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
              <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
              <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
            </criteria>
            <criteria operator="OR" comment="Packages section">
              <criterion comment="kdelibs4-dev is earlier than 3.5.10.dfsg.1-0lenny4" test_ref="oval:org.mitre.oval:tst:26210"/>
              <criterion comment="kdelibs4c2a is earlier than 3.5.10.dfsg.1-0lenny4" test_ref="oval:org.mitre.oval:tst:26771"/>
              <criterion comment="kdelibs-dbg is earlier than 3.5.10.dfsg.1-0lenny4" test_ref="oval:org.mitre.oval:tst:26648"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6808" version="3" class="patch">
      <metadata>
        <title>DSA-2046 phpgroupware -- several vulnerabilities</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <product>phpgroupware</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2010/dsa-2046" ref_id="DSA-2046"/>
        <description>Several remote vulnerabilities have been discovered in phpgroupware, a Web based groupware system written in PHP. The Common Vulnerabilities and Exposures project identifies the following problems: A local file inclusion vulnerability allows remote attackers to execute arbitrary PHP code and include arbitrary local files. Multiple SQL injection vulnerabilities allows remote attackers to execute arbitrary SQL commands.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-05-24T19:04:34-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2010-05-26T13:27:55.510-04:00">DRAFT</status_change>
            <status_change date="2010-06-14T04:00:13.588-04:00">INTERIM</status_change>
            <status_change date="2010-06-29T11:48:55.866-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
        <criteria operator="OR" comment="Architecture section">
          <criteria operator="AND" comment="Architecture independent section">
            <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
            <criteria operator="OR" comment="Packages section">
              <criterion comment="phpgroupware-0.9.16-phpgwapi is earlier than 0.9.16.012+dfsg-8+lenny2" test_ref="oval:org.mitre.oval:tst:24999"/>
              <criterion comment="phpgroupware-0.9.16-addressbook is earlier than 0.9.16.012+dfsg-8+lenny2" test_ref="oval:org.mitre.oval:tst:25931"/>
              <criterion comment="phpgroupware-0.9.16-news-admin is earlier than 0.9.16.012+dfsg-8+lenny2" test_ref="oval:org.mitre.oval:tst:25800"/>
              <criterion comment="phpgroupware-0.9.16-setup is earlier than 0.9.16.012+dfsg-8+lenny2" test_ref="oval:org.mitre.oval:tst:25812"/>
              <criterion comment="phpgroupware-0.9.16-phpgwapi-doc is earlier than 0.9.16.012+dfsg-8+lenny2" test_ref="oval:org.mitre.oval:tst:25912"/>
              <criterion comment="phpgroupware-0.9.16-todo is earlier than 0.9.16.012+dfsg-8+lenny2" test_ref="oval:org.mitre.oval:tst:25353"/>
              <criterion comment="phpgroupware-0.9.16-preferences is earlier than 0.9.16.012+dfsg-8+lenny2" test_ref="oval:org.mitre.oval:tst:25591"/>
              <criterion comment="phpgroupware-0.9.16-core-base is earlier than 0.9.16.012+dfsg-8+lenny2" test_ref="oval:org.mitre.oval:tst:25712"/>
              <criterion comment="phpgroupware-0.9.16-email is earlier than 0.9.16.012+dfsg-8+lenny2" test_ref="oval:org.mitre.oval:tst:25592"/>
              <criterion comment="phpgroupware-0.9.16-filemanager is earlier than 0.9.16.012+dfsg-8+lenny2" test_ref="oval:org.mitre.oval:tst:25900"/>
              <criterion comment="phpgroupware-0.9.16 is earlier than 0.9.16.012+dfsg-8+lenny2" test_ref="oval:org.mitre.oval:tst:25910"/>
              <criterion comment="phpgroupware is earlier than 0.9.16.012+dfsg-8+lenny2" test_ref="oval:org.mitre.oval:tst:25710"/>
              <criterion comment="phpgroupware-0.9.16-core is earlier than 0.9.16.012+dfsg-8+lenny2" test_ref="oval:org.mitre.oval:tst:25928"/>
              <criterion comment="phpgroupware-0.9.16-calendar is earlier than 0.9.16.012+dfsg-8+lenny2" test_ref="oval:org.mitre.oval:tst:25643"/>
              <criterion comment="phpgroupware-0.9.16-manual is earlier than 0.9.16.012+dfsg-8+lenny2" test_ref="oval:org.mitre.oval:tst:25866"/>
              <criterion comment="phpgroupware-0.9.16-admin is earlier than 0.9.16.012+dfsg-8+lenny2" test_ref="oval:org.mitre.oval:tst:25861"/>
              <criterion comment="phpgroupware-0.9.16-doc is earlier than 0.9.16.012+dfsg-8+lenny2" test_ref="oval:org.mitre.oval:tst:25695"/>
              <criterion comment="phpgroupware-0.9.16-notes is earlier than 0.9.16.012+dfsg-8+lenny2" test_ref="oval:org.mitre.oval:tst:25721"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6799" version="3" class="patch">
      <metadata>
        <title>DSA-1997 mysql-dfsg-5.0 -- several vulnerabilities</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <platform>Debian GNU/Linux 4.0</platform>
          <product>mysql-dfsg-5.0</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2010/dsa-1997" ref_id="DSA-1997"/>
        <description>Several vulnerabilities have been discovered in the MySQL database server. The Common Vulnerabilities and Exposures project identifies the following problems: Domas Mituzas discovered that mysqld does not properly handle errors during execution of certain SELECT statements with subqueries, and does not preserve certain null_value flags during execution of statements that use the GeomFromWKB function, which allows remote authenticated users to cause a denial of service  via a crafted statement. Sergei Golubchik discovered that MySQL allows local users to bypass certain privilege checks by calling CREATE TABLE on a MyISAM table with modified DATA DIRECTORY or INDEX DIRECTORY arguments that are originally associated with pathnames without symlinks, and that can point to tables created at a future time at which a pathname is modified to contain a symlink to a subdirectory of the MySQL data home directory. Multiple stack-based buffer overflows in the CertDecoder::GetName function in src/asn.cpp in TaoCrypt in yaSSL before 1.9.9, as used in mysqld, allow remote attackers to execute arbitrary code or cause a denial of service  by establishing an SSL connection and sending an X.509 client certificate with a crafted name field.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-05-24T19:08:04-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2010-05-26T13:28:43.943-04:00">DRAFT</status_change>
            <status_change date="2010-06-14T04:00:12.942-04:00">INTERIM</status_change>
            <status_change date="2010-06-29T11:48:55.287-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Release section">
          <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
          <criteria operator="OR" comment="Architecture section">
            <criteria operator="AND" comment="Architecture independent section">
              <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criteria operator="OR" comment="Packages section">
                <criterion comment="mysql-client is earlier than 5.0.51a-24+lenny3" test_ref="oval:org.mitre.oval:tst:26386"/>
                <criterion comment="mysql-common is earlier than 5.0.51a-24+lenny3" test_ref="oval:org.mitre.oval:tst:26135"/>
                <criterion comment="mysql-server is earlier than 5.0.51a-24+lenny3" test_ref="oval:org.mitre.oval:tst:26602"/>
              </criteria>
            </criteria>
            <criteria operator="OR" comment="Packages section">
              <criterion comment="libmysqlclient15-dev is earlier than 5.0.51a-24+lenny3" test_ref="oval:org.mitre.oval:tst:26294"/>
              <criterion comment="mysql-client-5.0 is earlier than 5.0.51a-24+lenny3" test_ref="oval:org.mitre.oval:tst:26526"/>
              <criterion comment="libmysqlclient15off is earlier than 5.0.51a-24+lenny3" test_ref="oval:org.mitre.oval:tst:26614"/>
              <criterion comment="mysql-server-5.0 is earlier than 5.0.51a-24+lenny3" test_ref="oval:org.mitre.oval:tst:26581"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Release section">
          <extend_definition comment="Debian 4.0 is installed." definition_ref="oval:org.mitre.oval:def:6461"/>
          <criteria operator="OR" comment="Architecture section">
            <criteria operator="AND" comment="Architecture independent section">
              <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criteria operator="OR" comment="Packages section">
                <criterion comment="mysql-client is earlier than 5.0.32-7etch12" test_ref="oval:org.mitre.oval:tst:26394"/>
                <criterion comment="mysql-common is earlier than 5.0.32-7etch12" test_ref="oval:org.mitre.oval:tst:26470"/>
                <criterion comment="mysql-server is earlier than 5.0.32-7etch12" test_ref="oval:org.mitre.oval:tst:26454"/>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Architecture dependent section">
              <criteria operator="OR" comment="Supported architectures section">
                <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
                <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
                <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
                <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
                <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
                <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
                <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
                <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
                <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
              </criteria>
              <criteria operator="OR" comment="Packages section">
                <criterion comment="libmysqlclient15-dev is earlier than 5.0.32-7etch12" test_ref="oval:org.mitre.oval:tst:26353"/>
                <criterion comment="mysql-server-4.1 is earlier than 5.0.32-7etch12" test_ref="oval:org.mitre.oval:tst:26468"/>
                <criterion comment="mysql-client-5.0 is earlier than 5.0.32-7etch12" test_ref="oval:org.mitre.oval:tst:26215"/>
                <criterion comment="mysql-server-5.0 is earlier than 5.0.32-7etch12" test_ref="oval:org.mitre.oval:tst:26457"/>
                <criterion comment="libmysqlclient15off is earlier than 5.0.32-7etch12" test_ref="oval:org.mitre.oval:tst:26477"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6777" version="3" class="patch">
      <metadata>
        <title>DSA-1971 libthai -- integer overflow</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <platform>Debian GNU/Linux 4.0</platform>
          <product>libthai</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2010/dsa-1971" ref_id="DSA-1971"/>
        <description>Tim Starling discovered that libthai, a set of Thai language support routines, is vulnerable of integer/heap overflow. This vulnerability could allow an attacker to run arbitrary code by sending a very long string.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-05-24T19:10:59-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2010-05-26T13:29:27.790-04:00">DRAFT</status_change>
            <status_change date="2010-06-14T04:00:12.440-04:00">INTERIM</status_change>
            <status_change date="2010-06-29T11:48:54.371-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Release section">
          <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
          <criteria operator="OR" comment="Architecture section">
            <criteria operator="AND" comment="Architecture independent section">
              <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criteria operator="OR" comment="Packages section">
                <criterion comment="libthai-doc is earlier than 0.1.9-4+lenny1" test_ref="oval:org.mitre.oval:tst:26928"/>
                <criterion comment="libthai-data is earlier than 0.1.9-4+lenny1" test_ref="oval:org.mitre.oval:tst:26875"/>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Architecture dependent section">
              <criteria operator="OR" comment="Supported architectures section">
                <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
                <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
                <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
                <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
                <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
                <criterion comment="Installed architecture is armel" test_ref="oval:org.mitre.oval:tst:11101"/>
                <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
                <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
                <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
                <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
                <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
              </criteria>
              <criteria operator="OR" comment="Packages section">
                <criterion comment="libthai0 is earlier than 0.1.9-4+lenny1" test_ref="oval:org.mitre.oval:tst:27085"/>
                <criterion comment="libthai-dev is earlier than 0.1.9-4+lenny1" test_ref="oval:org.mitre.oval:tst:27082"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Release section">
          <extend_definition comment="Debian 4.0 is installed." definition_ref="oval:org.mitre.oval:def:6461"/>
          <criteria operator="OR" comment="Architecture section">
            <criteria operator="AND" comment="Architecture independent section">
              <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criterion comment="libthai-doc is earlier than 0.1.6-1+etch1" test_ref="oval:org.mitre.oval:tst:27170"/>
            </criteria>
            <criteria operator="AND" comment="Architecture dependent section">
              <criteria operator="OR" comment="Supported architectures section">
                <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
                <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
                <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
                <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
                <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
                <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
                <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
                <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
                <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
                <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
              </criteria>
              <criteria operator="OR" comment="Packages section">
                <criterion comment="libthai0 is earlier than 0.1.6-1+etch1" test_ref="oval:org.mitre.oval:tst:26997"/>
                <criterion comment="libthai-dev is earlier than 0.1.6-1+etch1" test_ref="oval:org.mitre.oval:tst:26962"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6767" version="3" class="patch">
      <metadata>
        <title>DSA-2044 mplayer -- integer overflow</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <product>mplayer</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2010/dsa-2044" ref_id="DSA-2044"/>
        <description>tixxDZ  discovered a vulnerability in the mplayer movie player. Missing data validation in mplayer"s real data transport  implementation enable an integer underflow and consequently an unbounded buffer operation. A maliciously crafted stream could thus enable an attacker to execute arbitrary code. No Common Vulnerabilities and Exposures project identifier is available for this issue.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-05-24T19:04:47-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2010-05-26T13:27:56.152-04:00">DRAFT</status_change>
            <status_change date="2010-06-14T04:00:11.807-04:00">INTERIM</status_change>
            <status_change date="2010-06-29T11:48:53.128-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
        <criteria operator="OR" comment="Architecture section">
          <criteria operator="AND" comment="Architecture independent section">
            <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
            <criterion comment="mplayer-doc is earlier than 1.0~rc2-17+lenny3.2" test_ref="oval:org.mitre.oval:tst:25835"/>
          </criteria>
          <criteria operator="AND" comment="Architecture dependent section">
            <criteria operator="OR" comment="Supported architectures section">
              <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
              <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
              <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
              <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
              <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
              <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
              <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
              <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
              <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
              <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
              <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
            </criteria>
            <criteria operator="OR" comment="Packages section">
              <criterion comment="mplayer-dbg is earlier than 1.0~rc2-17+lenny3.2" test_ref="oval:org.mitre.oval:tst:25839"/>
              <criterion comment="mplayer is earlier than 1.0~rc2-17+lenny3.2" test_ref="oval:org.mitre.oval:tst:25530"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6760" version="3" class="patch">
      <metadata>
        <title>DSA-1953 expat -- denial of service</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <platform>Debian GNU/Linux 4.0</platform>
          <product>expat</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2009/dsa-1953" ref_id="DSA-1953"/>
        <description>Jan Lieskovsky discovered an error in expat, an XML parsing C library, when parsing certain UTF-8 sequences, which can be exploited to crash an application using the library.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-05-24T19:04:21-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2010-05-26T13:27:51.566-04:00">DRAFT</status_change>
            <status_change date="2010-06-14T04:00:11.258-04:00">INTERIM</status_change>
            <status_change date="2010-06-29T11:48:51.219-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Release section">
          <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
          <criteria operator="OR" comment="Architecture section">
            <criteria operator="AND" comment="Architecture dependent section">
              <criteria operator="OR" comment="Supported architectures section">
                <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
                <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
                <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
                <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
              </criteria>
              <criteria operator="OR" comment="Packages section">
                <criterion comment="lib64expat1 is earlier than 2.0.1-4+lenny2" test_ref="oval:org.mitre.oval:tst:25646"/>
                <criterion comment="lib64expat1-dev is earlier than 2.0.1-4+lenny2" test_ref="oval:org.mitre.oval:tst:25551"/>
                <criterion comment="expat is earlier than 2.0.1-4+lenny2" test_ref="oval:org.mitre.oval:tst:24950"/>
                <criterion comment="libexpat1-dev is earlier than 2.0.1-4+lenny2" test_ref="oval:org.mitre.oval:tst:25270"/>
                <criterion comment="libexpat1 is earlier than 2.0.1-4+lenny2" test_ref="oval:org.mitre.oval:tst:25940"/>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Architecture dependent section">
              <criteria operator="OR" comment="Supported architectures section">
                <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
                <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
                <criterion comment="Installed architecture is armel" test_ref="oval:org.mitre.oval:tst:11101"/>
                <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
                <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
                <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
                <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
                <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
              </criteria>
              <criteria operator="OR" comment="Packages section">
                <criterion comment="expat is earlier than 2.0.1-4+lenny2" test_ref="oval:org.mitre.oval:tst:25698"/>
                <criterion comment="libexpat1-dev is earlier than 2.0.1-4+lenny2" test_ref="oval:org.mitre.oval:tst:25610"/>
                <criterion comment="libexpat1 is earlier than 2.0.1-4+lenny2" test_ref="oval:org.mitre.oval:tst:25842"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Release section">
          <extend_definition comment="Debian 4.0 is installed." definition_ref="oval:org.mitre.oval:def:6461"/>
          <criteria operator="OR" comment="Architecture section">
            <criteria operator="AND" comment="Architecture dependent section">
              <criteria operator="OR" comment="Supported architectures section">
                <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
                <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
                <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
                <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
                <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
                <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
                <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
                <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
                <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
                <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
              </criteria>
              <criteria operator="OR" comment="Packages section">
                <criterion comment="libexpat1 is earlier than 1.95.8-3.4+etch2" test_ref="oval:org.mitre.oval:tst:25564"/>
                <criterion comment="expat is earlier than 1.95.8-3.4+etch2" test_ref="oval:org.mitre.oval:tst:25617"/>
                <criterion comment="libexpat1-dev is earlier than 1.95.8-3.4+etch2" test_ref="oval:org.mitre.oval:tst:25615"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6752" version="3" class="patch">
      <metadata>
        <title>DSA-1973 glibc, eglibc -- information disclosure</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <platform>Debian GNU/Linux 4.0</platform>
          <product>glibc</product>
          <product>eglibc</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2010/dsa-1973" ref_id="DSA-1973"/>
        <description>Christoph Pleger has discovered that the GNU C Library  and its derivatives add information from the passwd.adjunct.byname map to entries in the passwd map, which allows local users to obtain the encrypted passwords of NIS accounts by calling the getpwnam function.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-05-24T19:10:33-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2010-05-26T13:29:25.906-04:00">DRAFT</status_change>
            <status_change date="2010-06-14T04:00:10.374-04:00">INTERIM</status_change>
            <status_change date="2010-06-29T11:48:49.862-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Release section">
          <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
          <criteria operator="OR" comment="Architecture section">
            <criteria operator="AND" comment="Architecture independent section">
              <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criteria operator="OR" comment="Packages section">
                <criterion comment="glibc-doc is earlier than 2.7-18lenny2" test_ref="oval:org.mitre.oval:tst:26923"/>
                <criterion comment="glibc-source is earlier than 2.7-18lenny2" test_ref="oval:org.mitre.oval:tst:26787"/>
                <criterion comment="locales is earlier than 2.7-18lenny2" test_ref="oval:org.mitre.oval:tst:26336"/>
              </criteria>
            </criteria>
            <criteria operator="OR" comment="Packages section">
              <criterion comment="libc6-prof is earlier than 2.7-18lenny2" test_ref="oval:org.mitre.oval:tst:26575"/>
              <criterion comment="nscd is earlier than 2.7-18lenny2" test_ref="oval:org.mitre.oval:tst:26979"/>
              <criterion comment="libc6-dev is earlier than 2.7-18lenny2" test_ref="oval:org.mitre.oval:tst:26768"/>
              <criterion comment="libc6-pic is earlier than 2.7-18lenny2" test_ref="oval:org.mitre.oval:tst:27024"/>
              <criterion comment="libc6 is earlier than 2.7-18lenny2" test_ref="oval:org.mitre.oval:tst:27143"/>
              <criterion comment="locales-all is earlier than 2.7-18lenny2" test_ref="oval:org.mitre.oval:tst:26399"/>
              <criterion comment="libc6-dbg is earlier than 2.7-18lenny2" test_ref="oval:org.mitre.oval:tst:26251"/>
            </criteria>
            <criteria operator="AND" comment="Architecture dependent section">
              <criteria operator="OR" comment="Supported architectures section">
                <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
              </criteria>
              <criteria operator="OR" comment="Packages section">
                <criterion comment="libc6-dev-s390x is earlier than 2.7-18lenny2" test_ref="oval:org.mitre.oval:tst:27060"/>
                <criterion comment="libc6-s390x is earlier than 2.7-18lenny2" test_ref="oval:org.mitre.oval:tst:26814"/>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Architecture depended section">
              <criteria operator="AND" comment="Supported platform section">
                <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
                <criteria operator="OR" comment="Packages section">
                  <criterion comment="libc6-mips64 is earlier than 2.7-18lenny2" test_ref="oval:org.mitre.oval:tst:27034"/>
                  <criterion comment="libc6-dev-mips64 is earlier than 2.7-18lenny2" test_ref="oval:org.mitre.oval:tst:26754"/>
                  <criterion comment="libc6-dev-mipsn32 is earlier than 2.7-18lenny2" test_ref="oval:org.mitre.oval:tst:27163"/>
                  <criterion comment="libc6-mipsn32 is earlier than 2.7-18lenny2" test_ref="oval:org.mitre.oval:tst:27048"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Release section">
          <extend_definition comment="Debian 4.0 is installed." definition_ref="oval:org.mitre.oval:def:6461"/>
          <criteria operator="OR" comment="Architecture section">
            <criteria operator="AND" comment="Architecture independent section">
              <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criteria operator="OR" comment="Packages section">
                <criterion comment="glibc-doc is earlier than 2.3.6.ds1-13etch10" test_ref="oval:org.mitre.oval:tst:27141"/>
                <criterion comment="locales is earlier than 2.3.6.ds1-13etch10" test_ref="oval:org.mitre.oval:tst:27125"/>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Architecture dependent section">
              <criteria operator="OR" comment="Supported architectures section">
                <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
                <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
                <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
                <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
                <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
                <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
                <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
                <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
              </criteria>
              <criteria operator="OR" comment="Packages section">
                <criterion comment="locales-all is earlier than 2.3.6.ds1-13etch10" test_ref="oval:org.mitre.oval:tst:27139"/>
                <criterion comment="libc6-prof is earlier than 2.3.6.ds1-13etch10" test_ref="oval:org.mitre.oval:tst:26769"/>
                <criterion comment="libc6-dev is earlier than 2.3.6.ds1-13etch10" test_ref="oval:org.mitre.oval:tst:26325"/>
                <criterion comment="libc6-pic is earlier than 2.3.6.ds1-13etch10" test_ref="oval:org.mitre.oval:tst:26920"/>
                <criterion comment="libc6 is earlier than 2.3.6.ds1-13etch10" test_ref="oval:org.mitre.oval:tst:26666"/>
                <criterion comment="nscd is earlier than 2.3.6.ds1-13etch10" test_ref="oval:org.mitre.oval:tst:27167"/>
                <criterion comment="libc6-dbg is earlier than 2.3.6.ds1-13etch10" test_ref="oval:org.mitre.oval:tst:27049"/>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Architecture dependent section">
              <criteria operator="OR" comment="Supported architectures section">
                <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
              </criteria>
              <criteria operator="OR" comment="Packages section">
                <criterion comment="libc6-dev-s390x is earlier than 2.3.6.ds1-13etch10" test_ref="oval:org.mitre.oval:tst:27151"/>
                <criterion comment="libc6-s390x is earlier than 2.3.6.ds1-13etch10" test_ref="oval:org.mitre.oval:tst:26994"/>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Architecture depended section">
              <criteria operator="AND" comment="Supported platform section">
                <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
                <criteria operator="OR" comment="Packages section">
                  <criterion comment="libc6.1-pic is earlier than 2.3.6.ds1-13etch10" test_ref="oval:org.mitre.oval:tst:26999"/>
                  <criterion comment="libc6.1-dev is earlier than 2.3.6.ds1-13etch10" test_ref="oval:org.mitre.oval:tst:27075"/>
                  <criterion comment="libc6.1-dbg is earlier than 2.3.6.ds1-13etch10" test_ref="oval:org.mitre.oval:tst:26974"/>
                  <criterion comment="nscd is earlier than 2.3.6.ds1-13etch10" test_ref="oval:org.mitre.oval:tst:27083"/>
                  <criterion comment="libc6.1-prof is earlier than 2.3.6.ds1-13etch10" test_ref="oval:org.mitre.oval:tst:26953"/>
                  <criterion comment="locales-all is earlier than 2.3.6.ds1-13etch10" test_ref="oval:org.mitre.oval:tst:26843"/>
                  <criterion comment="libc6.1 is earlier than 2.3.6.ds1-13etch10" test_ref="oval:org.mitre.oval:tst:27115"/>
                </criteria>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6751" version="3" class="patch">
      <metadata>
        <title>DSA-1976 dokuwiki -- several vulnerabilities</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <product>dokuwiki</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2010/dsa-1976" ref_id="DSA-1976"/>
        <description>Several vulnerabilities have been discovered in dokuwiki, a standards compliant simple to use wiki. The Common Vulnerabilities and Exposures project identifies the following problems: It was discovered that an internal variable is not properly sanitized before being used to list directories. This can be exploited to list contents of arbitrary directories. It was discovered that the ACL Manager plugin doesn"t properly check the administrator permissions. This allow an attacker to introduce arbitrary ACL rules and thus gaining access to a closed Wiki. It was discovered that the ACL Manager plugin doesn"t have protections against cross-site request forgeries . This can be exploited to change the access control rules by tricking a logged in administrator into visiting a malicious web site. The oldstable distribution  is not affected by these problems.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-05-24T19:10:31-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2010-05-26T13:29:22.809-04:00">DRAFT</status_change>
            <status_change date="2010-06-14T04:00:10.127-04:00">INTERIM</status_change>
            <status_change date="2010-06-29T11:48:49.596-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
        <criteria operator="OR" comment="Architecture section">
          <criteria operator="AND" comment="Architecture independent section">
            <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
            <criterion comment="dokuwiki is earlier than 0.0.20080505-4+lenny1" test_ref="oval:org.mitre.oval:tst:26992"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6745" version="3" class="patch">
      <metadata>
        <title>DSA-2029 imlib2 -- several vulnerabilities</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <product>imlib2</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2010/dsa-2029" ref_id="DSA-2029"/>
        <description>It was discovered that imlib2, a library to load and process several image formats, did not properly process various image file types. Several heap and stack based buffer overflows - partly due to integer overflows - in the ARGB, BMP, JPEG, LBM, PNM, TGA and XPM loaders can lead to the execution of arbitrary code via crafted image files.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-05-24T19:08:29-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2010-05-26T13:28:55.060-04:00">DRAFT</status_change>
            <status_change date="2010-06-14T04:00:09.647-04:00">INTERIM</status_change>
            <status_change date="2010-06-29T11:48:49.227-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
        <criteria operator="OR" comment="Architecture section">
          <criteria operator="AND" comment="Architecture dependent section">
            <criteria operator="OR" comment="Supported architectures section">
              <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
              <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
              <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
              <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
              <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
              <criterion comment="Installed architecture is armel" test_ref="oval:org.mitre.oval:tst:11101"/>
              <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
              <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
              <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
              <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
              <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
            </criteria>
            <criteria operator="OR" comment="Packages section">
              <criterion comment="libimlib2-dev is earlier than 1.4.0-1.2+lenny1" test_ref="oval:org.mitre.oval:tst:26697"/>
              <criterion comment="libimlib2 is earlier than 1.4.0-1.2+lenny1" test_ref="oval:org.mitre.oval:tst:26893"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6724" version="3" class="patch">
      <metadata>
        <title>DSA-2031 krb5 -- use-after-free</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <product>krb5</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2010/dsa-2031" ref_id="DSA-2031"/>
        <description>Sol Jerome discovered that kadmind service in krb5, a system for authenticating users and services on a network, allows remote authenticated users to cause a denial of service  via a request from a kadmin client that sends an invalid API version number.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-05-24T19:10:14-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2010-05-26T13:29:16.350-04:00">DRAFT</status_change>
            <status_change date="2010-06-14T04:00:09.074-04:00">INTERIM</status_change>
            <status_change date="2010-06-29T11:48:48.654-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
        <criteria operator="OR" comment="Architecture section">
          <criteria operator="AND" comment="Architecture independent section">
            <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
            <criterion comment="krb5-doc is earlier than 1.6.dfsg.4~beta1-5lenny3" test_ref="oval:org.mitre.oval:tst:26965"/>
          </criteria>
          <criteria operator="AND" comment="Architecture dependent section">
            <criteria operator="OR" comment="Supported architectures section">
              <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
              <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
              <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
              <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
              <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
              <criterion comment="Installed architecture is armel" test_ref="oval:org.mitre.oval:tst:11101"/>
              <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
              <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
              <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
              <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
              <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
            </criteria>
            <criteria operator="OR" comment="Packages section">
              <criterion comment="krb5-rsh-server is earlier than 1.6.dfsg.4~beta1-5lenny3" test_ref="oval:org.mitre.oval:tst:26933"/>
              <criterion comment="krb5-kdc-ldap is earlier than 1.6.dfsg.4~beta1-5lenny3" test_ref="oval:org.mitre.oval:tst:26511"/>
              <criterion comment="krb5-telnetd is earlier than 1.6.dfsg.4~beta1-5lenny3" test_ref="oval:org.mitre.oval:tst:26739"/>
              <criterion comment="libkrb5-dev is earlier than 1.6.dfsg.4~beta1-5lenny3" test_ref="oval:org.mitre.oval:tst:26713"/>
              <criterion comment="libkrb53 is earlier than 1.6.dfsg.4~beta1-5lenny3" test_ref="oval:org.mitre.oval:tst:26662"/>
              <criterion comment="krb5-ftpd is earlier than 1.6.dfsg.4~beta1-5lenny3" test_ref="oval:org.mitre.oval:tst:26898"/>
              <criterion comment="krb5-pkinit is earlier than 1.6.dfsg.4~beta1-5lenny3" test_ref="oval:org.mitre.oval:tst:27006"/>
              <criterion comment="krb5-admin-server is earlier than 1.6.dfsg.4~beta1-5lenny3" test_ref="oval:org.mitre.oval:tst:26772"/>
              <criterion comment="libkadm55 is earlier than 1.6.dfsg.4~beta1-5lenny3" test_ref="oval:org.mitre.oval:tst:26690"/>
              <criterion comment="libkrb5-dbg is earlier than 1.6.dfsg.4~beta1-5lenny3" test_ref="oval:org.mitre.oval:tst:26393"/>
              <criterion comment="krb5-user is earlier than 1.6.dfsg.4~beta1-5lenny3" test_ref="oval:org.mitre.oval:tst:26429"/>
              <criterion comment="krb5-clients is earlier than 1.6.dfsg.4~beta1-5lenny3" test_ref="oval:org.mitre.oval:tst:26742"/>
              <criterion comment="krb5-kdc is earlier than 1.6.dfsg.4~beta1-5lenny3" test_ref="oval:org.mitre.oval:tst:26950"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6723" version="3" class="patch">
      <metadata>
        <title>DSA-2021 spamass-milter -- missing input sanitization</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <product>spamass-milter</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2010/dsa-2021" ref_id="DSA-2021"/>
        <description>A missing input sanitization in spamass-milter, a milter used to filter mail through spamassassin, was discovered. This allows a remote attacker to inject and execute arbitrary shell commands.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-05-24T19:08:21-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2010-05-26T13:28:52.734-04:00">DRAFT</status_change>
            <status_change date="2010-06-14T04:00:08.665-04:00">INTERIM</status_change>
            <status_change date="2010-06-29T11:48:48.303-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
        <criteria operator="OR" comment="Architecture section">
          <criteria operator="AND" comment="Architecture dependent section">
            <criteria operator="OR" comment="Supported architectures section">
              <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
              <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
              <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
              <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
              <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
              <criterion comment="Installed architecture is armel" test_ref="oval:org.mitre.oval:tst:11101"/>
              <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
              <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
              <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
              <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
              <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
            </criteria>
            <criteria operator="OR" comment="Packages section">
              <criterion comment="spamass-milter is earlier than 0.3.1-8+lenny1" test_ref="oval:org.mitre.oval:tst:26860"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6719" version="3" class="patch">
      <metadata>
        <title>DSA-1985 sendmail -- insufficient input validation</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <platform>Debian GNU/Linux 4.0</platform>
          <product>sendmail</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2010/dsa-1985" ref_id="DSA-1985"/>
        <description>It was discovered that sendmail, a Mail Transport Agent, does not properly handle a "\0" character in a Common Name  field of an X.509 certificate. This allows an attacker to spoof arbitrary SSL-based SMTP servers via a crafted server certificate issued by a legitimate Certification Authority, and to bypass intended access restrictions via a crafted client certificate issued by a legitimate Certification Authority.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-05-24T19:05:12-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2010-05-26T13:28:03.884-04:00">DRAFT</status_change>
            <status_change date="2010-06-14T04:00:07.894-04:00">INTERIM</status_change>
            <status_change date="2010-06-29T11:48:47.541-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Release section">
          <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
          <criteria operator="OR" comment="Architecture section">
            <criteria operator="AND" comment="Architecture independent section">
              <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criteria operator="OR" comment="Packages section">
                <criterion comment="sendmail-base is earlier than 8.14.3-5+lenny1" test_ref="oval:org.mitre.oval:tst:25769"/>
                <criterion comment="sendmail-cf is earlier than 8.14.3-5+lenny1" test_ref="oval:org.mitre.oval:tst:25074"/>
                <criterion comment="sendmail-doc is earlier than 8.14.3-5+lenny1" test_ref="oval:org.mitre.oval:tst:25633"/>
                <criterion comment="sendmail is earlier than 8.14.3-5+lenny1" test_ref="oval:org.mitre.oval:tst:25482"/>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Architecture dependent section">
              <criteria operator="OR" comment="Supported architectures section">
                <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
                <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
                <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
                <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
                <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
                <criterion comment="Installed architecture is armel" test_ref="oval:org.mitre.oval:tst:11101"/>
                <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
                <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
                <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
                <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
                <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
                <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
              </criteria>
              <criteria operator="OR" comment="Packages section">
                <criterion comment="rmail is earlier than 8.14.3-5+lenny1" test_ref="oval:org.mitre.oval:tst:25060"/>
                <criterion comment="sendmail-bin is earlier than 8.14.3-5+lenny1" test_ref="oval:org.mitre.oval:tst:25830"/>
                <criterion comment="libmilter-dev is earlier than 8.14.3-5+lenny1" test_ref="oval:org.mitre.oval:tst:25635"/>
                <criterion comment="sensible-mda is earlier than 8.14.3-5+lenny1" test_ref="oval:org.mitre.oval:tst:25947"/>
                <criterion comment="libmilter1.0.1 is earlier than 8.14.3-5+lenny1" test_ref="oval:org.mitre.oval:tst:25950"/>
                <criterion comment="libmilter1.0.1-dbg is earlier than 8.14.3-5+lenny1" test_ref="oval:org.mitre.oval:tst:25613"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Release section">
          <extend_definition comment="Debian 4.0 is installed." definition_ref="oval:org.mitre.oval:def:6461"/>
          <criteria operator="OR" comment="Architecture section">
            <criteria operator="AND" comment="Architecture independent section">
              <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criteria operator="OR" comment="Packages section">
                <criterion comment="sendmail-base is earlier than 8.13.8-3+etch1" test_ref="oval:org.mitre.oval:tst:25637"/>
                <criterion comment="sendmail-cf is earlier than 8.13.8-3+etch1" test_ref="oval:org.mitre.oval:tst:25796"/>
                <criterion comment="sendmail-doc is earlier than 8.13.8-3+etch1" test_ref="oval:org.mitre.oval:tst:25885"/>
                <criterion comment="sendmail is earlier than 8.13.8-3+etch1" test_ref="oval:org.mitre.oval:tst:25786"/>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="Architecture dependent section">
              <criteria operator="OR" comment="Supported architectures section">
                <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
                <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
                <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
                <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
                <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
                <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
                <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
                <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
                <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
                <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
              </criteria>
              <criteria operator="OR" comment="Packages section">
                <criterion comment="rmail is earlier than 8.13.8-3+etch1" test_ref="oval:org.mitre.oval:tst:25723"/>
                <criterion comment="libmilter0 is earlier than 8.13.8-3+etch1" test_ref="oval:org.mitre.oval:tst:25823"/>
                <criterion comment="sendmail-bin is earlier than 8.13.8-3+etch1" test_ref="oval:org.mitre.oval:tst:25926"/>
                <criterion comment="libmilter0-dbg is earlier than 8.13.8-3+etch1" test_ref="oval:org.mitre.oval:tst:25834"/>
                <criterion comment="libmilter-dev is earlier than 8.13.8-3+etch1" test_ref="oval:org.mitre.oval:tst:25116"/>
                <criterion comment="sensible-mda is earlier than 8.13.8-3+etch1" test_ref="oval:org.mitre.oval:tst:25851"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6714" version="3" class="patch">
      <metadata>
        <title>DSA-2042 iscsitarget -- format string</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <product>iscsitarget</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2010/dsa-2042" ref_id="DSA-2042"/>
        <description>Florent Daigniere discovered multiple format string vulnerabilities in Linux SCSI target framework  allow remote attackers to cause a denial of service in the ietd daemon. The flaw could be trigger by sending a carefully-crafted Internet Storage Name Service  request.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-05-24T19:04:52-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2010-05-26T13:27:57.341-04:00">DRAFT</status_change>
            <status_change date="2010-06-14T04:00:07.474-04:00">INTERIM</status_change>
            <status_change date="2010-06-29T11:48:47.118-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
        <criteria operator="OR" comment="Architecture section">
          <criteria operator="AND" comment="Architecture independent section">
            <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
            <criterion comment="iscsitarget-source is earlier than 0.4.16+svn162-3.1+lenny1" test_ref="oval:org.mitre.oval:tst:25547"/>
          </criteria>
          <criteria operator="AND" comment="Architecture dependent section">
            <criteria operator="OR" comment="Supported architectures section">
              <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
              <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
              <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
              <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
              <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
              <criterion comment="Installed architecture is armel" test_ref="oval:org.mitre.oval:tst:11101"/>
              <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
              <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
              <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
              <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
              <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
              <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
            </criteria>
            <criteria operator="OR" comment="Packages section">
              <criterion comment="iscsitarget is earlier than 0.4.16+svn162-3.1+lenny1" test_ref="oval:org.mitre.oval:tst:25802"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6701" version="3" class="patch">
      <metadata>
        <title>DSA-2023 curl -- buffer overflow</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <product>curl</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2010/dsa-2023" ref_id="DSA-2023"/>
        <description>Wesley Miaw discovered that libcurl, a multi-protocol file transfer library, is prone to a buffer overflow via the callback function when an application relies on libcurl to automatically uncompress data. Note that this only affects applications that trust libcurl"s maximum limit for a fixed buffer size and do not perform any sanity checks themselves.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-05-24T19:08:22-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2010-05-26T13:28:54.008-04:00">DRAFT</status_change>
            <status_change date="2010-06-14T04:00:07.115-04:00">INTERIM</status_change>
            <status_change date="2010-06-29T11:48:46.647-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
        <criteria operator="OR" comment="Architecture section">
          <criteria operator="AND" comment="Architecture dependent section">
            <criteria operator="OR" comment="Supported architectures section">
              <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
              <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
              <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
              <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
              <criterion comment="Installed architecture is armel" test_ref="oval:org.mitre.oval:tst:11101"/>
              <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
              <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
            </criteria>
            <criteria operator="OR" comment="Packages section">
              <criterion comment="libcurl4-gnutls-dev is earlier than 7.18.2-8lenny4" test_ref="oval:org.mitre.oval:tst:26683"/>
              <criterion comment="libcurl4-openssl-dev is earlier than 7.18.2-8lenny4" test_ref="oval:org.mitre.oval:tst:26698"/>
              <criterion comment="libcurl3-gnutls is earlier than 7.18.2-8lenny4" test_ref="oval:org.mitre.oval:tst:26474"/>
              <criterion comment="libcurl3-dbg is earlier than 7.18.2-8lenny4" test_ref="oval:org.mitre.oval:tst:25906"/>
              <criterion comment="libcurl3 is earlier than 7.18.2-8lenny4" test_ref="oval:org.mitre.oval:tst:26653"/>
              <criterion comment="curl is earlier than 7.18.2-8lenny4" test_ref="oval:org.mitre.oval:tst:26644"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6699" version="3" class="patch">
      <metadata>
        <title>DSA-2025 icedove -- several vulnerabilities</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <product>icedove</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2010/dsa-2025" ref_id="DSA-2025"/>
        <description>Several remote vulnerabilities have been discovered in the Icedove mail client, an unbranded version of the Thunderbird mail client. The Common Vulnerabilities and Exposures project identifies the following problems: Dan Kaminsky and Moxie Marlinspike discovered that icedove does not properly handle a "\0" character in a domain name in the subject"s Common Name  field of an X.509 certificate . Moxie Marlinspike reported a heap overflow vulnerability in the code that handles regular expressions in certificate names . monarch2020 discovered an integer overflow in a base64 decoding function . Josh Soref discovered a crash in the BinHex decoder . Carsten Book reported a crash in the JavaScript engine . Ludovic Hirlimann reported a crash indexing some messages with attachments, which could lead to the execution of arbitrary code .</description>
        <oval_repository>
          <dates>
            <submitted date="2010-05-24T19:08:14-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2010-05-26T13:28:50.421-04:00">DRAFT</status_change>
            <status_change date="2010-06-14T04:00:06.716-04:00">INTERIM</status_change>
            <status_change date="2010-06-29T11:48:46.267-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
        <criteria operator="OR" comment="Architecture section">
          <criteria operator="AND" comment="Architecture dependent section">
            <criteria operator="OR" comment="Supported architectures section">
              <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
              <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
              <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
              <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
              <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
              <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
              <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
            </criteria>
            <criteria operator="OR" comment="Packages section">
              <criterion comment="icedove-dev is earlier than 2.0.0.24-0lenny1" test_ref="oval:org.mitre.oval:tst:26361"/>
              <criterion comment="icedove-dbg is earlier than 2.0.0.24-0lenny1" test_ref="oval:org.mitre.oval:tst:26265"/>
              <criterion comment="icedove-gnome-support is earlier than 2.0.0.24-0lenny1" test_ref="oval:org.mitre.oval:tst:26832"/>
              <criterion comment="icedove is earlier than 2.0.0.24-0lenny1" test_ref="oval:org.mitre.oval:tst:26306"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6675" version="3" class="patch">
      <metadata>
        <title>DSA-1978 phpgroupware -- several vulnerabilities</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <product>phpgroupware</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2010/dsa-1978" ref_id="DSA-1978"/>
        <description>Several remote vulnerabilities have been discovered in phpgroupware, a Web based groupware system written in PHP. The Common Vulnerabilities and Exposures project identifies the following problems: An SQL injection vulnerability was found in the authentication module. Multiple directory traversal vulnerabilities were found in the addressbook module. The authentication module is affected by cross-site scripting.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-05-24T19:10:22-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2010-05-26T13:29:19.845-04:00">DRAFT</status_change>
            <status_change date="2010-06-14T04:00:06.009-04:00">INTERIM</status_change>
            <status_change date="2010-06-29T11:48:43.799-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
        <criteria operator="OR" comment="Architecture section">
          <criteria operator="AND" comment="Architecture independent section">
            <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
            <criteria operator="OR" comment="Packages section">
              <criterion comment="phpgroupware-0.9.16-phpgwapi is earlier than 0.9.16.012+dfsg-8+lenny1" test_ref="oval:org.mitre.oval:tst:26315"/>
              <criterion comment="phpgroupware-0.9.16-addressbook is earlier than 0.9.16.012+dfsg-8+lenny1" test_ref="oval:org.mitre.oval:tst:26833"/>
              <criterion comment="phpgroupware-0.9.16-news-admin is earlier than 0.9.16.012+dfsg-8+lenny1" test_ref="oval:org.mitre.oval:tst:26848"/>
              <criterion comment="phpgroupware-0.9.16-setup is earlier than 0.9.16.012+dfsg-8+lenny1" test_ref="oval:org.mitre.oval:tst:26751"/>
              <criterion comment="phpgroupware-0.9.16-phpgwapi-doc is earlier than 0.9.16.012+dfsg-8+lenny1" test_ref="oval:org.mitre.oval:tst:26896"/>
              <criterion comment="phpgroupware-0.9.16-filemanager is earlier than 0.9.16.012+dfsg-8+lenny1" test_ref="oval:org.mitre.oval:tst:27008"/>
              <criterion comment="phpgroupware-0.9.16-preferences is earlier than 0.9.16.012+dfsg-8+lenny1" test_ref="oval:org.mitre.oval:tst:26932"/>
              <criterion comment="phpgroupware-0.9.16-todo is earlier than 0.9.16.012+dfsg-8+lenny1" test_ref="oval:org.mitre.oval:tst:26967"/>
              <criterion comment="phpgroupware-0.9.16-core-base is earlier than 0.9.16.012+dfsg-8+lenny1" test_ref="oval:org.mitre.oval:tst:26770"/>
              <criterion comment="phpgroupware-0.9.16-email is earlier than 0.9.16.012+dfsg-8+lenny1" test_ref="oval:org.mitre.oval:tst:26070"/>
              <criterion comment="phpgroupware is earlier than 0.9.16.012+dfsg-8+lenny1" test_ref="oval:org.mitre.oval:tst:26913"/>
              <criterion comment="phpgroupware-0.9.16 is earlier than 0.9.16.012+dfsg-8+lenny1" test_ref="oval:org.mitre.oval:tst:26756"/>
              <criterion comment="phpgroupware-0.9.16-manual is earlier than 0.9.16.012+dfsg-8+lenny1" test_ref="oval:org.mitre.oval:tst:27012"/>
              <criterion comment="phpgroupware-0.9.16-core is earlier than 0.9.16.012+dfsg-8+lenny1" test_ref="oval:org.mitre.oval:tst:27029"/>
              <criterion comment="phpgroupware-0.9.16-calendar is earlier than 0.9.16.012+dfsg-8+lenny1" test_ref="oval:org.mitre.oval:tst:26128"/>
              <criterion comment="phpgroupware-0.9.16-admin is earlier than 0.9.16.012+dfsg-8+lenny1" test_ref="oval:org.mitre.oval:tst:27092"/>
              <criterion comment="phpgroupware-0.9.16-doc is earlier than 0.9.16.012+dfsg-8+lenny1" test_ref="oval:org.mitre.oval:tst:27011"/>
              <criterion comment="phpgroupware-0.9.16-notes is earlier than 0.9.16.012+dfsg-8+lenny1" test_ref="oval:org.mitre.oval:tst:27018"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6671" version="3" class="patch">
      <metadata>
        <title>DSA-1986 moodle -- several vulnerabilities</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <product>moodle</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2010/dsa-1986" ref_id="DSA-1986"/>
        <description>Several vulnerabilities have been discovered in Moodle, an online course management system. The Common Vulnerabilities and Exposures project identifies the following problems: Multiple cross-site request forgery  vulnerabilities have been discovered. It has been discovered that the LAMS module is prone to the disclosure of user account information. The Glossary module has an insufficient access control mechanism. Moodle does not properly check permissions when the MNET service is enabled, which allows remote authenticated servers to execute arbitrary MNET functions. The login/index_form.html page links to an HTTP page instead of using an SSL secured connection. Moodle stores sensitive data in backup files, which might make it possible for attackers to obtain them. It has been discovered that the SCORM module is prone to an SQL injection. Additionally, an SQL injection in the update_record function, a problem with symbolic links and a verification problem with Glossary, database and forum ratings have been fixed.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-05-24T19:05:04-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2010-05-26T13:28:00.149-04:00">DRAFT</status_change>
            <status_change date="2010-06-14T04:00:05.781-04:00">INTERIM</status_change>
            <status_change date="2010-06-29T11:48:43.569-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
        <criteria operator="OR" comment="Architecture section">
          <criteria operator="AND" comment="Architecture independent section">
            <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
            <criterion comment="moodle is earlier than 1.8.2.dfsg-3+lenny3" test_ref="oval:org.mitre.oval:tst:25862"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6658" version="3" class="patch">
      <metadata>
        <title>DSA-2045 libtheora -- integer overflow</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <product>libtheora</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2010/dsa-2045" ref_id="DSA-2045"/>
        <description>Bob Clary, Dan Kaminsky and David Keeler discovered that in libtheora, a video library part of the Ogg project, several flaws allow context-dependent attackers via a large and specially crafted media file, to cause a denial of service , and possibly arbitrary code execution.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-05-24T19:04:49-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2010-05-26T13:27:56.812-04:00">DRAFT</status_change>
            <status_change date="2010-06-14T04:00:05.417-04:00">INTERIM</status_change>
            <status_change date="2010-06-29T11:48:43.184-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
        <criteria operator="OR" comment="Architecture section">
          <criteria operator="AND" comment="Architecture dependent section">
            <criteria operator="OR" comment="Supported architectures section">
              <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
              <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
              <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
              <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
              <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
              <criterion comment="Installed architecture is armel" test_ref="oval:org.mitre.oval:tst:11101"/>
              <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
              <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
              <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
              <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
              <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
            </criteria>
            <criteria operator="OR" comment="Packages section">
              <criterion comment="libtheora0 is earlier than 1.0~beta3-1+lenny1" test_ref="oval:org.mitre.oval:tst:25765"/>
              <criterion comment="libtheora-dev is earlier than 1.0~beta3-1+lenny1" test_ref="oval:org.mitre.oval:tst:25562"/>
              <criterion comment="libtheora-bin is earlier than 1.0~beta3-1+lenny1" test_ref="oval:org.mitre.oval:tst:25898"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6637" version="3" class="patch">
      <metadata>
        <title>DSA-2038 pidgin -- several vulnerabilities</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <product>pidgin</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2010/dsa-2038" ref_id="DSA-2038"/>
        <description>Several remote vulnerabilities have been discovered in Pidgin, a multi protocol instant messaging client. The Common Vulnerabilities and Exposures project identifies the following problems: Crafted nicknames in the XMPP protocol can crash Pidgin remotely. Remote contacts may send too many custom smilies, crashing Pidgin. Since a few months, Microsoft"s servers for MSN have changed the protocol, making Pidgin non-functional for use with MSN. It is not feasible to port these changes to the version of Pidgin in Debian Lenny. This update formalises that situation by disabling the protocol in the client. Users of the MSN protocol are advised to use the version of Pidgin in the repositories of www.backports.org.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-05-24T19:10:15-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2010-05-26T13:29:18.042-04:00">DRAFT</status_change>
            <status_change date="2010-06-14T04:00:04.848-04:00">INTERIM</status_change>
            <status_change date="2010-06-29T11:48:41.846-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
        <criteria operator="OR" comment="Architecture section">
          <criteria operator="AND" comment="Architecture independent section">
            <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
            <criteria operator="OR" comment="Packages section">
              <criterion comment="libpurple-dev is earlier than 2.4.3-4lenny6" test_ref="oval:org.mitre.oval:tst:26452"/>
              <criterion comment="finch-dev is earlier than 2.4.3-4lenny6" test_ref="oval:org.mitre.oval:tst:26959"/>
              <criterion comment="pidgin-dev is earlier than 2.4.3-4lenny6" test_ref="oval:org.mitre.oval:tst:26910"/>
              <criterion comment="libpurple-bin is earlier than 2.4.3-4lenny6" test_ref="oval:org.mitre.oval:tst:26667"/>
              <criterion comment="pidgin-data is earlier than 2.4.3-4lenny6" test_ref="oval:org.mitre.oval:tst:26985"/>
            </criteria>
          </criteria>
          <criteria operator="AND" comment="Architecture dependent section">
            <criteria operator="OR" comment="Supported architectures section">
              <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
              <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
              <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
              <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
              <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
              <criterion comment="Installed architecture is armel" test_ref="oval:org.mitre.oval:tst:11101"/>
              <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
              <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
              <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
              <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
              <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
              <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
            </criteria>
            <criteria operator="OR" comment="Packages section">
              <criterion comment="libpurple0 is earlier than 2.4.3-4lenny6" test_ref="oval:org.mitre.oval:tst:26924"/>
              <criterion comment="pidgin-dbg is earlier than 2.4.3-4lenny6" test_ref="oval:org.mitre.oval:tst:26383"/>
              <criterion comment="pidgin is earlier than 2.4.3-4lenny6" test_ref="oval:org.mitre.oval:tst:26987"/>
              <criterion comment="finch is earlier than 2.4.3-4lenny6" test_ref="oval:org.mitre.oval:tst:26334"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6557" version="1" class="patch">
      <metadata>
        <title>DSA-1750 libpng -- several vulnerabilities</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <platform>Debian GNU/Linux 4.0</platform>
          <product>libpng</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2009/dsa-1750" ref_id="DSA-1750"/>
        <description>Several vulnerabilities have been discovered in libpng, a library for reading and writing PNG files. The Common Vulnerabilities and Exposures project identifies the following problems: The png_handle_tRNS function allows attackers to cause a denial of service    (application crash) via a grayscale PNG image with a bad tRNS chunk CRC value. Certain chunk handlers allow attackers to cause a denial of service (crash)    via crafted pCAL, sCAL, tEXt, iTXt, and ztXT chunking in PNG images, which    trigger out-of-bounds read operations. libpng allows context-dependent attackers to cause a denial of service    (crash) and possibly execute arbitrary code via a PNG file with zero    length "unknown" chunks, which trigger an access of uninitialized    memory. The png_check_keyword might allow context-dependent attackers to set the    value of an arbitrary memory location to zero via vectors involving    creation of crafted PNG files with keywords. A memory leak in the png_handle_tEXt function allows context-dependent    attackers to cause a denial of service (memory exhaustion) via a crafted    PNG file. libpng allows context-dependent attackers to cause a denial of service    (application crash) or possibly execute arbitrary code via a crafted PNG    file that triggers a free of an uninitialized pointer in (1) the    png_read_png function, (2) pCAL chunk handling, or (3) setup of 16-bit    gamma tables.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-04T16:44:51">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-06T20:14:47.577-05:00">DRAFT</status_change>
            <status_change date="2009-12-21T04:01:10.556-05:00">INTERIM</status_change>
            <status_change date="2010-01-11T04:01:59.885-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Platform section">
        <criteria operator="AND" comment="Release section">
          <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
          <criteria operator="OR" comment="Architecture section">
            <criteria operator="AND" comment="Architecture independent section">
              <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criterion comment="libpng3 is earlier than 1.2.27-2+lenny2" test_ref="oval:org.mitre.oval:tst:10860"/>
            </criteria>
            <criteria operator="AND" comment="Architecture dependent section">
              <criteria operator="OR" comment="Supported architectures section">
                <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
                <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
                <criterion comment="sparc architecture" test_ref="oval:org.mitre.oval:tst:2465"/>
                <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
                <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
                <criterion comment="Installed architecture is armel" test_ref="oval:org.mitre.oval:tst:11101"/>
                <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
                <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
                <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
                <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
                <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
                <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
              </criteria>
              <criteria operator="OR" comment="Packages section">
                <criterion comment="libpng12-dev is earlier than 1.2.27-2+lenny2" test_ref="oval:org.mitre.oval:tst:11142"/>
                <criterion comment="libpng12-0 is earlier than 1.2.27-2+lenny2" test_ref="oval:org.mitre.oval:tst:11051"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Release section">
          <extend_definition comment="Debian 4.0 is installed" definition_ref="oval:org.mitre.oval:def:6461"/>
          <criteria operator="OR" comment="Architecture section">
            <criteria operator="AND" comment="Architecture independent section">
              <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
              <criterion comment="libpng3 is earlier than 1.2.15~beta5-1+etch2" test_ref="oval:org.mitre.oval:tst:11231"/>
            </criteria>
            <criteria operator="OR" comment="Packages section">
              <criterion comment="libpng12-dev is earlier than 1.2.15~beta5-1+etch2" test_ref="oval:org.mitre.oval:tst:10903"/>
              <criterion comment="libpng12-0 is earlier than 1.2.15~beta5-1+etch2" test_ref="oval:org.mitre.oval:tst:11146"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6461" version="7" class="inventory">
      <metadata>
        <title>Debian 4.0 is installed.</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 4.0</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/o:debian:debian_linux:4.0"/>
        <description>Debian 4.0 is installed</description>
        <oval_repository>
          <dates>
            <submitted date="2010-05-24T18:49:34">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2010-05-24T18:50:00-05:00">DRAFT</status_change>
            <status_change date="2010-08-30T04:00:11.858-04:00">INTERIM</status_change>
            <status_change date="2010-09-15T18:16:22.918-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6461 - Update textfilecontent_test to textfilecontent54_test" date="2011-01-20T13:46:00.381-05:00">
              <contributor organization="SecPod Technologies">Preeti Subramanian</contributor>
            </modified>
            <status_change date="2011-01-20T13:47:26.928-05:00">INTERIM</status_change>
            <status_change date="2011-02-07T04:00:15.267-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:12237 - Pattern match updated &amp; used subexpression in textfilecontent54_state for all states" date="2011-10-21T10:10:00.778-04:00">
              <contributor organization="SecPod Technologies">Chandan S</contributor>
            </modified>
            <status_change date="2011-10-21T10:13:39.418-04:00">INTERIM</status_change>
            <status_change date="2011-11-07T04:01:05.879-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="Debian GNU/Linux 4.0 is installed" test_ref="oval:org.mitre.oval:tst:41743"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11944" version="3" class="patch">
      <metadata>
        <title>DSA-2070 freetype -- several vulnerabilities</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <product>freetype</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2010/dsa-2070" ref_id="DSA-2070"/>
        <description>Robert Swiecki discovered several vulnerabilities in the FreeType font library, which could lead to the execution of arbitrary code if a malformed font file is processed. Also, several buffer overflows were found in the included demo programs.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-31T15:50:51-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2010-08-03T12:18:41.091-04:00">DRAFT</status_change>
            <status_change date="2010-08-23T04:00:33.414-04:00">INTERIM</status_change>
            <status_change date="2010-09-13T04:00:39.859-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
        <criteria operator="OR" comment="Architecture section">
          <criteria operator="AND" comment="Architecture dependent section">
            <criteria operator="OR" comment="Supported architectures section">
              <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
              <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
              <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
              <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
              <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
              <criterion comment="Installed architecture is armel" test_ref="oval:org.mitre.oval:tst:11101"/>
              <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
              <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
              <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
              <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
              <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
              <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
            </criteria>
            <criteria operator="OR" comment="Packages section">
              <criterion comment="libfreetype6-dev is earlier than 2.3.7-2+lenny2" test_ref="oval:org.mitre.oval:tst:41126"/>
              <criterion comment="freetype2-demos is earlier than 2.3.7-2+lenny2" test_ref="oval:org.mitre.oval:tst:41233"/>
              <criterion comment="libfreetype6 is earlier than 2.3.7-2+lenny2" test_ref="oval:org.mitre.oval:tst:41330"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11917" version="3" class="patch">
      <metadata>
        <title>DSA-2064 xulrunner -- several vulnerabilities</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <product>xulrunner</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2010/dsa-2064" ref_id="DSA-2064"/>
        <description>Several remote vulnerabilities have been discovered in Xulrunner, a runtime environment for XUL applications. The Common Vulnerabilities and Exposures project identifies the following problems: "wushi" discovered that incorrect pointer handling in the frame processing code could lead to the execution of arbitrary code. "Nils" discovered that an integer overflow in DOM node parsing could lead to the execution of arbitrary code. Ilja von Sprundel discovered that incorrect parsing of Content-Disposition headers could lead to cross-site scripting. Microsoft engineers discovered that incorrect memory handling in the interaction of browser plugins could lead to the execution of arbitrary code. Martin Barbella discovered that an integer overflow in XSLT node parsing could lead to the execution of arbitrary code. Olli Pettay, Martijn Wargers, Justin Lebar, Jesse Ruderman, Ben Turner, Jonathan Kew and David Humphrey discovered crashes in the layout engine, which might allow the execution of arbitrary code. "boardraider" and "stedenon" discovered crashes in the layout engine, which might allow the execution of arbitrary code. Bob Clary, Igor Bukanov, Gary Kwong and Andreas Gal discovered crashes in the Javascript engine, which might allow the execution of arbitrary code.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-31T15:50:52-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2010-08-03T12:18:48.469-04:00">DRAFT</status_change>
            <status_change date="2010-08-23T04:00:31.735-04:00">INTERIM</status_change>
            <status_change date="2010-09-13T04:00:36.989-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
        <criteria operator="OR" comment="Architecture section">
          <criteria operator="AND" comment="Architecture independent section">
            <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
            <criterion comment="libmozillainterfaces-java is earlier than 1.9.0.19-2" test_ref="oval:org.mitre.oval:tst:40535"/>
          </criteria>
          <criteria operator="AND" comment="Architecture dependent section">
            <criteria operator="OR" comment="Supported architectures section">
              <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
              <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
              <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
              <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
              <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
              <criterion comment="Installed architecture is armel" test_ref="oval:org.mitre.oval:tst:11101"/>
              <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
              <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
              <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
              <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
              <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
              <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
            </criteria>
            <criteria operator="OR" comment="Packages section">
              <criterion comment="libmozjs-dev is earlier than 1.9.0.19-2" test_ref="oval:org.mitre.oval:tst:41292"/>
              <criterion comment="spidermonkey-bin is earlier than 1.9.0.19-2" test_ref="oval:org.mitre.oval:tst:41501"/>
              <criterion comment="xulrunner-1.9-gnome-support is earlier than 1.9.0.19-2" test_ref="oval:org.mitre.oval:tst:41515"/>
              <criterion comment="xulrunner-1.9 is earlier than 1.9.0.19-2" test_ref="oval:org.mitre.oval:tst:41349"/>
              <criterion comment="libmozjs1d-dbg is earlier than 1.9.0.19-2" test_ref="oval:org.mitre.oval:tst:41479"/>
              <criterion comment="libmozjs1d is earlier than 1.9.0.19-2" test_ref="oval:org.mitre.oval:tst:41191"/>
              <criterion comment="python-xpcom is earlier than 1.9.0.19-2" test_ref="oval:org.mitre.oval:tst:41448"/>
              <criterion comment="xulrunner-1.9-dbg is earlier than 1.9.0.19-2" test_ref="oval:org.mitre.oval:tst:41436"/>
              <criterion comment="xulrunner-dev is earlier than 1.9.0.19-2" test_ref="oval:org.mitre.oval:tst:41387"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11908" version="3" class="patch">
      <metadata>
        <title>DSA-2052 krb5 -- null pointer dereference</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <product>krb5</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2010/dsa-2052" ref_id="DSA-2052"/>
        <description>Shawn Emery discovered that in MIT Kerberos 5 , a system for authenticating users and services on a network, a null pointer dereference flaw in the Generic Security Service Application Program Interface  library could allow an authenticated remote attacker to crash any server application using the GSS-API authentication mechanism, by sending a specially-crafted GSS-API token with a missing checksum field.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-31T15:50:51-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2010-08-03T12:18:22.729-04:00">DRAFT</status_change>
            <status_change date="2010-08-23T04:00:31.166-04:00">INTERIM</status_change>
            <status_change date="2010-09-13T04:00:35.259-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
        <criteria operator="OR" comment="Architecture section">
          <criteria operator="AND" comment="Architecture independent section">
            <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
            <criterion comment="krb5-doc is earlier than 1.6.dfsg.4~beta1-5lenny4" test_ref="oval:org.mitre.oval:tst:41315"/>
          </criteria>
          <criteria operator="AND" comment="Architecture dependent section">
            <criteria operator="OR" comment="Supported architectures section">
              <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
              <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
              <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
              <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
              <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
              <criterion comment="Installed architecture is armel" test_ref="oval:org.mitre.oval:tst:11101"/>
              <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
              <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
              <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
              <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
              <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
              <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
            </criteria>
            <criteria operator="OR" comment="Packages section">
              <criterion comment="krb5-rsh-server is earlier than 1.6.dfsg.4~beta1-5lenny4" test_ref="oval:org.mitre.oval:tst:40386"/>
              <criterion comment="krb5-kdc-ldap is earlier than 1.6.dfsg.4~beta1-5lenny4" test_ref="oval:org.mitre.oval:tst:41022"/>
              <criterion comment="krb5-telnetd is earlier than 1.6.dfsg.4~beta1-5lenny4" test_ref="oval:org.mitre.oval:tst:41338"/>
              <criterion comment="libkrb53 is earlier than 1.6.dfsg.4~beta1-5lenny4" test_ref="oval:org.mitre.oval:tst:40655"/>
              <criterion comment="libkrb5-dev is earlier than 1.6.dfsg.4~beta1-5lenny4" test_ref="oval:org.mitre.oval:tst:41209"/>
              <criterion comment="krb5-ftpd is earlier than 1.6.dfsg.4~beta1-5lenny4" test_ref="oval:org.mitre.oval:tst:40684"/>
              <criterion comment="krb5-pkinit is earlier than 1.6.dfsg.4~beta1-5lenny4" test_ref="oval:org.mitre.oval:tst:41204"/>
              <criterion comment="libkadm55 is earlier than 1.6.dfsg.4~beta1-5lenny4" test_ref="oval:org.mitre.oval:tst:40978"/>
              <criterion comment="libkrb5-dbg is earlier than 1.6.dfsg.4~beta1-5lenny4" test_ref="oval:org.mitre.oval:tst:41148"/>
              <criterion comment="krb5-user is earlier than 1.6.dfsg.4~beta1-5lenny4" test_ref="oval:org.mitre.oval:tst:40666"/>
              <criterion comment="krb5-kdc is earlier than 1.6.dfsg.4~beta1-5lenny4" test_ref="oval:org.mitre.oval:tst:41166"/>
              <criterion comment="krb5-clients is earlier than 1.6.dfsg.4~beta1-5lenny4" test_ref="oval:org.mitre.oval:tst:40941"/>
              <criterion comment="krb5-admin-server is earlier than 1.6.dfsg.4~beta1-5lenny4" test_ref="oval:org.mitre.oval:tst:41189"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11904" version="3" class="patch">
      <metadata>
        <title>DSA-2056 zonecheck -- missing input sanitizing</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <product>zonecheck</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2010/dsa-2056" ref_id="DSA-2056"/>
        <description>It was discovered that in zonecheck, a tool to check DNS configurations, the CGI does not perform sufficient sanitation of user input; an attacker can take advantage of this and pass script code in order to perform cross-site scripting attacks.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-31T15:50:51-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2010-08-03T12:18:38.469-04:00">DRAFT</status_change>
            <status_change date="2010-08-23T04:00:30.512-04:00">INTERIM</status_change>
            <status_change date="2010-09-13T04:00:34.937-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
        <criteria operator="OR" comment="Architecture section">
          <criteria operator="AND" comment="Architecture independent section">
            <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
            <criteria operator="OR" comment="Packages section">
              <criterion comment="zonecheck is earlier than 2.0.4-13lenny1" test_ref="oval:org.mitre.oval:tst:41160"/>
              <criterion comment="zonecheck-cgi is earlier than 2.0.4-13lenny1" test_ref="oval:org.mitre.oval:tst:41437"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11897" version="3" class="patch">
      <metadata>
        <title>DSA-2074 ncompress -- integer underflow</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <product>ncompress</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2010/dsa-2074" ref_id="DSA-2074"/>
        <description>Aki Helin discovered an integer underflow in ncompress, the original Lempel-Ziv compress/uncompress programs. This could lead to the execution of arbitrary code when trying to decompress a crafted LZW compressed gzip archive.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-31T15:50:51-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2010-08-03T12:18:42.942-04:00">DRAFT</status_change>
            <status_change date="2010-08-23T04:00:29.786-04:00">INTERIM</status_change>
            <status_change date="2010-09-13T04:00:33.473-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
        <criteria operator="OR" comment="Architecture section">
          <criteria operator="AND" comment="Architecture dependent section">
            <criteria operator="OR" comment="Supported architectures section">
              <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
              <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
              <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
              <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
              <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
              <criterion comment="Installed architecture is armel" test_ref="oval:org.mitre.oval:tst:11101"/>
              <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
              <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
              <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
              <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
              <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
              <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
            </criteria>
            <criteria operator="OR" comment="Packages section">
              <criterion comment="ncompress is earlier than 4.2.4.2-1+lenny1" test_ref="oval:org.mitre.oval:tst:40641"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11886" version="3" class="patch">
      <metadata>
        <title>DSA-2067 mahara -- several vulnerabilities</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <product>mahara</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2010/dsa-2067" ref_id="DSA-2067"/>
        <description>Several vulnerabilities were discovered in mahara, an electronic portfolio, weblog, and resume builder. The following Common Vulnerabilities and Exposures project ids identify them: Multiple pages performed insufficient input sanitising, making them vulnerable to cross-site scripting attacks. Multiple forms lacked protection against cross-site request forgery attacks, therefore making them vulnerable. Gregor Anzelj discovered that it was possible to accidentally configure an installation of mahara that allows access to another user"s account without a password. Certain Internet Explorer-specific cross-site scripting vulnerabilities were discovered in HTML Purifier, of which a copy is included in the mahara package.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-31T15:50:52-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2010-08-03T12:18:50.174-04:00">DRAFT</status_change>
            <status_change date="2010-08-23T04:00:29.262-04:00">INTERIM</status_change>
            <status_change date="2010-09-13T04:00:31.598-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
        <criteria operator="OR" comment="Architecture section">
          <criteria operator="AND" comment="Architecture independent section">
            <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
            <criteria operator="OR" comment="Packages section">
              <criterion comment="mahara-apache2 is earlier than 1.0.4-4+lenny6" test_ref="oval:org.mitre.oval:tst:41469"/>
              <criterion comment="mahara is earlier than 1.0.4-4+lenny6" test_ref="oval:org.mitre.oval:tst:41494"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11867" version="3" class="patch">
      <metadata>
        <title>DSA-2049 barnowl -- buffer overflow</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <product>barnowl</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2010/dsa-2049" ref_id="DSA-2049"/>
        <description>It has been discovered that barnowl, a curses-based tty Jabber, IRC, AIM and Zephyr client, is prone to a buffer overflow via its "CC:" handling, which could lead to the execution of arbitrary code.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-31T15:50:51-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2010-08-03T12:18:44.159-04:00">DRAFT</status_change>
            <status_change date="2010-08-23T04:00:28.478-04:00">INTERIM</status_change>
            <status_change date="2010-09-13T04:00:30.405-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
        <criteria operator="OR" comment="Architecture section">
          <criteria operator="AND" comment="Architecture independent section">
            <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
            <criterion comment="barnowl-irc is earlier than 1.0.1-4+lenny1" test_ref="oval:org.mitre.oval:tst:41171"/>
          </criteria>
          <criteria operator="AND" comment="Architecture dependent section">
            <criteria operator="OR" comment="Supported architectures section">
              <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
              <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
              <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
              <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
              <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
              <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
              <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
              <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
              <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
              <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
            </criteria>
            <criteria operator="OR" comment="Packages section">
              <criterion comment="barnowl is earlier than 1.0.1-4+lenny1" test_ref="oval:org.mitre.oval:tst:40572"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11828" version="3" class="patch">
      <metadata>
        <title>DSA-2069 znc -- denial of service</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <product>znc</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2010/dsa-2069" ref_id="DSA-2069"/>
        <description>It was discovered that znc, an IRC bouncer, is vulnerable to denial of service attacks via a NULL pointer dereference when traffic statistics are requested while there is an unauthenticated connection.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-31T15:50:51-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2010-08-03T12:18:44.946-04:00">DRAFT</status_change>
            <status_change date="2010-08-23T04:00:26.867-04:00">INTERIM</status_change>
            <status_change date="2010-09-13T04:00:27.595-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
        <criteria operator="OR" comment="Architecture section">
          <criteria operator="AND" comment="Architecture dependent section">
            <criteria operator="OR" comment="Supported architectures section">
              <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
              <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
              <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
              <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
              <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
              <criterion comment="Installed architecture is armel" test_ref="oval:org.mitre.oval:tst:11101"/>
              <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
              <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
              <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
              <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
              <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
              <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
            </criteria>
            <criteria operator="OR" comment="Packages section">
              <criterion comment="znc is earlier than 0.058-2+lenny4" test_ref="oval:org.mitre.oval:tst:41532"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11826" version="3" class="patch">
      <metadata>
        <title>DSA-2050 kdegraphics -- several vulnerabilities</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <product>kdegraphics</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2010/dsa-2050" ref_id="DSA-2050"/>
        <description>Several local vulnerabilities have been discovered in KPDF, a PDF viewer for KDE, which allow the execution of arbitrary code or denial of service if a user is tricked into opening a crafted PDF document.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-31T15:50:51-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2010-08-03T12:18:21.196-04:00">DRAFT</status_change>
            <status_change date="2010-08-23T04:00:26.208-04:00">INTERIM</status_change>
            <status_change date="2010-09-13T04:00:26.821-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
        <criteria operator="OR" comment="Architecture section">
          <criteria operator="AND" comment="Architecture independent section">
            <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
            <criteria operator="OR" comment="Packages section">
              <criterion comment="kdegraphics is earlier than 3.5.9-3+lenny3" test_ref="oval:org.mitre.oval:tst:40868"/>
              <criterion comment="kdegraphics-doc-html is earlier than 3.5.9-3+lenny3" test_ref="oval:org.mitre.oval:tst:41214"/>
            </criteria>
          </criteria>
          <criteria operator="AND" comment="Architecture dependent section">
            <criteria operator="OR" comment="Supported architectures section">
              <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
              <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
              <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
              <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
              <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
              <criterion comment="Installed architecture is armel" test_ref="oval:org.mitre.oval:tst:11101"/>
              <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
              <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
              <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
              <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
              <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
              <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
            </criteria>
            <criteria operator="OR" comment="Packages section">
              <criterion comment="kdegraphics-kfile-plugins is earlier than 3.5.9-3+lenny3" test_ref="oval:org.mitre.oval:tst:41017"/>
              <criterion comment="ksvg is earlier than 3.5.9-3+lenny3" test_ref="oval:org.mitre.oval:tst:41107"/>
              <criterion comment="libkscan-dev is earlier than 3.5.9-3+lenny3" test_ref="oval:org.mitre.oval:tst:40234"/>
              <criterion comment="kgamma is earlier than 3.5.9-3+lenny3" test_ref="oval:org.mitre.oval:tst:40720"/>
              <criterion comment="libkscan1 is earlier than 3.5.9-3+lenny3" test_ref="oval:org.mitre.oval:tst:40270"/>
              <criterion comment="kpovmodeler is earlier than 3.5.9-3+lenny3" test_ref="oval:org.mitre.oval:tst:41007"/>
              <criterion comment="kooka is earlier than 3.5.9-3+lenny3" test_ref="oval:org.mitre.oval:tst:40558"/>
              <criterion comment="kdegraphics-dev is earlier than 3.5.9-3+lenny3" test_ref="oval:org.mitre.oval:tst:41125"/>
              <criterion comment="kghostview is earlier than 3.5.9-3+lenny3" test_ref="oval:org.mitre.oval:tst:41089"/>
              <criterion comment="kfaxview is earlier than 3.5.9-3+lenny3" test_ref="oval:org.mitre.oval:tst:41226"/>
              <criterion comment="kviewshell is earlier than 3.5.9-3+lenny3" test_ref="oval:org.mitre.oval:tst:41176"/>
              <criterion comment="kview is earlier than 3.5.9-3+lenny3" test_ref="oval:org.mitre.oval:tst:41256"/>
              <criterion comment="kfax is earlier than 3.5.9-3+lenny3" test_ref="oval:org.mitre.oval:tst:40884"/>
              <criterion comment="ksnapshot is earlier than 3.5.9-3+lenny3" test_ref="oval:org.mitre.oval:tst:40991"/>
              <criterion comment="kmrml is earlier than 3.5.9-3+lenny3" test_ref="oval:org.mitre.oval:tst:40838"/>
              <criterion comment="kpdf is earlier than 3.5.9-3+lenny3" test_ref="oval:org.mitre.oval:tst:40926"/>
              <criterion comment="kcoloredit is earlier than 3.5.9-3+lenny3" test_ref="oval:org.mitre.oval:tst:40909"/>
              <criterion comment="kiconedit is earlier than 3.5.9-3+lenny3" test_ref="oval:org.mitre.oval:tst:40912"/>
              <criterion comment="kruler is earlier than 3.5.9-3+lenny3" test_ref="oval:org.mitre.oval:tst:40492"/>
              <criterion comment="kuickshow is earlier than 3.5.9-3+lenny3" test_ref="oval:org.mitre.oval:tst:41090"/>
              <criterion comment="kdvi is earlier than 3.5.9-3+lenny3" test_ref="oval:org.mitre.oval:tst:40336"/>
              <criterion comment="kdegraphics-dbg is earlier than 3.5.9-3+lenny3" test_ref="oval:org.mitre.oval:tst:41235"/>
              <criterion comment="kolourpaint is earlier than 3.5.9-3+lenny3" test_ref="oval:org.mitre.oval:tst:40986"/>
              <criterion comment="kamera is earlier than 3.5.9-3+lenny3" test_ref="oval:org.mitre.oval:tst:40340"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11797" version="3" class="patch">
      <metadata>
        <title>DSA-2055 openoffice.org -- macro execution</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <product>openoffice.org</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2010/dsa-2055" ref_id="DSA-2055"/>
        <description>It was discovered that OpenOffice.org, a full-featured office productivity suite that provides a near drop-in replacement for Microsoft&amp;reg; Office, is not properly handling python macros embedded in an office document. This allows an attacker to perform user-assisted execution of arbitrary code in certain use cases of the python macro viewer component.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-31T15:50:51-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2010-08-03T12:18:33.512-04:00">DRAFT</status_change>
            <status_change date="2010-08-23T04:00:23.059-04:00">INTERIM</status_change>
            <status_change date="2010-09-13T04:00:22.734-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
        <criteria operator="OR" comment="Architecture section">
          <criteria operator="AND" comment="Architecture independent section">
            <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
            <criteria operator="OR" comment="Packages section">
              <criterion comment="openoffice.org-dtd-officedocument1.0 is earlier than 2.4.1+dfsg-1+lenny7" test_ref="oval:org.mitre.oval:tst:41280"/>
              <criterion comment="openoffice.org-l10n-cy is earlier than 2.4.1+dfsg-1+lenny7" test_ref="oval:org.mitre.oval:tst:41302"/>
              <criterion comment="openoffice.org-l10n-cs is earlier than 2.4.1+dfsg-1+lenny7" test_ref="oval:org.mitre.oval:tst:41314"/>
              <criterion comment="openoffice.org-help-hu is earlier than 2.4.1+dfsg-1+lenny7" test_ref="oval:org.mitre.oval:tst:41323"/>
              <criterion comment="openoffice.org-l10n-vi is earlier than 2.4.1+dfsg-1+lenny7" test_ref="oval:org.mitre.oval:tst:41282"/>
              <criterion comment="openoffice.org-l10n-ca is earlier than 2.4.1+dfsg-1+lenny7" test_ref="oval:org.mitre.oval:tst:41060"/>
              <criterion comment="openoffice.org-style-industrial is earlier than 2.4.1+dfsg-1+lenny7" test_ref="oval:org.mitre.oval:tst:40946"/>
              <criterion comment="openoffice.org-help-en-us is earlier than 2.4.1+dfsg-1+lenny7" test_ref="oval:org.mitre.oval:tst:41239"/>
              <criterion comment="ttf-opensymbol is earlier than 2.4.1+dfsg-1+lenny7" test_ref="oval:org.mitre.oval:tst:41281"/>
              <criterion comment="openoffice.org-l10n-ka is earlier than 2.4.1+dfsg-1+lenny7" test_ref="oval:org.mitre.oval:tst:41196"/>
              <criterion comment="openoffice.org-l10n-km is earlier than 2.4.1+dfsg-1+lenny7" test_ref="oval:org.mitre.oval:tst:40350"/>
              <criterion comment="openoffice.org-l10n-ko is earlier than 2.4.1+dfsg-1+lenny7" test_ref="oval:org.mitre.oval:tst:41183"/>
              <criterion comment="openoffice.org-l10n-pl is earlier than 2.4.1+dfsg-1+lenny7" test_ref="oval:org.mitre.oval:tst:41241"/>
              <criterion comment="broffice.org is earlier than 2.4.1+dfsg-1+lenny7" test_ref="oval:org.mitre.oval:tst:41178"/>
              <criterion comment="openoffice.org-l10n-ku is earlier than 2.4.1+dfsg-1+lenny7" test_ref="oval:org.mitre.oval:tst:41327"/>
              <criterion comment="openoffice.org-l10n-pt is earlier than 2.4.1+dfsg-1+lenny7" test_ref="oval:org.mitre.oval:tst:40406"/>
              <criterion comment="openoffice.org-l10n-xh is earlier than 2.4.1+dfsg-1+lenny7" test_ref="oval:org.mitre.oval:tst:40695"/>
              <criterion comment="openoffice.org-help-pt is earlier than 2.4.1+dfsg-1+lenny7" test_ref="oval:org.mitre.oval:tst:40967"/>
              <criterion comment="openoffice.org-help-it is earlier than 2.4.1+dfsg-1+lenny7" test_ref="oval:org.mitre.oval:tst:41307"/>
              <criterion comment="openoffice.org-help-pl is earlier than 2.4.1+dfsg-1+lenny7" test_ref="oval:org.mitre.oval:tst:41103"/>
              <criterion comment="openoffice.org-l10n-bg is earlier than 2.4.1+dfsg-1+lenny7" test_ref="oval:org.mitre.oval:tst:41173"/>
              <criterion comment="openoffice.org-l10n-be-by is earlier than 2.4.1+dfsg-1+lenny7" test_ref="oval:org.mitre.oval:tst:41172"/>
              <criterion comment="openoffice.org-l10n-eu is earlier than 2.4.1+dfsg-1+lenny7" test_ref="oval:org.mitre.oval:tst:40517"/>
              <criterion comment="openoffice.org-l10n-hr is earlier than 2.4.1+dfsg-1+lenny7" test_ref="oval:org.mitre.oval:tst:41198"/>
              <criterion comment="openoffice.org-l10n-hu is earlier than 2.4.1+dfsg-1+lenny7" test_ref="oval:org.mitre.oval:tst:41395"/>
              <criterion comment="openoffice.org-l10n-mk is earlier than 2.4.1+dfsg-1+lenny7" test_ref="oval:org.mitre.oval:tst:41141"/>
              <criterion comment="openoffice.org-l10n-sr-cs is earlier than 2.4.1+dfsg-1+lenny7" test_ref="oval:org.mitre.oval:tst:41158"/>
              <criterion comment="openoffice.org-l10n-he is earlier than 2.4.1+dfsg-1+lenny7" test_ref="oval:org.mitre.oval:tst:41259"/>
              <criterion comment="openoffice.org-l10n-en-za is earlier than 2.4.1+dfsg-1+lenny7" test_ref="oval:org.mitre.oval:tst:40943"/>
              <criterion comment="libuno-cli-types1.1-cil is earlier than 1.1.13.0+OOo2.4.1+dfsg-1+lenny7" test_ref="oval:org.mitre.oval:tst:40553"/>
              <criterion comment="openoffice.org-l10n-as-in is earlier than 2.4.1+dfsg-1+lenny7" test_ref="oval:org.mitre.oval:tst:41342"/>
              <criterion comment="openoffice.org-l10n-ta-in is earlier than 2.4.1+dfsg-1+lenny7" test_ref="oval:org.mitre.oval:tst:41347"/>
              <criterion comment="openoffice.org-help-nl is earlier than 2.4.1+dfsg-1+lenny7" test_ref="oval:org.mitre.oval:tst:40939"/>
              <criterion comment="openoffice.org-l10n-eo is earlier than 2.4.1+dfsg-1+lenny7" test_ref="oval:org.mitre.oval:tst:41295"/>
              <criterion comment="openoffice.org-l10n-el is earlier than 2.4.1+dfsg-1+lenny7" test_ref="oval:org.mitre.oval:tst:41403"/>
              <criterion comment="openoffice.org-l10n-ro is earlier than 2.4.1+dfsg-1+lenny7" test_ref="oval:org.mitre.oval:tst:40409"/>
              <criterion comment="openoffice.org-l10n-zu is earlier than 2.4.1+dfsg-1+lenny7" test_ref="oval:org.mitre.oval:tst:41287"/>
              <criterion comment="openoffice.org-l10n-hi-in is earlier than 2.4.1+dfsg-1+lenny7" test_ref="oval:org.mitre.oval:tst:41044"/>
              <criterion comment="openoffice.org-l10n-zh-tw is earlier than 2.4.1+dfsg-1+lenny7" test_ref="oval:org.mitre.oval:tst:41072"/>
              <criterion comment="openoffice.org-l10n-za is earlier than 2.4.1+dfsg-1+lenny7" test_ref="oval:org.mitre.oval:tst:41285"/>
              <criterion comment="openoffice.org-l10n-et is earlier than 2.4.1+dfsg-1+lenny7" test_ref="oval:org.mitre.oval:tst:41402"/>
              <criterion comment="openoffice.org-help-fr is earlier than 2.4.1+dfsg-1+lenny7" test_ref="oval:org.mitre.oval:tst:41361"/>
              <criterion comment="openoffice.org-l10n-rw is earlier than 2.4.1+dfsg-1+lenny7" test_ref="oval:org.mitre.oval:tst:41186"/>
              <criterion comment="openoffice.org-l10n-es is earlier than 2.4.1+dfsg-1+lenny7" test_ref="oval:org.mitre.oval:tst:41224"/>
              <criterion comment="openoffice.org-l10n-ru is earlier than 2.4.1+dfsg-1+lenny7" test_ref="oval:org.mitre.oval:tst:41346"/>
              <criterion comment="openoffice.org-l10n-bs is earlier than 2.4.1+dfsg-1+lenny7" test_ref="oval:org.mitre.oval:tst:40903"/>
              <criterion comment="openoffice.org-l10n-br is earlier than 2.4.1+dfsg-1+lenny7" test_ref="oval:org.mitre.oval:tst:41203"/>
              <criterion comment="openoffice.org-style-tango is earlier than 2.4.1+dfsg-1+lenny7" test_ref="oval:org.mitre.oval:tst:41393"/>
              <criterion comment="openoffice.org-style-andromeda is earlier than 2.4.1+dfsg-1+lenny7" test_ref="oval:org.mitre.oval:tst:40503"/>
              <criterion comment="openoffice.org-l10n-bn is earlier than 2.4.1+dfsg-1+lenny7" test_ref="oval:org.mitre.oval:tst:40658"/>
              <criterion comment="openoffice.org-emailmerge is earlier than 2.4.1+dfsg-1+lenny7" test_ref="oval:org.mitre.oval:tst:41163"/>
              <criterion comment="openoffice.org-l10n-sl is earlier than 2.4.1+dfsg-1+lenny7" test_ref="oval:org.mitre.oval:tst:41202"/>
              <criterion comment="openoffice.org-l10n-ja is earlier than 2.4.1+dfsg-1+lenny7" test_ref="oval:org.mitre.oval:tst:41312"/>
              <criterion comment="openoffice.org-l10n-en-gb is earlier than 2.4.1+dfsg-1+lenny7" test_ref="oval:org.mitre.oval:tst:41290"/>
              <criterion comment="openoffice.org-help-gl is earlier than 2.4.1+dfsg-1+lenny7" test_ref="oval:org.mitre.oval:tst:40977"/>
              <criterion comment="openoffice.org-l10n-sk is earlier than 2.4.1+dfsg-1+lenny7" test_ref="oval:org.mitre.oval:tst:40414"/>
              <criterion comment="openoffice.org-l10n-st is earlier than 2.4.1+dfsg-1+lenny7" test_ref="oval:org.mitre.oval:tst:40446"/>
              <criterion comment="openoffice.org-l10n-sv is earlier than 2.4.1+dfsg-1+lenny7" test_ref="oval:org.mitre.oval:tst:41275"/>
              <criterion comment="openoffice.org-l10n-sr is earlier than 2.4.1+dfsg-1+lenny7" test_ref="oval:org.mitre.oval:tst:40855"/>
              <criterion comment="openoffice.org-l10n-ss is earlier than 2.4.1+dfsg-1+lenny7" test_ref="oval:org.mitre.oval:tst:41385"/>
              <criterion comment="openoffice.org-help-sv is earlier than 2.4.1+dfsg-1+lenny7" test_ref="oval:org.mitre.oval:tst:40743"/>
              <criterion comment="openoffice.org-style-hicontrast is earlier than 2.4.1+dfsg-1+lenny7" test_ref="oval:org.mitre.oval:tst:41250"/>
              <criterion comment="openoffice.org-help-dz is earlier than 2.4.1+dfsg-1+lenny7" test_ref="oval:org.mitre.oval:tst:41157"/>
              <criterion comment="openoffice.org-help-da is earlier than 2.4.1+dfsg-1+lenny7" test_ref="oval:org.mitre.oval:tst:40511"/>
              <criterion comment="openoffice.org-help-de is earlier than 2.4.1+dfsg-1+lenny7" test_ref="oval:org.mitre.oval:tst:41245"/>
              <criterion comment="openoffice.org-help-sl is earlier than 2.4.1+dfsg-1+lenny7" test_ref="oval:org.mitre.oval:tst:41391"/>
              <criterion comment="openoffice.org-l10n-gl is earlier than 2.4.1+dfsg-1+lenny7" test_ref="oval:org.mitre.oval:tst:41273"/>
              <criterion comment="openoffice.org-java-common is earlier than 2.4.1+dfsg-1+lenny7" test_ref="oval:org.mitre.oval:tst:41339"/>
              <criterion comment="openoffice.org-l10n-ga is earlier than 2.4.1+dfsg-1+lenny7" test_ref="oval:org.mitre.oval:tst:41131"/>
              <criterion comment="openoffice.org-l10n-lv is earlier than 2.4.1+dfsg-1+lenny7" test_ref="oval:org.mitre.oval:tst:40450"/>
              <criterion comment="openoffice.org-l10n-ts is earlier than 2.4.1+dfsg-1+lenny7" test_ref="oval:org.mitre.oval:tst:40425"/>
              <criterion comment="openoffice.org-l10n-tr is earlier than 2.4.1+dfsg-1+lenny7" test_ref="oval:org.mitre.oval:tst:41354"/>
              <criterion comment="openoffice.org-l10n-tn is earlier than 2.4.1+dfsg-1+lenny7" test_ref="oval:org.mitre.oval:tst:41139"/>
              <criterion comment="openoffice.org-l10n-th is earlier than 2.4.1+dfsg-1+lenny7" test_ref="oval:org.mitre.oval:tst:41367"/>
              <criterion comment="openoffice.org-l10n-tg is earlier than 2.4.1+dfsg-1+lenny7" test_ref="oval:org.mitre.oval:tst:41248"/>
              <criterion comment="openoffice.org-help-et is earlier than 2.4.1+dfsg-1+lenny7" test_ref="oval:org.mitre.oval:tst:41303"/>
              <criterion comment="openoffice.org-help-eu is earlier than 2.4.1+dfsg-1+lenny7" test_ref="oval:org.mitre.oval:tst:40908"/>
              <criterion comment="libuno-cli-basetypes1.0-cil is earlier than 1.0.10.0+OOo2.4.1+dfsg-1+lenny7" test_ref="oval:org.mitre.oval:tst:41381"/>
              <criterion comment="openoffice.org-help-es is earlier than 2.4.1+dfsg-1+lenny7" test_ref="oval:org.mitre.oval:tst:41424"/>
              <criterion comment="openoffice.org-filter-mobiledev is earlier than 2.4.1+dfsg-1+lenny7" test_ref="oval:org.mitre.oval:tst:41351"/>
              <criterion comment="openoffice.org-l10n-or-in is earlier than 2.4.1+dfsg-1+lenny7" test_ref="oval:org.mitre.oval:tst:41054"/>
              <criterion comment="openoffice.org-l10n-lt is earlier than 2.4.1+dfsg-1+lenny7" test_ref="oval:org.mitre.oval:tst:40701"/>
              <criterion comment="openoffice.org-l10n-te-in is earlier than 2.4.1+dfsg-1+lenny7" test_ref="oval:org.mitre.oval:tst:41199"/>
              <criterion comment="openoffice.org-l10n-uz is earlier than 2.4.1+dfsg-1+lenny7" test_ref="oval:org.mitre.oval:tst:41114"/>
              <criterion comment="openoffice.org-l10n-de is earlier than 2.4.1+dfsg-1+lenny7" test_ref="oval:org.mitre.oval:tst:41069"/>
              <criterion comment="openoffice.org-l10n-da is earlier than 2.4.1+dfsg-1+lenny7" test_ref="oval:org.mitre.oval:tst:41286"/>
              <criterion comment="openoffice.org-l10n-uk is earlier than 2.4.1+dfsg-1+lenny7" test_ref="oval:org.mitre.oval:tst:41236"/>
              <criterion comment="openoffice.org-l10n-dz is earlier than 2.4.1+dfsg-1+lenny7" test_ref="oval:org.mitre.oval:tst:41425"/>
              <criterion comment="libuno-cli-cppuhelper1.0-cil is earlier than 1.0.13.0+OOo2.4.1+dfsg-1+lenny7" test_ref="oval:org.mitre.oval:tst:41074"/>
              <criterion comment="openoffice.org-l10n-lo is earlier than 2.4.1+dfsg-1+lenny7" test_ref="oval:org.mitre.oval:tst:40797"/>
              <criterion comment="libuno-cli-ure1.0-cil is earlier than 1.0.13.0+OOo2.4.1+dfsg-1+lenny7" test_ref="oval:org.mitre.oval:tst:41249"/>
              <criterion comment="openoffice.org-l10n-ar is earlier than 2.4.1+dfsg-1+lenny7" test_ref="oval:org.mitre.oval:tst:40972"/>
              <criterion comment="openoffice.org-l10n-ml-in is earlier than 2.4.1+dfsg-1+lenny7" test_ref="oval:org.mitre.oval:tst:41344"/>
              <criterion comment="openoffice.org-help-en-gb is earlier than 2.4.1+dfsg-1+lenny7" test_ref="oval:org.mitre.oval:tst:41365"/>
              <criterion comment="openoffice.org-l10n-af is earlier than 2.4.1+dfsg-1+lenny7" test_ref="oval:org.mitre.oval:tst:41002"/>
              <criterion comment="openoffice.org-common is earlier than 2.4.1+dfsg-1+lenny7" test_ref="oval:org.mitre.oval:tst:41410"/>
              <criterion comment="openoffice.org-help-ja is earlier than 2.4.1+dfsg-1+lenny7" test_ref="oval:org.mitre.oval:tst:40918"/>
              <criterion comment="openoffice.org-l10n-zh-cn is earlier than 2.4.1+dfsg-1+lenny7" test_ref="oval:org.mitre.oval:tst:41322"/>
              <criterion comment="openoffice.org-l10n-ve is earlier than 2.4.1+dfsg-1+lenny7" test_ref="oval:org.mitre.oval:tst:40433"/>
              <criterion comment="openoffice.org-help-zh-cn is earlier than 2.4.1+dfsg-1+lenny7" test_ref="oval:org.mitre.oval:tst:41263"/>
              <criterion comment="openoffice.org-l10n-it is earlier than 2.4.1+dfsg-1+lenny7" test_ref="oval:org.mitre.oval:tst:41021"/>
              <criterion comment="openoffice.org-l10n-gu-in is earlier than 2.4.1+dfsg-1+lenny7" test_ref="oval:org.mitre.oval:tst:41252"/>
              <criterion comment="openoffice.org-l10n-in is earlier than 2.4.1+dfsg-1+lenny7" test_ref="oval:org.mitre.oval:tst:40847"/>
              <criterion comment="openoffice.org-help-zh-tw is earlier than 2.4.1+dfsg-1+lenny7" test_ref="oval:org.mitre.oval:tst:41353"/>
              <criterion comment="openoffice.org-style-crystal is earlier than 2.4.1+dfsg-1+lenny7" test_ref="oval:org.mitre.oval:tst:41299"/>
              <criterion comment="openoffice.org-l10n-mr-in is earlier than 2.4.1+dfsg-1+lenny7" test_ref="oval:org.mitre.oval:tst:41398"/>
              <criterion comment="openoffice.org-help-ru is earlier than 2.4.1+dfsg-1+lenny7" test_ref="oval:org.mitre.oval:tst:40574"/>
              <criterion comment="openoffice.org-l10n-fr is earlier than 2.4.1+dfsg-1+lenny7" test_ref="oval:org.mitre.oval:tst:40794"/>
              <criterion comment="openoffice.org-l10n-pt-br is earlier than 2.4.1+dfsg-1+lenny7" test_ref="oval:org.mitre.oval:tst:41137"/>
              <criterion comment="openoffice.org-report-builder is earlier than 1.0.2+OOo2.4.1+dfsg-1+lenny7" test_ref="oval:org.mitre.oval:tst:40717"/>
              <criterion comment="openoffice.org-help-pt-br is earlier than 2.4.1+dfsg-1+lenny7" test_ref="oval:org.mitre.oval:tst:40866"/>
              <criterion comment="openoffice.org-help-ko is earlier than 2.4.1+dfsg-1+lenny7" test_ref="oval:org.mitre.oval:tst:41247"/>
              <criterion comment="openoffice.org-help-km is earlier than 2.4.1+dfsg-1+lenny7" test_ref="oval:org.mitre.oval:tst:41432"/>
              <criterion comment="openoffice.org-l10n-fa is earlier than 2.4.1+dfsg-1+lenny7" test_ref="oval:org.mitre.oval:tst:41434"/>
              <criterion comment="openoffice.org-l10n-fi is earlier than 2.4.1+dfsg-1+lenny7" test_ref="oval:org.mitre.oval:tst:41366"/>
              <criterion comment="openoffice.org-qa-api-tests is earlier than 2.4.1+dfsg-1+lenny7" test_ref="oval:org.mitre.oval:tst:41218"/>
              <criterion comment="openoffice.org-help-hi-in is earlier than 2.4.1+dfsg-1+lenny7" test_ref="oval:org.mitre.oval:tst:41297"/>
              <criterion comment="openoffice.org-l10n-ns is earlier than 2.4.1+dfsg-1+lenny7" test_ref="oval:org.mitre.oval:tst:41294"/>
              <criterion comment="openoffice.org-l10n-nr is earlier than 2.4.1+dfsg-1+lenny7" test_ref="oval:org.mitre.oval:tst:41109"/>
              <criterion comment="openoffice.org-l10n-nb is earlier than 2.4.1+dfsg-1+lenny7" test_ref="oval:org.mitre.oval:tst:41188"/>
              <criterion comment="openoffice.org-l10n-nn is earlier than 2.4.1+dfsg-1+lenny7" test_ref="oval:org.mitre.oval:tst:41261"/>
              <criterion comment="openoffice.org-l10n-nl is earlier than 2.4.1+dfsg-1+lenny7" test_ref="oval:org.mitre.oval:tst:40441"/>
              <criterion comment="openoffice.org-help-cs is earlier than 2.4.1+dfsg-1+lenny7" test_ref="oval:org.mitre.oval:tst:41086"/>
              <criterion comment="openoffice.org-l10n-ne is earlier than 2.4.1+dfsg-1+lenny7" test_ref="oval:org.mitre.oval:tst:41350"/>
              <criterion comment="openoffice.org-l10n-pa-in is earlier than 2.4.1+dfsg-1+lenny7" test_ref="oval:org.mitre.oval:tst:41095"/>
              <criterion comment="openoffice.org-dev-doc is earlier than 2.4.1+dfsg-1+lenny7" test_ref="oval:org.mitre.oval:tst:41296"/>
            </criteria>
          </criteria>
          <criteria operator="AND" comment="Architecture dependent section">
            <criteria operator="OR" comment="Supported architectures section">
              <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
              <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
              <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
              <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
              <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
              <criterion comment="Installed architecture is armel" test_ref="oval:org.mitre.oval:tst:11101"/>
              <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
              <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
              <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
            </criteria>
            <criteria operator="OR" comment="Packages section">
              <criterion comment="openoffice.org is earlier than 2.4.1+dfsg-1+lenny7" test_ref="oval:org.mitre.oval:tst:41193"/>
              <criterion comment="openoffice.org-dbg is earlier than 2.4.1+dfsg-1+lenny7" test_ref="oval:org.mitre.oval:tst:41427"/>
              <criterion comment="python-uno is earlier than 2.4.1+dfsg-1+lenny7" test_ref="oval:org.mitre.oval:tst:40484"/>
              <criterion comment="openoffice.org-draw is earlier than 2.4.1+dfsg-1+lenny7" test_ref="oval:org.mitre.oval:tst:40872"/>
              <criterion comment="openoffice.org-kde is earlier than 2.4.1+dfsg-1+lenny7" test_ref="oval:org.mitre.oval:tst:40990"/>
              <criterion comment="openoffice.org-sdbc-postgresql is earlier than 0.7.6+OOo2.4.1+dfsg-1+lenny7" test_ref="oval:org.mitre.oval:tst:40514"/>
              <criterion comment="openoffice.org-base is earlier than 2.4.1+dfsg-1+lenny7" test_ref="oval:org.mitre.oval:tst:41433"/>
              <criterion comment="ure-dbg is earlier than 1.4+OOo2.4.1+dfsg-1+lenny7" test_ref="oval:org.mitre.oval:tst:41253"/>
              <criterion comment="openoffice.org-headless is earlier than 2.4.1+dfsg-1+lenny7" test_ref="oval:org.mitre.oval:tst:41500"/>
              <criterion comment="libmythes-dev is earlier than 2.4.1+dfsg-1+lenny7" test_ref="oval:org.mitre.oval:tst:41475"/>
              <criterion comment="openoffice.org-gnome is earlier than 2.4.1+dfsg-1+lenny7" test_ref="oval:org.mitre.oval:tst:40643"/>
              <criterion comment="openoffice.org-evolution is earlier than 2.4.1+dfsg-1+lenny7" test_ref="oval:org.mitre.oval:tst:41117"/>
              <criterion comment="openoffice.org-math is earlier than 2.4.1+dfsg-1+lenny7" test_ref="oval:org.mitre.oval:tst:41213"/>
              <criterion comment="openoffice.org-calc is earlier than 2.4.1+dfsg-1+lenny7" test_ref="oval:org.mitre.oval:tst:41438"/>
              <criterion comment="openoffice.org-base-core is earlier than 2.4.1+dfsg-1+lenny7" test_ref="oval:org.mitre.oval:tst:41283"/>
              <criterion comment="openoffice.org-report-builder-bin is earlier than 2.4.1+dfsg-1+lenny7" test_ref="oval:org.mitre.oval:tst:41134"/>
              <criterion comment="openoffice.org-impress is earlier than 2.4.1+dfsg-1+lenny7" test_ref="oval:org.mitre.oval:tst:41375"/>
              <criterion comment="openoffice.org-dev is earlier than 2.4.1+dfsg-1+lenny7" test_ref="oval:org.mitre.oval:tst:41478"/>
              <criterion comment="openoffice.org-core is earlier than 2.4.1+dfsg-1+lenny7" test_ref="oval:org.mitre.oval:tst:41343"/>
              <criterion comment="ure is earlier than 1.4+OOo2.4.1+dfsg-1+lenny7" test_ref="oval:org.mitre.oval:tst:41463"/>
              <criterion comment="openoffice.org-writer is earlier than 2.4.1+dfsg-1+lenny7" test_ref="oval:org.mitre.oval:tst:41409"/>
              <criterion comment="mozilla-openoffice.org is earlier than 2.4.1+dfsg-1+lenny7" test_ref="oval:org.mitre.oval:tst:41318"/>
              <criterion comment="openoffice.org-gtk is earlier than 2.4.1+dfsg-1+lenny7" test_ref="oval:org.mitre.oval:tst:41377"/>
              <criterion comment="openoffice.org-officebean is earlier than 2.4.1+dfsg-1+lenny7" test_ref="oval:org.mitre.oval:tst:41340"/>
              <criterion comment="openoffice.org-presentation-minimizer is earlier than 1.0+OOo2.4.1+dfsg-1+lenny7" test_ref="oval:org.mitre.oval:tst:41489"/>
            </criteria>
          </criteria>
          <criteria operator="AND" comment="Architecture dependent section">
            <criteria operator="OR" comment="Supported architectures section">
              <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
              <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
              <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
              <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
              <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
              <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
            </criteria>
            <criteria operator="OR" comment="Packages section">
              <criterion comment="openoffice.org-gcj is earlier than 2.4.1+dfsg-1+lenny7" test_ref="oval:org.mitre.oval:tst:40934"/>
              <criterion comment="openoffice.org-filter-binfilter is earlier than 2.4.1+dfsg-1+lenny7" test_ref="oval:org.mitre.oval:tst:41063"/>
              <criterion comment="openoffice.org-qa-tools is earlier than 2.4.1+dfsg-1+lenny7" test_ref="oval:org.mitre.oval:tst:41211"/>
            </criteria>
          </criteria>
          <criteria operator="AND" comment="Architecture depended section">
            <criteria operator="AND" comment="Supported platform section">
              <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
              <criteria operator="OR" comment="Packages section">
                <criterion comment="openoffice.org-gcj is earlier than 2.4.1+dfsg-1+lenny7" test_ref="oval:org.mitre.oval:tst:41423"/>
                <criterion comment="openoffice.org-filter-binfilter is earlier than 2.4.1+dfsg-1+lenny7" test_ref="oval:org.mitre.oval:tst:41212"/>
                <criterion comment="cli-uno-bridge is earlier than 2.4.1+dfsg-1+lenny7" test_ref="oval:org.mitre.oval:tst:40953"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11795" version="3" class="patch">
      <metadata>
        <title>DSA-2065 kvirc -- several vulnerabilities</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <product>kvirc</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2010/dsa-2065" ref_id="DSA-2065"/>
        <description>Two security issues have been discovered in the DCC protocol support code of kvirc, a KDE-based next generation IRC client, which allow the overwriting of local files through directory traversal and the execution of arbitrary code through a format string attack.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-31T15:50:52-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2010-08-03T12:18:49.122-04:00">DRAFT</status_change>
            <status_change date="2010-08-23T04:00:22.542-04:00">INTERIM</status_change>
            <status_change date="2010-09-13T04:00:22.139-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
        <criteria operator="OR" comment="Architecture section">
          <criteria operator="AND" comment="Architecture independent section">
            <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
            <criterion comment="kvirc-data is earlier than 3.4.0-5" test_ref="oval:org.mitre.oval:tst:41368"/>
          </criteria>
          <criteria operator="AND" comment="Architecture dependent section">
            <criteria operator="OR" comment="Supported architectures section">
              <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
              <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
              <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
              <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
              <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
              <criterion comment="Installed architecture is armel" test_ref="oval:org.mitre.oval:tst:11101"/>
              <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
              <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
              <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
              <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
              <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
              <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
            </criteria>
            <criteria operator="OR" comment="Packages section">
              <criterion comment="kvirc-dev is earlier than 3.4.0-5" test_ref="oval:org.mitre.oval:tst:41415"/>
              <criterion comment="kvirc is earlier than 3.4.0-5" test_ref="oval:org.mitre.oval:tst:41267"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11794" version="3" class="patch">
      <metadata>
        <title>DSA-2071 libmikmod -- buffer overflows</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <product>libmikmod</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2010/dsa-2071" ref_id="DSA-2071"/>
        <description>Dyon Balding discovered buffer overflows in the MikMod sound library, which could lead to the execution of arbitrary code if a user is tricked into opening malformed Impulse Tracker or Ultratracker sound files.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-31T15:50:51-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2010-08-03T12:18:40.557-04:00">DRAFT</status_change>
            <status_change date="2010-08-23T04:00:22.140-04:00">INTERIM</status_change>
            <status_change date="2010-09-13T04:00:21.717-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
        <criteria operator="OR" comment="Architecture section">
          <criteria operator="AND" comment="Architecture dependent section">
            <criteria operator="OR" comment="Supported architectures section">
              <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
              <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
              <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
              <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
              <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
              <criterion comment="Installed architecture is armel" test_ref="oval:org.mitre.oval:tst:11101"/>
              <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
              <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
              <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
              <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
              <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
              <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
            </criteria>
            <criteria operator="OR" comment="Packages section">
              <criterion comment="libmikmod2-dev is earlier than 3.1.11-a-6+lenny1" test_ref="oval:org.mitre.oval:tst:41522"/>
              <criterion comment="libmikmod2 is earlier than 3.1.11-a-6+lenny1" test_ref="oval:org.mitre.oval:tst:41413"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11784" version="3" class="patch">
      <metadata>
        <title>DSA-2062 sudo -- missing input sanitization</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <product>sudo</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2010/dsa-2062" ref_id="DSA-2062"/>
        <description>Anders Kaseorg and Evan Broder discovered a vulnerability in sudo, a program designed to allow a sysadmin to give limited root privileges to users, that allows a user with sudo permissions on certain programs to use those programs with an untrusted value of PATH. This could possibly lead to certain intended restrictions being bypassed, such as the secure_path setting.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-31T15:50:51-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2010-08-03T12:18:47.288-04:00">DRAFT</status_change>
            <status_change date="2010-08-23T04:00:21.394-04:00">INTERIM</status_change>
            <status_change date="2010-09-13T04:00:21.008-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
        <criteria operator="OR" comment="Architecture section">
          <criteria operator="AND" comment="Architecture dependent section">
            <criteria operator="OR" comment="Supported architectures section">
              <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
              <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
              <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
              <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
              <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
              <criterion comment="Installed architecture is armel" test_ref="oval:org.mitre.oval:tst:11101"/>
              <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
              <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
              <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
              <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
              <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
              <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
            </criteria>
            <criteria operator="OR" comment="Packages section">
              <criterion comment="sudo-ldap is earlier than 1.6.9p17-3" test_ref="oval:org.mitre.oval:tst:41219"/>
              <criterion comment="sudo is earlier than 1.6.9p17-3" test_ref="oval:org.mitre.oval:tst:40962"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11783" version="5" class="patch">
      <metadata>
        <title>DSA-2054 bind9 -- DNS cache poisoning</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <product>bind9</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2010/dsa-2054" ref_id="DSA-2054"/>
        <description>Several cache-poisoning vulnerabilities have been discovered in BIND. These vulnerabilities apply only if DNSSEC validation is enabled and trust anchors have been installed, which is not the default. The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2010-0097 BIND does not properly validate DNSSEC NSEC records, which allows remote attackers to add the Authenticated Data  flag to a forged NXDOMAIN response for an existing domain. When processing crafted responses containing CNAME or DNAME records, BIND is subject to a DNS cache poisoning vulnerability, provided that DNSSEC validation is enabled and trust anchors have been installed. When processing certain responses containing out-of-bailiwick data, BIND is subject to a DNS cache poisoning vulnerability, provided that DNSSEC validation is enabled and trust anchors have been installed. In addition, this update introduce a more conservative query behavior in the presence of repeated DNSSEC validation failures, addressing the "roll over and die" phenomenon. The new version also supports the cryptographic algorithm used by the upcoming signed ICANN DNS root , and the NSEC3 secure denial of existence algorithm used by some signed top-level domains. This update is based on a new upstream version of BIND 9, 9.6-ESV-R1. Because of the scope of changes, extra care is recommended when installing the update. Due to ABI changes, new Debian packages are included, and the update has to be installed using "apt-get dist-upgrade" .</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-31T15:50:51-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2010-08-03T12:18:36.879-04:00">DRAFT</status_change>
            <status_change date="2010-08-23T04:00:20.750-04:00">INTERIM</status_change>
            <status_change date="2010-09-13T04:00:20.456-04:00">ACCEPTED</status_change>
            <modified comment="Corrected ste:11659 to have the correct epoch component of the version, as stated in the original advisory." date="2010-12-09T13:55:00.732-05:00">
              <contributor organization="DCIT, a.s.">Pavel Kankovsky</contributor>
            </modified>
            <status_change date="2010-12-09T13:57:36.692-05:00">INTERIM</status_change>
            <status_change date="2010-12-27T04:00:07.628-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
        <criteria operator="OR" comment="Architecture section">
          <criteria operator="AND" comment="Architecture independent section">
            <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
            <criterion comment="bind9-doc is earlier than 9.6.ESV.R1+dfsg-0+lenny1" test_ref="oval:org.mitre.oval:tst:41374"/>
          </criteria>
          <criteria operator="AND" comment="Architecture dependent section">
            <criteria operator="OR" comment="Supported architectures section">
              <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
              <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
              <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
              <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
              <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
              <criterion comment="Installed architecture is armel" test_ref="oval:org.mitre.oval:tst:11101"/>
              <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
              <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
              <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
              <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
              <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
              <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
            </criteria>
            <criteria operator="OR" comment="Packages section">
              <criterion comment="dnsutils is earlier than 9.6.ESV.R1+dfsg-0+lenny1" test_ref="oval:org.mitre.oval:tst:41442"/>
              <criterion comment="libbind-dev is earlier than 9.6.ESV.R1+dfsg-0+lenny1" test_ref="oval:org.mitre.oval:tst:41284"/>
              <criterion comment="bind9 is earlier than 9.6.ESV.R1+dfsg-0+lenny1" test_ref="oval:org.mitre.oval:tst:41371"/>
              <criterion comment="libisc52 is earlier than 9.6.ESV.R1+dfsg-0+lenny1" test_ref="oval:org.mitre.oval:tst:40765"/>
              <criterion comment="libbind9-50 is earlier than 9.6.ESV.R1+dfsg-0+lenny1" test_ref="oval:org.mitre.oval:tst:41429"/>
              <criterion comment="bind9utils is earlier than 9.6.ESV.R1+dfsg-0+lenny1" test_ref="oval:org.mitre.oval:tst:41269"/>
              <criterion comment="libdns55 is earlier than 9.6.ESV.R1+dfsg-0+lenny1" test_ref="oval:org.mitre.oval:tst:41316"/>
              <criterion comment="liblwres50 is earlier than 9.6.ESV.R1+dfsg-0+lenny1" test_ref="oval:org.mitre.oval:tst:41313"/>
              <criterion comment="lwresd is earlier than 9.6.ESV.R1+dfsg-0+lenny1" test_ref="oval:org.mitre.oval:tst:41420"/>
              <criterion comment="libisccfg50 is earlier than 9.6.ESV.R1+dfsg-0+lenny1" test_ref="oval:org.mitre.oval:tst:41405"/>
              <criterion comment="libisccc50 is earlier than 9.6.ESV.R1+dfsg-0+lenny1" test_ref="oval:org.mitre.oval:tst:41222"/>
              <criterion comment="bind9-host is earlier than 9.6.ESV.R1+dfsg-0+lenny1" test_ref="oval:org.mitre.oval:tst:41514"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11765" version="3" class="patch">
      <metadata>
        <title>DSA-2057 mysql-dfsg-5.0 -- several vulnerabilities</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <product>mysql-dfsg-5.0</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2010/dsa-2057" ref_id="DSA-2057"/>
        <description>Several vulnerabilities have been discovered in the MySQL database server. The Common Vulnerabilities and Exposures project identifies the following problems: MySQL allows local users to delete the data and index files of another user"s MyISAM table via a symlink attack in conjunction with the DROP TABLE command. MySQL failed to check the table name argument of a COM_FIELD_LIST command packet for validity and compliance to acceptable table name standards. This allows an authenticated user with SELECT privileges on one table to obtain the field definitions of any table in all other databases and potentially of other MySQL instances accessible from the server"s file system. MySQL could be tricked to read packets indefinitely if it received a packet larger than the maximum size of one packet. This results in high CPU usage and thus denial of service conditions. MySQL was susceptible to a buffer-overflow attack due to a failure to perform bounds checking on the table name argument of a COM_FIELD_LIST command packet. By sending long data for the table name, a buffer is overflown, which could be exploited by an authenticated user to inject malicious code.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-31T15:50:51-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2010-08-03T12:18:37.862-04:00">DRAFT</status_change>
            <status_change date="2010-08-23T04:00:19.309-04:00">INTERIM</status_change>
            <status_change date="2010-09-13T04:00:19.319-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
        <criteria operator="OR" comment="Architecture section">
          <criteria operator="AND" comment="Architecture independent section">
            <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
            <criteria operator="OR" comment="Packages section">
              <criterion comment="mysql-client is earlier than 5.0.51a-24+lenny4" test_ref="oval:org.mitre.oval:tst:40530"/>
              <criterion comment="mysql-common is earlier than 5.0.51a-24+lenny4" test_ref="oval:org.mitre.oval:tst:41416"/>
              <criterion comment="mysql-server is earlier than 5.0.51a-24+lenny4" test_ref="oval:org.mitre.oval:tst:41406"/>
            </criteria>
          </criteria>
          <criteria operator="AND" comment="Architecture dependent section">
            <criteria operator="OR" comment="Supported architectures section">
              <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
              <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
              <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
              <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
              <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
              <criterion comment="Installed architecture is armel" test_ref="oval:org.mitre.oval:tst:11101"/>
              <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
              <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
              <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
              <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
              <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
              <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
            </criteria>
            <criteria operator="OR" comment="Packages section">
              <criterion comment="libmysqlclient15-dev is earlier than 5.0.51a-24+lenny4" test_ref="oval:org.mitre.oval:tst:41332"/>
              <criterion comment="mysql-client-5.0 is earlier than 5.0.51a-24+lenny4" test_ref="oval:org.mitre.oval:tst:41268"/>
              <criterion comment="mysql-server-5.0 is earlier than 5.0.51a-24+lenny4" test_ref="oval:org.mitre.oval:tst:41276"/>
              <criterion comment="libmysqlclient15off is earlier than 5.0.51a-24+lenny4" test_ref="oval:org.mitre.oval:tst:41471"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11742" version="3" class="patch">
      <metadata>
        <title>DSA-2073 mlmmj -- insufficient input sanitising</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <product>mlmmj</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2010/dsa-2073" ref_id="DSA-2073"/>
        <description>Florian Streibelt reported a directory traversal flaw in the way the Mailing List Managing Made Joyful mailing list manager processed users" requests originating from the administrator web interface without enough input validation. A remote, authenticated attacker could use these flaws to write and/or delete arbitrary files.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-31T15:50:51-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2010-08-03T12:18:39.418-04:00">DRAFT</status_change>
            <status_change date="2010-08-23T04:00:18.581-04:00">INTERIM</status_change>
            <status_change date="2010-09-13T04:00:18.824-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
        <criteria operator="OR" comment="Architecture section">
          <criteria operator="AND" comment="Architecture independent section">
            <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
            <criteria operator="OR" comment="Packages section">
              <criterion comment="mlmmj-php-web is earlier than 1.2.15-1.1+lenny1" test_ref="oval:org.mitre.oval:tst:40957"/>
              <criterion comment="mlmmj-php-web-admin is earlier than 1.2.15-1.1+lenny1" test_ref="oval:org.mitre.oval:tst:41334"/>
            </criteria>
          </criteria>
          <criteria operator="AND" comment="Architecture dependent section">
            <criteria operator="OR" comment="Supported architectures section">
              <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
              <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
              <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
              <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
              <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
              <criterion comment="Installed architecture is armel" test_ref="oval:org.mitre.oval:tst:11101"/>
              <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
              <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
              <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
              <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
              <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
              <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
            </criteria>
            <criteria operator="OR" comment="Packages section">
              <criterion comment="mlmmj is earlier than 1.2.15-1.1+lenny1" test_ref="oval:org.mitre.oval:tst:40952"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11705" version="3" class="patch">
      <metadata>
        <title>DSA-2063 pmount -- insecure temporary file</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <product>pmount</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2010/dsa-2063" ref_id="DSA-2063"/>
        <description>Dan Rosenberg discovered that pmount, a wrapper around the standard mount program which permits normal users to mount removable devices without a matching /etc/fstab entry, creates files in /var/lock insecurely. A local attacker could overwrite arbitrary files utilising a symlink attack.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-31T15:50:51-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2010-08-03T12:18:47.660-04:00">DRAFT</status_change>
            <status_change date="2010-08-23T04:00:17.480-04:00">INTERIM</status_change>
            <status_change date="2010-09-13T04:00:18.140-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
        <criteria operator="OR" comment="Architecture section">
          <criteria operator="AND" comment="Architecture dependent section">
            <criteria operator="OR" comment="Supported architectures section">
              <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
              <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
              <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
              <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
              <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
              <criterion comment="Installed architecture is armel" test_ref="oval:org.mitre.oval:tst:11101"/>
              <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
              <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
              <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
              <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
              <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
              <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
            </criteria>
            <criteria operator="OR" comment="Packages section">
              <criterion comment="pmount is earlier than 0.9.18-2+lenny1" test_ref="oval:org.mitre.oval:tst:41363"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11696" version="3" class="patch">
      <metadata>
        <title>DSA-2060 cacti -- insufficient input sanitization</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <product>cacti</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2010/dsa-2060" ref_id="DSA-2060"/>
        <description>Stefan Esser discovered that cacti, a front-end to rrdtool for monitoring systems and services, is not properly validating input passed to the rra_id parameter of the graph.php script. Due to checking the input of $_REQUEST but using $_GET input in a query an unauthenticated attacker is able to perform SQL injections via a crafted rra_id $_GET value and an additional valid rra_id $_POST or $_COOKIE value.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-31T15:50:51-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2010-08-03T12:18:45.352-04:00">DRAFT</status_change>
            <status_change date="2010-08-23T04:00:17.261-04:00">INTERIM</status_change>
            <status_change date="2010-09-13T04:00:17.882-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
        <criteria operator="OR" comment="Architecture section">
          <criteria operator="AND" comment="Architecture independent section">
            <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
            <criterion comment="cacti is earlier than 0.8.7b-2.1+lenny3" test_ref="oval:org.mitre.oval:tst:41138"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11655" version="3" class="patch">
      <metadata>
        <title>DSA-2051 postgresql-8.3 -- several vulnerabilities</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <product>postgresql-8.3</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2010/dsa-2051" ref_id="DSA-2051"/>
        <description>Several local vulnerabilities have been discovered in PostgreSQL, an object-relational SQL database. The Common Vulnerabilities and Exposures project identifies the following problems: Tim Bunce discovered that the implementation of the procedural language PL/Perl insufficiently restricts the subset of allowed code, which allows authenticated users the execution of arbitrary Perl code. Tom Lane discovered that the implementation of the procedural language PL/Tcl insufficiently restricts the subset of allowed code, which allows authenticated users the execution of arbitrary Tcl code. It was discovered that an unprivileged user could reset superuser-only parameter settings.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-31T15:50:51-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2010-08-03T12:18:18.961-04:00">DRAFT</status_change>
            <status_change date="2010-08-23T04:00:15.558-04:00">INTERIM</status_change>
            <status_change date="2010-09-13T04:00:16.331-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
        <criteria operator="OR" comment="Architecture section">
          <criteria operator="AND" comment="Architecture independent section">
            <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
            <criteria operator="OR" comment="Packages section">
              <criterion comment="postgresql-doc-8.3 is earlier than 8.3.11-0lenny1" test_ref="oval:org.mitre.oval:tst:41152"/>
              <criterion comment="postgresql-contrib is earlier than 8.3.11-0lenny1" test_ref="oval:org.mitre.oval:tst:40775"/>
              <criterion comment="postgresql-client is earlier than 8.3.11-0lenny1" test_ref="oval:org.mitre.oval:tst:41195"/>
              <criterion comment="postgresql is earlier than 8.3.11-0lenny1" test_ref="oval:org.mitre.oval:tst:40854"/>
              <criterion comment="postgresql-doc is earlier than 8.3.11-0lenny1" test_ref="oval:org.mitre.oval:tst:40976"/>
            </criteria>
          </criteria>
          <criteria operator="AND" comment="Architecture dependent section">
            <criteria operator="OR" comment="Supported architectures section">
              <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
              <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
              <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
              <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
              <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
              <criterion comment="Installed architecture is armel" test_ref="oval:org.mitre.oval:tst:11101"/>
              <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
              <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
              <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
              <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
              <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
              <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
            </criteria>
            <criteria operator="OR" comment="Packages section">
              <criterion comment="postgresql-client-8.3 is earlier than 8.3.11-0lenny1" test_ref="oval:org.mitre.oval:tst:40716"/>
              <criterion comment="postgresql-8.3 is earlier than 8.3.11-0lenny1" test_ref="oval:org.mitre.oval:tst:40849"/>
              <criterion comment="libecpg6 is earlier than 8.3.11-0lenny1" test_ref="oval:org.mitre.oval:tst:40227"/>
              <criterion comment="libpq-dev is earlier than 8.3.11-0lenny1" test_ref="oval:org.mitre.oval:tst:41149"/>
              <criterion comment="postgresql-plpython-8.3 is earlier than 8.3.11-0lenny1" test_ref="oval:org.mitre.oval:tst:41187"/>
              <criterion comment="postgresql-pltcl-8.3 is earlier than 8.3.11-0lenny1" test_ref="oval:org.mitre.oval:tst:40905"/>
              <criterion comment="postgresql-server-dev-8.3 is earlier than 8.3.11-0lenny1" test_ref="oval:org.mitre.oval:tst:40617"/>
              <criterion comment="libpgtypes3 is earlier than 8.3.11-0lenny1" test_ref="oval:org.mitre.oval:tst:41168"/>
              <criterion comment="libecpg-dev is earlier than 8.3.11-0lenny1" test_ref="oval:org.mitre.oval:tst:41227"/>
              <criterion comment="postgresql-contrib-8.3 is earlier than 8.3.11-0lenny1" test_ref="oval:org.mitre.oval:tst:40917"/>
              <criterion comment="libpq5 is earlier than 8.3.11-0lenny1" test_ref="oval:org.mitre.oval:tst:41143"/>
              <criterion comment="postgresql-plperl-8.3 is earlier than 8.3.11-0lenny1" test_ref="oval:org.mitre.oval:tst:40359"/>
              <criterion comment="libecpg-compat3 is earlier than 8.3.11-0lenny1" test_ref="oval:org.mitre.oval:tst:41201"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11634" version="3" class="patch">
      <metadata>
        <title>DSA-2068 python-cjson -- buffer overflow</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <product>python-cjson</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2010/dsa-2068" ref_id="DSA-2068"/>
        <description>Matt Giuca discovered a buffer overflow in python-cjson, a fast JSON encoder/decoder for Python. This allows a remote attacker to cause a denial of service  through a specially-crafted Python script.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-31T15:50:51-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2010-08-03T12:18:44.580-04:00">DRAFT</status_change>
            <status_change date="2010-08-23T04:00:14.494-04:00">INTERIM</status_change>
            <status_change date="2010-09-13T04:00:15.172-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
        <criteria operator="OR" comment="Architecture section">
          <criteria operator="AND" comment="Architecture dependent section">
            <criteria operator="OR" comment="Supported architectures section">
              <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
              <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
              <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
              <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
              <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
              <criterion comment="Installed architecture is armel" test_ref="oval:org.mitre.oval:tst:11101"/>
              <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
              <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
              <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
              <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
              <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
              <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
            </criteria>
            <criteria operator="OR" comment="Packages section">
              <criterion comment="python-cjson is earlier than 1.0.5-1+lenny1" test_ref="oval:org.mitre.oval:tst:41207"/>
              <criterion comment="python-cjson-dbg is earlier than 1.0.5-1+lenny1" test_ref="oval:org.mitre.oval:tst:41379"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11631" version="3" class="patch">
      <metadata>
        <title>DSA-2076 gnupg2 -- use-after-free</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <product>gnupg2</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2010/dsa-2076" ref_id="DSA-2076"/>
        <description>It was discovered that GnuPG 2 uses a freed pointer when verifying a signature or importing a certificate with many Subject Alternate Names, potentially leading to arbitrary code execution.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-31T15:50:51-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2010-08-03T12:18:41.560-04:00">DRAFT</status_change>
            <status_change date="2010-08-23T04:00:14.002-04:00">INTERIM</status_change>
            <status_change date="2010-09-13T04:00:14.705-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
        <criteria operator="OR" comment="Architecture section">
          <criteria operator="AND" comment="Architecture dependent section">
            <criteria operator="OR" comment="Supported architectures section">
              <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
              <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
              <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
              <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
              <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
              <criterion comment="Installed architecture is armel" test_ref="oval:org.mitre.oval:tst:11101"/>
              <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
              <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
              <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
              <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
              <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
              <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
            </criteria>
            <criteria operator="OR" comment="Packages section">
              <criterion comment="gpgsm is earlier than 2.0.9-3.1+lenny1" test_ref="oval:org.mitre.oval:tst:41262"/>
              <criterion comment="gnupg-agent is earlier than 2.0.9-3.1+lenny1" test_ref="oval:org.mitre.oval:tst:41523"/>
              <criterion comment="gnupg2 is earlier than 2.0.9-3.1+lenny1" test_ref="oval:org.mitre.oval:tst:41003"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11620" version="3" class="patch">
      <metadata>
        <title>DSA-2047 aria2 -- insufficient input sanitising</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <product>aria2</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2010/dsa-2047" ref_id="DSA-2047"/>
        <description>A vulnerability was discovered in aria2, a download client. The "name" attribute of the "file" element of metalink files is not properly sanitised before using it to download files. If a user is tricked into downloading from a specially crafted metalink file, this can be exploited to download files to directories outside of the intended download directory.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-31T15:50:51-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2010-08-03T12:18:43.380-04:00">DRAFT</status_change>
            <status_change date="2010-08-23T04:00:12.847-04:00">INTERIM</status_change>
            <status_change date="2010-09-13T04:00:13.945-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
        <criteria operator="OR" comment="Architecture section">
          <criteria operator="AND" comment="Architecture dependent section">
            <criteria operator="OR" comment="Supported architectures section">
              <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
              <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
              <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
              <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
              <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
              <criterion comment="Installed architecture is armel" test_ref="oval:org.mitre.oval:tst:11101"/>
              <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
              <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
              <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
              <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
              <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
              <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
            </criteria>
            <criteria operator="OR" comment="Packages section">
              <criterion comment="aria2 is earlier than 0.14.0-1+lenny2" test_ref="oval:org.mitre.oval:tst:41467"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11582" version="3" class="patch">
      <metadata>
        <title>DSA-2048 dvipng -- buffer overflow</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <product>dvipng</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2010/dsa-2048" ref_id="DSA-2048"/>
        <description>Dan Rosenberg discovered that in dvipng, a utility that converts DVI files to PNG graphics, several array index errors allow context-dependent attackers, via a specially crafted DVI file, to cause a denial of service , and possibly arbitrary code execution.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-31T15:50:51-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2010-08-03T12:18:43.721-04:00">DRAFT</status_change>
            <status_change date="2010-08-23T04:00:11.321-04:00">INTERIM</status_change>
            <status_change date="2010-09-13T04:00:12.619-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
        <criteria operator="OR" comment="Architecture section">
          <criteria operator="AND" comment="Architecture dependent section">
            <criteria operator="OR" comment="Supported architectures section">
              <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
              <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
              <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
              <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
              <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
              <criterion comment="Installed architecture is armel" test_ref="oval:org.mitre.oval:tst:11101"/>
              <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
              <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
              <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
              <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
            </criteria>
            <criteria operator="OR" comment="Packages section">
              <criterion comment="dvipng is earlier than 1.11-1+lenny1" test_ref="oval:org.mitre.oval:tst:41006"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11543" version="3" class="patch">
      <metadata>
        <title>DSA-2061 samba -- memory corruption</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <product>samba</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2010/dsa-2061" ref_id="DSA-2061"/>
        <description>Jun Mao discovered that Samba, an implementation of the SMB/CIFS protocol for Unix systems, is not properly handling certain offset values when processing chained SMB1 packets. This enables an unauthenticated attacker to write to an arbitrary memory location resulting in the possibility to execute arbitrary code with root privileges or to perform denial of service attacks by crashing the samba daemon.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-31T15:50:51-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2010-08-03T12:18:46.566-04:00">DRAFT</status_change>
            <status_change date="2010-08-23T04:00:09.596-04:00">INTERIM</status_change>
            <status_change date="2010-09-13T04:00:10.106-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
        <criteria operator="OR" comment="Architecture section">
          <criteria operator="AND" comment="Architecture independent section">
            <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
            <criteria operator="OR" comment="Packages section">
              <criterion comment="samba-doc is earlier than 3.2.5-4lenny12" test_ref="oval:org.mitre.oval:tst:41333"/>
              <criterion comment="samba-doc-pdf is earlier than 3.2.5-4lenny12" test_ref="oval:org.mitre.oval:tst:41076"/>
            </criteria>
          </criteria>
          <criteria operator="AND" comment="Architecture dependent section">
            <criteria operator="OR" comment="Supported architectures section">
              <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
              <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
              <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
              <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
              <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
              <criterion comment="Installed architecture is armel" test_ref="oval:org.mitre.oval:tst:11101"/>
              <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
              <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
              <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
              <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
              <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
              <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
            </criteria>
            <criteria operator="OR" comment="Packages section">
              <criterion comment="smbfs is earlier than 3.2.5-4lenny12" test_ref="oval:org.mitre.oval:tst:41359"/>
              <criterion comment="samba is earlier than 3.2.5-4lenny12" test_ref="oval:org.mitre.oval:tst:41010"/>
              <criterion comment="swat is earlier than 3.2.5-4lenny12" test_ref="oval:org.mitre.oval:tst:41396"/>
              <criterion comment="samba-tools is earlier than 3.2.5-4lenny12" test_ref="oval:org.mitre.oval:tst:41441"/>
              <criterion comment="libsmbclient is earlier than 3.2.5-4lenny12" test_ref="oval:org.mitre.oval:tst:41278"/>
              <criterion comment="smbclient is earlier than 3.2.5-4lenny12" test_ref="oval:org.mitre.oval:tst:41450"/>
              <criterion comment="libwbclient0 is earlier than 3.2.5-4lenny12" test_ref="oval:org.mitre.oval:tst:41345"/>
              <criterion comment="winbind is earlier than 3.2.5-4lenny12" test_ref="oval:org.mitre.oval:tst:41288"/>
              <criterion comment="libpam-smbpass is earlier than 3.2.5-4lenny12" test_ref="oval:org.mitre.oval:tst:41221"/>
              <criterion comment="libsmbclient-dev is earlier than 3.2.5-4lenny12" test_ref="oval:org.mitre.oval:tst:41145"/>
              <criterion comment="samba-common is earlier than 3.2.5-4lenny12" test_ref="oval:org.mitre.oval:tst:41094"/>
              <criterion comment="samba-dbg is earlier than 3.2.5-4lenny12" test_ref="oval:org.mitre.oval:tst:41521"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11531" version="3" class="patch">
      <metadata>
        <title>DSA-2075 xulrunner -- several vulnerabilities</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <product>xulrunner</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2010/dsa-2075" ref_id="DSA-2075"/>
        <description>Several remote vulnerabilities have been discovered in Xulrunner, a runtime environment for XUL applications. The Common Vulnerabilities and Exposures project identifies the following problems: Wladimir Palant discovered that security checks in XML processing were insufficiently enforced. Chris Evans discovered that insecure CSS handling could lead to reading data across domain boundaries. Aki Helin discovered a buffer overflow in the internal copy of libpng, which could lead to the execution of arbitrary code. "regenrecht" discovered that incorrect memory handling in DOM parsing could lead to the execution of arbitrary code. Jesse Ruderman, Ehsan Akhgari, Mats Palmgren, Igor Bukanov, Gary Kwong, Tobias Markus and Daniel Holbert discovered crashes in the layout engine, which might allow the execution of arbitrary code. "JS3" discovered an integer overflow in the plugin code, which could lead to the execution of arbitrary code. Jordi Chancel discovered that the location could be spoofed to appear like a secured page. "regenrecht" discovered that incorrect memory handling in XUL parsing could lead to the execution of arbitrary code. Soroush Dalili discovered an information leak in script processing.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-31T15:50:51-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2010-08-03T12:18:42.476-04:00">DRAFT</status_change>
            <status_change date="2010-08-23T04:00:08.933-04:00">INTERIM</status_change>
            <status_change date="2010-09-13T04:00:09.232-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
        <criteria operator="OR" comment="Architecture section">
          <criteria operator="AND" comment="Architecture independent section">
            <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
            <criterion comment="libmozillainterfaces-java is earlier than 1.9.0.19-3" test_ref="oval:org.mitre.oval:tst:40537"/>
          </criteria>
          <criteria operator="AND" comment="Architecture dependent section">
            <criteria operator="OR" comment="Supported architectures section">
              <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
              <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
              <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
              <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
              <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
              <criterion comment="Installed architecture is armel" test_ref="oval:org.mitre.oval:tst:11101"/>
              <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
              <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
              <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
              <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
              <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
              <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
            </criteria>
            <criteria operator="OR" comment="Packages section">
              <criterion comment="libmozjs-dev is earlier than 1.9.0.19-3" test_ref="oval:org.mitre.oval:tst:41310"/>
              <criterion comment="spidermonkey-bin is earlier than 1.9.0.19-3" test_ref="oval:org.mitre.oval:tst:41355"/>
              <criterion comment="xulrunner-dev is earlier than 1.9.0.19-3" test_ref="oval:org.mitre.oval:tst:41317"/>
              <criterion comment="xulrunner-1.9 is earlier than 1.9.0.19-3" test_ref="oval:org.mitre.oval:tst:41472"/>
              <criterion comment="libmozjs1d-dbg is earlier than 1.9.0.19-3" test_ref="oval:org.mitre.oval:tst:41258"/>
              <criterion comment="libmozjs1d is earlier than 1.9.0.19-3" test_ref="oval:org.mitre.oval:tst:41243"/>
              <criterion comment="python-xpcom is earlier than 1.9.0.19-3" test_ref="oval:org.mitre.oval:tst:41534"/>
              <criterion comment="xulrunner-1.9-dbg is earlier than 1.9.0.19-3" test_ref="oval:org.mitre.oval:tst:41380"/>
              <criterion comment="xulrunner-1.9-gnome-support is earlier than 1.9.0.19-3" test_ref="oval:org.mitre.oval:tst:41531"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11512" version="3" class="patch">
      <metadata>
        <title>DSA-2072 libpng -- several vulnerabilities</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <product>libpng</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2010/dsa-2072" ref_id="DSA-2072"/>
        <description>Several vulnerabilities have been discovered in libpng, a library for reading and writing PNG files. The Common Vulnerabilities and Exposures project identifies the following problems: It was discovered a buffer overflow in libpng which allows remote attackers to execute arbitrary code via a PNG image that triggers an additional data row. It was discovered a memory leak in libpng which allows remote attackers to cause a denial of service  via a PNG image containing malformed Physical Scale  chunks</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-31T15:50:51-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2010-08-03T12:18:39.937-04:00">DRAFT</status_change>
            <status_change date="2010-08-23T04:00:07.291-04:00">INTERIM</status_change>
            <status_change date="2010-09-13T04:00:07.712-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
        <criteria operator="OR" comment="Architecture section">
          <criteria operator="AND" comment="Architecture independent section">
            <criterion comment="Installed architecture is all" test_ref="oval:org.mitre.oval:tst:10881"/>
            <criterion comment="libpng3 is earlier than 1.2.27-2+lenny4" test_ref="oval:org.mitre.oval:tst:41468"/>
          </criteria>
          <criteria operator="AND" comment="Architecture dependent section">
            <criteria operator="OR" comment="Supported architectures section">
              <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
              <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
              <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
              <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
              <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
              <criterion comment="Installed architecture is armel" test_ref="oval:org.mitre.oval:tst:11101"/>
              <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
              <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
              <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
              <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
              <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
              <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
            </criteria>
            <criteria operator="OR" comment="Packages section">
              <criterion comment="libpng12-dev is earlier than 1.2.27-2+lenny4" test_ref="oval:org.mitre.oval:tst:40534"/>
              <criterion comment="libpng12-0 is earlier than 1.2.27-2+lenny4" test_ref="oval:org.mitre.oval:tst:40756"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11359" version="3" class="patch">
      <metadata>
        <title>DSA-2059 pcsc-lite -- buffer overflow</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <product>pcsc-lite</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2010/dsa-2059" ref_id="DSA-2059"/>
        <description>It was discovered that PCSCD, a daemon to access smart cards, was vulnerable to a buffer overflow allowing a local attacker to elevate his privileges to root.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-31T15:50:51-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2010-08-03T12:18:38.853-04:00">DRAFT</status_change>
            <status_change date="2010-08-23T04:00:05.708-04:00">INTERIM</status_change>
            <status_change date="2010-09-13T04:00:05.993-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
        <criteria operator="OR" comment="Architecture section">
          <criteria operator="AND" comment="Architecture dependent section">
            <criteria operator="OR" comment="Supported architectures section">
              <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
              <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
              <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
              <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
              <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
              <criterion comment="Installed architecture is armel" test_ref="oval:org.mitre.oval:tst:11101"/>
              <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
              <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
              <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
              <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
              <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
              <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
            </criteria>
            <criteria operator="OR" comment="Packages section">
              <criterion comment="libpcsclite1 is earlier than 1.4.102-1+lenny1" test_ref="oval:org.mitre.oval:tst:41394"/>
              <criterion comment="pcscd is earlier than 1.4.102-1+lenny1" test_ref="oval:org.mitre.oval:tst:41458"/>
              <criterion comment="libpcsclite-dev is earlier than 1.4.102-1+lenny1" test_ref="oval:org.mitre.oval:tst:40886"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:10970" version="3" class="patch">
      <metadata>
        <title>DSA-2066 wireshark -- several vulnerabilities</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
          <product>wireshark</product>
        </affected>
        <reference source="DSA" ref_url="http://www.debian.org/security/2010/dsa-2066" ref_id="DSA-2066"/>
        <description>Several remote vulnerabilities have been discovered in the Wireshark network traffic analyzer. It was discovered that null pointer dereferences, buffer overflows and infinite loops in the SMB, SMB PIPE, ASN1.1 and SigComp dissectors could lead to denial of service or the execution of arbitrary code.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-31T15:50:52-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2010-08-03T12:18:49.693-04:00">DRAFT</status_change>
            <status_change date="2010-08-23T04:00:03.677-04:00">INTERIM</status_change>
            <status_change date="2010-09-13T04:00:02.849-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Debian 5.0 is installed" definition_ref="oval:org.mitre.oval:def:6513"/>
        <criteria operator="OR" comment="Architecture section">
          <criteria operator="AND" comment="Architecture dependent section">
            <criteria operator="OR" comment="Supported architectures section">
              <criterion comment="Installed architecture is s390" test_ref="oval:org.mitre.oval:tst:11024"/>
              <criterion comment="Installed architecture is amd64" test_ref="oval:org.mitre.oval:tst:10392"/>
              <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
              <criterion comment="Installed architecture is arm" test_ref="oval:org.mitre.oval:tst:10933"/>
              <criterion comment="Installed architecture is i386" test_ref="oval:org.mitre.oval:tst:10864"/>
              <criterion comment="Installed architecture is armel" test_ref="oval:org.mitre.oval:tst:11101"/>
              <criterion comment="Installed architecture is mips" test_ref="oval:org.mitre.oval:tst:11195"/>
              <criterion comment="Installed architecture is ia64" test_ref="oval:org.mitre.oval:tst:10830"/>
              <criterion comment="Installed architecture is alpha" test_ref="oval:org.mitre.oval:tst:10654"/>
              <criterion comment="Installed architecture is powerpc" test_ref="oval:org.mitre.oval:tst:11168"/>
              <criterion comment="Installed architecture is mipsel" test_ref="oval:org.mitre.oval:tst:11110"/>
              <criterion comment="Installed architecture is hppa" test_ref="oval:org.mitre.oval:tst:11164"/>
            </criteria>
            <criteria operator="OR" comment="Packages section">
              <criterion comment="wireshark-dev is earlier than 1.0.2-3+lenny9" test_ref="oval:org.mitre.oval:tst:41298"/>
              <criterion comment="wireshark-common is earlier than 1.0.2-3+lenny9" test_ref="oval:org.mitre.oval:tst:40820"/>
              <criterion comment="tshark is earlier than 1.0.2-3+lenny9" test_ref="oval:org.mitre.oval:tst:40763"/>
              <criterion comment="wireshark is earlier than 1.0.2-3+lenny9" test_ref="oval:org.mitre.oval:tst:41231"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6513" version="5" class="inventory">
      <metadata>
        <title>Debian 5.0 is installed</title>
        <affected family="unix">
          <platform>Debian GNU/Linux 5.0</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/o:debian:debian_linux:5.0"/>
        <description>Debian 5.0 is installed</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-04T16:44:51-05:00">
              <contributor organization="SecPod Technologies">SecPod Team</contributor>
            </submitted>
            <status_change date="2009-12-06T20:14:46.813-05:00">DRAFT</status_change>
            <status_change date="2010-01-04T04:01:52.112-05:00">INTERIM</status_change>
            <status_change date="2010-01-25T04:00:22.163-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6513 - Update textfilecontent_test to textfilecontent54_test" date="2011-01-20T13:45:00.069-05:00">
              <contributor organization="SecPod Technologies">Preeti Subramanian</contributor>
            </modified>
            <status_change date="2011-01-20T13:46:58.156-05:00">INTERIM</status_change>
            <status_change date="2011-02-07T04:00:15.513-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:12238 - Pattern match updated &amp; used subexpression in textfilecontent54_state for all states" date="2011-10-21T10:10:00.778-04:00">
              <contributor organization="SecPod Technologies">Chandan S</contributor>
            </modified>
            <status_change date="2011-10-21T10:13:35.218-04:00">INTERIM</status_change>
            <status_change date="2011-11-07T04:01:06.197-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="Debian GNU/Linux 5.0 is installed" test_ref="oval:org.mitre.oval:tst:42061"/>
      </criteria>
    </definition>
  </definitions>
  <tests>
    <dpkginfo_test comment="squirrelmail is earlier than 1.4.15-4+lenny2" check="all" version="1" id="oval:org.mitre.oval:tst:20530" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11639"/>
      <state state_ref="oval:org.mitre.oval:ste:6179"/>
    </dpkginfo_test>
    <dpkginfo_test comment="squirrelmail is earlier than 1.4.9a-5" check="all" version="1" id="oval:org.mitre.oval:tst:20305" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11639"/>
      <state state_ref="oval:org.mitre.oval:ste:6116"/>
    </dpkginfo_test>
    <dpkginfo_test comment="libicu-dev is earlier than 3.8.1-3+lenny1" check="all" version="1" id="oval:org.mitre.oval:tst:20455" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:8785"/>
      <state state_ref="oval:org.mitre.oval:ste:5958"/>
    </dpkginfo_test>
    <dpkginfo_test comment="lib32icu38 is earlier than 3.8.1-3+lenny1" check="all" version="1" id="oval:org.mitre.oval:tst:20426" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:8673"/>
      <state state_ref="oval:org.mitre.oval:ste:5958"/>
    </dpkginfo_test>
    <dpkginfo_test comment="lib32icu-dev is earlier than 3.8.1-3+lenny1" check="all" version="1" id="oval:org.mitre.oval:tst:20422" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:8654"/>
      <state state_ref="oval:org.mitre.oval:ste:5958"/>
    </dpkginfo_test>
    <dpkginfo_test comment="icu-doc is earlier than 3.8.1-3+lenny1" check="all" version="1" id="oval:org.mitre.oval:tst:20386" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:8772"/>
      <state state_ref="oval:org.mitre.oval:ste:5958"/>
    </dpkginfo_test>
    <dpkginfo_test comment="libicu38-dbg is earlier than 3.8.1-3+lenny1" check="all" version="1" id="oval:org.mitre.oval:tst:20268" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:7880"/>
      <state state_ref="oval:org.mitre.oval:ste:5958"/>
    </dpkginfo_test>
    <dpkginfo_test comment="icu-doc is earlier than 3.6-2etch2" check="all" version="1" id="oval:org.mitre.oval:tst:20067" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:8772"/>
      <state state_ref="oval:org.mitre.oval:ste:6263"/>
    </dpkginfo_test>
    <dpkginfo_test comment="libicu36-dev is earlier than 3.6-2etch2" check="all" version="1" id="oval:org.mitre.oval:tst:20050" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:8802"/>
      <state state_ref="oval:org.mitre.oval:ste:6263"/>
    </dpkginfo_test>
    <dpkginfo_test comment="libicu36 is earlier than 3.6-2etch2" check="all" version="1" id="oval:org.mitre.oval:tst:19727" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:8067"/>
      <state state_ref="oval:org.mitre.oval:ste:6263"/>
    </dpkginfo_test>
    <dpkginfo_test comment="libicu38 is earlier than 3.8.1-3+lenny1" check="all" version="1" id="oval:org.mitre.oval:tst:19463" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:8242"/>
      <state state_ref="oval:org.mitre.oval:ste:5958"/>
    </dpkginfo_test>
    <dpkginfo_test comment="dovecot-dev is earlier than 1.0.15-2.3+lenny1" check="all" version="1" id="oval:org.mitre.oval:tst:20214" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11859"/>
      <state state_ref="oval:org.mitre.oval:ste:6446"/>
    </dpkginfo_test>
    <dpkginfo_test comment="dovecot-imapd is earlier than 1.0.rc15-2etch5" check="all" version="1" id="oval:org.mitre.oval:tst:20210" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11464"/>
      <state state_ref="oval:org.mitre.oval:ste:6390"/>
    </dpkginfo_test>
    <dpkginfo_test comment="dovecot-pop3d is earlier than 1.0.15-2.3+lenny1" check="all" version="1" id="oval:org.mitre.oval:tst:20162" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11468"/>
      <state state_ref="oval:org.mitre.oval:ste:6446"/>
    </dpkginfo_test>
    <dpkginfo_test comment="dovecot-pop3d is earlier than 1.0.rc15-2etch5" check="all" version="1" id="oval:org.mitre.oval:tst:20136" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11468"/>
      <state state_ref="oval:org.mitre.oval:ste:6390"/>
    </dpkginfo_test>
    <dpkginfo_test comment="dovecot-imapd is earlier than 1.0.15-2.3+lenny1" check="all" version="1" id="oval:org.mitre.oval:tst:20133" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11464"/>
      <state state_ref="oval:org.mitre.oval:ste:6446"/>
    </dpkginfo_test>
    <dpkginfo_test comment="dovecot-common is earlier than 1.0.rc15-2etch5" check="all" version="1" id="oval:org.mitre.oval:tst:19805" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11337"/>
      <state state_ref="oval:org.mitre.oval:ste:6390"/>
    </dpkginfo_test>
    <dpkginfo_test comment="dovecot-common is earlier than 1.0.15-2.3+lenny1" check="all" version="1" id="oval:org.mitre.oval:tst:19778" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11337"/>
      <state state_ref="oval:org.mitre.oval:ste:6446"/>
    </dpkginfo_test>
    <dpkginfo_test comment="libopensc2-dbg is earlier than 0.11.4-5+lenny1" check="all" version="1" id="oval:org.mitre.oval:tst:19635" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:8618"/>
      <state state_ref="oval:org.mitre.oval:ste:6440"/>
    </dpkginfo_test>
    <dpkginfo_test comment="libopensc2-dev is earlier than 0.11.4-5+lenny1" check="all" version="1" id="oval:org.mitre.oval:tst:19505" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:8465"/>
      <state state_ref="oval:org.mitre.oval:ste:6440"/>
    </dpkginfo_test>
    <dpkginfo_test comment="opensc is earlier than 0.11.4-5+lenny1" check="all" version="1" id="oval:org.mitre.oval:tst:19501" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:8302"/>
      <state state_ref="oval:org.mitre.oval:ste:6440"/>
    </dpkginfo_test>
    <dpkginfo_test comment="libopensc2 is earlier than 0.11.4-5+lenny1" check="all" version="1" id="oval:org.mitre.oval:tst:19122" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:8580"/>
      <state state_ref="oval:org.mitre.oval:ste:6440"/>
    </dpkginfo_test>
    <dpkginfo_test comment="mozilla-opensc is earlier than 0.11.4-5+lenny1" check="all" version="1" id="oval:org.mitre.oval:tst:18934" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:8393"/>
      <state state_ref="oval:org.mitre.oval:ste:6440"/>
    </dpkginfo_test>
    <dpkginfo_test comment="linux-headers-2.6.26-1-common is earlier than 2.6.26-13lenny2" check="all" version="1" id="oval:org.mitre.oval:tst:20086" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11620"/>
      <state state_ref="oval:org.mitre.oval:ste:5813"/>
    </dpkginfo_test>
    <dpkginfo_test comment="linux-headers-2.6.26-1-parisc is earlier than 2.6.26-13lenny2" check="all" version="1" id="oval:org.mitre.oval:tst:20081" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11685"/>
      <state state_ref="oval:org.mitre.oval:ste:5813"/>
    </dpkginfo_test>
    <dpkginfo_test comment="linux-headers-2.6.26-1-all-hppa is earlier than 2.6.26-13lenny2" check="all" version="1" id="oval:org.mitre.oval:tst:19978" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11704"/>
      <state state_ref="oval:org.mitre.oval:ste:5813"/>
    </dpkginfo_test>
    <dpkginfo_test comment="linux-image-2.6.26-1-parisc64 is earlier than 2.6.26-13lenny2" check="all" version="1" id="oval:org.mitre.oval:tst:19969" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11778"/>
      <state state_ref="oval:org.mitre.oval:ste:5813"/>
    </dpkginfo_test>
    <dpkginfo_test comment="linux-headers-2.6.26-1-parisc64-smp is earlier than 2.6.26-13lenny2" check="all" version="1" id="oval:org.mitre.oval:tst:19964" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11757"/>
      <state state_ref="oval:org.mitre.oval:ste:5813"/>
    </dpkginfo_test>
    <dpkginfo_test comment="linux-image-2.6.26-1-openvz-amd64 is earlier than 2.6.26-13lenny2" check="all" version="1" id="oval:org.mitre.oval:tst:19936" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11145"/>
      <state state_ref="oval:org.mitre.oval:ste:5813"/>
    </dpkginfo_test>
    <dpkginfo_test comment="linux-image-2.6.26-1-parisc-smp is earlier than 2.6.26-13lenny2" check="all" version="1" id="oval:org.mitre.oval:tst:19931" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11741"/>
      <state state_ref="oval:org.mitre.oval:ste:5813"/>
    </dpkginfo_test>
    <dpkginfo_test comment="linux-headers-2.6.26-1-vserver-amd64 is earlier than 2.6.26-13lenny2" check="all" version="1" id="oval:org.mitre.oval:tst:19916" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11686"/>
      <state state_ref="oval:org.mitre.oval:ste:5813"/>
    </dpkginfo_test>
    <dpkginfo_test comment="linux-headers-2.6.26-1-amd64 is earlier than 2.6.26-13lenny2" check="all" version="1" id="oval:org.mitre.oval:tst:19911" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11622"/>
      <state state_ref="oval:org.mitre.oval:ste:5813"/>
    </dpkginfo_test>
    <dpkginfo_test comment="linux-support-2.6.26-1 is earlier than 2.6.26-13lenny2" check="all" version="1" id="oval:org.mitre.oval:tst:19910" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11667"/>
      <state state_ref="oval:org.mitre.oval:ste:5813"/>
    </dpkginfo_test>
    <dpkginfo_test comment="linux-source-2.6.26 is earlier than 2.6.26-13lenny2" check="all" version="1" id="oval:org.mitre.oval:tst:19907" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:8224"/>
      <state state_ref="oval:org.mitre.oval:ste:5813"/>
    </dpkginfo_test>
    <dpkginfo_test comment="linux-headers-2.6.26-1-s390x is earlier than 2.6.26-13lenny2" check="all" version="1" id="oval:org.mitre.oval:tst:19894" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11664"/>
      <state state_ref="oval:org.mitre.oval:ste:5813"/>
    </dpkginfo_test>
    <dpkginfo_test comment="linux-image-2.6.26-1-parisc64-smp is earlier than 2.6.26-13lenny2" check="all" version="1" id="oval:org.mitre.oval:tst:19888" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11755"/>
      <state state_ref="oval:org.mitre.oval:ste:5813"/>
    </dpkginfo_test>
    <dpkginfo_test comment="linux-libc-dev is earlier than 2.6.26-13lenny2" check="all" version="1" id="oval:org.mitre.oval:tst:19886" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:7932"/>
      <state state_ref="oval:org.mitre.oval:ste:5813"/>
    </dpkginfo_test>
    <dpkginfo_test comment="xen-linux-system-2.6.26-1-xen-amd64 is earlier than 2.6.26-13lenny2" check="all" version="1" id="oval:org.mitre.oval:tst:19882" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11355"/>
      <state state_ref="oval:org.mitre.oval:ste:5813"/>
    </dpkginfo_test>
    <dpkginfo_test comment="linux-tree-2.6.26 is earlier than 2.6.26-13lenny2" check="all" version="1" id="oval:org.mitre.oval:tst:19875" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:7896"/>
      <state state_ref="oval:org.mitre.oval:ste:5813"/>
    </dpkginfo_test>
    <dpkginfo_test comment="linux-headers-2.6.26-1-vserver-s390x is earlier than 2.6.26-13lenny2" check="all" version="1" id="oval:org.mitre.oval:tst:19872" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11712"/>
      <state state_ref="oval:org.mitre.oval:ste:5813"/>
    </dpkginfo_test>
    <dpkginfo_test comment="linux-headers-2.6.26-1-all is earlier than 2.6.26-13lenny2" check="all" version="1" id="oval:org.mitre.oval:tst:19865" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11571"/>
      <state state_ref="oval:org.mitre.oval:ste:5813"/>
    </dpkginfo_test>
    <dpkginfo_test comment="linux-image-2.6.26-1-vserver-amd64 is earlier than 2.6.26-13lenny2" check="all" version="1" id="oval:org.mitre.oval:tst:19861" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11443"/>
      <state state_ref="oval:org.mitre.oval:ste:5813"/>
    </dpkginfo_test>
    <dpkginfo_test comment="linux-image-2.6.26-1-s390 is earlier than 2.6.26-13lenny2" check="all" version="1" id="oval:org.mitre.oval:tst:19858" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11691"/>
      <state state_ref="oval:org.mitre.oval:ste:5813"/>
    </dpkginfo_test>
    <dpkginfo_test comment="linux-headers-2.6.26-1-parisc64 is earlier than 2.6.26-13lenny2" check="all" version="1" id="oval:org.mitre.oval:tst:19857" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11598"/>
      <state state_ref="oval:org.mitre.oval:ste:5813"/>
    </dpkginfo_test>
    <dpkginfo_test comment="linux-image-2.6.26-1-s390x is earlier than 2.6.26-13lenny2" check="all" version="1" id="oval:org.mitre.oval:tst:19851" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11452"/>
      <state state_ref="oval:org.mitre.oval:ste:5813"/>
    </dpkginfo_test>
    <dpkginfo_test comment="linux-headers-2.6.26-1-all is earlier than 2.6.26-13lenny2" check="all" version="1" id="oval:org.mitre.oval:tst:19849" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11571"/>
      <state state_ref="oval:org.mitre.oval:ste:5813"/>
    </dpkginfo_test>
    <dpkginfo_test comment="linux-headers-2.6.26-1-s390 is earlier than 2.6.26-13lenny2" check="all" version="1" id="oval:org.mitre.oval:tst:19827" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11278"/>
      <state state_ref="oval:org.mitre.oval:ste:5813"/>
    </dpkginfo_test>
    <dpkginfo_test comment="linux-image-2.6.26-1-amd64 is earlier than 2.6.26-13lenny2" check="all" version="1" id="oval:org.mitre.oval:tst:19809" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11119"/>
      <state state_ref="oval:org.mitre.oval:ste:5813"/>
    </dpkginfo_test>
    <dpkginfo_test comment="linux-headers-2.6.26-1-common-openvz is earlier than 2.6.26-13lenny2" check="all" version="1" id="oval:org.mitre.oval:tst:19807" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11617"/>
      <state state_ref="oval:org.mitre.oval:ste:5813"/>
    </dpkginfo_test>
    <dpkginfo_test comment="linux-image-2.6.26-1-xen-amd64 is earlier than 2.6.26-13lenny2" check="all" version="1" id="oval:org.mitre.oval:tst:19794" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11589"/>
      <state state_ref="oval:org.mitre.oval:ste:5813"/>
    </dpkginfo_test>
    <dpkginfo_test comment="linux-headers-2.6.26-1-all-amd64 is earlier than 2.6.26-13lenny2" check="all" version="1" id="oval:org.mitre.oval:tst:19763" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11660"/>
      <state state_ref="oval:org.mitre.oval:ste:5813"/>
    </dpkginfo_test>
    <dpkginfo_test comment="linux-headers-2.6.26-1-parisc-smp is earlier than 2.6.26-13lenny2" check="all" version="1" id="oval:org.mitre.oval:tst:19760" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11797"/>
      <state state_ref="oval:org.mitre.oval:ste:5813"/>
    </dpkginfo_test>
    <dpkginfo_test comment="linux-headers-2.6.26-1-openvz-amd64 is earlier than 2.6.26-13lenny2" check="all" version="1" id="oval:org.mitre.oval:tst:19745" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11444"/>
      <state state_ref="oval:org.mitre.oval:ste:5813"/>
    </dpkginfo_test>
    <dpkginfo_test comment="linux-headers-2.6.26-1-all is earlier than 2.6.26-13lenny2" check="all" version="1" id="oval:org.mitre.oval:tst:19734" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11571"/>
      <state state_ref="oval:org.mitre.oval:ste:5813"/>
    </dpkginfo_test>
    <dpkginfo_test comment="linux-image-2.6.26-1-parisc is earlier than 2.6.26-13lenny2" check="all" version="1" id="oval:org.mitre.oval:tst:19707" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11517"/>
      <state state_ref="oval:org.mitre.oval:ste:5813"/>
    </dpkginfo_test>
    <dpkginfo_test comment="linux-headers-2.6.26-1-all-s390 is earlier than 2.6.26-13lenny2" check="all" version="1" id="oval:org.mitre.oval:tst:19704" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11549"/>
      <state state_ref="oval:org.mitre.oval:ste:5813"/>
    </dpkginfo_test>
    <dpkginfo_test comment="linux-image-2.6.26-1-s390-tape is earlier than 2.6.26-13lenny2" check="all" version="1" id="oval:org.mitre.oval:tst:19688" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11695"/>
      <state state_ref="oval:org.mitre.oval:ste:5813"/>
    </dpkginfo_test>
    <dpkginfo_test comment="linux-libc-dev is earlier than 2.6.26-13lenny2" check="all" version="1" id="oval:org.mitre.oval:tst:19667" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:7932"/>
      <state state_ref="oval:org.mitre.oval:ste:5813"/>
    </dpkginfo_test>
    <dpkginfo_test comment="linux-headers-2.6.26-1-common is earlier than 2.6.26-13lenny2" check="all" version="1" id="oval:org.mitre.oval:tst:19663" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11620"/>
      <state state_ref="oval:org.mitre.oval:ste:5813"/>
    </dpkginfo_test>
    <dpkginfo_test comment="linux-headers-2.6.26-1-xen-amd64 is earlier than 2.6.26-13lenny2" check="all" version="1" id="oval:org.mitre.oval:tst:19585" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11635"/>
      <state state_ref="oval:org.mitre.oval:ste:5813"/>
    </dpkginfo_test>
    <dpkginfo_test comment="linux-libc-dev is earlier than 2.6.26-13lenny2" check="all" version="1" id="oval:org.mitre.oval:tst:19515" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:7932"/>
      <state state_ref="oval:org.mitre.oval:ste:5813"/>
    </dpkginfo_test>
    <dpkginfo_test comment="linux-headers-2.6.26-1-common-vserver is earlier than 2.6.26-13lenny2" check="all" version="1" id="oval:org.mitre.oval:tst:19442" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:10947"/>
      <state state_ref="oval:org.mitre.oval:ste:5813"/>
    </dpkginfo_test>
    <dpkginfo_test comment="linux-image-2.6.26-1-vserver-s390x is earlier than 2.6.26-13lenny2" check="all" version="1" id="oval:org.mitre.oval:tst:19422" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11124"/>
      <state state_ref="oval:org.mitre.oval:ste:5813"/>
    </dpkginfo_test>
    <dpkginfo_test comment="linux-doc-2.6.26 is earlier than 2.6.26-13lenny2" check="all" version="1" id="oval:org.mitre.oval:tst:19400" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:8320"/>
      <state state_ref="oval:org.mitre.oval:ste:5813"/>
    </dpkginfo_test>
    <dpkginfo_test comment="linux-modules-2.6.26-1-xen-amd64 is earlier than 2.6.26-13lenny2" check="all" version="1" id="oval:org.mitre.oval:tst:19389" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11701"/>
      <state state_ref="oval:org.mitre.oval:ste:5813"/>
    </dpkginfo_test>
    <dpkginfo_test comment="linux-headers-2.6.26-1-common-xen is earlier than 2.6.26-13lenny2" check="all" version="1" id="oval:org.mitre.oval:tst:19157" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11204"/>
      <state state_ref="oval:org.mitre.oval:ste:5813"/>
    </dpkginfo_test>
    <dpkginfo_test comment="linux-headers-2.6.26-1-common-vserver is earlier than 2.6.26-13lenny2" check="all" version="1" id="oval:org.mitre.oval:tst:19149" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:10947"/>
      <state state_ref="oval:org.mitre.oval:ste:5813"/>
    </dpkginfo_test>
    <dpkginfo_test comment="linux-manual-2.6.26 is earlier than 2.6.26-13lenny2" check="all" version="1" id="oval:org.mitre.oval:tst:19029" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:8217"/>
      <state state_ref="oval:org.mitre.oval:ste:5813"/>
    </dpkginfo_test>
    <dpkginfo_test comment="linux-patch-debian-2.6.26 is earlier than 2.6.26-13lenny2" check="all" version="1" id="oval:org.mitre.oval:tst:19025" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:7796"/>
      <state state_ref="oval:org.mitre.oval:ste:5813"/>
    </dpkginfo_test>
    <dpkginfo_test comment="linux-headers-2.6.26-1-common is earlier than 2.6.26-13lenny2" check="all" version="1" id="oval:org.mitre.oval:tst:18980" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11620"/>
      <state state_ref="oval:org.mitre.oval:ste:5813"/>
    </dpkginfo_test>
    <dpkginfo_test comment="mahara is earlier than 1.0.4-4+lenny1" check="all" version="1" id="oval:org.mitre.oval:tst:19440" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11453"/>
      <state state_ref="oval:org.mitre.oval:ste:5634"/>
    </dpkginfo_test>
    <dpkginfo_test comment="mahara-apache2 is earlier than 1.0.4-4+lenny1" check="all" version="1" id="oval:org.mitre.oval:tst:18975" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11385"/>
      <state state_ref="oval:org.mitre.oval:ste:5634"/>
    </dpkginfo_test>
    <dpkginfo_test comment="wesnoth-editor is earlier than 1.2-5" check="all" version="1" id="oval:org.mitre.oval:tst:19710" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11544"/>
      <state state_ref="oval:org.mitre.oval:ste:5997"/>
    </dpkginfo_test>
    <dpkginfo_test comment="wesnoth is earlier than 1.4.4-2+lenny1" check="all" version="1" id="oval:org.mitre.oval:tst:19693" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11343"/>
      <state state_ref="oval:org.mitre.oval:ste:6380"/>
    </dpkginfo_test>
    <dpkginfo_test comment="wesnoth-utbs is earlier than 1.4.4-2+lenny1" check="all" version="1" id="oval:org.mitre.oval:tst:19691" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11147"/>
      <state state_ref="oval:org.mitre.oval:ste:6380"/>
    </dpkginfo_test>
    <dpkginfo_test comment="wesnoth-server is earlier than 1.4.4-2+lenny1" check="all" version="1" id="oval:org.mitre.oval:tst:19684" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11196"/>
      <state state_ref="oval:org.mitre.oval:ste:6380"/>
    </dpkginfo_test>
    <dpkginfo_test comment="wesnoth-all is earlier than 1.4.4-2+lenny1" check="all" version="1" id="oval:org.mitre.oval:tst:19658" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11532"/>
      <state state_ref="oval:org.mitre.oval:ste:6380"/>
    </dpkginfo_test>
    <dpkginfo_test comment="wesnoth-sof is earlier than 1.4.4-2+lenny1" check="all" version="1" id="oval:org.mitre.oval:tst:19647" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11605"/>
      <state state_ref="oval:org.mitre.oval:ste:6380"/>
    </dpkginfo_test>
    <dpkginfo_test comment="wesnoth-sotbe is earlier than 1.4.4-2+lenny1" check="all" version="1" id="oval:org.mitre.oval:tst:19644" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11707"/>
      <state state_ref="oval:org.mitre.oval:ste:6380"/>
    </dpkginfo_test>
    <dpkginfo_test comment="wesnoth-tsg is earlier than 1.4.4-2+lenny1" check="all" version="1" id="oval:org.mitre.oval:tst:19642" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11705"/>
      <state state_ref="oval:org.mitre.oval:ste:6380"/>
    </dpkginfo_test>
    <dpkginfo_test comment="wesnoth-data is earlier than 1.2-5" check="all" version="1" id="oval:org.mitre.oval:tst:19639" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11541"/>
      <state state_ref="oval:org.mitre.oval:ste:5997"/>
    </dpkginfo_test>
    <dpkginfo_test comment="wesnoth-httt is earlier than 1.4.4-2+lenny1" check="all" version="1" id="oval:org.mitre.oval:tst:19623" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11436"/>
      <state state_ref="oval:org.mitre.oval:ste:6380"/>
    </dpkginfo_test>
    <dpkginfo_test comment="wesnoth-l is earlier than 1.4.4-2+lenny1" check="all" version="1" id="oval:org.mitre.oval:tst:19621" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11677"/>
      <state state_ref="oval:org.mitre.oval:ste:6380"/>
    </dpkginfo_test>
    <dpkginfo_test comment="wesnoth-trow is earlier than 1.2-5" check="all" version="1" id="oval:org.mitre.oval:tst:19610" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11285"/>
      <state state_ref="oval:org.mitre.oval:ste:5997"/>
    </dpkginfo_test>
    <dpkginfo_test comment="wesnoth-dbg is earlier than 1.4.4-2+lenny1" check="all" version="1" id="oval:org.mitre.oval:tst:19609" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11696"/>
      <state state_ref="oval:org.mitre.oval:ste:6380"/>
    </dpkginfo_test>
    <dpkginfo_test comment="wesnoth-aoi is earlier than 1.4.4-2+lenny1" check="all" version="1" id="oval:org.mitre.oval:tst:19599" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11351"/>
      <state state_ref="oval:org.mitre.oval:ste:6380"/>
    </dpkginfo_test>
    <dpkginfo_test comment="wesnoth-did is earlier than 1.4.4-2+lenny1" check="all" version="1" id="oval:org.mitre.oval:tst:19593" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11611"/>
      <state state_ref="oval:org.mitre.oval:ste:6380"/>
    </dpkginfo_test>
    <dpkginfo_test comment="wesnoth-editor is earlier than 1.4.4-2+lenny1" check="all" version="1" id="oval:org.mitre.oval:tst:19589" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11544"/>
      <state state_ref="oval:org.mitre.oval:ste:6380"/>
    </dpkginfo_test>
    <dpkginfo_test comment="wesnoth-trow is earlier than 1.4.4-2+lenny1" check="all" version="1" id="oval:org.mitre.oval:tst:19580" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11285"/>
      <state state_ref="oval:org.mitre.oval:ste:6380"/>
    </dpkginfo_test>
    <dpkginfo_test comment="wesnoth-music is earlier than 1.2-5" check="all" version="1" id="oval:org.mitre.oval:tst:19552" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11573"/>
      <state state_ref="oval:org.mitre.oval:ste:5997"/>
    </dpkginfo_test>
    <dpkginfo_test comment="wesnoth-httt is earlier than 1.2-5" check="all" version="1" id="oval:org.mitre.oval:tst:19496" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11436"/>
      <state state_ref="oval:org.mitre.oval:ste:5997"/>
    </dpkginfo_test>
    <dpkginfo_test comment="wesnoth-utbs is earlier than 1.2-5" check="all" version="1" id="oval:org.mitre.oval:tst:19280" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11147"/>
      <state state_ref="oval:org.mitre.oval:ste:5997"/>
    </dpkginfo_test>
    <dpkginfo_test comment="wesnoth-server is earlier than 1.2-5" check="all" version="1" id="oval:org.mitre.oval:tst:19262" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11196"/>
      <state state_ref="oval:org.mitre.oval:ste:5997"/>
    </dpkginfo_test>
    <dpkginfo_test comment="wesnoth-tools is earlier than 1.4.4-2+lenny1" check="all" version="1" id="oval:org.mitre.oval:tst:19254" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11332"/>
      <state state_ref="oval:org.mitre.oval:ste:6380"/>
    </dpkginfo_test>
    <dpkginfo_test comment="wesnoth-nr is earlier than 1.4.4-2+lenny1" check="all" version="1" id="oval:org.mitre.oval:tst:19252" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11692"/>
      <state state_ref="oval:org.mitre.oval:ste:6380"/>
    </dpkginfo_test>
    <dpkginfo_test comment="wesnoth-data is earlier than 1.4.4-2+lenny1" check="all" version="1" id="oval:org.mitre.oval:tst:19180" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11541"/>
      <state state_ref="oval:org.mitre.oval:ste:6380"/>
    </dpkginfo_test>
    <dpkginfo_test comment="wesnoth-ei is earlier than 1.2-5" check="all" version="1" id="oval:org.mitre.oval:tst:19105" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11129"/>
      <state state_ref="oval:org.mitre.oval:ste:5997"/>
    </dpkginfo_test>
    <dpkginfo_test comment="wesnoth-music is earlier than 1.4.4-2+lenny1" check="all" version="1" id="oval:org.mitre.oval:tst:19102" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11573"/>
      <state state_ref="oval:org.mitre.oval:ste:6380"/>
    </dpkginfo_test>
    <dpkginfo_test comment="wesnoth is earlier than 1.2-5" check="all" version="1" id="oval:org.mitre.oval:tst:19011" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11343"/>
      <state state_ref="oval:org.mitre.oval:ste:5997"/>
    </dpkginfo_test>
    <dpkginfo_test comment="wesnoth-ttb is earlier than 1.2-5" check="all" version="1" id="oval:org.mitre.oval:tst:18990" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:10778"/>
      <state state_ref="oval:org.mitre.oval:ste:5997"/>
    </dpkginfo_test>
    <dpkginfo_test comment="wesnoth-tsg is earlier than 1.2-5" check="all" version="1" id="oval:org.mitre.oval:tst:18938" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11705"/>
      <state state_ref="oval:org.mitre.oval:ste:5997"/>
    </dpkginfo_test>
    <dpkginfo_test comment="wesnoth-ttb is earlier than 1.4.4-2+lenny1" check="all" version="1" id="oval:org.mitre.oval:tst:18852" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:10778"/>
      <state state_ref="oval:org.mitre.oval:ste:6380"/>
    </dpkginfo_test>
    <dpkginfo_test comment="wesnoth-ei is earlier than 1.4.4-2+lenny1" check="all" version="1" id="oval:org.mitre.oval:tst:18711" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11129"/>
      <state state_ref="oval:org.mitre.oval:ste:6380"/>
    </dpkginfo_test>
    <dpkginfo_test comment="wesnoth-thot is earlier than 1.4.4-2+lenny1" check="all" version="1" id="oval:org.mitre.oval:tst:18684" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11426"/>
      <state state_ref="oval:org.mitre.oval:ste:6380"/>
    </dpkginfo_test>
    <dpkginfo_test comment="openswan is earlier than 2.4.12+dfsg-1.3+lenny2" check="all" version="1" id="oval:org.mitre.oval:tst:19979" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11118"/>
      <state state_ref="oval:org.mitre.oval:ste:5581"/>
    </dpkginfo_test>
    <dpkginfo_test comment="linux-patch-openswan is earlier than 2.4.6+dfsg.2-1.1+etch2" check="all" version="1" id="oval:org.mitre.oval:tst:19963" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11201"/>
      <state state_ref="oval:org.mitre.oval:ste:6542"/>
    </dpkginfo_test>
    <dpkginfo_test comment="linux-patch-openswan is earlier than 2.4.12+dfsg-1.3+lenny2" check="all" version="1" id="oval:org.mitre.oval:tst:19959" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11201"/>
      <state state_ref="oval:org.mitre.oval:ste:5581"/>
    </dpkginfo_test>
    <dpkginfo_test comment="openswan-modules-source is earlier than 2.4.12+dfsg-1.3+lenny2" check="all" version="1" id="oval:org.mitre.oval:tst:19789" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11053"/>
      <state state_ref="oval:org.mitre.oval:ste:5581"/>
    </dpkginfo_test>
    <dpkginfo_test comment="openswan-modules-source is earlier than 2.4.6+dfsg.2-1.1+etch2" check="all" version="1" id="oval:org.mitre.oval:tst:19531" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11053"/>
      <state state_ref="oval:org.mitre.oval:ste:6542"/>
    </dpkginfo_test>
    <dpkginfo_test comment="openswan is earlier than 2.4.6+dfsg.2-1.1+etch2" check="all" version="1" id="oval:org.mitre.oval:tst:19100" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11118"/>
      <state state_ref="oval:org.mitre.oval:ste:6542"/>
    </dpkginfo_test>
    <dpkginfo_test comment="libxmltooling-doc is earlier than 1.0-2+lenny1" check="all" version="1" id="oval:org.mitre.oval:tst:20173" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11465"/>
      <state state_ref="oval:org.mitre.oval:ste:6370"/>
    </dpkginfo_test>
    <dpkginfo_test comment="libxmltooling-dev is earlier than 1.0-2+lenny1" check="all" version="1" id="oval:org.mitre.oval:tst:20154" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11559"/>
      <state state_ref="oval:org.mitre.oval:ste:6370"/>
    </dpkginfo_test>
    <dpkginfo_test comment="libxmltooling1 is earlier than 1.0-2+lenny1" check="all" version="1" id="oval:org.mitre.oval:tst:19846" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11728"/>
      <state state_ref="oval:org.mitre.oval:ste:6370"/>
    </dpkginfo_test>
    <dpkginfo_test comment="xmltooling-schemas is earlier than 1.0-2+lenny1" check="all" version="1" id="oval:org.mitre.oval:tst:19568" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11857"/>
      <state state_ref="oval:org.mitre.oval:ste:6370"/>
    </dpkginfo_test>
    <dpkginfo_test comment="libtk-img is earlier than 1.3-release-7+lenny1" check="all" version="1" id="oval:org.mitre.oval:tst:20000" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11563"/>
      <state state_ref="oval:org.mitre.oval:ste:6546"/>
    </dpkginfo_test>
    <dpkginfo_test comment="libtk-img-dev is earlier than 1.3-release-7+lenny1" check="all" version="1" id="oval:org.mitre.oval:tst:19985" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11880"/>
      <state state_ref="oval:org.mitre.oval:ste:6546"/>
    </dpkginfo_test>
    <dpkginfo_test comment="libtk-img is earlier than 1.3-15etch3" check="all" version="1" id="oval:org.mitre.oval:tst:19877" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11563"/>
      <state state_ref="oval:org.mitre.oval:ste:6335"/>
    </dpkginfo_test>
    <dpkginfo_test comment="libtk-img-doc is earlier than 1.3-release-7+lenny1" check="all" version="1" id="oval:org.mitre.oval:tst:19876" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11865"/>
      <state state_ref="oval:org.mitre.oval:ste:6546"/>
    </dpkginfo_test>
    <dpkginfo_test comment="libsasl2-modules is earlier than 2.1.22.dfsg1-23+lenny1" check="all" version="1" id="oval:org.mitre.oval:tst:20458" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11935"/>
      <state state_ref="oval:org.mitre.oval:ste:6369"/>
    </dpkginfo_test>
    <dpkginfo_test comment="cyrus-sasl2-doc is earlier than 2.1.22.dfsg1-23+lenny1" check="all" version="1" id="oval:org.mitre.oval:tst:20447" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11505"/>
      <state state_ref="oval:org.mitre.oval:ste:6369"/>
    </dpkginfo_test>
    <dpkginfo_test comment="libsasl2-modules-gssapi-mit is earlier than 2.1.22.dfsg1-23+lenny1" check="all" version="1" id="oval:org.mitre.oval:tst:20409" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:10942"/>
      <state state_ref="oval:org.mitre.oval:ste:6369"/>
    </dpkginfo_test>
    <dpkginfo_test comment="libsasl2-modules-otp is earlier than 2.1.22.dfsg1-23+lenny1" check="all" version="1" id="oval:org.mitre.oval:tst:20402" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11748"/>
      <state state_ref="oval:org.mitre.oval:ste:6369"/>
    </dpkginfo_test>
    <dpkginfo_test comment="sasl2-bin is earlier than 2.1.22.dfsg1-23+lenny1" check="all" version="1" id="oval:org.mitre.oval:tst:20378" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11501"/>
      <state state_ref="oval:org.mitre.oval:ste:6369"/>
    </dpkginfo_test>
    <dpkginfo_test comment="cyrus-sasl2-heimdal-dbg is earlier than 2.1.22.dfsg1-23+lenny1" check="all" version="1" id="oval:org.mitre.oval:tst:20365" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11874"/>
      <state state_ref="oval:org.mitre.oval:ste:6369"/>
    </dpkginfo_test>
    <dpkginfo_test comment="libsasl2-dev is earlier than 2.1.22.dfsg1-23+lenny1" check="all" version="1" id="oval:org.mitre.oval:tst:20331" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:10944"/>
      <state state_ref="oval:org.mitre.oval:ste:6369"/>
    </dpkginfo_test>
    <dpkginfo_test comment="libsasl2-2 is earlier than 2.1.22.dfsg1-23+lenny1" check="all" version="1" id="oval:org.mitre.oval:tst:20234" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11902"/>
      <state state_ref="oval:org.mitre.oval:ste:6369"/>
    </dpkginfo_test>
    <dpkginfo_test comment="libsasl2-modules-ldap is earlier than 2.1.22.dfsg1-23+lenny1" check="all" version="1" id="oval:org.mitre.oval:tst:20215" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11562"/>
      <state state_ref="oval:org.mitre.oval:ste:6369"/>
    </dpkginfo_test>
    <dpkginfo_test comment="libsasl2-modules-gssapi-heimdal is earlier than 2.1.22.dfsg1-23+lenny1" check="all" version="1" id="oval:org.mitre.oval:tst:20148" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11827"/>
      <state state_ref="oval:org.mitre.oval:ste:6369"/>
    </dpkginfo_test>
    <dpkginfo_test comment="cyrus-sasl2-dbg is earlier than 2.1.22.dfsg1-23+lenny1" check="all" version="1" id="oval:org.mitre.oval:tst:19990" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11924"/>
      <state state_ref="oval:org.mitre.oval:ste:6369"/>
    </dpkginfo_test>
    <dpkginfo_test comment="libsasl2-modules-sql is earlier than 2.1.22.dfsg1-23+lenny1" check="all" version="1" id="oval:org.mitre.oval:tst:19896" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11506"/>
      <state state_ref="oval:org.mitre.oval:ste:6369"/>
    </dpkginfo_test>
    <dpkginfo_test comment="pidgin-dbg is earlier than 2.4.3-4lenny2" check="all" version="1" id="oval:org.mitre.oval:tst:20510" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:9749"/>
      <state state_ref="oval:org.mitre.oval:ste:6476"/>
    </dpkginfo_test>
    <dpkginfo_test comment="pidgin-data is earlier than 2.4.3-4lenny2" check="all" version="1" id="oval:org.mitre.oval:tst:20394" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:10503"/>
      <state state_ref="oval:org.mitre.oval:ste:6476"/>
    </dpkginfo_test>
    <dpkginfo_test comment="libpurple-dev is earlier than 2.4.3-4lenny2" check="all" version="1" id="oval:org.mitre.oval:tst:20333" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:10588"/>
      <state state_ref="oval:org.mitre.oval:ste:6476"/>
    </dpkginfo_test>
    <dpkginfo_test comment="libpurple-bin is earlier than 2.4.3-4lenny2" check="all" version="1" id="oval:org.mitre.oval:tst:20245" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:10543"/>
      <state state_ref="oval:org.mitre.oval:ste:6476"/>
    </dpkginfo_test>
    <dpkginfo_test comment="finch-dev is earlier than 2.4.3-4lenny2" check="all" version="1" id="oval:org.mitre.oval:tst:20175" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:10713"/>
      <state state_ref="oval:org.mitre.oval:ste:6476"/>
    </dpkginfo_test>
    <dpkginfo_test comment="pidgin-dev is earlier than 2.4.3-4lenny2" check="all" version="1" id="oval:org.mitre.oval:tst:20002" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:9897"/>
      <state state_ref="oval:org.mitre.oval:ste:6476"/>
    </dpkginfo_test>
    <dpkginfo_test comment="libpurple0 is earlier than 2.4.3-4lenny2" check="all" version="1" id="oval:org.mitre.oval:tst:19613" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:10703"/>
      <state state_ref="oval:org.mitre.oval:ste:6476"/>
    </dpkginfo_test>
    <dpkginfo_test comment="pidgin is earlier than 2.4.3-4lenny2" check="all" version="1" id="oval:org.mitre.oval:tst:19582" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:10640"/>
      <state state_ref="oval:org.mitre.oval:ste:6476"/>
    </dpkginfo_test>
    <dpkginfo_test comment="finch is earlier than 2.4.3-4lenny2" check="all" version="1" id="oval:org.mitre.oval:tst:19558" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:9976"/>
      <state state_ref="oval:org.mitre.oval:ste:6476"/>
    </dpkginfo_test>
    <dpkginfo_test comment="libmodplug-dev is earlier than 0.7-5.2+etch1" check="all" version="1" id="oval:org.mitre.oval:tst:19258" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:10643"/>
      <state state_ref="oval:org.mitre.oval:ste:6211"/>
    </dpkginfo_test>
    <dpkginfo_test comment="libmodplug0c2 is earlier than 0.8.4-1+lenny1" check="all" version="1" id="oval:org.mitre.oval:tst:19028" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11242"/>
      <state state_ref="oval:org.mitre.oval:ste:5484"/>
    </dpkginfo_test>
    <dpkginfo_test comment="libmodplug-dev is earlier than 0.8.4-1+lenny1" check="all" version="1" id="oval:org.mitre.oval:tst:18977" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:10643"/>
      <state state_ref="oval:org.mitre.oval:ste:5484"/>
    </dpkginfo_test>
    <dpkginfo_test comment="libmodplug0c2 is earlier than 0.7-5.2+etch1" check="all" version="1" id="oval:org.mitre.oval:tst:18805" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11242"/>
      <state state_ref="oval:org.mitre.oval:ste:6211"/>
    </dpkginfo_test>
    <dpkginfo_test comment="linux-headers-2.6.26-2-all is earlier than 2.6.26-15lenny2" check="all" version="1" id="oval:org.mitre.oval:tst:20741" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:8298"/>
      <state state_ref="oval:org.mitre.oval:ste:6519"/>
    </dpkginfo_test>
    <dpkginfo_test comment="linux-headers-2.6.26-2-parisc64-smp is earlier than 2.6.26-15lenny2" check="all" version="1" id="oval:org.mitre.oval:tst:20740" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:8251"/>
      <state state_ref="oval:org.mitre.oval:ste:6519"/>
    </dpkginfo_test>
    <dpkginfo_test comment="linux-headers-2.6.26-2-all-hppa is earlier than 2.6.26-15lenny2" check="all" version="1" id="oval:org.mitre.oval:tst:20652" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:7966"/>
      <state state_ref="oval:org.mitre.oval:ste:6519"/>
    </dpkginfo_test>
    <dpkginfo_test comment="linux-image-2.6.26-2-parisc64 is earlier than 2.6.26-15lenny2" check="all" version="1" id="oval:org.mitre.oval:tst:20610" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:8318"/>
      <state state_ref="oval:org.mitre.oval:ste:6519"/>
    </dpkginfo_test>
    <dpkginfo_test comment="linux-headers-2.6.26-2-parisc64 is earlier than 2.6.26-15lenny2" check="all" version="1" id="oval:org.mitre.oval:tst:20604" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:7946"/>
      <state state_ref="oval:org.mitre.oval:ste:6519"/>
    </dpkginfo_test>
    <dpkginfo_test comment="linux-headers-2.6.26-2-all is earlier than 2.6.26-15lenny2" check="all" version="1" id="oval:org.mitre.oval:tst:20602" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:8298"/>
      <state state_ref="oval:org.mitre.oval:ste:6519"/>
    </dpkginfo_test>
    <dpkginfo_test comment="linux-manual-2.6.26 is earlier than 2.6.26-15lenny2" check="all" version="1" id="oval:org.mitre.oval:tst:20586" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:8217"/>
      <state state_ref="oval:org.mitre.oval:ste:6519"/>
    </dpkginfo_test>
    <dpkginfo_test comment="user-mode-linux is earlier than 2.6.26-1um-2+15lenny2" check="all" version="1" id="oval:org.mitre.oval:tst:20584" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:7848"/>
      <state state_ref="oval:org.mitre.oval:ste:6625"/>
    </dpkginfo_test>
    <dpkginfo_test comment="linux-doc-2.6.26 is earlier than 2.6.26-15lenny2" check="all" version="1" id="oval:org.mitre.oval:tst:20581" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:8320"/>
      <state state_ref="oval:org.mitre.oval:ste:6519"/>
    </dpkginfo_test>
    <dpkginfo_test comment="linux-headers-2.6.26-2-all is earlier than 2.6.26-15lenny2" check="all" version="1" id="oval:org.mitre.oval:tst:20576" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:8298"/>
      <state state_ref="oval:org.mitre.oval:ste:6519"/>
    </dpkginfo_test>
    <dpkginfo_test comment="linux-headers-2.6.26-2-common-vserver is earlier than 2.6.26-15lenny2" check="all" version="1" id="oval:org.mitre.oval:tst:20555" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:8228"/>
      <state state_ref="oval:org.mitre.oval:ste:6519"/>
    </dpkginfo_test>
    <dpkginfo_test comment="linux-headers-2.6.26-2-parisc-smp is earlier than 2.6.26-15lenny2" check="all" version="1" id="oval:org.mitre.oval:tst:20553" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:8442"/>
      <state state_ref="oval:org.mitre.oval:ste:6519"/>
    </dpkginfo_test>
    <dpkginfo_test comment="linux-image-2.6.26-2-openvz-amd64 is earlier than 2.6.26-15lenny2" check="all" version="1" id="oval:org.mitre.oval:tst:20549" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:8239"/>
      <state state_ref="oval:org.mitre.oval:ste:6519"/>
    </dpkginfo_test>
    <dpkginfo_test comment="linux-libc-dev is earlier than 2.6.26-15lenny2" check="all" version="1" id="oval:org.mitre.oval:tst:20546" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:7932"/>
      <state state_ref="oval:org.mitre.oval:ste:6519"/>
    </dpkginfo_test>
    <dpkginfo_test comment="linux-headers-2.6.26-2-amd64 is earlier than 2.6.26-15lenny2" check="all" version="1" id="oval:org.mitre.oval:tst:20540" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:7711"/>
      <state state_ref="oval:org.mitre.oval:ste:6519"/>
    </dpkginfo_test>
    <dpkginfo_test comment="linux-headers-2.6.26-2-vserver-s390x is earlier than 2.6.26-15lenny2" check="all" version="1" id="oval:org.mitre.oval:tst:20539" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:8296"/>
      <state state_ref="oval:org.mitre.oval:ste:6519"/>
    </dpkginfo_test>
    <dpkginfo_test comment="xen-linux-system-2.6.26-2-xen-amd64 is earlier than 2.6.26-15lenny2" check="all" version="1" id="oval:org.mitre.oval:tst:20537" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:8341"/>
      <state state_ref="oval:org.mitre.oval:ste:6519"/>
    </dpkginfo_test>
    <dpkginfo_test comment="linux-headers-2.6.26-2-all-amd64 is earlier than 2.6.26-15lenny2" check="all" version="1" id="oval:org.mitre.oval:tst:20527" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:8214"/>
      <state state_ref="oval:org.mitre.oval:ste:6519"/>
    </dpkginfo_test>
    <dpkginfo_test comment="linux-modules-2.6.26-2-xen-amd64 is earlier than 2.6.26-15lenny2" check="all" version="1" id="oval:org.mitre.oval:tst:20523" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:7588"/>
      <state state_ref="oval:org.mitre.oval:ste:6519"/>
    </dpkginfo_test>
    <dpkginfo_test comment="linux-tree-2.6.26 is earlier than 2.6.26-15lenny2" check="all" version="1" id="oval:org.mitre.oval:tst:20515" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:7896"/>
      <state state_ref="oval:org.mitre.oval:ste:6519"/>
    </dpkginfo_test>
    <dpkginfo_test comment="linux-source-2.6.26 is earlier than 2.6.26-15lenny2" check="all" version="1" id="oval:org.mitre.oval:tst:20509" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:8224"/>
      <state state_ref="oval:org.mitre.oval:ste:6519"/>
    </dpkginfo_test>
    <dpkginfo_test comment="linux-libc-dev is earlier than 2.6.26-15lenny2" check="all" version="1" id="oval:org.mitre.oval:tst:20501" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:7932"/>
      <state state_ref="oval:org.mitre.oval:ste:6519"/>
    </dpkginfo_test>
    <dpkginfo_test comment="linux-image-2.6.26-2-s390 is earlier than 2.6.26-15lenny2" check="all" version="1" id="oval:org.mitre.oval:tst:20499" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:7925"/>
      <state state_ref="oval:org.mitre.oval:ste:6519"/>
    </dpkginfo_test>
    <dpkginfo_test comment="linux-headers-2.6.26-2-xen-amd64 is earlier than 2.6.26-15lenny2" check="all" version="1" id="oval:org.mitre.oval:tst:20494" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:8372"/>
      <state state_ref="oval:org.mitre.oval:ste:6519"/>
    </dpkginfo_test>
    <dpkginfo_test comment="linux-support-2.6.26-2 is earlier than 2.6.26-15lenny2" check="all" version="1" id="oval:org.mitre.oval:tst:20463" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:8112"/>
      <state state_ref="oval:org.mitre.oval:ste:6519"/>
    </dpkginfo_test>
    <dpkginfo_test comment="linux-libc-dev is earlier than 2.6.26-15lenny2" check="all" version="1" id="oval:org.mitre.oval:tst:20461" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:7932"/>
      <state state_ref="oval:org.mitre.oval:ste:6519"/>
    </dpkginfo_test>
    <dpkginfo_test comment="linux-image-2.6.26-2-amd64 is earlier than 2.6.26-15lenny2" check="all" version="1" id="oval:org.mitre.oval:tst:20460" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:8404"/>
      <state state_ref="oval:org.mitre.oval:ste:6519"/>
    </dpkginfo_test>
    <dpkginfo_test comment="linux-headers-2.6.26-2-common-openvz is earlier than 2.6.26-15lenny2" check="all" version="1" id="oval:org.mitre.oval:tst:20446" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:8209"/>
      <state state_ref="oval:org.mitre.oval:ste:6519"/>
    </dpkginfo_test>
    <dpkginfo_test comment="linux-headers-2.6.26-2-parisc is earlier than 2.6.26-15lenny2" check="all" version="1" id="oval:org.mitre.oval:tst:20442" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:8562"/>
      <state state_ref="oval:org.mitre.oval:ste:6519"/>
    </dpkginfo_test>
    <dpkginfo_test comment="linux-image-2.6.26-2-vserver-amd64 is earlier than 2.6.26-15lenny2" check="all" version="1" id="oval:org.mitre.oval:tst:20437" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:8059"/>
      <state state_ref="oval:org.mitre.oval:ste:6519"/>
    </dpkginfo_test>
    <dpkginfo_test comment="linux-headers-2.6.26-2-openvz-amd64 is earlier than 2.6.26-15lenny2" check="all" version="1" id="oval:org.mitre.oval:tst:20434" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:8357"/>
      <state state_ref="oval:org.mitre.oval:ste:6519"/>
    </dpkginfo_test>
    <dpkginfo_test comment="linux-headers-2.6.26-2-vserver-amd64 is earlier than 2.6.26-15lenny2" check="all" version="1" id="oval:org.mitre.oval:tst:20414" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:8020"/>
      <state state_ref="oval:org.mitre.oval:ste:6519"/>
    </dpkginfo_test>
    <dpkginfo_test comment="linux-image-2.6.26-2-s390-tape is earlier than 2.6.26-15lenny2" check="all" version="1" id="oval:org.mitre.oval:tst:20404" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:7991"/>
      <state state_ref="oval:org.mitre.oval:ste:6519"/>
    </dpkginfo_test>
    <dpkginfo_test comment="linux-headers-2.6.26-2-s390 is earlier than 2.6.26-15lenny2" check="all" version="1" id="oval:org.mitre.oval:tst:20375" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:8329"/>
      <state state_ref="oval:org.mitre.oval:ste:6519"/>
    </dpkginfo_test>
    <dpkginfo_test comment="linux-headers-2.6.26-2-common-vserver is earlier than 2.6.26-15lenny2" check="all" version="1" id="oval:org.mitre.oval:tst:20373" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:8228"/>
      <state state_ref="oval:org.mitre.oval:ste:6519"/>
    </dpkginfo_test>
    <dpkginfo_test comment="linux-image-2.6.26-2-vserver-s390x is earlier than 2.6.26-15lenny2" check="all" version="1" id="oval:org.mitre.oval:tst:20358" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:8153"/>
      <state state_ref="oval:org.mitre.oval:ste:6519"/>
    </dpkginfo_test>
    <dpkginfo_test comment="linux-headers-2.6.26-2-s390x is earlier than 2.6.26-15lenny2" check="all" version="1" id="oval:org.mitre.oval:tst:20354" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:8177"/>
      <state state_ref="oval:org.mitre.oval:ste:6519"/>
    </dpkginfo_test>
    <dpkginfo_test comment="linux-headers-2.6.26-2-all-s390 is earlier than 2.6.26-15lenny2" check="all" version="1" id="oval:org.mitre.oval:tst:20335" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:7435"/>
      <state state_ref="oval:org.mitre.oval:ste:6519"/>
    </dpkginfo_test>
    <dpkginfo_test comment="linux-headers-2.6.26-2-common is earlier than 2.6.26-15lenny2" check="all" version="1" id="oval:org.mitre.oval:tst:20281" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:8307"/>
      <state state_ref="oval:org.mitre.oval:ste:6519"/>
    </dpkginfo_test>
    <dpkginfo_test comment="linux-image-2.6.26-2-parisc64-smp is earlier than 2.6.26-15lenny2" check="all" version="1" id="oval:org.mitre.oval:tst:20179" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:8429"/>
      <state state_ref="oval:org.mitre.oval:ste:6519"/>
    </dpkginfo_test>
    <dpkginfo_test comment="linux-image-2.6.26-2-xen-amd64 is earlier than 2.6.26-15lenny2" check="all" version="1" id="oval:org.mitre.oval:tst:20167" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:7975"/>
      <state state_ref="oval:org.mitre.oval:ste:6519"/>
    </dpkginfo_test>
    <dpkginfo_test comment="linux-patch-debian-2.6.26 is earlier than 2.6.26-15lenny2" check="all" version="1" id="oval:org.mitre.oval:tst:20152" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:7796"/>
      <state state_ref="oval:org.mitre.oval:ste:6519"/>
    </dpkginfo_test>
    <dpkginfo_test comment="linux-image-2.6.26-2-s390x is earlier than 2.6.26-15lenny2" check="all" version="1" id="oval:org.mitre.oval:tst:20117" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:8410"/>
      <state state_ref="oval:org.mitre.oval:ste:6519"/>
    </dpkginfo_test>
    <dpkginfo_test comment="linux-image-2.6.26-2-parisc-smp is earlier than 2.6.26-15lenny2" check="all" version="1" id="oval:org.mitre.oval:tst:20082" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:7936"/>
      <state state_ref="oval:org.mitre.oval:ste:6519"/>
    </dpkginfo_test>
    <dpkginfo_test comment="linux-headers-2.6.26-2-common is earlier than 2.6.26-15lenny2" check="all" version="1" id="oval:org.mitre.oval:tst:19880" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:8307"/>
      <state state_ref="oval:org.mitre.oval:ste:6519"/>
    </dpkginfo_test>
    <dpkginfo_test comment="linux-headers-2.6.26-2-common is earlier than 2.6.26-15lenny2" check="all" version="1" id="oval:org.mitre.oval:tst:19838" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:8307"/>
      <state state_ref="oval:org.mitre.oval:ste:6519"/>
    </dpkginfo_test>
    <dpkginfo_test comment="linux-image-2.6.26-2-parisc is earlier than 2.6.26-15lenny2" check="all" version="1" id="oval:org.mitre.oval:tst:19821" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:8464"/>
      <state state_ref="oval:org.mitre.oval:ste:6519"/>
    </dpkginfo_test>
    <dpkginfo_test comment="linux-headers-2.6.26-2-common-xen is earlier than 2.6.26-15lenny2" check="all" version="1" id="oval:org.mitre.oval:tst:19738" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:7926"/>
      <state state_ref="oval:org.mitre.oval:ste:6519"/>
    </dpkginfo_test>
    <dpkginfo_test comment="fetchmail is earlier than 6.3.9~rc2-4+lenny1" check="all" version="1" id="oval:org.mitre.oval:tst:19217" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:10880"/>
      <state state_ref="oval:org.mitre.oval:ste:5861"/>
    </dpkginfo_test>
    <dpkginfo_test comment="fetchmail is earlier than 6.3.6-1etch2" check="all" version="1" id="oval:org.mitre.oval:tst:19174" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:10880"/>
      <state state_ref="oval:org.mitre.oval:ste:5779"/>
    </dpkginfo_test>
    <dpkginfo_test comment="fetchmailconf is earlier than 6.3.9~rc2-4+lenny1" check="all" version="1" id="oval:org.mitre.oval:tst:18983" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11252"/>
      <state state_ref="oval:org.mitre.oval:ste:5861"/>
    </dpkginfo_test>
    <dpkginfo_test comment="fetchmailconf is earlier than 6.3.6-1etch2" check="all" version="1" id="oval:org.mitre.oval:tst:18503" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11252"/>
      <state state_ref="oval:org.mitre.oval:ste:5779"/>
    </dpkginfo_test>
    <dpkginfo_test comment="nsd is earlier than 2.3.7-1.1+lenny1" check="all" version="1" id="oval:org.mitre.oval:tst:20552" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11841"/>
      <state state_ref="oval:org.mitre.oval:ste:6437"/>
    </dpkginfo_test>
    <dpkginfo_test comment="nsd is earlier than 2.3.6-1+etch1" check="all" version="1" id="oval:org.mitre.oval:tst:20410" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11841"/>
      <state state_ref="oval:org.mitre.oval:ste:5774"/>
    </dpkginfo_test>
    <dpkginfo_test comment="nsd3 is earlier than 3.0.7-3.lenny2" check="all" version="1" id="oval:org.mitre.oval:tst:19874" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11824"/>
      <state state_ref="oval:org.mitre.oval:ste:6457"/>
    </dpkginfo_test>
    <dpkginfo_test comment="libgnutls13-dbg is earlier than 1.4.4-3+etch5" check="all" version="1" id="oval:org.mitre.oval:tst:19467" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:10091"/>
      <state state_ref="oval:org.mitre.oval:ste:5640"/>
    </dpkginfo_test>
    <dpkginfo_test comment="gnutls-bin is earlier than 1.4.4-3+etch5" check="all" version="1" id="oval:org.mitre.oval:tst:19427" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:10196"/>
      <state state_ref="oval:org.mitre.oval:ste:5640"/>
    </dpkginfo_test>
    <dpkginfo_test comment="gnutls-doc is earlier than 1.4.4-3+etch5" check="all" version="1" id="oval:org.mitre.oval:tst:19426" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:10599"/>
      <state state_ref="oval:org.mitre.oval:ste:5640"/>
    </dpkginfo_test>
    <dpkginfo_test comment="libgnutls-dev is earlier than 2.4.2-6+lenny2" check="all" version="1" id="oval:org.mitre.oval:tst:19418" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:10356"/>
      <state state_ref="oval:org.mitre.oval:ste:6366"/>
    </dpkginfo_test>
    <dpkginfo_test comment="libgnutls-dev is earlier than 1.4.4-3+etch5" check="all" version="1" id="oval:org.mitre.oval:tst:19377" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:10356"/>
      <state state_ref="oval:org.mitre.oval:ste:5640"/>
    </dpkginfo_test>
    <dpkginfo_test comment="libgnutls26-dbg is earlier than 2.4.2-6+lenny2" check="all" version="1" id="oval:org.mitre.oval:tst:19207" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11291"/>
      <state state_ref="oval:org.mitre.oval:ste:6366"/>
    </dpkginfo_test>
    <dpkginfo_test comment="libgnutls13 is earlier than 1.4.4-3+etch5" check="all" version="1" id="oval:org.mitre.oval:tst:19199" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:10397"/>
      <state state_ref="oval:org.mitre.oval:ste:5640"/>
    </dpkginfo_test>
    <dpkginfo_test comment="gnutls-doc is earlier than 2.4.2-6+lenny2" check="all" version="1" id="oval:org.mitre.oval:tst:19120" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:10599"/>
      <state state_ref="oval:org.mitre.oval:ste:6366"/>
    </dpkginfo_test>
    <dpkginfo_test comment="gnutls-bin is earlier than 2.4.2-6+lenny2" check="all" version="1" id="oval:org.mitre.oval:tst:19103" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:10196"/>
      <state state_ref="oval:org.mitre.oval:ste:6366"/>
    </dpkginfo_test>
    <dpkginfo_test comment="guile-gnutls is earlier than 2.4.2-6+lenny2" check="all" version="1" id="oval:org.mitre.oval:tst:18710" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11002"/>
      <state state_ref="oval:org.mitre.oval:ste:6366"/>
    </dpkginfo_test>
    <dpkginfo_test comment="libgnutls26 is earlier than 2.4.2-6+lenny2" check="all" version="1" id="oval:org.mitre.oval:tst:18509" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11578"/>
      <state state_ref="oval:org.mitre.oval:ste:6366"/>
    </dpkginfo_test>
    <dpkginfo_test comment="libnewt0.52 is earlier than 0.52.2-10+etch1" check="all" version="1" id="oval:org.mitre.oval:tst:20156" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11898"/>
      <state state_ref="oval:org.mitre.oval:ste:6570"/>
    </dpkginfo_test>
    <dpkginfo_test comment="newt-tcl is earlier than 0.52.2-10+etch1" check="all" version="1" id="oval:org.mitre.oval:tst:20138" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11021"/>
      <state state_ref="oval:org.mitre.oval:ste:6570"/>
    </dpkginfo_test>
    <dpkginfo_test comment="python-newt is earlier than 0.52.2-10+etch1" check="all" version="1" id="oval:org.mitre.oval:tst:20132" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11706"/>
      <state state_ref="oval:org.mitre.oval:ste:6570"/>
    </dpkginfo_test>
    <dpkginfo_test comment="whiptail is earlier than 0.52.2-11.3+lenny1" check="all" version="1" id="oval:org.mitre.oval:tst:20041" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11895"/>
      <state state_ref="oval:org.mitre.oval:ste:6563"/>
    </dpkginfo_test>
    <dpkginfo_test comment="newt-tcl is earlier than 0.52.2-11.3+lenny1" check="all" version="1" id="oval:org.mitre.oval:tst:20033" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11021"/>
      <state state_ref="oval:org.mitre.oval:ste:6563"/>
    </dpkginfo_test>
    <dpkginfo_test comment="libnewt-pic is earlier than 0.52.2-11.3+lenny1" check="all" version="1" id="oval:org.mitre.oval:tst:19994" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11612"/>
      <state state_ref="oval:org.mitre.oval:ste:6563"/>
    </dpkginfo_test>
    <dpkginfo_test comment="libnewt-pic is earlier than 0.52.2-10+etch1" check="all" version="1" id="oval:org.mitre.oval:tst:19908" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11612"/>
      <state state_ref="oval:org.mitre.oval:ste:6570"/>
    </dpkginfo_test>
    <dpkginfo_test comment="libnewt0.52 is earlier than 0.52.2-11.3+lenny1" check="all" version="1" id="oval:org.mitre.oval:tst:19853" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11898"/>
      <state state_ref="oval:org.mitre.oval:ste:6563"/>
    </dpkginfo_test>
    <dpkginfo_test comment="libnewt-dev is earlier than 0.52.2-11.3+lenny1" check="all" version="1" id="oval:org.mitre.oval:tst:19799" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11863"/>
      <state state_ref="oval:org.mitre.oval:ste:6563"/>
    </dpkginfo_test>
    <dpkginfo_test comment="python-newt is earlier than 0.52.2-11.3+lenny1" check="all" version="1" id="oval:org.mitre.oval:tst:19786" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11706"/>
      <state state_ref="oval:org.mitre.oval:ste:6563"/>
    </dpkginfo_test>
    <dpkginfo_test comment="whiptail is earlier than 0.52.2-10+etch1" check="all" version="1" id="oval:org.mitre.oval:tst:19370" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11895"/>
      <state state_ref="oval:org.mitre.oval:ste:6570"/>
    </dpkginfo_test>
    <dpkginfo_test comment="libnewt-dev is earlier than 0.52.2-10+etch1" check="all" version="1" id="oval:org.mitre.oval:tst:19278" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11863"/>
      <state state_ref="oval:org.mitre.oval:ste:6570"/>
    </dpkginfo_test>
    <dpkginfo_test comment="libwxbase2.6-dbg is earlier than 2.6.3.2.1.5+etch1" check="all" version="1" id="oval:org.mitre.oval:tst:20242" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11848"/>
      <state state_ref="oval:org.mitre.oval:ste:6582"/>
    </dpkginfo_test>
    <dpkginfo_test comment="libwxgtk2.4-contrib-dev is earlier than 2.4.5.1.1+etch1" check="all" version="1" id="oval:org.mitre.oval:tst:20235" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11006"/>
      <state state_ref="oval:org.mitre.oval:ste:6482"/>
    </dpkginfo_test>
    <dpkginfo_test comment="libwxbase2.4-1 is earlier than 2.4.5.1.1+etch1" check="all" version="1" id="oval:org.mitre.oval:tst:20230" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11875"/>
      <state state_ref="oval:org.mitre.oval:ste:6482"/>
    </dpkginfo_test>
    <dpkginfo_test comment="libwxbase2.4-dbg is earlier than 2.4.5.1.1+etch1" check="all" version="1" id="oval:org.mitre.oval:tst:20226" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11925"/>
      <state state_ref="oval:org.mitre.oval:ste:6482"/>
    </dpkginfo_test>
    <dpkginfo_test comment="libwxbase2.4-dev is earlier than 2.4.5.1.1+etch1" check="all" version="1" id="oval:org.mitre.oval:tst:20222" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11891"/>
      <state state_ref="oval:org.mitre.oval:ste:6482"/>
    </dpkginfo_test>
    <dpkginfo_test comment="libwxgtk2.6-0 is earlier than 2.6.3.2.1.5+etch1" check="all" version="1" id="oval:org.mitre.oval:tst:20213" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11911"/>
      <state state_ref="oval:org.mitre.oval:ste:6582"/>
    </dpkginfo_test>
    <dpkginfo_test comment="libwxgtk2.8-0 is earlier than 2.8.7.1-1.1+lenny1" check="all" version="1" id="oval:org.mitre.oval:tst:20212" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11862"/>
      <state state_ref="oval:org.mitre.oval:ste:6165"/>
    </dpkginfo_test>
    <dpkginfo_test comment="libwxgtk2.8-dev is earlier than 2.8.7.1-1.1+lenny1" check="all" version="1" id="oval:org.mitre.oval:tst:20211" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11420"/>
      <state state_ref="oval:org.mitre.oval:ste:6165"/>
    </dpkginfo_test>
    <dpkginfo_test comment="libwxgtk2.4-dev is earlier than 2.4.5.1.1+etch1" check="all" version="1" id="oval:org.mitre.oval:tst:20205" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11127"/>
      <state state_ref="oval:org.mitre.oval:ste:6482"/>
    </dpkginfo_test>
    <dpkginfo_test comment="wx-common is earlier than 2.6.3.2.1.5+etch1" check="all" version="1" id="oval:org.mitre.oval:tst:20202" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11643"/>
      <state state_ref="oval:org.mitre.oval:ste:6582"/>
    </dpkginfo_test>
    <dpkginfo_test comment="libwxgtk2.4-1 is earlier than 2.4.5.1.1+etch1" check="all" version="1" id="oval:org.mitre.oval:tst:20199" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11210"/>
      <state state_ref="oval:org.mitre.oval:ste:6482"/>
    </dpkginfo_test>
    <dpkginfo_test comment="wx2.4-doc is earlier than 2.4.5.1.1+etch1" check="all" version="1" id="oval:org.mitre.oval:tst:20198" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11303"/>
      <state state_ref="oval:org.mitre.oval:ste:6482"/>
    </dpkginfo_test>
    <dpkginfo_test comment="libwxbase2.6-dbg is earlier than 2.6.3.2.1.5+etch1" check="all" version="1" id="oval:org.mitre.oval:tst:20194" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11848"/>
      <state state_ref="oval:org.mitre.oval:ste:6582"/>
    </dpkginfo_test>
    <dpkginfo_test comment="libwxbase2.8-dev is earlier than 2.8.7.1-1.1+lenny1" check="all" version="1" id="oval:org.mitre.oval:tst:20191" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:10925"/>
      <state state_ref="oval:org.mitre.oval:ste:6165"/>
    </dpkginfo_test>
    <dpkginfo_test comment="libwxgtk2.4-1-contrib is earlier than 2.4.5.1.1+etch1" check="all" version="1" id="oval:org.mitre.oval:tst:20186" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11574"/>
      <state state_ref="oval:org.mitre.oval:ste:6482"/>
    </dpkginfo_test>
    <dpkginfo_test comment="wx2.6-headers is earlier than 2.6.3.2.1.5+etch1" check="all" version="1" id="oval:org.mitre.oval:tst:20184" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11715"/>
      <state state_ref="oval:org.mitre.oval:ste:6582"/>
    </dpkginfo_test>
    <dpkginfo_test comment="libwxgtk2.6-0 is earlier than 2.6.3.2.2-3+lenny1" check="all" version="1" id="oval:org.mitre.oval:tst:20177" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11911"/>
      <state state_ref="oval:org.mitre.oval:ste:6333"/>
    </dpkginfo_test>
    <dpkginfo_test comment="libwxgtk2.6-dev is earlier than 2.6.3.2.1.5+etch1" check="all" version="1" id="oval:org.mitre.oval:tst:20174" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11876"/>
      <state state_ref="oval:org.mitre.oval:ste:6582"/>
    </dpkginfo_test>
    <dpkginfo_test comment="libwxgtk2.4-contrib-dev is earlier than 2.4.5.1.1+etch1" check="all" version="1" id="oval:org.mitre.oval:tst:20172" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11006"/>
      <state state_ref="oval:org.mitre.oval:ste:6482"/>
    </dpkginfo_test>
    <dpkginfo_test comment="python-wxgtk2.8 is earlier than 2.8.7.1-1.1+lenny1" check="all" version="1" id="oval:org.mitre.oval:tst:20165" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11719"/>
      <state state_ref="oval:org.mitre.oval:ste:6165"/>
    </dpkginfo_test>
    <dpkginfo_test comment="wx2.4-examples is earlier than 2.4.5.1.1+etch1" check="all" version="1" id="oval:org.mitre.oval:tst:20149" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11900"/>
      <state state_ref="oval:org.mitre.oval:ste:6482"/>
    </dpkginfo_test>
    <dpkginfo_test comment="libwxbase2.6-dev is earlier than 2.6.3.2.2-3+lenny1" check="all" version="1" id="oval:org.mitre.oval:tst:20143" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11615"/>
      <state state_ref="oval:org.mitre.oval:ste:6333"/>
    </dpkginfo_test>
    <dpkginfo_test comment="python-wxversion is earlier than 2.6.3.2.1.5+etch1" check="all" version="1" id="oval:org.mitre.oval:tst:20140" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11885"/>
      <state state_ref="oval:org.mitre.oval:ste:6582"/>
    </dpkginfo_test>
    <dpkginfo_test comment="libwxgtk2.4-dbg is earlier than 2.4.5.1.1+etch1" check="all" version="1" id="oval:org.mitre.oval:tst:20139" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11840"/>
      <state state_ref="oval:org.mitre.oval:ste:6482"/>
    </dpkginfo_test>
    <dpkginfo_test comment="libwxbase2.8-dbg is earlier than 2.8.7.1-1.1+lenny1" check="all" version="1" id="oval:org.mitre.oval:tst:20128" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11861"/>
      <state state_ref="oval:org.mitre.oval:ste:6165"/>
    </dpkginfo_test>
    <dpkginfo_test comment="libwxgtk2.8-dbg is earlier than 2.8.7.1-1.1+lenny1" check="all" version="1" id="oval:org.mitre.oval:tst:20126" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11846"/>
      <state state_ref="oval:org.mitre.oval:ste:6165"/>
    </dpkginfo_test>
    <dpkginfo_test comment="libwxbase2.8-dbg is earlier than 2.8.7.1-1.1+lenny1" check="all" version="1" id="oval:org.mitre.oval:tst:20125" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11861"/>
      <state state_ref="oval:org.mitre.oval:ste:6165"/>
    </dpkginfo_test>
    <dpkginfo_test comment="python-wxgtk2.6-dbg is earlier than 2.6.3.2.2-3+lenny1" check="all" version="1" id="oval:org.mitre.oval:tst:20119" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11668"/>
      <state state_ref="oval:org.mitre.oval:ste:6333"/>
    </dpkginfo_test>
    <dpkginfo_test comment="python-wxgtk2.6 is earlier than 2.6.3.2.2-3+lenny1" check="all" version="1" id="oval:org.mitre.oval:tst:20112" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11088"/>
      <state state_ref="oval:org.mitre.oval:ste:6333"/>
    </dpkginfo_test>
    <dpkginfo_test comment="python-wxgtk2.8-dbg is earlier than 2.8.7.1-1.1+lenny1" check="all" version="1" id="oval:org.mitre.oval:tst:20109" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11676"/>
      <state state_ref="oval:org.mitre.oval:ste:6165"/>
    </dpkginfo_test>
    <dpkginfo_test comment="wx2.4-headers is earlier than 2.4.5.1.1+etch1" check="all" version="1" id="oval:org.mitre.oval:tst:20106" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11679"/>
      <state state_ref="oval:org.mitre.oval:ste:6482"/>
    </dpkginfo_test>
    <dpkginfo_test comment="libwxbase2.4-1 is earlier than 2.4.5.1.1+etch1" check="all" version="1" id="oval:org.mitre.oval:tst:20093" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11875"/>
      <state state_ref="oval:org.mitre.oval:ste:6482"/>
    </dpkginfo_test>
    <dpkginfo_test comment="libwxbase2.6-0 is earlier than 2.6.3.2.2-3+lenny1" check="all" version="1" id="oval:org.mitre.oval:tst:20091" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11909"/>
      <state state_ref="oval:org.mitre.oval:ste:6333"/>
    </dpkginfo_test>
    <dpkginfo_test comment="python-wxversion is earlier than 2.6.3.2.2-3+lenny1" check="all" version="1" id="oval:org.mitre.oval:tst:20087" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11885"/>
      <state state_ref="oval:org.mitre.oval:ste:6333"/>
    </dpkginfo_test>
    <dpkginfo_test comment="wx2.6-headers is earlier than 2.6.3.2.2-3+lenny1" check="all" version="1" id="oval:org.mitre.oval:tst:20078" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11715"/>
      <state state_ref="oval:org.mitre.oval:ste:6333"/>
    </dpkginfo_test>
    <dpkginfo_test comment="libwxbase2.6-dbg is earlier than 2.6.3.2.2-3+lenny1" check="all" version="1" id="oval:org.mitre.oval:tst:20071" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11848"/>
      <state state_ref="oval:org.mitre.oval:ste:6333"/>
    </dpkginfo_test>
    <dpkginfo_test comment="libwxbase2.8-0 is earlier than 2.8.7.1-1.1+lenny1" check="all" version="1" id="oval:org.mitre.oval:tst:20070" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11844"/>
      <state state_ref="oval:org.mitre.oval:ste:6165"/>
    </dpkginfo_test>
    <dpkginfo_test comment="wx-common is earlier than 2.6.3.2.2-3+lenny1" check="all" version="1" id="oval:org.mitre.oval:tst:20064" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11643"/>
      <state state_ref="oval:org.mitre.oval:ste:6333"/>
    </dpkginfo_test>
    <dpkginfo_test comment="libwxgtk2.6-0 is earlier than 2.6.3.2.1.5+etch1" check="all" version="1" id="oval:org.mitre.oval:tst:20055" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11911"/>
      <state state_ref="oval:org.mitre.oval:ste:6582"/>
    </dpkginfo_test>
    <dpkginfo_test comment="python-wxgtk2.6 is earlier than 2.6.3.2.1.5+etch1" check="all" version="1" id="oval:org.mitre.oval:tst:20053" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11088"/>
      <state state_ref="oval:org.mitre.oval:ste:6582"/>
    </dpkginfo_test>
    <dpkginfo_test comment="python-wxgtk2.4 is earlier than 2.4.5.1.1+etch1" check="all" version="1" id="oval:org.mitre.oval:tst:20046" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11878"/>
      <state state_ref="oval:org.mitre.oval:ste:6482"/>
    </dpkginfo_test>
    <dpkginfo_test comment="libwxbase2.6-0 is earlier than 2.6.3.2.2-3+lenny1" check="all" version="1" id="oval:org.mitre.oval:tst:20043" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11909"/>
      <state state_ref="oval:org.mitre.oval:ste:6333"/>
    </dpkginfo_test>
    <dpkginfo_test comment="libwxgtk2.6-0 is earlier than 2.6.3.2.2-3+lenny1" check="all" version="1" id="oval:org.mitre.oval:tst:20031" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11911"/>
      <state state_ref="oval:org.mitre.oval:ste:6333"/>
    </dpkginfo_test>
    <dpkginfo_test comment="libwxbase2.4-dbg is earlier than 2.4.5.1.1+etch1" check="all" version="1" id="oval:org.mitre.oval:tst:20028" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11925"/>
      <state state_ref="oval:org.mitre.oval:ste:6482"/>
    </dpkginfo_test>
    <dpkginfo_test comment="libwxgtk2.4-1-contrib is earlier than 2.4.5.1.1+etch1" check="all" version="1" id="oval:org.mitre.oval:tst:20027" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11574"/>
      <state state_ref="oval:org.mitre.oval:ste:6482"/>
    </dpkginfo_test>
    <dpkginfo_test comment="python-wxtools is earlier than 2.6.3.2.2-3+lenny1" check="all" version="1" id="oval:org.mitre.oval:tst:20019" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11673"/>
      <state state_ref="oval:org.mitre.oval:ste:6333"/>
    </dpkginfo_test>
    <dpkginfo_test comment="libwxbase2.4-dev is earlier than 2.4.5.1.1+etch1" check="all" version="1" id="oval:org.mitre.oval:tst:20006" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11891"/>
      <state state_ref="oval:org.mitre.oval:ste:6482"/>
    </dpkginfo_test>
    <dpkginfo_test comment="wx2.4-i18n is earlier than 2.4.5.1.1+etch1" check="all" version="1" id="oval:org.mitre.oval:tst:19998" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11814"/>
      <state state_ref="oval:org.mitre.oval:ste:6482"/>
    </dpkginfo_test>
    <dpkginfo_test comment="libwxgtk2.8-dev is earlier than 2.8.7.1-1.1+lenny1" check="all" version="1" id="oval:org.mitre.oval:tst:19991" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11420"/>
      <state state_ref="oval:org.mitre.oval:ste:6165"/>
    </dpkginfo_test>
    <dpkginfo_test comment="python-wxgtk2.6-dbg is earlier than 2.6.3.2.2-3+lenny1" check="all" version="1" id="oval:org.mitre.oval:tst:19982" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11668"/>
      <state state_ref="oval:org.mitre.oval:ste:6333"/>
    </dpkginfo_test>
    <dpkginfo_test comment="libwxbase2.8-dev is earlier than 2.8.7.1-1.1+lenny1" check="all" version="1" id="oval:org.mitre.oval:tst:19968" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:10925"/>
      <state state_ref="oval:org.mitre.oval:ste:6165"/>
    </dpkginfo_test>
    <dpkginfo_test comment="libwxbase2.6-dbg is earlier than 2.6.3.2.2-3+lenny1" check="all" version="1" id="oval:org.mitre.oval:tst:19955" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11848"/>
      <state state_ref="oval:org.mitre.oval:ste:6333"/>
    </dpkginfo_test>
    <dpkginfo_test comment="wx2.6-examples is earlier than 2.6.3.2.1.5+etch1" check="all" version="1" id="oval:org.mitre.oval:tst:19953" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11650"/>
      <state state_ref="oval:org.mitre.oval:ste:6582"/>
    </dpkginfo_test>
    <dpkginfo_test comment="wx2.6-doc is earlier than 2.6.3.2.2-3+lenny1" check="all" version="1" id="oval:org.mitre.oval:tst:19944" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11847"/>
      <state state_ref="oval:org.mitre.oval:ste:6333"/>
    </dpkginfo_test>
    <dpkginfo_test comment="wx2.6-i18n is earlier than 2.6.3.2.1.5+etch1" check="all" version="1" id="oval:org.mitre.oval:tst:19930" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11609"/>
      <state state_ref="oval:org.mitre.oval:ste:6582"/>
    </dpkginfo_test>
    <dpkginfo_test comment="wx2.4-headers is earlier than 2.4.5.1.1+etch1" check="all" version="1" id="oval:org.mitre.oval:tst:19909" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11679"/>
      <state state_ref="oval:org.mitre.oval:ste:6482"/>
    </dpkginfo_test>
    <dpkginfo_test comment="wx2.6-examples is earlier than 2.6.3.2.2-3+lenny1" check="all" version="1" id="oval:org.mitre.oval:tst:19904" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11650"/>
      <state state_ref="oval:org.mitre.oval:ste:6333"/>
    </dpkginfo_test>
    <dpkginfo_test comment="libwxbase2.6-0 is earlier than 2.6.3.2.1.5+etch1" check="all" version="1" id="oval:org.mitre.oval:tst:19899" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11909"/>
      <state state_ref="oval:org.mitre.oval:ste:6582"/>
    </dpkginfo_test>
    <dpkginfo_test comment="libwxbase2.8-0 is earlier than 2.8.7.1-1.1+lenny1" check="all" version="1" id="oval:org.mitre.oval:tst:19898" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11844"/>
      <state state_ref="oval:org.mitre.oval:ste:6165"/>
    </dpkginfo_test>
    <dpkginfo_test comment="python-wxgtk2.4 is earlier than 2.4.5.1.1+etch1" check="all" version="1" id="oval:org.mitre.oval:tst:19892" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11878"/>
      <state state_ref="oval:org.mitre.oval:ste:6482"/>
    </dpkginfo_test>
    <dpkginfo_test comment="libwxgtk2.6-dev is earlier than 2.6.3.2.2-3+lenny1" check="all" version="1" id="oval:org.mitre.oval:tst:19864" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11876"/>
      <state state_ref="oval:org.mitre.oval:ste:6333"/>
    </dpkginfo_test>
    <dpkginfo_test comment="libwxgtk2.6-dev is earlier than 2.6.3.2.1.5+etch1" check="all" version="1" id="oval:org.mitre.oval:tst:19860" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11876"/>
      <state state_ref="oval:org.mitre.oval:ste:6582"/>
    </dpkginfo_test>
    <dpkginfo_test comment="wx2.6-doc is earlier than 2.6.3.2.1.5+etch1" check="all" version="1" id="oval:org.mitre.oval:tst:19859" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11847"/>
      <state state_ref="oval:org.mitre.oval:ste:6582"/>
    </dpkginfo_test>
    <dpkginfo_test comment="libwxgtk2.6-dbg is earlier than 2.6.3.2.1.5+etch1" check="all" version="1" id="oval:org.mitre.oval:tst:19856" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11893"/>
      <state state_ref="oval:org.mitre.oval:ste:6582"/>
    </dpkginfo_test>
    <dpkginfo_test comment="python-wxtools is earlier than 2.6.3.2.1.5+etch1" check="all" version="1" id="oval:org.mitre.oval:tst:19852" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11673"/>
      <state state_ref="oval:org.mitre.oval:ste:6582"/>
    </dpkginfo_test>
    <dpkginfo_test comment="libwxgtk2.6-dbg is earlier than 2.6.3.2.2-3+lenny1" check="all" version="1" id="oval:org.mitre.oval:tst:19837" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11893"/>
      <state state_ref="oval:org.mitre.oval:ste:6333"/>
    </dpkginfo_test>
    <dpkginfo_test comment="wx2.8-doc is earlier than 2.8.7.1-1.1+lenny1" check="all" version="1" id="oval:org.mitre.oval:tst:19822" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11491"/>
      <state state_ref="oval:org.mitre.oval:ste:6165"/>
    </dpkginfo_test>
    <dpkginfo_test comment="python-wxgtk2.6 is earlier than 2.6.3.2.2-3+lenny1" check="all" version="1" id="oval:org.mitre.oval:tst:19820" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11088"/>
      <state state_ref="oval:org.mitre.oval:ste:6333"/>
    </dpkginfo_test>
    <dpkginfo_test comment="libwxbase2.6-dev is earlier than 2.6.3.2.1.5+etch1" check="all" version="1" id="oval:org.mitre.oval:tst:19810" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11615"/>
      <state state_ref="oval:org.mitre.oval:ste:6582"/>
    </dpkginfo_test>
    <dpkginfo_test comment="wx-common is earlier than 2.6.3.2.1.5+etch1" check="all" version="1" id="oval:org.mitre.oval:tst:19780" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11643"/>
      <state state_ref="oval:org.mitre.oval:ste:6582"/>
    </dpkginfo_test>
    <dpkginfo_test comment="wx2.6-headers is earlier than 2.6.3.2.1.5+etch1" check="all" version="1" id="oval:org.mitre.oval:tst:19753" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11715"/>
      <state state_ref="oval:org.mitre.oval:ste:6582"/>
    </dpkginfo_test>
    <dpkginfo_test comment="python-wxgtk2.6 is earlier than 2.6.3.2.1.5+etch1" check="all" version="1" id="oval:org.mitre.oval:tst:19731" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11088"/>
      <state state_ref="oval:org.mitre.oval:ste:6582"/>
    </dpkginfo_test>
    <dpkginfo_test comment="libwxgtk2.4-dbg is earlier than 2.4.5.1.1+etch1" check="all" version="1" id="oval:org.mitre.oval:tst:19730" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11840"/>
      <state state_ref="oval:org.mitre.oval:ste:6482"/>
    </dpkginfo_test>
    <dpkginfo_test comment="libwxgtk2.8-0 is earlier than 2.8.7.1-1.1+lenny1" check="all" version="1" id="oval:org.mitre.oval:tst:19700" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11862"/>
      <state state_ref="oval:org.mitre.oval:ste:6165"/>
    </dpkginfo_test>
    <dpkginfo_test comment="libwxgtk2.4-1 is earlier than 2.4.5.1.1+etch1" check="all" version="1" id="oval:org.mitre.oval:tst:19699" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11210"/>
      <state state_ref="oval:org.mitre.oval:ste:6482"/>
    </dpkginfo_test>
    <dpkginfo_test comment="libwxgtk2.8-dbg is earlier than 2.8.7.1-1.1+lenny1" check="all" version="1" id="oval:org.mitre.oval:tst:19692" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11846"/>
      <state state_ref="oval:org.mitre.oval:ste:6165"/>
    </dpkginfo_test>
    <dpkginfo_test comment="wx2.8-headers is earlier than 2.8.7.1-1.1+lenny1" check="all" version="1" id="oval:org.mitre.oval:tst:19683" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11184"/>
      <state state_ref="oval:org.mitre.oval:ste:6165"/>
    </dpkginfo_test>
    <dpkginfo_test comment="wx2.6-i18n is earlier than 2.6.3.2.2-3+lenny1" check="all" version="1" id="oval:org.mitre.oval:tst:19678" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11609"/>
      <state state_ref="oval:org.mitre.oval:ste:6333"/>
    </dpkginfo_test>
    <dpkginfo_test comment="libwxbase2.6-0 is earlier than 2.6.3.2.1.5+etch1" check="all" version="1" id="oval:org.mitre.oval:tst:19674" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11909"/>
      <state state_ref="oval:org.mitre.oval:ste:6582"/>
    </dpkginfo_test>
    <dpkginfo_test comment="libwxgtk2.6-dbg is earlier than 2.6.3.2.2-3+lenny1" check="all" version="1" id="oval:org.mitre.oval:tst:19652" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11893"/>
      <state state_ref="oval:org.mitre.oval:ste:6333"/>
    </dpkginfo_test>
    <dpkginfo_test comment="wx2.6-headers is earlier than 2.6.3.2.2-3+lenny1" check="all" version="1" id="oval:org.mitre.oval:tst:19591" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11715"/>
      <state state_ref="oval:org.mitre.oval:ste:6333"/>
    </dpkginfo_test>
    <dpkginfo_test comment="libwxbase2.6-dev is earlier than 2.6.3.2.2-3+lenny1" check="all" version="1" id="oval:org.mitre.oval:tst:19581" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11615"/>
      <state state_ref="oval:org.mitre.oval:ste:6333"/>
    </dpkginfo_test>
    <dpkginfo_test comment="wx2.8-i18n is earlier than 2.8.7.1-1.1+lenny1" check="all" version="1" id="oval:org.mitre.oval:tst:19532" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11586"/>
      <state state_ref="oval:org.mitre.oval:ste:6165"/>
    </dpkginfo_test>
    <dpkginfo_test comment="wx-common is earlier than 2.6.3.2.2-3+lenny1" check="all" version="1" id="oval:org.mitre.oval:tst:19508" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11643"/>
      <state state_ref="oval:org.mitre.oval:ste:6333"/>
    </dpkginfo_test>
    <dpkginfo_test comment="libwxbase2.6-dev is earlier than 2.6.3.2.1.5+etch1" check="all" version="1" id="oval:org.mitre.oval:tst:19486" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11615"/>
      <state state_ref="oval:org.mitre.oval:ste:6582"/>
    </dpkginfo_test>
    <dpkginfo_test comment="wx2.8-headers is earlier than 2.8.7.1-1.1+lenny1" check="all" version="1" id="oval:org.mitre.oval:tst:19454" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11184"/>
      <state state_ref="oval:org.mitre.oval:ste:6165"/>
    </dpkginfo_test>
    <dpkginfo_test comment="libwxgtk2.4-dev is earlier than 2.4.5.1.1+etch1" check="all" version="1" id="oval:org.mitre.oval:tst:19430" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11127"/>
      <state state_ref="oval:org.mitre.oval:ste:6482"/>
    </dpkginfo_test>
    <dpkginfo_test comment="libwxgtk2.6-dbg is earlier than 2.6.3.2.1.5+etch1" check="all" version="1" id="oval:org.mitre.oval:tst:19346" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11893"/>
      <state state_ref="oval:org.mitre.oval:ste:6582"/>
    </dpkginfo_test>
    <dpkginfo_test comment="python-wxgtk2.8 is earlier than 2.8.7.1-1.1+lenny1" check="all" version="1" id="oval:org.mitre.oval:tst:19329" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11719"/>
      <state state_ref="oval:org.mitre.oval:ste:6165"/>
    </dpkginfo_test>
    <dpkginfo_test comment="python-wxgtk2.8-dbg is earlier than 2.8.7.1-1.1+lenny1" check="all" version="1" id="oval:org.mitre.oval:tst:19265" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11676"/>
      <state state_ref="oval:org.mitre.oval:ste:6165"/>
    </dpkginfo_test>
    <dpkginfo_test comment="libwxgtk2.6-dev is earlier than 2.6.3.2.2-3+lenny1" check="all" version="1" id="oval:org.mitre.oval:tst:19245" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11876"/>
      <state state_ref="oval:org.mitre.oval:ste:6333"/>
    </dpkginfo_test>
    <dpkginfo_test comment="wx2.8-examples is earlier than 2.8.7.1-1.1+lenny1" check="all" version="1" id="oval:org.mitre.oval:tst:19226" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11647"/>
      <state state_ref="oval:org.mitre.oval:ste:6165"/>
    </dpkginfo_test>
    <dpkginfo_test comment="gstreamer0.10-plugins-bad is earlier than 0.10.7-2+lenny2" check="all" version="1" id="oval:org.mitre.oval:tst:19266" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11344"/>
      <state state_ref="oval:org.mitre.oval:ste:6297"/>
    </dpkginfo_test>
    <dpkginfo_test comment="gstreamer0.10-sdl is earlier than 0.10.7-2+lenny2" check="all" version="1" id="oval:org.mitre.oval:tst:19111" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11287"/>
      <state state_ref="oval:org.mitre.oval:ste:6297"/>
    </dpkginfo_test>
    <dpkginfo_test comment="gstreamer0.10-plugins-bad-doc is earlier than 0.10.7-2+lenny2" check="all" version="1" id="oval:org.mitre.oval:tst:19107" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11642"/>
      <state state_ref="oval:org.mitre.oval:ste:6297"/>
    </dpkginfo_test>
    <dpkginfo_test comment="gstreamer0.10-plugins-bad is earlier than 0.10.3-3.1+etch3" check="all" version="1" id="oval:org.mitre.oval:tst:18889" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11344"/>
      <state state_ref="oval:org.mitre.oval:ste:5903"/>
    </dpkginfo_test>
    <dpkginfo_test comment="gstreamer0.10-plugins-bad-dbg is earlier than 0.10.7-2+lenny2" check="all" version="1" id="oval:org.mitre.oval:tst:18287" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11633"/>
      <state state_ref="oval:org.mitre.oval:ste:6297"/>
    </dpkginfo_test>
    <dpkginfo_test comment="libapt-pkg-dev is earlier than 0.6.46.4-0.1+etch1" check="all" version="1" id="oval:org.mitre.oval:tst:19098" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11417"/>
      <state state_ref="oval:org.mitre.oval:ste:6421"/>
    </dpkginfo_test>
    <dpkginfo_test comment="libapt-pkg-doc is earlier than 0.6.46.4-0.1+etch1" check="all" version="1" id="oval:org.mitre.oval:tst:19094" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11425"/>
      <state state_ref="oval:org.mitre.oval:ste:6421"/>
    </dpkginfo_test>
    <dpkginfo_test comment="apt is earlier than 0.6.46.4-0.1+etch1" check="all" version="1" id="oval:org.mitre.oval:tst:19085" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11158"/>
      <state state_ref="oval:org.mitre.oval:ste:6421"/>
    </dpkginfo_test>
    <dpkginfo_test comment="apt-transport-https is earlier than 0.7.20.2+lenny1" check="all" version="1" id="oval:org.mitre.oval:tst:18992" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11516"/>
      <state state_ref="oval:org.mitre.oval:ste:5426"/>
    </dpkginfo_test>
    <dpkginfo_test comment="libapt-pkg-dev is earlier than 0.7.20.2+lenny1" check="all" version="1" id="oval:org.mitre.oval:tst:18930" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11417"/>
      <state state_ref="oval:org.mitre.oval:ste:5426"/>
    </dpkginfo_test>
    <dpkginfo_test comment="apt-doc is earlier than 0.6.46.4-0.1+etch1" check="all" version="1" id="oval:org.mitre.oval:tst:18921" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:10587"/>
      <state state_ref="oval:org.mitre.oval:ste:6421"/>
    </dpkginfo_test>
    <dpkginfo_test comment="apt-utils is earlier than 0.6.46.4-0.1+etch1" check="all" version="1" id="oval:org.mitre.oval:tst:18849" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11110"/>
      <state state_ref="oval:org.mitre.oval:ste:6421"/>
    </dpkginfo_test>
    <dpkginfo_test comment="apt is earlier than 0.7.20.2+lenny1" check="all" version="1" id="oval:org.mitre.oval:tst:18712" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11158"/>
      <state state_ref="oval:org.mitre.oval:ste:5426"/>
    </dpkginfo_test>
    <dpkginfo_test comment="libapt-pkg-doc is earlier than 0.7.20.2+lenny1" check="all" version="1" id="oval:org.mitre.oval:tst:18385" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11425"/>
      <state state_ref="oval:org.mitre.oval:ste:5426"/>
    </dpkginfo_test>
    <dpkginfo_test comment="apt-utils is earlier than 0.7.20.2+lenny1" check="all" version="1" id="oval:org.mitre.oval:tst:18142" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11110"/>
      <state state_ref="oval:org.mitre.oval:ste:5426"/>
    </dpkginfo_test>
    <dpkginfo_test comment="apt-doc is earlier than 0.7.20.2+lenny1" check="all" version="1" id="oval:org.mitre.oval:tst:18082" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:10587"/>
      <state state_ref="oval:org.mitre.oval:ste:5426"/>
    </dpkginfo_test>
    <dpkginfo_test comment="psi is earlier than 0.11-9" check="all" version="1" id="oval:org.mitre.oval:tst:20057" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11190"/>
      <state state_ref="oval:org.mitre.oval:ste:6501"/>
    </dpkginfo_test>
    <dpkginfo_test comment="ctorrent is earlier than 1.3.4-dnh3.2-1+lenny1" check="all" version="1" id="oval:org.mitre.oval:tst:18425" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11438"/>
      <state state_ref="oval:org.mitre.oval:ste:6141"/>
    </dpkginfo_test>
    <dpkginfo_test comment="changetrack is earlier than 4.3-3+lenny1" check="all" version="1" id="oval:org.mitre.oval:tst:19869" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11166"/>
      <state state_ref="oval:org.mitre.oval:ste:6522"/>
    </dpkginfo_test>
    <dpkginfo_test comment="changetrack is earlier than 4.3-3+etch1" check="all" version="1" id="oval:org.mitre.oval:tst:19507" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11166"/>
      <state state_ref="oval:org.mitre.oval:ste:5904"/>
    </dpkginfo_test>
    <dpkginfo_test comment="libclamav-dev is earlier than 0.90.1dfsg-4etch19" check="all" version="1" id="oval:org.mitre.oval:tst:19054" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:7908"/>
      <state state_ref="oval:org.mitre.oval:ste:6262"/>
    </dpkginfo_test>
    <dpkginfo_test comment="libclamav2 is earlier than 0.90.1dfsg-4etch19" check="all" version="1" id="oval:org.mitre.oval:tst:19045" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:8151"/>
      <state state_ref="oval:org.mitre.oval:ste:6262"/>
    </dpkginfo_test>
    <dpkginfo_test comment="clamav-dbg is earlier than 0.90.1dfsg-4etch19" check="all" version="1" id="oval:org.mitre.oval:tst:18968" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:7772"/>
      <state state_ref="oval:org.mitre.oval:ste:6262"/>
    </dpkginfo_test>
    <dpkginfo_test comment="libclamav5 is earlier than 0.94.dfsg.2-1lenny2" check="all" version="1" id="oval:org.mitre.oval:tst:18967" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11011"/>
      <state state_ref="oval:org.mitre.oval:ste:5990"/>
    </dpkginfo_test>
    <dpkginfo_test comment="libclamav-dev is earlier than 0.94.dfsg.2-1lenny2" check="all" version="1" id="oval:org.mitre.oval:tst:18964" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:7908"/>
      <state state_ref="oval:org.mitre.oval:ste:5990"/>
    </dpkginfo_test>
    <dpkginfo_test comment="clamav is earlier than 0.94.dfsg.2-1lenny2" check="all" version="1" id="oval:org.mitre.oval:tst:18946" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:7963"/>
      <state state_ref="oval:org.mitre.oval:ste:5990"/>
    </dpkginfo_test>
    <dpkginfo_test comment="clamav-base is earlier than 0.94.dfsg.2-1lenny2" check="all" version="1" id="oval:org.mitre.oval:tst:18931" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:7924"/>
      <state state_ref="oval:org.mitre.oval:ste:5990"/>
    </dpkginfo_test>
    <dpkginfo_test comment="clamav-base is earlier than 0.90.1dfsg-4etch19" check="all" version="1" id="oval:org.mitre.oval:tst:18896" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:7924"/>
      <state state_ref="oval:org.mitre.oval:ste:6262"/>
    </dpkginfo_test>
    <dpkginfo_test comment="clamav-daemon is earlier than 0.94.dfsg.2-1lenny2" check="all" version="1" id="oval:org.mitre.oval:tst:18880" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:8010"/>
      <state state_ref="oval:org.mitre.oval:ste:5990"/>
    </dpkginfo_test>
    <dpkginfo_test comment="clamav-testfiles is earlier than 0.90.1dfsg-4etch19" check="all" version="1" id="oval:org.mitre.oval:tst:18877" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:8025"/>
      <state state_ref="oval:org.mitre.oval:ste:6262"/>
    </dpkginfo_test>
    <dpkginfo_test comment="clamav-dbg is earlier than 0.94.dfsg.2-1lenny2" check="all" version="1" id="oval:org.mitre.oval:tst:18859" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:7772"/>
      <state state_ref="oval:org.mitre.oval:ste:5990"/>
    </dpkginfo_test>
    <dpkginfo_test comment="clamav-daemon is earlier than 0.90.1dfsg-4etch19" check="all" version="1" id="oval:org.mitre.oval:tst:18835" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:8010"/>
      <state state_ref="oval:org.mitre.oval:ste:6262"/>
    </dpkginfo_test>
    <dpkginfo_test comment="clamav-freshclam is earlier than 0.94.dfsg.2-1lenny2" check="all" version="1" id="oval:org.mitre.oval:tst:18790" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:8194"/>
      <state state_ref="oval:org.mitre.oval:ste:5990"/>
    </dpkginfo_test>
    <dpkginfo_test comment="clamav-freshclam is earlier than 0.90.1dfsg-4etch19" check="all" version="1" id="oval:org.mitre.oval:tst:18754" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:8194"/>
      <state state_ref="oval:org.mitre.oval:ste:6262"/>
    </dpkginfo_test>
    <dpkginfo_test comment="clamav-testfiles is earlier than 0.94.dfsg.2-1lenny2" check="all" version="1" id="oval:org.mitre.oval:tst:18644" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:8025"/>
      <state state_ref="oval:org.mitre.oval:ste:5990"/>
    </dpkginfo_test>
    <dpkginfo_test comment="clamav-docs is earlier than 0.94.dfsg.2-1lenny2" check="all" version="1" id="oval:org.mitre.oval:tst:18614" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:7866"/>
      <state state_ref="oval:org.mitre.oval:ste:5990"/>
    </dpkginfo_test>
    <dpkginfo_test comment="clamav-milter is earlier than 0.90.1dfsg-4etch19" check="all" version="1" id="oval:org.mitre.oval:tst:18544" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:7358"/>
      <state state_ref="oval:org.mitre.oval:ste:6262"/>
    </dpkginfo_test>
    <dpkginfo_test comment="clamav is earlier than 0.90.1dfsg-4etch19" check="all" version="1" id="oval:org.mitre.oval:tst:18476" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:7963"/>
      <state state_ref="oval:org.mitre.oval:ste:6262"/>
    </dpkginfo_test>
    <dpkginfo_test comment="clamav-milter is earlier than 0.94.dfsg.2-1lenny2" check="all" version="1" id="oval:org.mitre.oval:tst:18391" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:7358"/>
      <state state_ref="oval:org.mitre.oval:ste:5990"/>
    </dpkginfo_test>
    <dpkginfo_test comment="clamav-docs is earlier than 0.90.1dfsg-4etch19" check="all" version="1" id="oval:org.mitre.oval:tst:18191" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:7866"/>
      <state state_ref="oval:org.mitre.oval:ste:6262"/>
    </dpkginfo_test>
    <dpkginfo_test comment="cscope is earlier than 15.6-6+lenny1" check="all" version="1" id="oval:org.mitre.oval:tst:20472" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11710"/>
      <state state_ref="oval:org.mitre.oval:ste:6113"/>
    </dpkginfo_test>
    <dpkginfo_test comment="websvn is earlier than 2.0-4+lenny1" check="all" version="1" id="oval:org.mitre.oval:tst:17582" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:10744"/>
      <state state_ref="oval:org.mitre.oval:ste:6347"/>
    </dpkginfo_test>
    <dpkginfo_test comment="cupsys is earlier than 1.2.7-4+etch9" check="all" version="1" id="oval:org.mitre.oval:tst:19342" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:8013"/>
      <state state_ref="oval:org.mitre.oval:ste:6450"/>
    </dpkginfo_test>
    <dpkginfo_test comment="cupsys-client is earlier than 1.3.8-1+lenny7" check="all" version="1" id="oval:org.mitre.oval:tst:19331" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:8538"/>
      <state state_ref="oval:org.mitre.oval:ste:6068"/>
    </dpkginfo_test>
    <dpkginfo_test comment="libcupsys2-gnutls10 is earlier than 1.2.7-4+etch9" check="all" version="1" id="oval:org.mitre.oval:tst:19318" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:8470"/>
      <state state_ref="oval:org.mitre.oval:ste:6450"/>
    </dpkginfo_test>
    <dpkginfo_test comment="libcupsimage2-dev is earlier than 1.3.8-1+lenny7" check="all" version="1" id="oval:org.mitre.oval:tst:19311" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:8575"/>
      <state state_ref="oval:org.mitre.oval:ste:6068"/>
    </dpkginfo_test>
    <dpkginfo_test comment="cupsys-client is earlier than 1.2.7-4+etch9" check="all" version="1" id="oval:org.mitre.oval:tst:19310" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:8538"/>
      <state state_ref="oval:org.mitre.oval:ste:6450"/>
    </dpkginfo_test>
    <dpkginfo_test comment="cups is earlier than 1.3.8-1+lenny7" check="all" version="1" id="oval:org.mitre.oval:tst:19288" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11475"/>
      <state state_ref="oval:org.mitre.oval:ste:6068"/>
    </dpkginfo_test>
    <dpkginfo_test comment="cupsys-bsd is earlier than 1.3.8-1+lenny7" check="all" version="1" id="oval:org.mitre.oval:tst:19285" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:8416"/>
      <state state_ref="oval:org.mitre.oval:ste:6068"/>
    </dpkginfo_test>
    <dpkginfo_test comment="cupsys-common is earlier than 1.2.7-4+etch9" check="all" version="1" id="oval:org.mitre.oval:tst:19277" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:8526"/>
      <state state_ref="oval:org.mitre.oval:ste:6450"/>
    </dpkginfo_test>
    <dpkginfo_test comment="libcupsys2-dev is earlier than 1.3.8-1+lenny7" check="all" version="1" id="oval:org.mitre.oval:tst:19275" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:7982"/>
      <state state_ref="oval:org.mitre.oval:ste:6068"/>
    </dpkginfo_test>
    <dpkginfo_test comment="libcups2-dev is earlier than 1.3.8-1+lenny7" check="all" version="1" id="oval:org.mitre.oval:tst:19271" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:10868"/>
      <state state_ref="oval:org.mitre.oval:ste:6068"/>
    </dpkginfo_test>
    <dpkginfo_test comment="libcupsys2 is earlier than 1.3.8-1+lenny7" check="all" version="1" id="oval:org.mitre.oval:tst:19225" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:8261"/>
      <state state_ref="oval:org.mitre.oval:ste:6068"/>
    </dpkginfo_test>
    <dpkginfo_test comment="cupsys-dbg is earlier than 1.3.8-1+lenny7" check="all" version="1" id="oval:org.mitre.oval:tst:19155" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:8422"/>
      <state state_ref="oval:org.mitre.oval:ste:6068"/>
    </dpkginfo_test>
    <dpkginfo_test comment="libcupsimage2 is earlier than 1.2.7-4+etch9" check="all" version="1" id="oval:org.mitre.oval:tst:19125" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:8515"/>
      <state state_ref="oval:org.mitre.oval:ste:6450"/>
    </dpkginfo_test>
    <dpkginfo_test comment="libcupsimage2 is earlier than 1.3.8-1+lenny7" check="all" version="1" id="oval:org.mitre.oval:tst:19104" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:8515"/>
      <state state_ref="oval:org.mitre.oval:ste:6068"/>
    </dpkginfo_test>
    <dpkginfo_test comment="cups-common is earlier than 1.3.8-1+lenny7" check="all" version="1" id="oval:org.mitre.oval:tst:19068" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11341"/>
      <state state_ref="oval:org.mitre.oval:ste:6068"/>
    </dpkginfo_test>
    <dpkginfo_test comment="libcups2 is earlier than 1.3.8-1+lenny7" check="all" version="1" id="oval:org.mitre.oval:tst:18969" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11340"/>
      <state state_ref="oval:org.mitre.oval:ste:6068"/>
    </dpkginfo_test>
    <dpkginfo_test comment="cups-bsd is earlier than 1.3.8-1+lenny7" check="all" version="1" id="oval:org.mitre.oval:tst:18902" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11223"/>
      <state state_ref="oval:org.mitre.oval:ste:6068"/>
    </dpkginfo_test>
    <dpkginfo_test comment="cups-client is earlier than 1.3.8-1+lenny7" check="all" version="1" id="oval:org.mitre.oval:tst:18803" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11370"/>
      <state state_ref="oval:org.mitre.oval:ste:6068"/>
    </dpkginfo_test>
    <dpkginfo_test comment="libcupsimage2-dev is earlier than 1.2.7-4+etch9" check="all" version="1" id="oval:org.mitre.oval:tst:18729" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:8575"/>
      <state state_ref="oval:org.mitre.oval:ste:6450"/>
    </dpkginfo_test>
    <dpkginfo_test comment="cupsys is earlier than 1.3.8-1+lenny7" check="all" version="1" id="oval:org.mitre.oval:tst:18634" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:8013"/>
      <state state_ref="oval:org.mitre.oval:ste:6068"/>
    </dpkginfo_test>
    <dpkginfo_test comment="libcupsys2 is earlier than 1.2.7-4+etch9" check="all" version="1" id="oval:org.mitre.oval:tst:18575" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:8261"/>
      <state state_ref="oval:org.mitre.oval:ste:6450"/>
    </dpkginfo_test>
    <dpkginfo_test comment="cupsys-dbg is earlier than 1.2.7-4+etch9" check="all" version="1" id="oval:org.mitre.oval:tst:18534" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:8422"/>
      <state state_ref="oval:org.mitre.oval:ste:6450"/>
    </dpkginfo_test>
    <dpkginfo_test comment="libcupsys2-dev is earlier than 1.2.7-4+etch9" check="all" version="1" id="oval:org.mitre.oval:tst:18521" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:7982"/>
      <state state_ref="oval:org.mitre.oval:ste:6450"/>
    </dpkginfo_test>
    <dpkginfo_test comment="cups-dbg is earlier than 1.3.8-1+lenny7" check="all" version="1" id="oval:org.mitre.oval:tst:18490" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11245"/>
      <state state_ref="oval:org.mitre.oval:ste:6068"/>
    </dpkginfo_test>
    <dpkginfo_test comment="cupsys-bsd is earlier than 1.2.7-4+etch9" check="all" version="1" id="oval:org.mitre.oval:tst:18483" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:8416"/>
      <state state_ref="oval:org.mitre.oval:ste:6450"/>
    </dpkginfo_test>
    <dpkginfo_test comment="cupsys-common is earlier than 1.3.8-1+lenny7" check="all" version="1" id="oval:org.mitre.oval:tst:18394" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:8526"/>
      <state state_ref="oval:org.mitre.oval:ste:6068"/>
    </dpkginfo_test>
    <dpkginfo_test comment="libgd2-xpm is earlier than 2.0.33-5.2etch2" check="all" version="1" id="oval:org.mitre.oval:tst:19482" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11133"/>
      <state state_ref="oval:org.mitre.oval:ste:6230"/>
    </dpkginfo_test>
    <dpkginfo_test comment="libgd2-xpm is earlier than 2.0.36~rc1~dfsg-3+lenny1" check="all" version="1" id="oval:org.mitre.oval:tst:19475" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11133"/>
      <state state_ref="oval:org.mitre.oval:ste:6494"/>
    </dpkginfo_test>
    <dpkginfo_test comment="libgd2-noxpm is earlier than 2.0.36~rc1~dfsg-3+lenny1" check="all" version="1" id="oval:org.mitre.oval:tst:19448" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11100"/>
      <state state_ref="oval:org.mitre.oval:ste:6494"/>
    </dpkginfo_test>
    <dpkginfo_test comment="libgd2-xpm-dev is earlier than 2.0.33-5.2etch2" check="all" version="1" id="oval:org.mitre.oval:tst:19223" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11103"/>
      <state state_ref="oval:org.mitre.oval:ste:6230"/>
    </dpkginfo_test>
    <dpkginfo_test comment="libgd-tools is earlier than 2.0.33-5.2etch2" check="all" version="1" id="oval:org.mitre.oval:tst:19188" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11037"/>
      <state state_ref="oval:org.mitre.oval:ste:6230"/>
    </dpkginfo_test>
    <dpkginfo_test comment="libgd2-xpm-dev is earlier than 2.0.36~rc1~dfsg-3+lenny1" check="all" version="1" id="oval:org.mitre.oval:tst:19143" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11103"/>
      <state state_ref="oval:org.mitre.oval:ste:6494"/>
    </dpkginfo_test>
    <dpkginfo_test comment="libgd-tools is earlier than 2.0.36~rc1~dfsg-3+lenny1" check="all" version="1" id="oval:org.mitre.oval:tst:19135" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11037"/>
      <state state_ref="oval:org.mitre.oval:ste:6494"/>
    </dpkginfo_test>
    <dpkginfo_test comment="libgd2-noxpm is earlier than 2.0.33-5.2etch2" check="all" version="1" id="oval:org.mitre.oval:tst:19026" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11100"/>
      <state state_ref="oval:org.mitre.oval:ste:6230"/>
    </dpkginfo_test>
    <dpkginfo_test comment="libgd2-noxpm-dev is earlier than 2.0.36~rc1~dfsg-3+lenny1" check="all" version="1" id="oval:org.mitre.oval:tst:19013" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11064"/>
      <state state_ref="oval:org.mitre.oval:ste:6494"/>
    </dpkginfo_test>
    <dpkginfo_test comment="libgd2-noxpm-dev is earlier than 2.0.33-5.2etch2" check="all" version="1" id="oval:org.mitre.oval:tst:18844" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11064"/>
      <state state_ref="oval:org.mitre.oval:ste:6230"/>
    </dpkginfo_test>
    <dpkginfo_test comment="libfreetype6 is earlier than 2.3.7-2+lenny1" check="all" version="1" id="oval:org.mitre.oval:tst:18761" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11428"/>
      <state state_ref="oval:org.mitre.oval:ste:6308"/>
    </dpkginfo_test>
    <dpkginfo_test comment="freetype2-demos is earlier than 2.3.7-2+lenny1" check="all" version="1" id="oval:org.mitre.oval:tst:18738" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11490"/>
      <state state_ref="oval:org.mitre.oval:ste:6308"/>
    </dpkginfo_test>
    <dpkginfo_test comment="freetype2-demos is earlier than 2.2.1-5+etch4" check="all" version="1" id="oval:org.mitre.oval:tst:18549" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11490"/>
      <state state_ref="oval:org.mitre.oval:ste:6125"/>
    </dpkginfo_test>
    <dpkginfo_test comment="libfreetype6-dev is earlier than 2.2.1-5+etch4" check="all" version="1" id="oval:org.mitre.oval:tst:18524" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11123"/>
      <state state_ref="oval:org.mitre.oval:ste:6125"/>
    </dpkginfo_test>
    <dpkginfo_test comment="libfreetype6-dev is earlier than 2.3.7-2+lenny1" check="all" version="1" id="oval:org.mitre.oval:tst:18520" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11123"/>
      <state state_ref="oval:org.mitre.oval:ste:6308"/>
    </dpkginfo_test>
    <dpkginfo_test comment="libfreetype6 is earlier than 2.2.1-5+etch4" check="all" version="1" id="oval:org.mitre.oval:tst:18342" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11428"/>
      <state state_ref="oval:org.mitre.oval:ste:6125"/>
    </dpkginfo_test>
    <dpkginfo_test comment="pidgin-data is earlier than 2.4.3-4lenny5" check="all" version="1" id="oval:org.mitre.oval:tst:19451" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:10503"/>
      <state state_ref="oval:org.mitre.oval:ste:5860"/>
    </dpkginfo_test>
    <dpkginfo_test comment="pidgin-dbg is earlier than 2.4.3-4lenny5" check="all" version="1" id="oval:org.mitre.oval:tst:19383" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:9749"/>
      <state state_ref="oval:org.mitre.oval:ste:5860"/>
    </dpkginfo_test>
    <dpkginfo_test comment="libpurple-bin is earlier than 2.4.3-4lenny5" check="all" version="1" id="oval:org.mitre.oval:tst:19352" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:10543"/>
      <state state_ref="oval:org.mitre.oval:ste:5860"/>
    </dpkginfo_test>
    <dpkginfo_test comment="finch is earlier than 2.4.3-4lenny5" check="all" version="1" id="oval:org.mitre.oval:tst:19231" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:9976"/>
      <state state_ref="oval:org.mitre.oval:ste:5860"/>
    </dpkginfo_test>
    <dpkginfo_test comment="finch-dev is earlier than 2.4.3-4lenny5" check="all" version="1" id="oval:org.mitre.oval:tst:18904" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:10713"/>
      <state state_ref="oval:org.mitre.oval:ste:5860"/>
    </dpkginfo_test>
    <dpkginfo_test comment="pidgin is earlier than 2.4.3-4lenny5" check="all" version="1" id="oval:org.mitre.oval:tst:18867" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:10640"/>
      <state state_ref="oval:org.mitre.oval:ste:5860"/>
    </dpkginfo_test>
    <dpkginfo_test comment="pidgin-dev is earlier than 2.4.3-4lenny5" check="all" version="1" id="oval:org.mitre.oval:tst:18847" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:9897"/>
      <state state_ref="oval:org.mitre.oval:ste:5860"/>
    </dpkginfo_test>
    <dpkginfo_test comment="libpurple0 is earlier than 2.4.3-4lenny5" check="all" version="1" id="oval:org.mitre.oval:tst:18808" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:10703"/>
      <state state_ref="oval:org.mitre.oval:ste:5860"/>
    </dpkginfo_test>
    <dpkginfo_test comment="libpurple-dev is earlier than 2.4.3-4lenny5" check="all" version="1" id="oval:org.mitre.oval:tst:18722" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:10588"/>
      <state state_ref="oval:org.mitre.oval:ste:5860"/>
    </dpkginfo_test>
    <dpkginfo_test comment="libvolume-id0 is earlier than 0.105-4etch1" check="all" version="1" id="oval:org.mitre.oval:tst:19015" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11499"/>
      <state state_ref="oval:org.mitre.oval:ste:6036"/>
    </dpkginfo_test>
    <dpkginfo_test comment="udev is earlier than 0.105-4etch1" check="all" version="1" id="oval:org.mitre.oval:tst:18997" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11373"/>
      <state state_ref="oval:org.mitre.oval:ste:6036"/>
    </dpkginfo_test>
    <dpkginfo_test comment="libvolume-id0 is earlier than 0.125-7+lenny1" check="all" version="1" id="oval:org.mitre.oval:tst:18915" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11499"/>
      <state state_ref="oval:org.mitre.oval:ste:6184"/>
    </dpkginfo_test>
    <dpkginfo_test comment="udev is earlier than 0.125-7+lenny1" check="all" version="1" id="oval:org.mitre.oval:tst:18875" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11373"/>
      <state state_ref="oval:org.mitre.oval:ste:6184"/>
    </dpkginfo_test>
    <dpkginfo_test comment="libvolume-id-dev is earlier than 0.125-7+lenny1" check="all" version="1" id="oval:org.mitre.oval:tst:18836" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11125"/>
      <state state_ref="oval:org.mitre.oval:ste:6184"/>
    </dpkginfo_test>
    <dpkginfo_test comment="libvolume-id-dev is earlier than 0.105-4etch1" check="all" version="1" id="oval:org.mitre.oval:tst:18811" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11125"/>
      <state state_ref="oval:org.mitre.oval:ste:6036"/>
    </dpkginfo_test>
    <dpkginfo_test comment="php-mail is earlier than 1.1.6-2+etch1" check="all" version="1" id="oval:org.mitre.oval:tst:19439" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:10699"/>
      <state state_ref="oval:org.mitre.oval:ste:6481"/>
    </dpkginfo_test>
    <dpkginfo_test comment="php-mail is earlier than 1.1.14-1+lenny1" check="all" version="1" id="oval:org.mitre.oval:tst:18641" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:10699"/>
      <state state_ref="oval:org.mitre.oval:ste:5938"/>
    </dpkginfo_test>
    <dpkginfo_test comment="yaws-yapp is earlier than 1.77-3+lenny1" check="all" version="1" id="oval:org.mitre.oval:tst:20045" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11828"/>
      <state state_ref="oval:org.mitre.oval:ste:5915"/>
    </dpkginfo_test>
    <dpkginfo_test comment="yaws-wiki is earlier than 1.77-3+lenny1" check="all" version="1" id="oval:org.mitre.oval:tst:20039" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11485"/>
      <state state_ref="oval:org.mitre.oval:ste:5915"/>
    </dpkginfo_test>
    <dpkginfo_test comment="yaws-mail is earlier than 1.77-3+lenny1" check="all" version="1" id="oval:org.mitre.oval:tst:20038" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:10906"/>
      <state state_ref="oval:org.mitre.oval:ste:5915"/>
    </dpkginfo_test>
    <dpkginfo_test comment="yaws is earlier than 1.77-3+lenny1" check="all" version="1" id="oval:org.mitre.oval:tst:20001" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11779"/>
      <state state_ref="oval:org.mitre.oval:ste:5915"/>
    </dpkginfo_test>
    <dpkginfo_test comment="yaws-chat is earlier than 1.77-3+lenny1" check="all" version="1" id="oval:org.mitre.oval:tst:19750" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11689"/>
      <state state_ref="oval:org.mitre.oval:ste:5915"/>
    </dpkginfo_test>
    <dpkginfo_test comment="yaws is earlier than 1.65-4etch1" check="all" version="1" id="oval:org.mitre.oval:tst:19697" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11779"/>
      <state state_ref="oval:org.mitre.oval:ste:6192"/>
    </dpkginfo_test>
    <dpkginfo_test comment="imagemagick is earlier than 6.3.7.9.dfsg2-1~lenny3" check="all" version="1" id="oval:org.mitre.oval:tst:19229" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11383"/>
      <state state_ref="oval:org.mitre.oval:ste:6431"/>
    </dpkginfo_test>
    <dpkginfo_test comment="libmagick10 is earlier than 6.3.7.9.dfsg2-1~lenny3" check="all" version="1" id="oval:org.mitre.oval:tst:19187" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11594"/>
      <state state_ref="oval:org.mitre.oval:ste:6431"/>
    </dpkginfo_test>
    <dpkginfo_test comment="libmagick++9c2a is earlier than 6.2.4.5.dfsg1-0.15+etch1" check="all" version="1" id="oval:org.mitre.oval:tst:19185" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11534"/>
      <state state_ref="oval:org.mitre.oval:ste:6094"/>
    </dpkginfo_test>
    <dpkginfo_test comment="perlmagick is earlier than 6.2.4.5.dfsg1-0.15+etch1" check="all" version="1" id="oval:org.mitre.oval:tst:19173" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11302"/>
      <state state_ref="oval:org.mitre.oval:ste:6094"/>
    </dpkginfo_test>
    <dpkginfo_test comment="libmagick++10 is earlier than 6.3.7.9.dfsg2-1~lenny3" check="all" version="1" id="oval:org.mitre.oval:tst:19162" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:10816"/>
      <state state_ref="oval:org.mitre.oval:ste:6431"/>
    </dpkginfo_test>
    <dpkginfo_test comment="libmagick++9-dev is earlier than 6.3.7.9.dfsg2-1~lenny3" check="all" version="1" id="oval:org.mitre.oval:tst:19014" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11403"/>
      <state state_ref="oval:org.mitre.oval:ste:6431"/>
    </dpkginfo_test>
    <dpkginfo_test comment="libmagick9 is earlier than 6.2.4.5.dfsg1-0.15+etch1" check="all" version="1" id="oval:org.mitre.oval:tst:18989" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11551"/>
      <state state_ref="oval:org.mitre.oval:ste:6094"/>
    </dpkginfo_test>
    <dpkginfo_test comment="libmagick9-dev is earlier than 6.3.7.9.dfsg2-1~lenny3" check="all" version="1" id="oval:org.mitre.oval:tst:18985" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11526"/>
      <state state_ref="oval:org.mitre.oval:ste:6431"/>
    </dpkginfo_test>
    <dpkginfo_test comment="libmagick++9-dev is earlier than 6.2.4.5.dfsg1-0.15+etch1" check="all" version="1" id="oval:org.mitre.oval:tst:18932" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11403"/>
      <state state_ref="oval:org.mitre.oval:ste:6094"/>
    </dpkginfo_test>
    <dpkginfo_test comment="libmagick9-dev is earlier than 6.2.4.5.dfsg1-0.15+etch1" check="all" version="1" id="oval:org.mitre.oval:tst:18832" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11526"/>
      <state state_ref="oval:org.mitre.oval:ste:6094"/>
    </dpkginfo_test>
    <dpkginfo_test comment="perlmagick is earlier than 6.3.7.9.dfsg2-1~lenny3" check="all" version="1" id="oval:org.mitre.oval:tst:18813" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11302"/>
      <state state_ref="oval:org.mitre.oval:ste:6431"/>
    </dpkginfo_test>
    <dpkginfo_test comment="imagemagick is earlier than 6.2.4.5.dfsg1-0.15+etch1" check="all" version="1" id="oval:org.mitre.oval:tst:18670" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11383"/>
      <state state_ref="oval:org.mitre.oval:ste:6094"/>
    </dpkginfo_test>
    <dpkginfo_test comment="mldonkey-server is earlier than 2.9.5-2+lenny1" check="all" version="1" id="oval:org.mitre.oval:tst:19453" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11648"/>
      <state state_ref="oval:org.mitre.oval:ste:6007"/>
    </dpkginfo_test>
    <dpkginfo_test comment="mldonkey-gui is earlier than 2.9.5-2+lenny1" check="all" version="1" id="oval:org.mitre.oval:tst:19392" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11644"/>
      <state state_ref="oval:org.mitre.oval:ste:6007"/>
    </dpkginfo_test>
    <dpkginfo_test comment="apache2-mpm-prefork is earlier than 2.2.9-10+lenny6" check="all" version="1" id="oval:org.mitre.oval:tst:19473" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:10645"/>
      <state state_ref="oval:org.mitre.oval:ste:6372"/>
    </dpkginfo_test>
    <dpkginfo_test comment="apache2-mpm-event is earlier than 2.2.3-4+etch11" check="all" version="1" id="oval:org.mitre.oval:tst:19469" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:10264"/>
      <state state_ref="oval:org.mitre.oval:ste:6385"/>
    </dpkginfo_test>
    <dpkginfo_test comment="apache2 is earlier than 2.2.9-10+lenny6" check="all" version="1" id="oval:org.mitre.oval:tst:19459" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:10648"/>
      <state state_ref="oval:org.mitre.oval:ste:6372"/>
    </dpkginfo_test>
    <dpkginfo_test comment="apache2-mpm-perchild is earlier than 2.2.3-4+etch11" check="all" version="1" id="oval:org.mitre.oval:tst:19447" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:10483"/>
      <state state_ref="oval:org.mitre.oval:ste:6385"/>
    </dpkginfo_test>
    <dpkginfo_test comment="apache2-doc is earlier than 2.2.3-4+etch11" check="all" version="1" id="oval:org.mitre.oval:tst:19425" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:10628"/>
      <state state_ref="oval:org.mitre.oval:ste:6385"/>
    </dpkginfo_test>
    <dpkginfo_test comment="apache2.2-common is earlier than 2.2.3-4+etch11" check="all" version="1" id="oval:org.mitre.oval:tst:19409" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:10626"/>
      <state state_ref="oval:org.mitre.oval:ste:6385"/>
    </dpkginfo_test>
    <dpkginfo_test comment="apache2-src is earlier than 2.2.9-10+lenny6" check="all" version="1" id="oval:org.mitre.oval:tst:19402" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:10286"/>
      <state state_ref="oval:org.mitre.oval:ste:6372"/>
    </dpkginfo_test>
    <dpkginfo_test comment="apache2-utils is earlier than 2.2.3-4+etch11" check="all" version="1" id="oval:org.mitre.oval:tst:19385" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:9781"/>
      <state state_ref="oval:org.mitre.oval:ste:6385"/>
    </dpkginfo_test>
    <dpkginfo_test comment="apache2-dbg is earlier than 2.2.9-10+lenny6" check="all" version="1" id="oval:org.mitre.oval:tst:19347" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:10441"/>
      <state state_ref="oval:org.mitre.oval:ste:6372"/>
    </dpkginfo_test>
    <dpkginfo_test comment="apache2-suexec-custom is earlier than 2.2.9-10+lenny6" check="all" version="1" id="oval:org.mitre.oval:tst:19323" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:10453"/>
      <state state_ref="oval:org.mitre.oval:ste:6372"/>
    </dpkginfo_test>
    <dpkginfo_test comment="apache2-mpm-event is earlier than 2.2.9-10+lenny6" check="all" version="1" id="oval:org.mitre.oval:tst:19299" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:10264"/>
      <state state_ref="oval:org.mitre.oval:ste:6372"/>
    </dpkginfo_test>
    <dpkginfo_test comment="apache2-utils is earlier than 2.2.9-10+lenny6" check="all" version="1" id="oval:org.mitre.oval:tst:19247" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:9781"/>
      <state state_ref="oval:org.mitre.oval:ste:6372"/>
    </dpkginfo_test>
    <dpkginfo_test comment="apache2-mpm-worker is earlier than 2.2.3-4+etch11" check="all" version="1" id="oval:org.mitre.oval:tst:19234" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:10570"/>
      <state state_ref="oval:org.mitre.oval:ste:6385"/>
    </dpkginfo_test>
    <dpkginfo_test comment="apache2-suexec is earlier than 2.2.9-10+lenny6" check="all" version="1" id="oval:org.mitre.oval:tst:19222" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:10639"/>
      <state state_ref="oval:org.mitre.oval:ste:6372"/>
    </dpkginfo_test>
    <dpkginfo_test comment="apache2-src is earlier than 2.2.3-4+etch11" check="all" version="1" id="oval:org.mitre.oval:tst:19160" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:10286"/>
      <state state_ref="oval:org.mitre.oval:ste:6385"/>
    </dpkginfo_test>
    <dpkginfo_test comment="apache2-mpm-worker is earlier than 2.2.9-10+lenny6" check="all" version="1" id="oval:org.mitre.oval:tst:19133" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:10570"/>
      <state state_ref="oval:org.mitre.oval:ste:6372"/>
    </dpkginfo_test>
    <dpkginfo_test comment="apache2.2-common is earlier than 2.2.9-10+lenny6" check="all" version="1" id="oval:org.mitre.oval:tst:19089" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:10626"/>
      <state state_ref="oval:org.mitre.oval:ste:6372"/>
    </dpkginfo_test>
    <dpkginfo_test comment="apache2-mpm-itk is earlier than 2.2.6-02-1+lenny2+b2" check="all" version="1" id="oval:org.mitre.oval:tst:19074" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:10636"/>
      <state state_ref="oval:org.mitre.oval:ste:5797"/>
    </dpkginfo_test>
    <dpkginfo_test comment="apache2-prefork-dev is earlier than 2.2.3-4+etch11" check="all" version="1" id="oval:org.mitre.oval:tst:19038" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:10566"/>
      <state state_ref="oval:org.mitre.oval:ste:6385"/>
    </dpkginfo_test>
    <dpkginfo_test comment="apache2-threaded-dev is earlier than 2.2.9-10+lenny6" check="all" version="1" id="oval:org.mitre.oval:tst:18986" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:10637"/>
      <state state_ref="oval:org.mitre.oval:ste:6372"/>
    </dpkginfo_test>
    <dpkginfo_test comment="apache2-doc is earlier than 2.2.9-10+lenny6" check="all" version="1" id="oval:org.mitre.oval:tst:18971" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:10628"/>
      <state state_ref="oval:org.mitre.oval:ste:6372"/>
    </dpkginfo_test>
    <dpkginfo_test comment="apache2-mpm-itk is earlier than 2.2.3-01-2+etch4+b1" check="all" version="1" id="oval:org.mitre.oval:tst:18893" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:10636"/>
      <state state_ref="oval:org.mitre.oval:ste:6402"/>
    </dpkginfo_test>
    <dpkginfo_test comment="apache2-mpm-prefork is earlier than 2.2.3-4+etch11" check="all" version="1" id="oval:org.mitre.oval:tst:18829" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:10645"/>
      <state state_ref="oval:org.mitre.oval:ste:6385"/>
    </dpkginfo_test>
    <dpkginfo_test comment="apache2 is earlier than 2.2.3-4+etch11" check="all" version="1" id="oval:org.mitre.oval:tst:18828" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:10648"/>
      <state state_ref="oval:org.mitre.oval:ste:6385"/>
    </dpkginfo_test>
    <dpkginfo_test comment="apache2-prefork-dev is earlier than 2.2.9-10+lenny6" check="all" version="1" id="oval:org.mitre.oval:tst:18822" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:10566"/>
      <state state_ref="oval:org.mitre.oval:ste:6372"/>
    </dpkginfo_test>
    <dpkginfo_test comment="apache2-threaded-dev is earlier than 2.2.3-4+etch11" check="all" version="1" id="oval:org.mitre.oval:tst:18734" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:10637"/>
      <state state_ref="oval:org.mitre.oval:ste:6385"/>
    </dpkginfo_test>
    <dpkginfo_test comment="nagios3-common is earlier than 3.0.6-4~lenny2" check="all" version="1" id="oval:org.mitre.oval:tst:17329" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11461"/>
      <state state_ref="oval:org.mitre.oval:ste:6248"/>
    </dpkginfo_test>
    <dpkginfo_test comment="nagios2-dbg is earlier than 2.6-2+etch3" check="all" version="1" id="oval:org.mitre.oval:tst:17299" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:8510"/>
      <state state_ref="oval:org.mitre.oval:ste:6078"/>
    </dpkginfo_test>
    <dpkginfo_test comment="nagios2 is earlier than 2.6-2+etch3" check="all" version="1" id="oval:org.mitre.oval:tst:17275" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:8833"/>
      <state state_ref="oval:org.mitre.oval:ste:6078"/>
    </dpkginfo_test>
    <dpkginfo_test comment="nagios3-dbg is earlier than 3.0.6-4~lenny2" check="all" version="1" id="oval:org.mitre.oval:tst:17221" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11216"/>
      <state state_ref="oval:org.mitre.oval:ste:6248"/>
    </dpkginfo_test>
    <dpkginfo_test comment="nagios2-common is earlier than 2.6-2+etch3" check="all" version="1" id="oval:org.mitre.oval:tst:17108" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:8790"/>
      <state state_ref="oval:org.mitre.oval:ste:6078"/>
    </dpkginfo_test>
    <dpkginfo_test comment="nagios2-doc is earlier than 2.6-2+etch3" check="all" version="1" id="oval:org.mitre.oval:tst:17015" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:8803"/>
      <state state_ref="oval:org.mitre.oval:ste:6078"/>
    </dpkginfo_test>
    <dpkginfo_test comment="nagios3-doc is earlier than 3.0.6-4~lenny2" check="all" version="1" id="oval:org.mitre.oval:tst:16887" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11195"/>
      <state state_ref="oval:org.mitre.oval:ste:6248"/>
    </dpkginfo_test>
    <dpkginfo_test comment="nagios3 is earlier than 3.0.6-4~lenny2" check="all" version="1" id="oval:org.mitre.oval:tst:16380" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11445"/>
      <state state_ref="oval:org.mitre.oval:ste:6248"/>
    </dpkginfo_test>
    <dpkginfo_test comment="libaprutil1-dev is earlier than 1.2.12+dfsg-8+lenny2" check="all" version="1" id="oval:org.mitre.oval:tst:18582" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11238"/>
      <state state_ref="oval:org.mitre.oval:ste:6034"/>
    </dpkginfo_test>
    <dpkginfo_test comment="libaprutil1-dbg is earlier than 1.2.7+dfsg-2+etch2" check="all" version="1" id="oval:org.mitre.oval:tst:18566" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11085"/>
      <state state_ref="oval:org.mitre.oval:ste:6154"/>
    </dpkginfo_test>
    <dpkginfo_test comment="libaprutil1-dev is earlier than 1.2.7+dfsg-2+etch2" check="all" version="1" id="oval:org.mitre.oval:tst:18562" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11238"/>
      <state state_ref="oval:org.mitre.oval:ste:6154"/>
    </dpkginfo_test>
    <dpkginfo_test comment="libaprutil1-dbg is earlier than 1.2.12+dfsg-8+lenny2" check="all" version="1" id="oval:org.mitre.oval:tst:18469" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11085"/>
      <state state_ref="oval:org.mitre.oval:ste:6034"/>
    </dpkginfo_test>
    <dpkginfo_test comment="libaprutil1 is earlier than 1.2.12+dfsg-8+lenny2" check="all" version="1" id="oval:org.mitre.oval:tst:18330" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11315"/>
      <state state_ref="oval:org.mitre.oval:ste:6034"/>
    </dpkginfo_test>
    <dpkginfo_test comment="libaprutil1 is earlier than 1.2.7+dfsg-2+etch2" check="all" version="1" id="oval:org.mitre.oval:tst:17861" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11315"/>
      <state state_ref="oval:org.mitre.oval:ste:6154"/>
    </dpkginfo_test>
    <dpkginfo_test comment="multipath-tools is earlier than 0.4.8-14+lenny1" check="all" version="1" id="oval:org.mitre.oval:tst:16626" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11153"/>
      <state state_ref="oval:org.mitre.oval:ste:5712"/>
    </dpkginfo_test>
    <dpkginfo_test comment="kpartx is earlier than 0.4.8-14+lenny1" check="all" version="1" id="oval:org.mitre.oval:tst:16625" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:10273"/>
      <state state_ref="oval:org.mitre.oval:ste:5712"/>
    </dpkginfo_test>
    <dpkginfo_test comment="multipath-tools is earlier than 0.4.7-1.1etch2" check="all" version="1" id="oval:org.mitre.oval:tst:16582" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11153"/>
      <state state_ref="oval:org.mitre.oval:ste:5961"/>
    </dpkginfo_test>
    <dpkginfo_test comment="multipath-tools-boot is earlier than 0.4.8-14+lenny1" check="all" version="1" id="oval:org.mitre.oval:tst:16216" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:10980"/>
      <state state_ref="oval:org.mitre.oval:ste:5712"/>
    </dpkginfo_test>
    <dpkginfo_test comment="tunapie is earlier than 2.1.8-2" check="all" version="1" id="oval:org.mitre.oval:tst:16706" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:10625"/>
      <state state_ref="oval:org.mitre.oval:ste:6049"/>
    </dpkginfo_test>
    <dpkginfo_test comment="ejabberd is earlier than 2.0.1-6+lenny1" check="all" version="1" id="oval:org.mitre.oval:tst:18688" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11524"/>
      <state state_ref="oval:org.mitre.oval:ste:6368"/>
    </dpkginfo_test>
    <dpkginfo_test comment="mahara is earlier than 1.0.4-4+lenny4" check="all" version="1" id="oval:org.mitre.oval:tst:17305" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11453"/>
      <state state_ref="oval:org.mitre.oval:ste:5777"/>
    </dpkginfo_test>
    <dpkginfo_test comment="mahara-apache2 is earlier than 1.0.4-4+lenny4" check="all" version="1" id="oval:org.mitre.oval:tst:16733" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11385"/>
      <state state_ref="oval:org.mitre.oval:ste:5777"/>
    </dpkginfo_test>
    <dpkginfo_test comment="krb5-user is earlier than 1.4.4-7etch7" check="all" version="1" id="oval:org.mitre.oval:tst:16842" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:10804"/>
      <state state_ref="oval:org.mitre.oval:ste:5836"/>
    </dpkginfo_test>
    <dpkginfo_test comment="libkrb5-dev is earlier than 1.6.dfsg.4~beta1-5lenny1" check="all" version="1" id="oval:org.mitre.oval:tst:16839" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11178"/>
      <state state_ref="oval:org.mitre.oval:ste:5313"/>
    </dpkginfo_test>
    <dpkginfo_test comment="krb5-rsh-server is earlier than 1.4.4-7etch7" check="all" version="1" id="oval:org.mitre.oval:tst:16837" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:10519"/>
      <state state_ref="oval:org.mitre.oval:ste:5836"/>
    </dpkginfo_test>
    <dpkginfo_test comment="krb5-clients is earlier than 1.6.dfsg.4~beta1-5lenny1" check="all" version="1" id="oval:org.mitre.oval:tst:16836" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11112"/>
      <state state_ref="oval:org.mitre.oval:ste:5313"/>
    </dpkginfo_test>
    <dpkginfo_test comment="krb5-user is earlier than 1.6.dfsg.4~beta1-5lenny1" check="all" version="1" id="oval:org.mitre.oval:tst:16819" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:10804"/>
      <state state_ref="oval:org.mitre.oval:ste:5313"/>
    </dpkginfo_test>
    <dpkginfo_test comment="libkrb53 is earlier than 1.4.4-7etch7" check="all" version="1" id="oval:org.mitre.oval:tst:16814" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:10557"/>
      <state state_ref="oval:org.mitre.oval:ste:5836"/>
    </dpkginfo_test>
    <dpkginfo_test comment="libkrb5-dbg is earlier than 1.4.4-7etch7" check="all" version="1" id="oval:org.mitre.oval:tst:16798" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:10882"/>
      <state state_ref="oval:org.mitre.oval:ste:5836"/>
    </dpkginfo_test>
    <dpkginfo_test comment="krb5-clients is earlier than 1.4.4-7etch7" check="all" version="1" id="oval:org.mitre.oval:tst:16768" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11112"/>
      <state state_ref="oval:org.mitre.oval:ste:5836"/>
    </dpkginfo_test>
    <dpkginfo_test comment="libkrb5-dev is earlier than 1.4.4-7etch7" check="all" version="1" id="oval:org.mitre.oval:tst:16754" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11178"/>
      <state state_ref="oval:org.mitre.oval:ste:5836"/>
    </dpkginfo_test>
    <dpkginfo_test comment="krb5-ftpd is earlier than 1.4.4-7etch7" check="all" version="1" id="oval:org.mitre.oval:tst:16694" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:10706"/>
      <state state_ref="oval:org.mitre.oval:ste:5836"/>
    </dpkginfo_test>
    <dpkginfo_test comment="krb5-kdc-ldap is earlier than 1.6.dfsg.4~beta1-5lenny1" check="all" version="1" id="oval:org.mitre.oval:tst:16660" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:10998"/>
      <state state_ref="oval:org.mitre.oval:ste:5313"/>
    </dpkginfo_test>
    <dpkginfo_test comment="krb5-admin-server is earlier than 1.4.4-7etch7" check="all" version="1" id="oval:org.mitre.oval:tst:16636" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11042"/>
      <state state_ref="oval:org.mitre.oval:ste:5836"/>
    </dpkginfo_test>
    <dpkginfo_test comment="krb5-rsh-server is earlier than 1.6.dfsg.4~beta1-5lenny1" check="all" version="1" id="oval:org.mitre.oval:tst:16590" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:10519"/>
      <state state_ref="oval:org.mitre.oval:ste:5313"/>
    </dpkginfo_test>
    <dpkginfo_test comment="libkrb53 is earlier than 1.6.dfsg.4~beta1-5lenny1" check="all" version="1" id="oval:org.mitre.oval:tst:16583" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:10557"/>
      <state state_ref="oval:org.mitre.oval:ste:5313"/>
    </dpkginfo_test>
    <dpkginfo_test comment="libkadm55 is earlier than 1.4.4-7etch7" check="all" version="1" id="oval:org.mitre.oval:tst:16477" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11044"/>
      <state state_ref="oval:org.mitre.oval:ste:5836"/>
    </dpkginfo_test>
    <dpkginfo_test comment="krb5-ftpd is earlier than 1.6.dfsg.4~beta1-5lenny1" check="all" version="1" id="oval:org.mitre.oval:tst:16462" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:10706"/>
      <state state_ref="oval:org.mitre.oval:ste:5313"/>
    </dpkginfo_test>
    <dpkginfo_test comment="krb5-admin-server is earlier than 1.6.dfsg.4~beta1-5lenny1" check="all" version="1" id="oval:org.mitre.oval:tst:16407" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11042"/>
      <state state_ref="oval:org.mitre.oval:ste:5313"/>
    </dpkginfo_test>
    <dpkginfo_test comment="krb5-doc is earlier than 1.6.dfsg.4~beta1-5lenny1" check="all" version="1" id="oval:org.mitre.oval:tst:16278" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:10742"/>
      <state state_ref="oval:org.mitre.oval:ste:5313"/>
    </dpkginfo_test>
    <dpkginfo_test comment="libkrb5-dbg is earlier than 1.6.dfsg.4~beta1-5lenny1" check="all" version="1" id="oval:org.mitre.oval:tst:16266" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:10882"/>
      <state state_ref="oval:org.mitre.oval:ste:5313"/>
    </dpkginfo_test>
    <dpkginfo_test comment="krb5-kdc is earlier than 1.4.4-7etch7" check="all" version="1" id="oval:org.mitre.oval:tst:16170" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:10475"/>
      <state state_ref="oval:org.mitre.oval:ste:5836"/>
    </dpkginfo_test>
    <dpkginfo_test comment="krb5-telnetd is earlier than 1.6.dfsg.4~beta1-5lenny1" check="all" version="1" id="oval:org.mitre.oval:tst:16148" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11211"/>
      <state state_ref="oval:org.mitre.oval:ste:5313"/>
    </dpkginfo_test>
    <dpkginfo_test comment="libkadm55 is earlier than 1.6.dfsg.4~beta1-5lenny1" check="all" version="1" id="oval:org.mitre.oval:tst:16050" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11044"/>
      <state state_ref="oval:org.mitre.oval:ste:5313"/>
    </dpkginfo_test>
    <dpkginfo_test comment="krb5-pkinit is earlier than 1.6.dfsg.4~beta1-5lenny1" check="all" version="1" id="oval:org.mitre.oval:tst:16027" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11180"/>
      <state state_ref="oval:org.mitre.oval:ste:5313"/>
    </dpkginfo_test>
    <dpkginfo_test comment="krb5-telnetd is earlier than 1.4.4-7etch7" check="all" version="1" id="oval:org.mitre.oval:tst:15941" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11211"/>
      <state state_ref="oval:org.mitre.oval:ste:5836"/>
    </dpkginfo_test>
    <dpkginfo_test comment="krb5-doc is earlier than 1.4.4-7etch7" check="all" version="1" id="oval:org.mitre.oval:tst:15857" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:10742"/>
      <state state_ref="oval:org.mitre.oval:ste:5836"/>
    </dpkginfo_test>
    <dpkginfo_test comment="krb5-kdc is earlier than 1.6.dfsg.4~beta1-5lenny1" check="all" version="1" id="oval:org.mitre.oval:tst:15852" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:10475"/>
      <state state_ref="oval:org.mitre.oval:ste:5313"/>
    </dpkginfo_test>
    <dpkginfo_test comment="ocsinventory-agent is earlier than 0.0.9.2repack1-4lenny1" check="all" version="1" id="oval:org.mitre.oval:tst:17225" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11447"/>
      <state state_ref="oval:org.mitre.oval:ste:6104"/>
    </dpkginfo_test>
    <dpkginfo_test comment="libnspr4-0d-dbg is earlier than 4.7.1-5" check="all" version="1" id="oval:org.mitre.oval:tst:19456" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:8188"/>
      <state state_ref="oval:org.mitre.oval:ste:6136"/>
    </dpkginfo_test>
    <dpkginfo_test comment="libnspr4-0d is earlier than 4.7.1-5" check="all" version="1" id="oval:org.mitre.oval:tst:19452" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:8172"/>
      <state state_ref="oval:org.mitre.oval:ste:6136"/>
    </dpkginfo_test>
    <dpkginfo_test comment="libnspr4-dev is earlier than 4.7.1-5" check="all" version="1" id="oval:org.mitre.oval:tst:19338" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:7821"/>
      <state state_ref="oval:org.mitre.oval:ste:6136"/>
    </dpkginfo_test>
    <dpkginfo_test comment="ipplan is earlier than 4.86a-7+lenny1" check="all" version="1" id="oval:org.mitre.oval:tst:17358" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11305"/>
      <state state_ref="oval:org.mitre.oval:ste:6182"/>
    </dpkginfo_test>
    <dpkginfo_test comment="memcached is earlier than 1.1.12-1+etch1" check="all" version="1" id="oval:org.mitre.oval:tst:19151" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:10977"/>
      <state state_ref="oval:org.mitre.oval:ste:5536"/>
    </dpkginfo_test>
    <dpkginfo_test comment="memcached is earlier than 1.2.2-1+lenny1" check="all" version="1" id="oval:org.mitre.oval:tst:18974" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:10977"/>
      <state state_ref="oval:org.mitre.oval:ste:6254"/>
    </dpkginfo_test>
    <dpkginfo_test comment="libapache2-mod-php5 is earlier than 5.2.0+dfsg-8+etch15" check="all" version="1" id="oval:org.mitre.oval:tst:18858" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:7266"/>
      <state state_ref="oval:org.mitre.oval:ste:5803"/>
    </dpkginfo_test>
    <dpkginfo_test comment="php5-dev is earlier than 5.2.0+dfsg-8+etch15" check="all" version="1" id="oval:org.mitre.oval:tst:18856" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:7161"/>
      <state state_ref="oval:org.mitre.oval:ste:5803"/>
    </dpkginfo_test>
    <dpkginfo_test comment="php5-cli is earlier than 5.2.0+dfsg-8+etch15" check="all" version="1" id="oval:org.mitre.oval:tst:18837" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:7641"/>
      <state state_ref="oval:org.mitre.oval:ste:5803"/>
    </dpkginfo_test>
    <dpkginfo_test comment="php5-tidy is earlier than 5.2.0+dfsg-8+etch15" check="all" version="1" id="oval:org.mitre.oval:tst:18827" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:7780"/>
      <state state_ref="oval:org.mitre.oval:ste:5803"/>
    </dpkginfo_test>
    <dpkginfo_test comment="libapache2-mod-php5filter is earlier than 5.2.6.dfsg.1-1+lenny3" check="all" version="1" id="oval:org.mitre.oval:tst:18825" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:7785"/>
      <state state_ref="oval:org.mitre.oval:ste:6009"/>
    </dpkginfo_test>
    <dpkginfo_test comment="php5-xsl is earlier than 5.2.0+dfsg-8+etch15" check="all" version="1" id="oval:org.mitre.oval:tst:18823" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:7539"/>
      <state state_ref="oval:org.mitre.oval:ste:5803"/>
    </dpkginfo_test>
    <dpkginfo_test comment="php5-odbc is earlier than 5.2.0+dfsg-8+etch15" check="all" version="1" id="oval:org.mitre.oval:tst:18799" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:7814"/>
      <state state_ref="oval:org.mitre.oval:ste:5803"/>
    </dpkginfo_test>
    <dpkginfo_test comment="php5-ldap is earlier than 5.2.0+dfsg-8+etch15" check="all" version="1" id="oval:org.mitre.oval:tst:18787" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:7632"/>
      <state state_ref="oval:org.mitre.oval:ste:5803"/>
    </dpkginfo_test>
    <dpkginfo_test comment="php5-pgsql is earlier than 5.2.6.dfsg.1-1+lenny3" check="all" version="1" id="oval:org.mitre.oval:tst:18785" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:7818"/>
      <state state_ref="oval:org.mitre.oval:ste:6009"/>
    </dpkginfo_test>
    <dpkginfo_test comment="php-pear is earlier than 5.2.0+dfsg-8+etch15" check="all" version="1" id="oval:org.mitre.oval:tst:18784" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:7629"/>
      <state state_ref="oval:org.mitre.oval:ste:5803"/>
    </dpkginfo_test>
    <dpkginfo_test comment="php5-pgsql is earlier than 5.2.0+dfsg-8+etch15" check="all" version="1" id="oval:org.mitre.oval:tst:18783" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:7818"/>
      <state state_ref="oval:org.mitre.oval:ste:5803"/>
    </dpkginfo_test>
    <dpkginfo_test comment="php5-recode is earlier than 5.2.0+dfsg-8+etch15" check="all" version="1" id="oval:org.mitre.oval:tst:18782" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:7108"/>
      <state state_ref="oval:org.mitre.oval:ste:5803"/>
    </dpkginfo_test>
    <dpkginfo_test comment="libapache-mod-php5 is earlier than 5.2.0+dfsg-8+etch15" check="all" version="1" id="oval:org.mitre.oval:tst:18781" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:7781"/>
      <state state_ref="oval:org.mitre.oval:ste:5803"/>
    </dpkginfo_test>
    <dpkginfo_test comment="php5-cgi is earlier than 5.2.0+dfsg-8+etch15" check="all" version="1" id="oval:org.mitre.oval:tst:18777" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:7631"/>
      <state state_ref="oval:org.mitre.oval:ste:5803"/>
    </dpkginfo_test>
    <dpkginfo_test comment="php5-tidy is earlier than 5.2.6.dfsg.1-1+lenny3" check="all" version="1" id="oval:org.mitre.oval:tst:18774" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:7780"/>
      <state state_ref="oval:org.mitre.oval:ste:6009"/>
    </dpkginfo_test>
    <dpkginfo_test comment="php5-xmlrpc is earlier than 5.2.6.dfsg.1-1+lenny3" check="all" version="1" id="oval:org.mitre.oval:tst:18766" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:7655"/>
      <state state_ref="oval:org.mitre.oval:ste:6009"/>
    </dpkginfo_test>
    <dpkginfo_test comment="php5-interbase is earlier than 5.2.0+dfsg-8+etch15" check="all" version="1" id="oval:org.mitre.oval:tst:18732" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:7559"/>
      <state state_ref="oval:org.mitre.oval:ste:5803"/>
    </dpkginfo_test>
    <dpkginfo_test comment="php5-sybase is earlier than 5.2.0+dfsg-8+etch15" check="all" version="1" id="oval:org.mitre.oval:tst:18730" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:7729"/>
      <state state_ref="oval:org.mitre.oval:ste:5803"/>
    </dpkginfo_test>
    <dpkginfo_test comment="php5-mcrypt is earlier than 5.2.6.dfsg.1-1+lenny3" check="all" version="1" id="oval:org.mitre.oval:tst:18728" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:7574"/>
      <state state_ref="oval:org.mitre.oval:ste:6009"/>
    </dpkginfo_test>
    <dpkginfo_test comment="php5-sqlite is earlier than 5.2.0+dfsg-8+etch15" check="all" version="1" id="oval:org.mitre.oval:tst:18721" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:7719"/>
      <state state_ref="oval:org.mitre.oval:ste:5803"/>
    </dpkginfo_test>
    <dpkginfo_test comment="php5-mysql is earlier than 5.2.6.dfsg.1-1+lenny3" check="all" version="1" id="oval:org.mitre.oval:tst:18718" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:7285"/>
      <state state_ref="oval:org.mitre.oval:ste:6009"/>
    </dpkginfo_test>
    <dpkginfo_test comment="php5-pspell is earlier than 5.2.0+dfsg-8+etch15" check="all" version="1" id="oval:org.mitre.oval:tst:18701" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:7331"/>
      <state state_ref="oval:org.mitre.oval:ste:5803"/>
    </dpkginfo_test>
    <dpkginfo_test comment="php5-mcrypt is earlier than 5.2.0+dfsg-8+etch15" check="all" version="1" id="oval:org.mitre.oval:tst:18697" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:7574"/>
      <state state_ref="oval:org.mitre.oval:ste:5803"/>
    </dpkginfo_test>
    <dpkginfo_test comment="php5-xmlrpc is earlier than 5.2.0+dfsg-8+etch15" check="all" version="1" id="oval:org.mitre.oval:tst:18691" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:7655"/>
      <state state_ref="oval:org.mitre.oval:ste:5803"/>
    </dpkginfo_test>
    <dpkginfo_test comment="php5-gd is earlier than 5.2.0+dfsg-8+etch15" check="all" version="1" id="oval:org.mitre.oval:tst:18681" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:7548"/>
      <state state_ref="oval:org.mitre.oval:ste:5803"/>
    </dpkginfo_test>
    <dpkginfo_test comment="php5-curl is earlier than 5.2.0+dfsg-8+etch15" check="all" version="1" id="oval:org.mitre.oval:tst:18671" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:7656"/>
      <state state_ref="oval:org.mitre.oval:ste:5803"/>
    </dpkginfo_test>
    <dpkginfo_test comment="php5 is earlier than 5.2.0+dfsg-8+etch15" check="all" version="1" id="oval:org.mitre.oval:tst:18666" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:7704"/>
      <state state_ref="oval:org.mitre.oval:ste:5803"/>
    </dpkginfo_test>
    <dpkginfo_test comment="php5-recode is earlier than 5.2.6.dfsg.1-1+lenny3" check="all" version="1" id="oval:org.mitre.oval:tst:18659" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:7108"/>
      <state state_ref="oval:org.mitre.oval:ste:6009"/>
    </dpkginfo_test>
    <dpkginfo_test comment="php5-common is earlier than 5.2.0+dfsg-8+etch15" check="all" version="1" id="oval:org.mitre.oval:tst:18658" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:7813"/>
      <state state_ref="oval:org.mitre.oval:ste:5803"/>
    </dpkginfo_test>
    <dpkginfo_test comment="php5-odbc is earlier than 5.2.6.dfsg.1-1+lenny3" check="all" version="1" id="oval:org.mitre.oval:tst:18657" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:7814"/>
      <state state_ref="oval:org.mitre.oval:ste:6009"/>
    </dpkginfo_test>
    <dpkginfo_test comment="php5-mhash is earlier than 5.2.6.dfsg.1-1+lenny3" check="all" version="1" id="oval:org.mitre.oval:tst:18642" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:7600"/>
      <state state_ref="oval:org.mitre.oval:ste:6009"/>
    </dpkginfo_test>
    <dpkginfo_test comment="php5-imap is earlier than 5.2.0+dfsg-8+etch15" check="all" version="1" id="oval:org.mitre.oval:tst:18640" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:7239"/>
      <state state_ref="oval:org.mitre.oval:ste:5803"/>
    </dpkginfo_test>
    <dpkginfo_test comment="php5-curl is earlier than 5.2.6.dfsg.1-1+lenny3" check="all" version="1" id="oval:org.mitre.oval:tst:18630" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:7656"/>
      <state state_ref="oval:org.mitre.oval:ste:6009"/>
    </dpkginfo_test>
    <dpkginfo_test comment="php5-mhash is earlier than 5.2.0+dfsg-8+etch15" check="all" version="1" id="oval:org.mitre.oval:tst:18618" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:7600"/>
      <state state_ref="oval:org.mitre.oval:ste:5803"/>
    </dpkginfo_test>
    <dpkginfo_test comment="php5-dev is earlier than 5.2.6.dfsg.1-1+lenny3" check="all" version="1" id="oval:org.mitre.oval:tst:18611" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:7161"/>
      <state state_ref="oval:org.mitre.oval:ste:6009"/>
    </dpkginfo_test>
    <dpkginfo_test comment="php5-pspell is earlier than 5.2.6.dfsg.1-1+lenny3" check="all" version="1" id="oval:org.mitre.oval:tst:18590" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:7331"/>
      <state state_ref="oval:org.mitre.oval:ste:6009"/>
    </dpkginfo_test>
    <dpkginfo_test comment="php5-snmp is earlier than 5.2.6.dfsg.1-1+lenny3" check="all" version="1" id="oval:org.mitre.oval:tst:18567" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:7529"/>
      <state state_ref="oval:org.mitre.oval:ste:6009"/>
    </dpkginfo_test>
    <dpkginfo_test comment="php5-gmp is earlier than 5.2.6.dfsg.1-1+lenny3" check="all" version="1" id="oval:org.mitre.oval:tst:18560" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:7601"/>
      <state state_ref="oval:org.mitre.oval:ste:6009"/>
    </dpkginfo_test>
    <dpkginfo_test comment="php5-cli is earlier than 5.2.6.dfsg.1-1+lenny3" check="all" version="1" id="oval:org.mitre.oval:tst:18553" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:7641"/>
      <state state_ref="oval:org.mitre.oval:ste:6009"/>
    </dpkginfo_test>
    <dpkginfo_test comment="php5-imap is earlier than 5.2.6.dfsg.1-1+lenny3" check="all" version="1" id="oval:org.mitre.oval:tst:18537" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:7239"/>
      <state state_ref="oval:org.mitre.oval:ste:6009"/>
    </dpkginfo_test>
    <dpkginfo_test comment="php5-dbg is earlier than 5.2.6.dfsg.1-1+lenny3" check="all" version="1" id="oval:org.mitre.oval:tst:18498" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:7621"/>
      <state state_ref="oval:org.mitre.oval:ste:6009"/>
    </dpkginfo_test>
    <dpkginfo_test comment="php5-common is earlier than 5.2.6.dfsg.1-1+lenny3" check="all" version="1" id="oval:org.mitre.oval:tst:18473" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:7813"/>
      <state state_ref="oval:org.mitre.oval:ste:6009"/>
    </dpkginfo_test>
    <dpkginfo_test comment="php5-snmp is earlier than 5.2.0+dfsg-8+etch15" check="all" version="1" id="oval:org.mitre.oval:tst:18384" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:7529"/>
      <state state_ref="oval:org.mitre.oval:ste:5803"/>
    </dpkginfo_test>
    <dpkginfo_test comment="php5-sybase is earlier than 5.2.6.dfsg.1-1+lenny3" check="all" version="1" id="oval:org.mitre.oval:tst:18375" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:7729"/>
      <state state_ref="oval:org.mitre.oval:ste:6009"/>
    </dpkginfo_test>
    <dpkginfo_test comment="php5-xsl is earlier than 5.2.6.dfsg.1-1+lenny3" check="all" version="1" id="oval:org.mitre.oval:tst:18372" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:7539"/>
      <state state_ref="oval:org.mitre.oval:ste:6009"/>
    </dpkginfo_test>
    <dpkginfo_test comment="php5-interbase is earlier than 5.2.6.dfsg.1-1+lenny3" check="all" version="1" id="oval:org.mitre.oval:tst:18293" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:7559"/>
      <state state_ref="oval:org.mitre.oval:ste:6009"/>
    </dpkginfo_test>
    <dpkginfo_test comment="php-pear is earlier than 5.2.6.dfsg.1-1+lenny3" check="all" version="1" id="oval:org.mitre.oval:tst:18225" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:7629"/>
      <state state_ref="oval:org.mitre.oval:ste:6009"/>
    </dpkginfo_test>
    <dpkginfo_test comment="php5-cgi is earlier than 5.2.6.dfsg.1-1+lenny3" check="all" version="1" id="oval:org.mitre.oval:tst:18192" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:7631"/>
      <state state_ref="oval:org.mitre.oval:ste:6009"/>
    </dpkginfo_test>
    <dpkginfo_test comment="php5-gd is earlier than 5.2.6.dfsg.1-1+lenny3" check="all" version="1" id="oval:org.mitre.oval:tst:18163" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:7548"/>
      <state state_ref="oval:org.mitre.oval:ste:6009"/>
    </dpkginfo_test>
    <dpkginfo_test comment="php5-ldap is earlier than 5.2.6.dfsg.1-1+lenny3" check="all" version="1" id="oval:org.mitre.oval:tst:18059" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:7632"/>
      <state state_ref="oval:org.mitre.oval:ste:6009"/>
    </dpkginfo_test>
    <dpkginfo_test comment="php5 is earlier than 5.2.6.dfsg.1-1+lenny3" check="all" version="1" id="oval:org.mitre.oval:tst:18001" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:7704"/>
      <state state_ref="oval:org.mitre.oval:ste:6009"/>
    </dpkginfo_test>
    <dpkginfo_test comment="php5-mysql is earlier than 5.2.0+dfsg-8+etch15" check="all" version="1" id="oval:org.mitre.oval:tst:17857" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:7285"/>
      <state state_ref="oval:org.mitre.oval:ste:5803"/>
    </dpkginfo_test>
    <dpkginfo_test comment="php5-sqlite is earlier than 5.2.6.dfsg.1-1+lenny3" check="all" version="1" id="oval:org.mitre.oval:tst:17824" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:7719"/>
      <state state_ref="oval:org.mitre.oval:ste:6009"/>
    </dpkginfo_test>
    <dpkginfo_test comment="libapache2-mod-php5 is earlier than 5.2.6.dfsg.1-1+lenny3" check="all" version="1" id="oval:org.mitre.oval:tst:17817" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:7266"/>
      <state state_ref="oval:org.mitre.oval:ste:6009"/>
    </dpkginfo_test>
    <dpkginfo_test comment="python-pygresql is earlier than 3.8.1-1etch2" check="all" version="1" id="oval:org.mitre.oval:tst:16147" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:10934"/>
      <state state_ref="oval:org.mitre.oval:ste:5849"/>
    </dpkginfo_test>
    <dpkginfo_test comment="python-pygresql-dbg is earlier than 3.8.1-3+lenny1" check="all" version="1" id="oval:org.mitre.oval:tst:15800" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:10918"/>
      <state state_ref="oval:org.mitre.oval:ste:5958"/>
    </dpkginfo_test>
    <dpkginfo_test comment="python-pygresql is earlier than 3.8.1-3+lenny1" check="all" version="1" id="oval:org.mitre.oval:tst:15228" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:10934"/>
      <state state_ref="oval:org.mitre.oval:ste:5958"/>
    </dpkginfo_test>
    <dpkginfo_test comment="libaprutil1-dbg is earlier than 1.2.7+dfsg-2+etch3" check="all" version="1" id="oval:org.mitre.oval:tst:19330" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11085"/>
      <state state_ref="oval:org.mitre.oval:ste:6458"/>
    </dpkginfo_test>
    <dpkginfo_test comment="libapr1-dev is earlier than 1.2.7-9" check="all" version="1" id="oval:org.mitre.oval:tst:19281" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11553"/>
      <state state_ref="oval:org.mitre.oval:ste:5639"/>
    </dpkginfo_test>
    <dpkginfo_test comment="libaprutil1 is earlier than 1.2.7+dfsg-2+etch3" check="all" version="1" id="oval:org.mitre.oval:tst:19235" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11315"/>
      <state state_ref="oval:org.mitre.oval:ste:6458"/>
    </dpkginfo_test>
    <dpkginfo_test comment="libaprutil1-dev is earlier than 1.2.7+dfsg-2+etch3" check="all" version="1" id="oval:org.mitre.oval:tst:19218" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11238"/>
      <state state_ref="oval:org.mitre.oval:ste:6458"/>
    </dpkginfo_test>
    <dpkginfo_test comment="libapr1-dev is earlier than 1.2.12-5+lenny1" check="all" version="1" id="oval:org.mitre.oval:tst:19214" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11553"/>
      <state state_ref="oval:org.mitre.oval:ste:6264"/>
    </dpkginfo_test>
    <dpkginfo_test comment="libapr1-dbg is earlier than 1.2.7-9" check="all" version="1" id="oval:org.mitre.oval:tst:19213" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11556"/>
      <state state_ref="oval:org.mitre.oval:ste:5639"/>
    </dpkginfo_test>
    <dpkginfo_test comment="libapr1 is earlier than 1.2.12-5+lenny1" check="all" version="1" id="oval:org.mitre.oval:tst:19194" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11025"/>
      <state state_ref="oval:org.mitre.oval:ste:6264"/>
    </dpkginfo_test>
    <dpkginfo_test comment="libaprutil1 is earlier than 1.2.7+dfsg-2+etch3" check="all" version="1" id="oval:org.mitre.oval:tst:19166" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11315"/>
      <state state_ref="oval:org.mitre.oval:ste:6458"/>
    </dpkginfo_test>
    <dpkginfo_test comment="libaprutil1-dev is earlier than 1.2.7+dfsg-2+etch3" check="all" version="1" id="oval:org.mitre.oval:tst:19147" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11238"/>
      <state state_ref="oval:org.mitre.oval:ste:6458"/>
    </dpkginfo_test>
    <dpkginfo_test comment="libaprutil1 is earlier than 1.2.12+dfsg-8+lenny4" check="all" version="1" id="oval:org.mitre.oval:tst:19070" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11315"/>
      <state state_ref="oval:org.mitre.oval:ste:6427"/>
    </dpkginfo_test>
    <dpkginfo_test comment="libapr1 is earlier than 1.2.7-9" check="all" version="1" id="oval:org.mitre.oval:tst:18954" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11025"/>
      <state state_ref="oval:org.mitre.oval:ste:5639"/>
    </dpkginfo_test>
    <dpkginfo_test comment="libaprutil1-dbg is earlier than 1.2.12+dfsg-8+lenny4" check="all" version="1" id="oval:org.mitre.oval:tst:18920" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11085"/>
      <state state_ref="oval:org.mitre.oval:ste:6427"/>
    </dpkginfo_test>
    <dpkginfo_test comment="libapr1-dbg is earlier than 1.2.12-5+lenny1" check="all" version="1" id="oval:org.mitre.oval:tst:18819" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11556"/>
      <state state_ref="oval:org.mitre.oval:ste:6264"/>
    </dpkginfo_test>
    <dpkginfo_test comment="libaprutil1-dbg is earlier than 1.2.7+dfsg-2+etch3" check="all" version="1" id="oval:org.mitre.oval:tst:18655" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11085"/>
      <state state_ref="oval:org.mitre.oval:ste:6458"/>
    </dpkginfo_test>
    <dpkginfo_test comment="libaprutil1-dev is earlier than 1.2.12+dfsg-8+lenny4" check="all" version="1" id="oval:org.mitre.oval:tst:18334" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11238"/>
      <state state_ref="oval:org.mitre.oval:ste:6427"/>
    </dpkginfo_test>
    <dpkginfo_test comment="libmozjs-dev is earlier than 1.9.0.13-0lenny1" check="all" version="1" id="oval:org.mitre.oval:tst:15738" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:7916"/>
      <state state_ref="oval:org.mitre.oval:ste:5895"/>
    </dpkginfo_test>
    <dpkginfo_test comment="xulrunner-1.9-dbg is earlier than 1.9.0.13-0lenny1" check="all" version="1" id="oval:org.mitre.oval:tst:15691" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:7323"/>
      <state state_ref="oval:org.mitre.oval:ste:5895"/>
    </dpkginfo_test>
    <dpkginfo_test comment="python-xpcom is earlier than 1.9.0.13-0lenny1" check="all" version="1" id="oval:org.mitre.oval:tst:15687" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:7786"/>
      <state state_ref="oval:org.mitre.oval:ste:5895"/>
    </dpkginfo_test>
    <dpkginfo_test comment="xulrunner-1.9 is earlier than 1.9.0.13-0lenny1" check="all" version="1" id="oval:org.mitre.oval:tst:15674" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:7759"/>
      <state state_ref="oval:org.mitre.oval:ste:5895"/>
    </dpkginfo_test>
    <dpkginfo_test comment="libmozjs1d-dbg is earlier than 1.9.0.13-0lenny1" check="all" version="1" id="oval:org.mitre.oval:tst:15664" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:7652"/>
      <state state_ref="oval:org.mitre.oval:ste:5895"/>
    </dpkginfo_test>
    <dpkginfo_test comment="libmozillainterfaces-java is earlier than 1.9.0.13-0lenny1" check="all" version="1" id="oval:org.mitre.oval:tst:15630" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:7345"/>
      <state state_ref="oval:org.mitre.oval:ste:5895"/>
    </dpkginfo_test>
    <dpkginfo_test comment="xulrunner-1.9-gnome-support is earlier than 1.9.0.13-0lenny1" check="all" version="1" id="oval:org.mitre.oval:tst:15600" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:7607"/>
      <state state_ref="oval:org.mitre.oval:ste:5895"/>
    </dpkginfo_test>
    <dpkginfo_test comment="libmozjs1d is earlier than 1.9.0.13-0lenny1" check="all" version="1" id="oval:org.mitre.oval:tst:15569" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:7900"/>
      <state state_ref="oval:org.mitre.oval:ste:5895"/>
    </dpkginfo_test>
    <dpkginfo_test comment="spidermonkey-bin is earlier than 1.9.0.13-0lenny1" check="all" version="1" id="oval:org.mitre.oval:tst:15458" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:7891"/>
      <state state_ref="oval:org.mitre.oval:ste:5895"/>
    </dpkginfo_test>
    <dpkginfo_test comment="xulrunner-dev is earlier than 1.9.0.13-0lenny1" check="all" version="1" id="oval:org.mitre.oval:tst:15155" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:7903"/>
      <state state_ref="oval:org.mitre.oval:ste:5895"/>
    </dpkginfo_test>
    <dpkginfo_test comment="libsvn-ruby1.8 is earlier than 1.4.2dfsg1-3" check="all" version="1" id="oval:org.mitre.oval:tst:19333" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11616"/>
      <state state_ref="oval:org.mitre.oval:ste:6432"/>
    </dpkginfo_test>
    <dpkginfo_test comment="libapache2-svn is earlier than 1.5.1dfsg1-4" check="all" version="1" id="oval:org.mitre.oval:tst:19326" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11458"/>
      <state state_ref="oval:org.mitre.oval:ste:6129"/>
    </dpkginfo_test>
    <dpkginfo_test comment="python-subversion is earlier than 1.5.1dfsg1-4" check="all" version="1" id="oval:org.mitre.oval:tst:19307" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11629"/>
      <state state_ref="oval:org.mitre.oval:ste:6129"/>
    </dpkginfo_test>
    <dpkginfo_test comment="libsvn1 is earlier than 1.5.1dfsg1-4" check="all" version="1" id="oval:org.mitre.oval:tst:19300" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11640"/>
      <state state_ref="oval:org.mitre.oval:ste:6129"/>
    </dpkginfo_test>
    <dpkginfo_test comment="libsvn-ruby is earlier than 1.5.1dfsg1-4" check="all" version="1" id="oval:org.mitre.oval:tst:19289" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11261"/>
      <state state_ref="oval:org.mitre.oval:ste:6129"/>
    </dpkginfo_test>
    <dpkginfo_test comment="subversion-tools is earlier than 1.5.1dfsg1-4" check="all" version="1" id="oval:org.mitre.oval:tst:19283" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11232"/>
      <state state_ref="oval:org.mitre.oval:ste:6129"/>
    </dpkginfo_test>
    <dpkginfo_test comment="libsvn-doc is earlier than 1.4.2dfsg1-3" check="all" version="1" id="oval:org.mitre.oval:tst:19276" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11604"/>
      <state state_ref="oval:org.mitre.oval:ste:6432"/>
    </dpkginfo_test>
    <dpkginfo_test comment="libsvn-java is earlier than 1.5.1dfsg1-4" check="all" version="1" id="oval:org.mitre.oval:tst:19273" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11366"/>
      <state state_ref="oval:org.mitre.oval:ste:6129"/>
    </dpkginfo_test>
    <dpkginfo_test comment="subversion-tools is earlier than 1.4.2dfsg1-3" check="all" version="1" id="oval:org.mitre.oval:tst:19256" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11232"/>
      <state state_ref="oval:org.mitre.oval:ste:6432"/>
    </dpkginfo_test>
    <dpkginfo_test comment="libsvn-doc is earlier than 1.5.1dfsg1-4" check="all" version="1" id="oval:org.mitre.oval:tst:19251" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11604"/>
      <state state_ref="oval:org.mitre.oval:ste:6129"/>
    </dpkginfo_test>
    <dpkginfo_test comment="subversion is earlier than 1.5.1dfsg1-4" check="all" version="1" id="oval:org.mitre.oval:tst:19248" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11585"/>
      <state state_ref="oval:org.mitre.oval:ste:6129"/>
    </dpkginfo_test>
    <dpkginfo_test comment="python-subversion is earlier than 1.4.2dfsg1-3" check="all" version="1" id="oval:org.mitre.oval:tst:19239" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11629"/>
      <state state_ref="oval:org.mitre.oval:ste:6432"/>
    </dpkginfo_test>
    <dpkginfo_test comment="libsvn-java is earlier than 1.4.2dfsg1-3" check="all" version="1" id="oval:org.mitre.oval:tst:19232" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11366"/>
      <state state_ref="oval:org.mitre.oval:ste:6432"/>
    </dpkginfo_test>
    <dpkginfo_test comment="libapache2-svn is earlier than 1.4.2dfsg1-3" check="all" version="1" id="oval:org.mitre.oval:tst:19230" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11458"/>
      <state state_ref="oval:org.mitre.oval:ste:6432"/>
    </dpkginfo_test>
    <dpkginfo_test comment="subversion is earlier than 1.4.2dfsg1-3" check="all" version="1" id="oval:org.mitre.oval:tst:19211" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11585"/>
      <state state_ref="oval:org.mitre.oval:ste:6432"/>
    </dpkginfo_test>
    <dpkginfo_test comment="libsvn1 is earlier than 1.4.2dfsg1-3" check="all" version="1" id="oval:org.mitre.oval:tst:19087" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11640"/>
      <state state_ref="oval:org.mitre.oval:ste:6432"/>
    </dpkginfo_test>
    <dpkginfo_test comment="libsvn-perl is earlier than 1.4.2dfsg1-3" check="all" version="1" id="oval:org.mitre.oval:tst:19078" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11538"/>
      <state state_ref="oval:org.mitre.oval:ste:6432"/>
    </dpkginfo_test>
    <dpkginfo_test comment="libsvn-ruby is earlier than 1.4.2dfsg1-3" check="all" version="1" id="oval:org.mitre.oval:tst:19036" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11261"/>
      <state state_ref="oval:org.mitre.oval:ste:6432"/>
    </dpkginfo_test>
    <dpkginfo_test comment="libsvn-dev is earlier than 1.4.2dfsg1-3" check="all" version="1" id="oval:org.mitre.oval:tst:18959" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11631"/>
      <state state_ref="oval:org.mitre.oval:ste:6432"/>
    </dpkginfo_test>
    <dpkginfo_test comment="libsvn-javahl is earlier than 1.4.2dfsg1-3" check="all" version="1" id="oval:org.mitre.oval:tst:18913" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:10655"/>
      <state state_ref="oval:org.mitre.oval:ste:6432"/>
    </dpkginfo_test>
    <dpkginfo_test comment="libsvn-perl is earlier than 1.5.1dfsg1-4" check="all" version="1" id="oval:org.mitre.oval:tst:18862" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11538"/>
      <state state_ref="oval:org.mitre.oval:ste:6129"/>
    </dpkginfo_test>
    <dpkginfo_test comment="libsvn-dev is earlier than 1.5.1dfsg1-4" check="all" version="1" id="oval:org.mitre.oval:tst:18830" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11631"/>
      <state state_ref="oval:org.mitre.oval:ste:6129"/>
    </dpkginfo_test>
    <dpkginfo_test comment="libsvn-ruby1.8 is earlier than 1.5.1dfsg1-4" check="all" version="1" id="oval:org.mitre.oval:tst:18672" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11616"/>
      <state state_ref="oval:org.mitre.oval:ste:6129"/>
    </dpkginfo_test>
    <dpkginfo_test comment="drupal6 is earlier than 6.6-3lenny2" check="all" version="1" id="oval:org.mitre.oval:tst:19913" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:7754"/>
      <state state_ref="oval:org.mitre.oval:ste:6483"/>
    </dpkginfo_test>
    <dpkginfo_test comment="kviewshell is earlier than 3.5.9-3+lenny2" check="all" version="1" id="oval:org.mitre.oval:tst:18456" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:7752"/>
      <state state_ref="oval:org.mitre.oval:ste:5829"/>
    </dpkginfo_test>
    <dpkginfo_test comment="kfaxview is earlier than 3.5.5-3etch4" check="all" version="1" id="oval:org.mitre.oval:tst:18435" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:7551"/>
      <state state_ref="oval:org.mitre.oval:ste:6331"/>
    </dpkginfo_test>
    <dpkginfo_test comment="kdegraphics-doc-html is earlier than 3.5.9-3+lenny2" check="all" version="1" id="oval:org.mitre.oval:tst:18434" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:7877"/>
      <state state_ref="oval:org.mitre.oval:ste:5829"/>
    </dpkginfo_test>
    <dpkginfo_test comment="kpovmodeler is earlier than 3.5.9-3+lenny2" check="all" version="1" id="oval:org.mitre.oval:tst:18429" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:7687"/>
      <state state_ref="oval:org.mitre.oval:ste:5829"/>
    </dpkginfo_test>
    <dpkginfo_test comment="kcoloredit is earlier than 3.5.5-3etch4" check="all" version="1" id="oval:org.mitre.oval:tst:18428" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:7838"/>
      <state state_ref="oval:org.mitre.oval:ste:6331"/>
    </dpkginfo_test>
    <dpkginfo_test comment="kooka is earlier than 3.5.9-3+lenny2" check="all" version="1" id="oval:org.mitre.oval:tst:18424" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:7727"/>
      <state state_ref="oval:org.mitre.oval:ste:5829"/>
    </dpkginfo_test>
    <dpkginfo_test comment="libkscan-dev is earlier than 3.5.9-3+lenny2" check="all" version="1" id="oval:org.mitre.oval:tst:18421" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:7578"/>
      <state state_ref="oval:org.mitre.oval:ste:5829"/>
    </dpkginfo_test>
    <dpkginfo_test comment="kdegraphics-dbg is earlier than 3.5.5-3etch4" check="all" version="1" id="oval:org.mitre.oval:tst:18415" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:7735"/>
      <state state_ref="oval:org.mitre.oval:ste:6331"/>
    </dpkginfo_test>
    <dpkginfo_test comment="kruler is earlier than 3.5.5-3etch4" check="all" version="1" id="oval:org.mitre.oval:tst:18397" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:7749"/>
      <state state_ref="oval:org.mitre.oval:ste:6331"/>
    </dpkginfo_test>
    <dpkginfo_test comment="kview is earlier than 3.5.9-3+lenny2" check="all" version="1" id="oval:org.mitre.oval:tst:18378" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:7544"/>
      <state state_ref="oval:org.mitre.oval:ste:5829"/>
    </dpkginfo_test>
    <dpkginfo_test comment="kfaxview is earlier than 3.5.9-3+lenny2" check="all" version="1" id="oval:org.mitre.oval:tst:18373" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:7551"/>
      <state state_ref="oval:org.mitre.oval:ste:5829"/>
    </dpkginfo_test>
    <dpkginfo_test comment="ksnapshot is earlier than 3.5.9-3+lenny2" check="all" version="1" id="oval:org.mitre.oval:tst:18363" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:7755"/>
      <state state_ref="oval:org.mitre.oval:ste:5829"/>
    </dpkginfo_test>
    <dpkginfo_test comment="kamera is earlier than 3.5.5-3etch4" check="all" version="1" id="oval:org.mitre.oval:tst:18360" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:7179"/>
      <state state_ref="oval:org.mitre.oval:ste:6331"/>
    </dpkginfo_test>
    <dpkginfo_test comment="libkscan1 is earlier than 3.5.9-3+lenny2" check="all" version="1" id="oval:org.mitre.oval:tst:18353" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:7673"/>
      <state state_ref="oval:org.mitre.oval:ste:5829"/>
    </dpkginfo_test>
    <dpkginfo_test comment="kdegraphics is earlier than 3.5.9-3+lenny2" check="all" version="1" id="oval:org.mitre.oval:tst:18343" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:7494"/>
      <state state_ref="oval:org.mitre.oval:ste:5829"/>
    </dpkginfo_test>
    <dpkginfo_test comment="kolourpaint is earlier than 3.5.9-3+lenny2" check="all" version="1" id="oval:org.mitre.oval:tst:18339" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:7902"/>
      <state state_ref="oval:org.mitre.oval:ste:5829"/>
    </dpkginfo_test>
    <dpkginfo_test comment="kmrml is earlier than 3.5.9-3+lenny2" check="all" version="1" id="oval:org.mitre.oval:tst:18333" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:7804"/>
      <state state_ref="oval:org.mitre.oval:ste:5829"/>
    </dpkginfo_test>
    <dpkginfo_test comment="ksnapshot is earlier than 3.5.5-3etch4" check="all" version="1" id="oval:org.mitre.oval:tst:18329" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:7755"/>
      <state state_ref="oval:org.mitre.oval:ste:6331"/>
    </dpkginfo_test>
    <dpkginfo_test comment="kview is earlier than 3.5.5-3etch4" check="all" version="1" id="oval:org.mitre.oval:tst:18320" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:7544"/>
      <state state_ref="oval:org.mitre.oval:ste:6331"/>
    </dpkginfo_test>
    <dpkginfo_test comment="kghostview is earlier than 3.5.5-3etch4" check="all" version="1" id="oval:org.mitre.oval:tst:18311" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:7862"/>
      <state state_ref="oval:org.mitre.oval:ste:6331"/>
    </dpkginfo_test>
    <dpkginfo_test comment="kfax is earlier than 3.5.9-3+lenny2" check="all" version="1" id="oval:org.mitre.oval:tst:18308" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:7506"/>
      <state state_ref="oval:org.mitre.oval:ste:5829"/>
    </dpkginfo_test>
    <dpkginfo_test comment="kgamma is earlier than 3.5.5-3etch4" check="all" version="1" id="oval:org.mitre.oval:tst:18306" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:7589"/>
      <state state_ref="oval:org.mitre.oval:ste:6331"/>
    </dpkginfo_test>
    <dpkginfo_test comment="kuickshow is earlier than 3.5.9-3+lenny2" check="all" version="1" id="oval:org.mitre.oval:tst:18304" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:6925"/>
      <state state_ref="oval:org.mitre.oval:ste:5829"/>
    </dpkginfo_test>
    <dpkginfo_test comment="kpdf is earlier than 3.5.9-3+lenny2" check="all" version="1" id="oval:org.mitre.oval:tst:18278" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:7514"/>
      <state state_ref="oval:org.mitre.oval:ste:5829"/>
    </dpkginfo_test>
    <dpkginfo_test comment="kpdf is earlier than 3.5.5-3etch4" check="all" version="1" id="oval:org.mitre.oval:tst:18277" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:7514"/>
      <state state_ref="oval:org.mitre.oval:ste:6331"/>
    </dpkginfo_test>
    <dpkginfo_test comment="kuickshow is earlier than 3.5.5-3etch4" check="all" version="1" id="oval:org.mitre.oval:tst:18275" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:6925"/>
      <state state_ref="oval:org.mitre.oval:ste:6331"/>
    </dpkginfo_test>
    <dpkginfo_test comment="ksvg is earlier than 3.5.9-3+lenny2" check="all" version="1" id="oval:org.mitre.oval:tst:18263" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:7458"/>
      <state state_ref="oval:org.mitre.oval:ste:5829"/>
    </dpkginfo_test>
    <dpkginfo_test comment="kdegraphics-dbg is earlier than 3.5.9-3+lenny2" check="all" version="1" id="oval:org.mitre.oval:tst:18235" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:7735"/>
      <state state_ref="oval:org.mitre.oval:ste:5829"/>
    </dpkginfo_test>
    <dpkginfo_test comment="kamera is earlier than 3.5.9-3+lenny2" check="all" version="1" id="oval:org.mitre.oval:tst:18227" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:7179"/>
      <state state_ref="oval:org.mitre.oval:ste:5829"/>
    </dpkginfo_test>
    <dpkginfo_test comment="kghostview is earlier than 3.5.9-3+lenny2" check="all" version="1" id="oval:org.mitre.oval:tst:18217" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:7862"/>
      <state state_ref="oval:org.mitre.oval:ste:5829"/>
    </dpkginfo_test>
    <dpkginfo_test comment="kdegraphics-doc-html is earlier than 3.5.5-3etch4" check="all" version="1" id="oval:org.mitre.oval:tst:18204" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:7877"/>
      <state state_ref="oval:org.mitre.oval:ste:6331"/>
    </dpkginfo_test>
    <dpkginfo_test comment="kgamma is earlier than 3.5.9-3+lenny2" check="all" version="1" id="oval:org.mitre.oval:tst:18198" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:7589"/>
      <state state_ref="oval:org.mitre.oval:ste:5829"/>
    </dpkginfo_test>
    <dpkginfo_test comment="kviewshell is earlier than 3.5.5-3etch4" check="all" version="1" id="oval:org.mitre.oval:tst:18196" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:7752"/>
      <state state_ref="oval:org.mitre.oval:ste:6331"/>
    </dpkginfo_test>
    <dpkginfo_test comment="kdvi is earlier than 3.5.5-3etch4" check="all" version="1" id="oval:org.mitre.oval:tst:18148" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:7509"/>
      <state state_ref="oval:org.mitre.oval:ste:6331"/>
    </dpkginfo_test>
    <dpkginfo_test comment="kolourpaint is earlier than 3.5.5-3etch4" check="all" version="1" id="oval:org.mitre.oval:tst:18144" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:7902"/>
      <state state_ref="oval:org.mitre.oval:ste:6331"/>
    </dpkginfo_test>
    <dpkginfo_test comment="kiconedit is earlier than 3.5.9-3+lenny2" check="all" version="1" id="oval:org.mitre.oval:tst:18106" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:7638"/>
      <state state_ref="oval:org.mitre.oval:ste:5829"/>
    </dpkginfo_test>
    <dpkginfo_test comment="kooka is earlier than 3.5.5-3etch4" check="all" version="1" id="oval:org.mitre.oval:tst:18103" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:7727"/>
      <state state_ref="oval:org.mitre.oval:ste:6331"/>
    </dpkginfo_test>
    <dpkginfo_test comment="kdegraphics-dev is earlier than 3.5.5-3etch4" check="all" version="1" id="oval:org.mitre.oval:tst:18078" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:7671"/>
      <state state_ref="oval:org.mitre.oval:ste:6331"/>
    </dpkginfo_test>
    <dpkginfo_test comment="libkscan1 is earlier than 3.5.5-3etch4" check="all" version="1" id="oval:org.mitre.oval:tst:18049" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:7673"/>
      <state state_ref="oval:org.mitre.oval:ste:6331"/>
    </dpkginfo_test>
    <dpkginfo_test comment="kdegraphics is earlier than 3.5.5-3etch4" check="all" version="1" id="oval:org.mitre.oval:tst:18035" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:7494"/>
      <state state_ref="oval:org.mitre.oval:ste:6331"/>
    </dpkginfo_test>
    <dpkginfo_test comment="kiconedit is earlier than 3.5.5-3etch4" check="all" version="1" id="oval:org.mitre.oval:tst:18006" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:7638"/>
      <state state_ref="oval:org.mitre.oval:ste:6331"/>
    </dpkginfo_test>
    <dpkginfo_test comment="kmrml is earlier than 3.5.5-3etch4" check="all" version="1" id="oval:org.mitre.oval:tst:17994" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:7804"/>
      <state state_ref="oval:org.mitre.oval:ste:6331"/>
    </dpkginfo_test>
    <dpkginfo_test comment="kpovmodeler is earlier than 3.5.5-3etch4" check="all" version="1" id="oval:org.mitre.oval:tst:17989" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:7687"/>
      <state state_ref="oval:org.mitre.oval:ste:6331"/>
    </dpkginfo_test>
    <dpkginfo_test comment="kcoloredit is earlier than 3.5.9-3+lenny2" check="all" version="1" id="oval:org.mitre.oval:tst:17952" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:7838"/>
      <state state_ref="oval:org.mitre.oval:ste:5829"/>
    </dpkginfo_test>
    <dpkginfo_test comment="libkscan-dev is earlier than 3.5.5-3etch4" check="all" version="1" id="oval:org.mitre.oval:tst:17927" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:7578"/>
      <state state_ref="oval:org.mitre.oval:ste:6331"/>
    </dpkginfo_test>
    <dpkginfo_test comment="ksvg is earlier than 3.5.5-3etch4" check="all" version="1" id="oval:org.mitre.oval:tst:17921" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:7458"/>
      <state state_ref="oval:org.mitre.oval:ste:6331"/>
    </dpkginfo_test>
    <dpkginfo_test comment="kdegraphics-kfile-plugins is earlier than 3.5.9-3+lenny2" check="all" version="1" id="oval:org.mitre.oval:tst:17911" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:7516"/>
      <state state_ref="oval:org.mitre.oval:ste:5829"/>
    </dpkginfo_test>
    <dpkginfo_test comment="kdegraphics-dev is earlier than 3.5.9-3+lenny2" check="all" version="1" id="oval:org.mitre.oval:tst:17814" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:7671"/>
      <state state_ref="oval:org.mitre.oval:ste:5829"/>
    </dpkginfo_test>
    <dpkginfo_test comment="kdegraphics-kfile-plugins is earlier than 3.5.5-3etch4" check="all" version="1" id="oval:org.mitre.oval:tst:17693" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:7516"/>
      <state state_ref="oval:org.mitre.oval:ste:6331"/>
    </dpkginfo_test>
    <dpkginfo_test comment="kruler is earlier than 3.5.9-3+lenny2" check="all" version="1" id="oval:org.mitre.oval:tst:17567" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:7749"/>
      <state state_ref="oval:org.mitre.oval:ste:5829"/>
    </dpkginfo_test>
    <dpkginfo_test comment="kdvi is earlier than 3.5.9-3+lenny2" check="all" version="1" id="oval:org.mitre.oval:tst:17515" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:7509"/>
      <state state_ref="oval:org.mitre.oval:ste:5829"/>
    </dpkginfo_test>
    <dpkginfo_test comment="kfax is earlier than 3.5.5-3etch4" check="all" version="1" id="oval:org.mitre.oval:tst:17496" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:7506"/>
      <state state_ref="oval:org.mitre.oval:ste:6331"/>
    </dpkginfo_test>
    <dpkginfo_test comment="libxml2 is earlier than 2.6.32.dfsg-5+lenny1" check="all" version="1" id="oval:org.mitre.oval:tst:19242" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:8060"/>
      <state state_ref="oval:org.mitre.oval:ste:6379"/>
    </dpkginfo_test>
    <dpkginfo_test comment="libxml2-utils is earlier than 2.6.32.dfsg-5+lenny1" check="all" version="1" id="oval:org.mitre.oval:tst:19227" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:8134"/>
      <state state_ref="oval:org.mitre.oval:ste:6379"/>
    </dpkginfo_test>
    <dpkginfo_test comment="python-libxml2 is earlier than 2.6.32.dfsg-5+lenny1" check="all" version="1" id="oval:org.mitre.oval:tst:19190" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:8066"/>
      <state state_ref="oval:org.mitre.oval:ste:6379"/>
    </dpkginfo_test>
    <dpkginfo_test comment="libxml2 is earlier than 2.6.27.dfsg-6+etch1" check="all" version="1" id="oval:org.mitre.oval:tst:19057" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:8060"/>
      <state state_ref="oval:org.mitre.oval:ste:6166"/>
    </dpkginfo_test>
    <dpkginfo_test comment="libxml2-dev is earlier than 2.6.27.dfsg-6+etch1" check="all" version="1" id="oval:org.mitre.oval:tst:19002" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:7212"/>
      <state state_ref="oval:org.mitre.oval:ste:6166"/>
    </dpkginfo_test>
    <dpkginfo_test comment="libxml2-utils is earlier than 2.6.27.dfsg-6+etch1" check="all" version="1" id="oval:org.mitre.oval:tst:18981" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:8134"/>
      <state state_ref="oval:org.mitre.oval:ste:6166"/>
    </dpkginfo_test>
    <dpkginfo_test comment="libxml2-dbg is earlier than 2.6.27.dfsg-6+etch1" check="all" version="1" id="oval:org.mitre.oval:tst:18906" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:7808"/>
      <state state_ref="oval:org.mitre.oval:ste:6166"/>
    </dpkginfo_test>
    <dpkginfo_test comment="python-libxml2 is earlier than 2.6.27.dfsg-6+etch1" check="all" version="1" id="oval:org.mitre.oval:tst:18621" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:8066"/>
      <state state_ref="oval:org.mitre.oval:ste:6166"/>
    </dpkginfo_test>
    <dpkginfo_test comment="libxml2-doc is earlier than 2.6.27.dfsg-6+etch1" check="all" version="1" id="oval:org.mitre.oval:tst:18581" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:8073"/>
      <state state_ref="oval:org.mitre.oval:ste:6166"/>
    </dpkginfo_test>
    <dpkginfo_test comment="libxml2-dev is earlier than 2.6.32.dfsg-5+lenny1" check="all" version="1" id="oval:org.mitre.oval:tst:18577" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:7212"/>
      <state state_ref="oval:org.mitre.oval:ste:6379"/>
    </dpkginfo_test>
    <dpkginfo_test comment="libxml2-dbg is earlier than 2.6.32.dfsg-5+lenny1" check="all" version="1" id="oval:org.mitre.oval:tst:18433" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:7808"/>
      <state state_ref="oval:org.mitre.oval:ste:6379"/>
    </dpkginfo_test>
    <dpkginfo_test comment="libxml2-doc is earlier than 2.6.32.dfsg-5+lenny1" check="all" version="1" id="oval:org.mitre.oval:tst:18272" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:8073"/>
      <state state_ref="oval:org.mitre.oval:ste:6379"/>
    </dpkginfo_test>
    <dpkginfo_test comment="finch is earlier than 2.4.3-4lenny3" check="all" version="1" id="oval:org.mitre.oval:tst:15702" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:9976"/>
      <state state_ref="oval:org.mitre.oval:ste:6173"/>
    </dpkginfo_test>
    <dpkginfo_test comment="pidgin-dev is earlier than 2.4.3-4lenny3" check="all" version="1" id="oval:org.mitre.oval:tst:15653" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:9897"/>
      <state state_ref="oval:org.mitre.oval:ste:6173"/>
    </dpkginfo_test>
    <dpkginfo_test comment="libpurple-bin is earlier than 2.4.3-4lenny3" check="all" version="1" id="oval:org.mitre.oval:tst:15646" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:10543"/>
      <state state_ref="oval:org.mitre.oval:ste:6173"/>
    </dpkginfo_test>
    <dpkginfo_test comment="pidgin-dbg is earlier than 2.4.3-4lenny3" check="all" version="1" id="oval:org.mitre.oval:tst:15465" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:9749"/>
      <state state_ref="oval:org.mitre.oval:ste:6173"/>
    </dpkginfo_test>
    <dpkginfo_test comment="pidgin is earlier than 2.4.3-4lenny3" check="all" version="1" id="oval:org.mitre.oval:tst:15417" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:10640"/>
      <state state_ref="oval:org.mitre.oval:ste:6173"/>
    </dpkginfo_test>
    <dpkginfo_test comment="finch-dev is earlier than 2.4.3-4lenny3" check="all" version="1" id="oval:org.mitre.oval:tst:15221" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:10713"/>
      <state state_ref="oval:org.mitre.oval:ste:6173"/>
    </dpkginfo_test>
    <dpkginfo_test comment="libpurple0 is earlier than 2.4.3-4lenny3" check="all" version="1" id="oval:org.mitre.oval:tst:15091" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:10703"/>
      <state state_ref="oval:org.mitre.oval:ste:6173"/>
    </dpkginfo_test>
    <dpkginfo_test comment="pidgin-data is earlier than 2.4.3-4lenny3" check="all" version="1" id="oval:org.mitre.oval:tst:15020" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:10503"/>
      <state state_ref="oval:org.mitre.oval:ste:6173"/>
    </dpkginfo_test>
    <dpkginfo_test comment="libpurple-dev is earlier than 2.4.3-4lenny3" check="all" version="1" id="oval:org.mitre.oval:tst:14856" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:10588"/>
      <state state_ref="oval:org.mitre.oval:ste:6173"/>
    </dpkginfo_test>
    <dpkginfo_test comment="horde3 is earlier than 3.1.3-4etch6" check="all" version="1" id="oval:org.mitre.oval:tst:19965" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:7672"/>
      <state state_ref="oval:org.mitre.oval:ste:6413"/>
    </dpkginfo_test>
    <dpkginfo_test comment="horde3 is earlier than 3.2.2+debian0-2+lenny1" check="all" version="1" id="oval:org.mitre.oval:tst:19814" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:7672"/>
      <state state_ref="oval:org.mitre.oval:ste:6558"/>
    </dpkginfo_test>
    <dpkginfo_test comment="smbclient is earlier than 3.2.5-4lenny6" check="all" version="1" id="oval:org.mitre.oval:tst:17391" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:8279"/>
      <state state_ref="oval:org.mitre.oval:ste:5926"/>
    </dpkginfo_test>
    <dpkginfo_test comment="samba-tools is earlier than 3.2.5-4lenny6" check="all" version="1" id="oval:org.mitre.oval:tst:17387" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:8512"/>
      <state state_ref="oval:org.mitre.oval:ste:5926"/>
    </dpkginfo_test>
    <dpkginfo_test comment="samba-dbg is earlier than 3.2.5-4lenny6" check="all" version="1" id="oval:org.mitre.oval:tst:17336" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:8389"/>
      <state state_ref="oval:org.mitre.oval:ste:5926"/>
    </dpkginfo_test>
    <dpkginfo_test comment="libsmbclient-dev is earlier than 3.2.5-4lenny6" check="all" version="1" id="oval:org.mitre.oval:tst:17314" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:7987"/>
      <state state_ref="oval:org.mitre.oval:ste:5926"/>
    </dpkginfo_test>
    <dpkginfo_test comment="samba-doc is earlier than 3.2.5-4lenny6" check="all" version="1" id="oval:org.mitre.oval:tst:17301" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:8610"/>
      <state state_ref="oval:org.mitre.oval:ste:5926"/>
    </dpkginfo_test>
    <dpkginfo_test comment="samba-common is earlier than 3.2.5-4lenny6" check="all" version="1" id="oval:org.mitre.oval:tst:17284" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:8042"/>
      <state state_ref="oval:org.mitre.oval:ste:5926"/>
    </dpkginfo_test>
    <dpkginfo_test comment="libwbclient0 is earlier than 3.2.5-4lenny6" check="all" version="1" id="oval:org.mitre.oval:tst:17205" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:7996"/>
      <state state_ref="oval:org.mitre.oval:ste:5926"/>
    </dpkginfo_test>
    <dpkginfo_test comment="samba-doc-pdf is earlier than 3.2.5-4lenny6" check="all" version="1" id="oval:org.mitre.oval:tst:17171" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:8283"/>
      <state state_ref="oval:org.mitre.oval:ste:5926"/>
    </dpkginfo_test>
    <dpkginfo_test comment="libpam-smbpass is earlier than 3.2.5-4lenny6" check="all" version="1" id="oval:org.mitre.oval:tst:17135" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:8550"/>
      <state state_ref="oval:org.mitre.oval:ste:5926"/>
    </dpkginfo_test>
    <dpkginfo_test comment="winbind is earlier than 3.2.5-4lenny6" check="all" version="1" id="oval:org.mitre.oval:tst:16976" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:8600"/>
      <state state_ref="oval:org.mitre.oval:ste:5926"/>
    </dpkginfo_test>
    <dpkginfo_test comment="swat is earlier than 3.2.5-4lenny6" check="all" version="1" id="oval:org.mitre.oval:tst:16902" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:8572"/>
      <state state_ref="oval:org.mitre.oval:ste:5926"/>
    </dpkginfo_test>
    <dpkginfo_test comment="libsmbclient is earlier than 3.2.5-4lenny6" check="all" version="1" id="oval:org.mitre.oval:tst:16724" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:8632"/>
      <state state_ref="oval:org.mitre.oval:ste:5926"/>
    </dpkginfo_test>
    <dpkginfo_test comment="smbfs is earlier than 3.2.5-4lenny6" check="all" version="1" id="oval:org.mitre.oval:tst:16587" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:8274"/>
      <state state_ref="oval:org.mitre.oval:ste:5926"/>
    </dpkginfo_test>
    <dpkginfo_test comment="samba is earlier than 3.2.5-4lenny6" check="all" version="1" id="oval:org.mitre.oval:tst:16503" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:8058"/>
      <state state_ref="oval:org.mitre.oval:ste:5926"/>
    </dpkginfo_test>
    <dpkginfo_test comment="nginx is earlier than 0.6.32-3+lenny3" check="all" version="1" id="oval:org.mitre.oval:tst:17353" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:8796"/>
      <state state_ref="oval:org.mitre.oval:ste:6032"/>
    </dpkginfo_test>
    <dpkginfo_test comment="nginx is earlier than 0.4.13-2+etch3" check="all" version="1" id="oval:org.mitre.oval:tst:17163" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:8796"/>
      <state state_ref="oval:org.mitre.oval:ste:6099"/>
    </dpkginfo_test>
    <dpkginfo_test comment="libnss3-dev is earlier than 3.12.3.1-0lenny1" check="all" version="1" id="oval:org.mitre.oval:tst:15554" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:7933"/>
      <state state_ref="oval:org.mitre.oval:ste:6095"/>
    </dpkginfo_test>
    <dpkginfo_test comment="libnss3-1d is earlier than 3.12.3.1-0lenny1" check="all" version="1" id="oval:org.mitre.oval:tst:15513" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:10514"/>
      <state state_ref="oval:org.mitre.oval:ste:6095"/>
    </dpkginfo_test>
    <dpkginfo_test comment="libnss3-tools is earlier than 3.12.3.1-0lenny1" check="all" version="1" id="oval:org.mitre.oval:tst:15437" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:7570"/>
      <state state_ref="oval:org.mitre.oval:ste:6095"/>
    </dpkginfo_test>
    <dpkginfo_test comment="libnss3-1d-dbg is earlier than 3.12.3.1-0lenny1" check="all" version="1" id="oval:org.mitre.oval:tst:14886" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:10615"/>
      <state state_ref="oval:org.mitre.oval:ste:6095"/>
    </dpkginfo_test>
    <dpkginfo_test comment="slurm-llnl-sview is earlier than 1.3.6-1lenny3" check="all" version="1" id="oval:org.mitre.oval:tst:19049" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11451"/>
      <state state_ref="oval:org.mitre.oval:ste:6405"/>
    </dpkginfo_test>
    <dpkginfo_test comment="libpmi0-dev is earlier than 1.3.6-1lenny3" check="all" version="1" id="oval:org.mitre.oval:tst:18995" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11348"/>
      <state state_ref="oval:org.mitre.oval:ste:6405"/>
    </dpkginfo_test>
    <dpkginfo_test comment="slurm-llnl-basic-plugins-dev is earlier than 1.3.6-1lenny3" check="all" version="1" id="oval:org.mitre.oval:tst:18955" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11557"/>
      <state state_ref="oval:org.mitre.oval:ste:6405"/>
    </dpkginfo_test>
    <dpkginfo_test comment="slurm-llnl-basic-plugins is earlier than 1.3.6-1lenny3" check="all" version="1" id="oval:org.mitre.oval:tst:18941" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11363"/>
      <state state_ref="oval:org.mitre.oval:ste:6405"/>
    </dpkginfo_test>
    <dpkginfo_test comment="libslurm13-dev is earlier than 1.3.6-1lenny3" check="all" version="1" id="oval:org.mitre.oval:tst:18821" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11513"/>
      <state state_ref="oval:org.mitre.oval:ste:6405"/>
    </dpkginfo_test>
    <dpkginfo_test comment="libpmi0 is earlier than 1.3.6-1lenny3" check="all" version="1" id="oval:org.mitre.oval:tst:18767" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11311"/>
      <state state_ref="oval:org.mitre.oval:ste:6405"/>
    </dpkginfo_test>
    <dpkginfo_test comment="libslurm13 is earlier than 1.3.6-1lenny3" check="all" version="1" id="oval:org.mitre.oval:tst:18745" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11412"/>
      <state state_ref="oval:org.mitre.oval:ste:6405"/>
    </dpkginfo_test>
    <dpkginfo_test comment="slurm-llnl-doc is earlier than 1.3.6-1lenny3" check="all" version="1" id="oval:org.mitre.oval:tst:18680" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11520"/>
      <state state_ref="oval:org.mitre.oval:ste:6405"/>
    </dpkginfo_test>
    <dpkginfo_test comment="slurm-llnl-slurmdbd is earlier than 1.3.6-1lenny3" check="all" version="1" id="oval:org.mitre.oval:tst:18600" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11528"/>
      <state state_ref="oval:org.mitre.oval:ste:6405"/>
    </dpkginfo_test>
    <dpkginfo_test comment="slurm-llnl is earlier than 1.3.6-1lenny3" check="all" version="1" id="oval:org.mitre.oval:tst:18569" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11554"/>
      <state state_ref="oval:org.mitre.oval:ste:6405"/>
    </dpkginfo_test>
    <dpkginfo_test comment="libglib2.0-dev is earlier than 2.12.4-2+etch1" check="all" version="1" id="oval:org.mitre.oval:tst:20029" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11753"/>
      <state state_ref="oval:org.mitre.oval:ste:6271"/>
    </dpkginfo_test>
    <dpkginfo_test comment="libglib2.0-0-dbg is earlier than 2.16.6-1+lenny1" check="all" version="1" id="oval:org.mitre.oval:tst:19884" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11539"/>
      <state state_ref="oval:org.mitre.oval:ste:6422"/>
    </dpkginfo_test>
    <dpkginfo_test comment="libglib2.0-0 is earlier than 2.12.4-2+etch1" check="all" version="1" id="oval:org.mitre.oval:tst:19866" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11749"/>
      <state state_ref="oval:org.mitre.oval:ste:6271"/>
    </dpkginfo_test>
    <dpkginfo_test comment="libglib2.0-0 is earlier than 2.16.6-1+lenny1" check="all" version="1" id="oval:org.mitre.oval:tst:19862" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11749"/>
      <state state_ref="oval:org.mitre.oval:ste:6422"/>
    </dpkginfo_test>
    <dpkginfo_test comment="libgio-fam is earlier than 2.16.6-1+lenny1" check="all" version="1" id="oval:org.mitre.oval:tst:19836" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11703"/>
      <state state_ref="oval:org.mitre.oval:ste:6422"/>
    </dpkginfo_test>
    <dpkginfo_test comment="libglib2.0-doc is earlier than 2.12.4-2+etch1" check="all" version="1" id="oval:org.mitre.oval:tst:19779" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11419"/>
      <state state_ref="oval:org.mitre.oval:ste:6271"/>
    </dpkginfo_test>
    <dpkginfo_test comment="libglib2.0-data is earlier than 2.12.4-2+etch1" check="all" version="1" id="oval:org.mitre.oval:tst:19775" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11457"/>
      <state state_ref="oval:org.mitre.oval:ste:6271"/>
    </dpkginfo_test>
    <dpkginfo_test comment="libglib2.0-data is earlier than 2.16.6-1+lenny1" check="all" version="1" id="oval:org.mitre.oval:tst:19743" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11457"/>
      <state state_ref="oval:org.mitre.oval:ste:6422"/>
    </dpkginfo_test>
    <dpkginfo_test comment="libglib2.0-doc is earlier than 2.16.6-1+lenny1" check="all" version="1" id="oval:org.mitre.oval:tst:19714" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11419"/>
      <state state_ref="oval:org.mitre.oval:ste:6422"/>
    </dpkginfo_test>
    <dpkginfo_test comment="libglib2.0-0-dbg is earlier than 2.12.4-2+etch1" check="all" version="1" id="oval:org.mitre.oval:tst:19643" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11539"/>
      <state state_ref="oval:org.mitre.oval:ste:6271"/>
    </dpkginfo_test>
    <dpkginfo_test comment="libglib2.0-dev is earlier than 2.16.6-1+lenny1" check="all" version="1" id="oval:org.mitre.oval:tst:19630" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11753"/>
      <state state_ref="oval:org.mitre.oval:ste:6422"/>
    </dpkginfo_test>
    <dpkginfo_test comment="gforge-mta-postfix is earlier than 4.5.14-22etch11" check="all" version="1" id="oval:org.mitre.oval:tst:18749" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:7865"/>
      <state state_ref="oval:org.mitre.oval:ste:6363"/>
    </dpkginfo_test>
    <dpkginfo_test comment="gforge-mta-exim4 is earlier than 4.7~rc2-7lenny1" check="all" version="1" id="oval:org.mitre.oval:tst:18747" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:7001"/>
      <state state_ref="oval:org.mitre.oval:ste:6389"/>
    </dpkginfo_test>
    <dpkginfo_test comment="gforge is earlier than 4.5.14-22etch11" check="all" version="1" id="oval:org.mitre.oval:tst:18743" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:7612"/>
      <state state_ref="oval:org.mitre.oval:ste:6363"/>
    </dpkginfo_test>
    <dpkginfo_test comment="gforge is earlier than 4.7~rc2-7lenny1" check="all" version="1" id="oval:org.mitre.oval:tst:18723" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:7612"/>
      <state state_ref="oval:org.mitre.oval:ste:6389"/>
    </dpkginfo_test>
    <dpkginfo_test comment="gforge-plugin-scmcvs is earlier than 4.7~rc2-7lenny1" check="all" version="1" id="oval:org.mitre.oval:tst:18705" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:7820"/>
      <state state_ref="oval:org.mitre.oval:ste:6389"/>
    </dpkginfo_test>
    <dpkginfo_test comment="gforge-mta-courier is earlier than 4.5.14-22etch11" check="all" version="1" id="oval:org.mitre.oval:tst:18686" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:7730"/>
      <state state_ref="oval:org.mitre.oval:ste:6363"/>
    </dpkginfo_test>
    <dpkginfo_test comment="gforge-ldap-openldap is earlier than 4.5.14-22etch11" check="all" version="1" id="oval:org.mitre.oval:tst:18654" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:7883"/>
      <state state_ref="oval:org.mitre.oval:ste:6363"/>
    </dpkginfo_test>
    <dpkginfo_test comment="gforge-db-postgresql is earlier than 4.7~rc2-7lenny1" check="all" version="1" id="oval:org.mitre.oval:tst:18651" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:7827"/>
      <state state_ref="oval:org.mitre.oval:ste:6389"/>
    </dpkginfo_test>
    <dpkginfo_test comment="gforge-mta-postfix is earlier than 4.7~rc2-7lenny1" check="all" version="1" id="oval:org.mitre.oval:tst:18636" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:7865"/>
      <state state_ref="oval:org.mitre.oval:ste:6389"/>
    </dpkginfo_test>
    <dpkginfo_test comment="gforge-ftp-proftpd is earlier than 4.7~rc2-7lenny1" check="all" version="1" id="oval:org.mitre.oval:tst:18624" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:7666"/>
      <state state_ref="oval:org.mitre.oval:ste:6389"/>
    </dpkginfo_test>
    <dpkginfo_test comment="gforge-shell-postgresql is earlier than 4.7~rc2-7lenny1" check="all" version="1" id="oval:org.mitre.oval:tst:18607" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:7833"/>
      <state state_ref="oval:org.mitre.oval:ste:6389"/>
    </dpkginfo_test>
    <dpkginfo_test comment="gforge-common is earlier than 4.5.14-22etch11" check="all" version="1" id="oval:org.mitre.oval:tst:18603" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:7685"/>
      <state state_ref="oval:org.mitre.oval:ste:6363"/>
    </dpkginfo_test>
    <dpkginfo_test comment="gforge-shell-ldap is earlier than 4.5.14-22etch11" check="all" version="1" id="oval:org.mitre.oval:tst:18594" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:7699"/>
      <state state_ref="oval:org.mitre.oval:ste:6363"/>
    </dpkginfo_test>
    <dpkginfo_test comment="gforge-mta-courier is earlier than 4.7~rc2-7lenny1" check="all" version="1" id="oval:org.mitre.oval:tst:18588" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:7730"/>
      <state state_ref="oval:org.mitre.oval:ste:6389"/>
    </dpkginfo_test>
    <dpkginfo_test comment="gforge-ftp-proftpd is earlier than 4.5.14-22etch11" check="all" version="1" id="oval:org.mitre.oval:tst:18574" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:7666"/>
      <state state_ref="oval:org.mitre.oval:ste:6363"/>
    </dpkginfo_test>
    <dpkginfo_test comment="gforge-dns-bind9 is earlier than 4.7~rc2-7lenny1" check="all" version="1" id="oval:org.mitre.oval:tst:18561" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:7722"/>
      <state state_ref="oval:org.mitre.oval:ste:6389"/>
    </dpkginfo_test>
    <dpkginfo_test comment="gforge-web-apache is earlier than 4.5.14-22etch11" check="all" version="1" id="oval:org.mitre.oval:tst:18538" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:7663"/>
      <state state_ref="oval:org.mitre.oval:ste:6363"/>
    </dpkginfo_test>
    <dpkginfo_test comment="gforge-shell-postgresql is earlier than 4.5.14-22etch11" check="all" version="1" id="oval:org.mitre.oval:tst:18510" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:7833"/>
      <state state_ref="oval:org.mitre.oval:ste:6363"/>
    </dpkginfo_test>
    <dpkginfo_test comment="gforge-plugin-scmsvn is earlier than 4.7~rc2-7lenny1" check="all" version="1" id="oval:org.mitre.oval:tst:18501" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:6863"/>
      <state state_ref="oval:org.mitre.oval:ste:6389"/>
    </dpkginfo_test>
    <dpkginfo_test comment="gforge-mta-exim is earlier than 4.5.14-22etch11" check="all" version="1" id="oval:org.mitre.oval:tst:18497" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:7485"/>
      <state state_ref="oval:org.mitre.oval:ste:6363"/>
    </dpkginfo_test>
    <dpkginfo_test comment="gforge-plugin-mediawiki is earlier than 4.7~rc2-7lenny1" check="all" version="1" id="oval:org.mitre.oval:tst:18494" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:7831"/>
      <state state_ref="oval:org.mitre.oval:ste:6389"/>
    </dpkginfo_test>
    <dpkginfo_test comment="gforge-common is earlier than 4.7~rc2-7lenny1" check="all" version="1" id="oval:org.mitre.oval:tst:18436" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:7685"/>
      <state state_ref="oval:org.mitre.oval:ste:6389"/>
    </dpkginfo_test>
    <dpkginfo_test comment="gforge-dns-bind9 is earlier than 4.5.14-22etch11" check="all" version="1" id="oval:org.mitre.oval:tst:18409" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:7722"/>
      <state state_ref="oval:org.mitre.oval:ste:6363"/>
    </dpkginfo_test>
    <dpkginfo_test comment="gforge-web-apache2 is earlier than 4.7~rc2-7lenny1" check="all" version="1" id="oval:org.mitre.oval:tst:18404" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:6884"/>
      <state state_ref="oval:org.mitre.oval:ste:6389"/>
    </dpkginfo_test>
    <dpkginfo_test comment="gforge-web-apache is earlier than 4.7~rc2-7lenny1" check="all" version="1" id="oval:org.mitre.oval:tst:18366" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:7663"/>
      <state state_ref="oval:org.mitre.oval:ste:6389"/>
    </dpkginfo_test>
    <dpkginfo_test comment="gforge-lists-mailman is earlier than 4.7~rc2-7lenny1" check="all" version="1" id="oval:org.mitre.oval:tst:18335" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:7252"/>
      <state state_ref="oval:org.mitre.oval:ste:6389"/>
    </dpkginfo_test>
    <dpkginfo_test comment="gforge-lists-mailman is earlier than 4.5.14-22etch11" check="all" version="1" id="oval:org.mitre.oval:tst:18324" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:7252"/>
      <state state_ref="oval:org.mitre.oval:ste:6363"/>
    </dpkginfo_test>
    <dpkginfo_test comment="gforge-mta-exim4 is earlier than 4.5.14-22etch11" check="all" version="1" id="oval:org.mitre.oval:tst:18305" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:7001"/>
      <state state_ref="oval:org.mitre.oval:ste:6363"/>
    </dpkginfo_test>
    <dpkginfo_test comment="gforge-db-postgresql is earlier than 4.5.14-22etch11" check="all" version="1" id="oval:org.mitre.oval:tst:18184" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:7827"/>
      <state state_ref="oval:org.mitre.oval:ste:6363"/>
    </dpkginfo_test>
    <dpkginfo_test comment="git-cvs is earlier than 1.4.4.4-4+etch2" check="all" version="1" id="oval:org.mitre.oval:tst:19041" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:8083"/>
      <state state_ref="oval:org.mitre.oval:ste:6146"/>
    </dpkginfo_test>
    <dpkginfo_test comment="git-svn is earlier than 1.4.4.4-4+etch2" check="all" version="1" id="oval:org.mitre.oval:tst:19008" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:7999"/>
      <state state_ref="oval:org.mitre.oval:ste:6146"/>
    </dpkginfo_test>
    <dpkginfo_test comment="git-doc is earlier than 1.5.6.5-3+lenny1" check="all" version="1" id="oval:org.mitre.oval:tst:18952" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:8051"/>
      <state state_ref="oval:org.mitre.oval:ste:6189"/>
    </dpkginfo_test>
    <dpkginfo_test comment="git-core is earlier than 1.4.4.4-4+etch2" check="all" version="1" id="oval:org.mitre.oval:tst:18944" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:7797"/>
      <state state_ref="oval:org.mitre.oval:ste:6146"/>
    </dpkginfo_test>
    <dpkginfo_test comment="git-daemon-run is earlier than 1.5.6.5-3+lenny1" check="all" version="1" id="oval:org.mitre.oval:tst:18935" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:7799"/>
      <state state_ref="oval:org.mitre.oval:ste:6189"/>
    </dpkginfo_test>
    <dpkginfo_test comment="gitweb is earlier than 1.5.6.5-3+lenny1" check="all" version="1" id="oval:org.mitre.oval:tst:18916" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:8155"/>
      <state state_ref="oval:org.mitre.oval:ste:6189"/>
    </dpkginfo_test>
    <dpkginfo_test comment="git-core is earlier than 1.5.6.5-3+lenny1" check="all" version="1" id="oval:org.mitre.oval:tst:18914" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:7797"/>
      <state state_ref="oval:org.mitre.oval:ste:6189"/>
    </dpkginfo_test>
    <dpkginfo_test comment="git-cvs is earlier than 1.5.6.5-3+lenny1" check="all" version="1" id="oval:org.mitre.oval:tst:18901" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:8083"/>
      <state state_ref="oval:org.mitre.oval:ste:6189"/>
    </dpkginfo_test>
    <dpkginfo_test comment="git-daemon-run is earlier than 1.4.4.4-4+etch2" check="all" version="1" id="oval:org.mitre.oval:tst:18882" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:7799"/>
      <state state_ref="oval:org.mitre.oval:ste:6146"/>
    </dpkginfo_test>
    <dpkginfo_test comment="git-email is earlier than 1.5.6.5-3+lenny1" check="all" version="1" id="oval:org.mitre.oval:tst:18814" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:8210"/>
      <state state_ref="oval:org.mitre.oval:ste:6189"/>
    </dpkginfo_test>
    <dpkginfo_test comment="git-email is earlier than 1.4.4.4-4+etch2" check="all" version="1" id="oval:org.mitre.oval:tst:18795" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:8210"/>
      <state state_ref="oval:org.mitre.oval:ste:6146"/>
    </dpkginfo_test>
    <dpkginfo_test comment="git-svn is earlier than 1.5.6.5-3+lenny1" check="all" version="1" id="oval:org.mitre.oval:tst:18788" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:7999"/>
      <state state_ref="oval:org.mitre.oval:ste:6189"/>
    </dpkginfo_test>
    <dpkginfo_test comment="git-arch is earlier than 1.4.4.4-4+etch2" check="all" version="1" id="oval:org.mitre.oval:tst:18760" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:7839"/>
      <state state_ref="oval:org.mitre.oval:ste:6146"/>
    </dpkginfo_test>
    <dpkginfo_test comment="git-arch is earlier than 1.5.6.5-3+lenny1" check="all" version="1" id="oval:org.mitre.oval:tst:18756" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:7839"/>
      <state state_ref="oval:org.mitre.oval:ste:6189"/>
    </dpkginfo_test>
    <dpkginfo_test comment="git-doc is earlier than 1.4.4.4-4+etch2" check="all" version="1" id="oval:org.mitre.oval:tst:18679" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:8051"/>
      <state state_ref="oval:org.mitre.oval:ste:6146"/>
    </dpkginfo_test>
    <dpkginfo_test comment="git-gui is earlier than 1.5.6.5-3+lenny1" check="all" version="1" id="oval:org.mitre.oval:tst:18647" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:7972"/>
      <state state_ref="oval:org.mitre.oval:ste:6189"/>
    </dpkginfo_test>
    <dpkginfo_test comment="gitk is earlier than 1.4.4.4-4+etch2" check="all" version="1" id="oval:org.mitre.oval:tst:18552" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:8169"/>
      <state state_ref="oval:org.mitre.oval:ste:6146"/>
    </dpkginfo_test>
    <dpkginfo_test comment="gitweb is earlier than 1.4.4.4-4+etch2" check="all" version="1" id="oval:org.mitre.oval:tst:18454" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:8155"/>
      <state state_ref="oval:org.mitre.oval:ste:6146"/>
    </dpkginfo_test>
    <dpkginfo_test comment="gitk is earlier than 1.5.6.5-3+lenny1" check="all" version="1" id="oval:org.mitre.oval:tst:18132" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:8169"/>
      <state state_ref="oval:org.mitre.oval:ste:6189"/>
    </dpkginfo_test>
    <dpkginfo_test comment="mantis is earlier than 1.1.6+dfsg-2lenny1" check="all" version="1" id="oval:org.mitre.oval:tst:19241" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:10617"/>
      <state state_ref="oval:org.mitre.oval:ste:6118"/>
    </dpkginfo_test>
    <dpkginfo_test comment="acpid is earlier than 1.0.8-1lenny1" check="all" version="1" id="oval:org.mitre.oval:tst:18876" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11473"/>
      <state state_ref="oval:org.mitre.oval:ste:6321"/>
    </dpkginfo_test>
    <dpkginfo_test comment="acpid is earlier than 1.0.4-5etch1" check="all" version="1" id="oval:org.mitre.oval:tst:18789" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11473"/>
      <state state_ref="oval:org.mitre.oval:ste:6341"/>
    </dpkginfo_test>
    <dpkginfo_test comment="kdelibs4-doc is earlier than 3.5.10.dfsg.1-0lenny2" check="all" version="1" id="oval:org.mitre.oval:tst:18414" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:10954"/>
      <state state_ref="oval:org.mitre.oval:ste:6345"/>
    </dpkginfo_test>
    <dpkginfo_test comment="kdelibs-dbg is earlier than 3.5.5a.dfsg.1-8etch2" check="all" version="1" id="oval:org.mitre.oval:tst:18402" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:10737"/>
      <state state_ref="oval:org.mitre.oval:ste:5595"/>
    </dpkginfo_test>
    <dpkginfo_test comment="kdelibs4-dev is earlier than 3.5.5a.dfsg.1-8etch2" check="all" version="1" id="oval:org.mitre.oval:tst:18399" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:10302"/>
      <state state_ref="oval:org.mitre.oval:ste:5595"/>
    </dpkginfo_test>
    <dpkginfo_test comment="kdelibs-dbg is earlier than 3.5.10.dfsg.1-0lenny2" check="all" version="1" id="oval:org.mitre.oval:tst:18361" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:10737"/>
      <state state_ref="oval:org.mitre.oval:ste:6345"/>
    </dpkginfo_test>
    <dpkginfo_test comment="kdelibs is earlier than 3.5.5a.dfsg.1-8etch2" check="all" version="1" id="oval:org.mitre.oval:tst:18294" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:10158"/>
      <state state_ref="oval:org.mitre.oval:ste:5595"/>
    </dpkginfo_test>
    <dpkginfo_test comment="kdelibs-data is earlier than 3.5.10.dfsg.1-0lenny2" check="all" version="1" id="oval:org.mitre.oval:tst:18276" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:10369"/>
      <state state_ref="oval:org.mitre.oval:ste:6345"/>
    </dpkginfo_test>
    <dpkginfo_test comment="kdelibs4c2a is earlier than 3.5.10.dfsg.1-0lenny2" check="all" version="1" id="oval:org.mitre.oval:tst:18246" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11144"/>
      <state state_ref="oval:org.mitre.oval:ste:6345"/>
    </dpkginfo_test>
    <dpkginfo_test comment="kdelibs4c2a is earlier than 3.5.5a.dfsg.1-8etch2" check="all" version="1" id="oval:org.mitre.oval:tst:18202" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:11144"/>
      <state state_ref="oval:org.mitre.oval:ste:5595"/>
    </dpkginfo_test>
    <dpkginfo_test comment="kdelibs-data is earlier than 3.5.5a.dfsg.1-8etch2" check="all" version="1" id="oval:org.mitre.oval:tst:18166" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:10369"/>
      <state state_ref="oval:org.mitre.oval:ste:5595"/>
    </dpkginfo_test>
    <dpkginfo_test comment="kdelibs4-dev is earlier than 3.5.10.dfsg.1-0lenny2" check="all" version="1" id="oval:org.mitre.oval:tst:18160" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:10302"/>
      <state state_ref="oval:org.mitre.oval:ste:6345"/>
    </dpkginfo_test>
    <dpkginfo_test comment="kdelibs4-doc is earlier than 3.5.5a.dfsg.1-8etch2" check="all" version="1" id="oval:org.mitre.oval:tst:18105" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:10954"/>
      <state state_ref="oval:org.mitre.oval:ste:5595"/>
    </dpkginfo_test>
    <dpkginfo_test comment="kdelibs is earlier than 3.5.10.dfsg.1-0lenny2" check="all" version="1" id="oval:org.mitre.oval:tst:18097" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:10158"/>
      <state state_ref="oval:org.mitre.oval:ste:6345"/>
    </dpkginfo_test>
    <dpkginfo_test comment="linux-headers-2.6.26-2-parisc is earlier than 2.6.26-15lenny3" check="all" version="1" id="oval:org.mitre.oval:tst:20818" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:8562"/>
      <state state_ref="oval:org.mitre.oval:ste:6176"/>
    </dpkginfo_test>
    <dpkginfo_test comment="linux-headers-2.6.26-2-all-hppa is earlier than 2.6.26-15lenny3" check="all" version="1" id="oval:org.mitre.oval:tst:20809" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:7966"/>
      <state state_ref="oval:org.mitre.oval:ste:6176"/>
    </dpkginfo_test>
    <dpkginfo_test comment="linux-image-2.6.26-2-parisc is earlier than 2.6.26-15lenny3" check="all" version="1" id="oval:org.mitre.oval:tst:20799" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:8464"/>
      <state state_ref="oval:org.mitre.oval:ste:6176"/>
    </dpkginfo_test>
    <dpkginfo_test comment="linux-headers-2.6.26-2-parisc-smp is earlier than 2.6.26-15lenny3" check="all" version="1" id="oval:org.mitre.oval:tst:20793" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:8442"/>
      <state state_ref="oval:org.mitre.oval:ste:6176"/>
    </dpkginfo_test>
    <dpkginfo_test comment="linux-image-2.6.26-2-s390-tape is earlier than 2.6.26-15lenny3" check="all" version="1" id="oval:org.mitre.oval:tst:20776" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:7991"/>
      <state state_ref="oval:org.mitre.oval:ste:6176"/>
    </dpkginfo_test>
    <dpkginfo_test comment="linux-doc-2.6.26 is earlier than 2.6.26-15lenny3" check="all" version="1" id="oval:org.mitre.oval:tst:20768" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:8320"/>
      <state state_ref="oval:org.mitre.oval:ste:6176"/>
    </dpkginfo_test>
    <dpkginfo_test comment="user-mode-linux is earlier than 2.6.26-1um-2+15lenny3" check="all" version="1" id="oval:org.mitre.oval:tst:20754" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:7848"/>
      <state state_ref="oval:org.mitre.oval:ste:6527"/>
    </dpkginfo_test>
    <dpkginfo_test comment="linux-support-2.6.26-2 is earlier than 2.6.26-15lenny3" check="all" version="1" id="oval:org.mitre.oval:tst:20747" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:8112"/>
      <state state_ref="oval:org.mitre.oval:ste:6176"/>
    </dpkginfo_test>
    <dpkginfo_test comment="linux-headers-2.6.26-2-all is earlier than 2.6.26-15lenny3" check="all" version="1" id="oval:org.mitre.oval:tst:20719" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:8298"/>
      <state state_ref="oval:org.mitre.oval:ste:6176"/>
    </dpkginfo_test>
    <dpkginfo_test comment="linux-modules-2.6.26-2-xen-amd64 is earlier than 2.6.26-15lenny3" check="all" version="1" id="oval:org.mitre.oval:tst:20717" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:7588"/>
      <state state_ref="oval:org.mitre.oval:ste:6176"/>
    </dpkginfo_test>
    <dpkginfo_test comment="linux-headers-2.6.26-2-xen-amd64 is earlier than 2.6.26-15lenny3" check="all" version="1" id="oval:org.mitre.oval:tst:20716" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:8372"/>
      <state state_ref="oval:org.mitre.oval:ste:6176"/>
    </dpkginfo_test>
    <dpkginfo_test comment="linux-patch-debian-2.6.26 is earlier than 2.6.26-15lenny3" check="all" version="1" id="oval:org.mitre.oval:tst:20713" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:7796"/>
      <state state_ref="oval:org.mitre.oval:ste:6176"/>
    </dpkginfo_test>
    <dpkginfo_test comment="linux-source-2.6.26 is earlier than 2.6.26-15lenny3" check="all" version="1" id="oval:org.mitre.oval:tst:20697" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:8224"/>
      <state state_ref="oval:org.mitre.oval:ste:6176"/>
    </dpkginfo_test>
    <dpkginfo_test comment="linux-image-2.6.26-2-parisc64-smp is earlier than 2.6.26-15lenny3" check="all" version="1" id="oval:org.mitre.oval:tst:20692" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:8429"/>
      <state state_ref="oval:org.mitre.oval:ste:6176"/>
    </dpkginfo_test>
    <dpkginfo_test comment="linux-headers-2.6.26-2-all is earlier than 2.6.26-15lenny3" check="all" version="1" id="oval:org.mitre.oval:tst:20679" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:8298"/>
      <state state_ref="oval:org.mitre.oval:ste:6176"/>
    </dpkginfo_test>
    <dpkginfo_test comment="linux-libc-dev is earlier than 2.6.26-15lenny3" check="all" version="1" id="oval:org.mitre.oval:tst:20675" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:7932"/>
      <state state_ref="oval:org.mitre.oval:ste:6176"/>
    </dpkginfo_test>
    <dpkginfo_test comment="linux-headers-2.6.26-2-vserver-s390x is earlier than 2.6.26-15lenny3" check="all" version="1" id="oval:org.mitre.oval:tst:20664" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:8296"/>
      <state state_ref="oval:org.mitre.oval:ste:6176"/>
    </dpkginfo_test>
    <dpkginfo_test comment="linux-image-2.6.26-2-parisc64 is earlier than 2.6.26-15lenny3" check="all" version="1" id="oval:org.mitre.oval:tst:20654" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:8318"/>
      <state state_ref="oval:org.mitre.oval:ste:6176"/>
    </dpkginfo_test>
    <dpkginfo_test comment="xen-linux-system-2.6.26-2-xen-amd64 is earlier than 2.6.26-15lenny3" check="all" version="1" id="oval:org.mitre.oval:tst:20650" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:8341"/>
      <state state_ref="oval:org.mitre.oval:ste:6176"/>
    </dpkginfo_test>
    <dpkginfo_test comment="linux-headers-2.6.26-2-common-vserver is earlier than 2.6.26-15lenny3" check="all" version="1" id="oval:org.mitre.oval:tst:20642" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:8228"/>
      <state state_ref="oval:org.mitre.oval:ste:6176"/>
    </dpkginfo_test>
    <dpkginfo_test comment="linux-headers-2.6.26-2-common is earlier than 2.6.26-15lenny3" check="all" version="1" id="oval:org.mitre.oval:tst:20626" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:8307"/>
      <state state_ref="oval:org.mitre.oval:ste:6176"/>
    </dpkginfo_test>
    <dpkginfo_test comment="linux-headers-2.6.26-2-all-s390 is earlier than 2.6.26-15lenny3" check="all" version="1" id="oval:org.mitre.oval:tst:20623" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:7435"/>
      <state state_ref="oval:org.mitre.oval:ste:6176"/>
    </dpkginfo_test>
    <dpkginfo_test comment="linux-headers-2.6.26-2-common-xen is earlier than 2.6.26-15lenny3" check="all" version="1" id="oval:org.mitre.oval:tst:20600" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:7926"/>
      <state state_ref="oval:org.mitre.oval:ste:6176"/>
    </dpkginfo_test>
    <dpkginfo_test comment="linux-image-2.6.26-2-s390x is earlier than 2.6.26-15lenny3" check="all" version="1" id="oval:org.mitre.oval:tst:20591" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:8410"/>
      <state state_ref="oval:org.mitre.oval:ste:6176"/>
    </dpkginfo_test>
    <dpkginfo_test comment="linux-image-2.6.26-2-vserver-s390x is earlier than 2.6.26-15lenny3" check="all" version="1" id="oval:org.mitre.oval:tst:20579" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:8153"/>
      <state state_ref="oval:org.mitre.oval:ste:6176"/>
    </dpkginfo_test>
    <dpkginfo_test comment="linux-image-2.6.26-2-openvz-amd64 is earlier than 2.6.26-15lenny3" check="all" version="1" id="oval:org.mitre.oval:tst:20564" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:8239"/>
      <state state_ref="oval:org.mitre.oval:ste:6176"/>
    </dpkginfo_test>
    <dpkginfo_test comment="linux-headers-2.6.26-2-vserver-amd64 is earlier than 2.6.26-15lenny3" check="all" version="1" id="oval:org.mitre.oval:tst:20557" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:8020"/>
      <state state_ref="oval:org.mitre.oval:ste:6176"/>
    </dpkginfo_test>
    <dpkginfo_test comment="linux-headers-2.6.26-2-common-openvz is earlier than 2.6.26-15lenny3" check="all" version="1" id="oval:org.mitre.oval:tst:20543" check_existence="a
