<?xml version="1.0" encoding="UTF-8"?>
<oval_definitions xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-definitions-5 oval-definitions-schema.xsd http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux hpux-definitions-schema.xsd http://oval.mitre.org/XMLSchema/oval-definitions-5#linux linux-definitions-schema.xsd http://oval.mitre.org/XMLSchema/oval-definitions-5#independent independent-definitions-schema.xsd http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris solaris-definitions-schema.xsd http://oval.mitre.org/XMLSchema/oval-definitions-5#aix aix-definitions-schema.xsd http://oval.mitre.org/XMLSchema/oval-definitions-5#esx esx-definitions-schema.xsd http://oval.mitre.org/XMLSchema/oval-common-5 oval-common-schema.xsd http://oval.mitre.org/XMLSchema/oval-definitions-5#unix unix-definitions-schema.xsd" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:oval="http://oval.mitre.org/XMLSchema/oval-common-5" xmlns:oval-def="http://oval.mitre.org/XMLSchema/oval-definitions-5">
  <generator>
    <oval:product_name>The OVAL Repository</oval:product_name>
    <oval:schema_version>5.6</oval:schema_version>
    <oval:timestamp>2009-11-20T04:32:23.852-05:00</oval:timestamp>
  </generator>
  <definitions>
    <definition id="oval:org.mitre.oval:def:5855" version="1" class="vulnerability">
      <metadata>
        <title>HP-UX Using libc, Remote Denial of Service (DoS)</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-1664" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1664"/>
        <description>Unspecified vulnerability in libc on HP HP-UX B.11.23 and B.11.31 allows remote attackers to cause a denial of service via unknown vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-08-07T10:53:22.000-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2008-08-11T11:11:29.603-04:00">DRAFT</status_change>
            <status_change date="2008-09-01T04:01:11.754-04:00">INTERIM</status_change>
            <status_change date="2008-09-22T04:00:34.470-04:00">ACCEPTED</status_change>
            <modified comment="Corrected the patch number for HP-UX B.11.31 based on the modification on HPSBUX02355" date="2009-11-16T17:18:00.073-05:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </modified>
            <status_change date="2009-11-16T17:19:30.081-05:00">INTERIM</status_change>
          </dates>
          <status>INTERIM</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02355">
          <criterion comment="HP-UX B.11.31" test_ref="oval:org.mitre.oval:tst:8260"/>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="ProgSupport.PROG-MIN is installed" test_ref="oval:org.mitre.oval:tst:8906"/>
            <criterion comment="OS-Core.CORE-64SLIB is installed" test_ref="oval:org.mitre.oval:tst:8378"/>
            <criterion comment="OS-Core.CORE-SHLIBS is installed" test_ref="oval:org.mitre.oval:tst:8981"/>
            <criterion comment="OS-Core.C-MIN is installed" test_ref="oval:org.mitre.oval:tst:8917"/>
            <criterion comment="OS-Core.C-MIN-64ALIB is installed" test_ref="oval:org.mitre.oval:tst:8551"/>
            <criterion comment="OS-Core.CORE2-64SLIB is installed" test_ref="oval:org.mitre.oval:tst:8680"/>
            <criterion comment="OS-Core.CORE2-SHLIBS is installed" test_ref="oval:org.mitre.oval:tst:9084"/>
            <criterion comment="ProgSupport.PROG2-AUX is installed" test_ref="oval:org.mitre.oval:tst:8594"/>
            <criterion comment="ProgSupport.PROG-AX-64ALIB is installed" test_ref="oval:org.mitre.oval:tst:8703"/>
          </criteria>
          <criterion negate="true" comment="Patch PHCO_38048 is installed" test_ref="oval:org.mitre.oval:tst:8563"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02355">
          <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="OS-Core.C-MIN is installed" test_ref="oval:org.mitre.oval:tst:8917"/>
            <criterion comment="OS-Core.C-MIN-64ALIB is installed" test_ref="oval:org.mitre.oval:tst:8551"/>
            <criterion comment="OS-Core.CORE2-64SLIB is installed" test_ref="oval:org.mitre.oval:tst:8680"/>
            <criterion comment="OS-Core.CORE2-SHLIBS is installed" test_ref="oval:org.mitre.oval:tst:9084"/>
            <criterion comment="ProgSupport.PROG2-AUX is installed" test_ref="oval:org.mitre.oval:tst:8594"/>
            <criterion comment="ProgSupport.PROG-AX-64ALIB is installed" test_ref="oval:org.mitre.oval:tst:8703"/>
            <criterion comment="ProgSupport.PROG-MIN is installed" test_ref="oval:org.mitre.oval:tst:8906"/>
          </criteria>
          <criterion negate="true" comment="Patch PHCO_38273 is installed" test_ref="oval:org.mitre.oval:tst:8692"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6328" version="1" class="vulnerability">
      <metadata>
        <title>HP-UX Running Role-Based Access Control (RBAC), Local Unauthorized Access</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-2682" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2682"/>
        <description>Unspecified vulnerability in Role-Based Access Control (RBAC) in HP HP-UX B.11.23 and B.11.31 allows local users to bypass intended access restrictions via unknown vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-10-07T11:33:53.000-04:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2009-10-09T14:07:00.581-04:00">DRAFT</status_change>
            <status_change date="2009-10-26T04:00:05.422-04:00">INTERIM</status_change>
            <status_change date="2009-11-16T04:00:19.006-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02457">
          <criterion comment="HP-UX B.11.31" test_ref="oval:org.mitre.oval:tst:8260"/>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="RBAC.RBAC-CONF is installed" test_ref="oval:org.mitre.oval:tst:10651"/>
            <criterion comment="RBAC.RBAC-RUN is installed" test_ref="oval:org.mitre.oval:tst:10540"/>
          </criteria>
          <criterion negate="true" comment="Patch PHCO_40131 is installed" test_ref="oval:org.mitre.oval:tst:10732"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02457">
          <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="RBAC.RBAC-CONF version is less than B.11.23.06" test_ref="oval:org.mitre.oval:tst:9940"/>
            <criterion comment="RBAC.RBAC-RUN version is less than B.11.23.06" test_ref="oval:org.mitre.oval:tst:10583"/>
            <criterion comment="RBAC.RBAC-WEB version is less than B.11.23.06" test_ref="oval:org.mitre.oval:tst:10906"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6496" version="1" class="vulnerability">
      <metadata>
        <title>Libxml2 Recursive Entity Evaluation Bug Lets Remote Users Deny Service</title>
        <affected family="unix">
          <platform>VMWare ESX Server 3</platform>
          <platform>VMWare ESX Server 3.5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-3281" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-3281"/>
        <description>libxml2 2.6.32 and earlier does not properly detect recursion during entity expansion in an attribute value, which allows context-dependent attackers to cause a denial of service (memory and CPU consumption) via a crafted XML document.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-09-23T15:39:02.000-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2009-09-29T20:37:01.188-04:00">DRAFT</status_change>
            <status_change date="2009-10-19T04:00:22.211-04:00">INTERIM</status_change>
            <status_change date="2009-11-09T04:01:08.913-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND">
          <extend_definition comment="VMWare ESX Server 3.0.3 is installed" definition_ref="oval:org.mitre.oval:def:6026"/>
          <criterion comment="Patch ESX303-200810503-SG is not installed" test_ref="oval:org.mitre.oval:tst:10758"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="VMWare ESX Server 3.0.2 is installed" definition_ref="oval:org.mitre.oval:def:5626"/>
          <criterion comment="Patch ESX-1006968 is not installed" test_ref="oval:org.mitre.oval:tst:10726"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="VMware ESX Server 3.5.0 is installed" definition_ref="oval:org.mitre.oval:def:5887"/>
          <criterion comment="Patch ESX350-200811405-SG is not installed" test_ref="oval:org.mitre.oval:tst:10390"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6467" version="0" class="vulnerability">
      <metadata>
        <title>Bzip2 Bug Lets Remote Users Deny Service</title>
        <affected family="unix">
          <platform>VMWare ESX Server 3</platform>
          <platform>VMWare ESX Server 3.5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-1372" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1372"/>
        <description>bzlib.c in bzip2 before 1.0.5 allows user-assisted remote attackers to cause a denial of service (crash) via a crafted file that triggers a buffer over-read, as demonstrated by the PROTOS GENOME test suite for Archive Formats.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-09-23T15:39:02.000-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2009-09-29T20:37:34.209-04:00">DRAFT</status_change>
            <modified comment="Extra criteria blocks added to handle multiple patch logic in def:6467" date="2009-10-20T13:45:00.084-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </modified>
            <status_change date="2009-11-09T04:01:03.979-05:00">INTERIM</status_change>
          </dates>
          <status>INTERIM</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND">
          <extend_definition comment="VMWare ESX Server 3.0.3 is installed" definition_ref="oval:org.mitre.oval:def:6026"/>
          <criteria operator="OR" comment="All patches must be installed to not be vulnerable">
            <criterion comment="Patch ESX303-200811401-BG is not installed" test_ref="oval:org.mitre.oval:tst:10427"/>
            <criterion comment="Patch ESX303-200811404-BG is not installed" test_ref="oval:org.mitre.oval:tst:10784"/>
          </criteria>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="VMWare ESX Server 3.0.2 is installed" definition_ref="oval:org.mitre.oval:def:5626"/>
          <criteria operator="OR" comment="All patches must be installed to not be vulnerable">
            <criterion comment="Patch ESX-1006980 is not installed" test_ref="oval:org.mitre.oval:tst:10716"/>
            <criterion comment="Patch ESX-1006982 is not installed" test_ref="oval:org.mitre.oval:tst:10728"/>
          </criteria>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="VMware ESX Server 3.5.0 is installed" definition_ref="oval:org.mitre.oval:def:5887"/>
          <criteria operator="OR" comment="All patches must be installed to not be vulnerable">
            <criterion comment="Patch ESX350-200811401-SG is not installed" test_ref="oval:org.mitre.oval:tst:10834"/>
            <criterion comment="Patch ESX350-200811406-SG is not installed" test_ref="oval:org.mitre.oval:tst:10809"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6463" version="0" class="vulnerability">
      <metadata>
        <title>Vim HelpTags Command Remote Format String Vulnerability</title>
        <affected family="unix">
          <platform>VMWare ESX Server 3</platform>
          <platform>VMWare ESX Server 3.5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-2953" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3953"/>
        <description>Format string vulnerability in the helptags_one function in src/ex_cmds.c in Vim 6.4 and earlier, and 7.x up to 7.1, allows user-assisted remote attackers to execute arbitrary code via format string specifiers in a help-tags tag in a help file, related to the helptags command.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-09-23T15:39:02.000-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2009-09-28T06:56:17.418-04:00">DRAFT</status_change>
            <modified comment="Extra criteria blocks added to handle multiple patch logic in def:6463" date="2009-10-20T13:58:00.694-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </modified>
            <status_change date="2009-11-09T04:01:03.195-05:00">INTERIM</status_change>
          </dates>
          <status>INTERIM</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND">
          <extend_definition comment="VMWare ESX Server 3.0.3 is installed" definition_ref="oval:org.mitre.oval:def:6026"/>
          <criteria operator="OR" comment="All patches must be installed to not be vulnerable">
            <criterion comment="Patch ESX303-200903406-SG is not installed" test_ref="oval:org.mitre.oval:tst:10431"/>
            <criterion comment="Patch ESX303-200903405-SG is not installed" test_ref="oval:org.mitre.oval:tst:10817"/>
            <criterion comment="Patch ESX303-200903403-SG is not installed" test_ref="oval:org.mitre.oval:tst:10649"/>
          </criteria>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="VMWare ESX Server 3.0.2 is installed" definition_ref="oval:org.mitre.oval:def:5613"/>
          <criteria operator="OR" comment="All patches must be installed to not be vulnerable">
            <criterion comment="Patch ESX-1008409 is not installed" test_ref="oval:org.mitre.oval:tst:9873"/>
            <criterion comment="Patch ESX-1008408 is not installed" test_ref="oval:org.mitre.oval:tst:10772"/>
            <criterion comment="Patch ESX-1008406 is not installed" test_ref="oval:org.mitre.oval:tst:10589"/>
          </criteria>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="VMware ESX Server 3.5.0 is installed" definition_ref="oval:org.mitre.oval:def:5887"/>
          <criteria operator="OR" comment="All patches must be installed to not be vulnerable">
            <criterion comment="Patch ESX350-200904408-SG is not installed" test_ref="oval:org.mitre.oval:tst:10852"/>
            <criterion comment="Patch ESX350-200904407-SG is not installed" test_ref="oval:org.mitre.oval:tst:10730"/>
            <criterion comment="Patch ESX350-200904406-SG is not installed" test_ref="oval:org.mitre.oval:tst:10114"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6462" version="0" class="vulnerability">
      <metadata>
        <title>Sudo Supplemental Group Privilege Error Lets Certain Local Users Gain Elevated Privileges</title>
        <affected family="unix">
          <platform>VMWare ESX Server 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-0034" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0034"/>
        <description>parse.c in sudo 1.6.9p17 through 1.6.9p19 does not properly interpret a system group (aka %group) in the sudoers file during authorization decisions for a user who belongs to that group, which allows local users to leverage an applicable sudoers file and gain root privileges via a sudo command.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-09-22T15:10:44.000-05:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2009-09-28T06:56:53.336-04:00">DRAFT</status_change>
            <modified comment="Extra criteria blocks added to handle multiple patch logic in def:6462" date="2009-10-20T13:59:00.494-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </modified>
            <status_change date="2009-11-09T04:01:02.903-05:00">INTERIM</status_change>
          </dates>
          <status>INTERIM</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="VMware ESX Server 4.0 is installed" definition_ref="oval:org.mitre.oval:def:6020"/>
        <criteria operator="OR" comment="All patches must be installed to not be vulnerable">
          <criterion comment="Patch ESX400-200906411-SG is not installed" test_ref="oval:org.mitre.oval:tst:10871"/>
          <criterion comment="Patch ESX400-200906407-SG is not installed" test_ref="oval:org.mitre.oval:tst:10674"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6020" version="1" class="inventory">
      <metadata>
        <title>VMware ESX Server 4.0 is installed</title>
        <affected family="unix">
          <platform>VMware ESX Server 4</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/o:vmware:esx:4.0"/>
        <description>The operating system installed on the system is VMware ESX Server 4.0.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-09-22T15:10:44.000-05:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2009-09-28T06:56:53.059-04:00">DRAFT</status_change>
            <status_change date="2009-10-26T04:00:04.560-04:00">INTERIM</status_change>
            <status_change date="2009-11-16T04:00:17.087-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="VMware ESX Server 4.0 is installed" test_ref="oval:org.mitre.oval:tst:10828"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6458" version="1" class="vulnerability">
      <metadata>
        <title>Libpng Library Uninitialized Pointer Arrays Memory Corruption Vulnerability</title>
        <affected family="unix">
          <platform>VMWare ESX Server 3</platform>
          <platform>VMWare ESX Server 3.5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-0040" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0040"/>
        <description>The PNG reference library (aka libpng) before 1.0.43, and 1.2.x before 1.2.35, as used in pngcrush and other applications, allows context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted PNG file that triggers a free of an uninitialized pointer in (1) the png_read_png function, (2) pCAL chunk handling, or (3) setup of 16-bit gamma tables.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-09-23T15:39:02.000-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2009-09-28T06:56:27.753-04:00">DRAFT</status_change>
            <status_change date="2009-10-19T04:00:20.944-04:00">INTERIM</status_change>
            <status_change date="2009-11-09T04:01:02.634-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND">
          <extend_definition comment="VMWare ESX Server 3.0.3 is installed" definition_ref="oval:org.mitre.oval:def:6026"/>
          <criterion comment="Patch ESX303-200905401-SG is not installed" test_ref="oval:org.mitre.oval:tst:9878"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="VMWare ESX Server 3.0.2 is installed" definition_ref="oval:org.mitre.oval:def:5613"/>
          <criterion comment="Patch ESX-1008420 is not installed" test_ref="oval:org.mitre.oval:tst:10635"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="VMware ESX Server 3.5.0 is installed" definition_ref="oval:org.mitre.oval:def:5887"/>
          <criterion comment="Patch ESX350-200904401-BG is not installed" test_ref="oval:org.mitre.oval:tst:10863"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6449" version="1" class="vulnerability">
      <metadata>
        <title>Kerberos GSS-API SPNEGO Null Pointer Dereference and Invalid Memory Access Bugs Let Remote Denial of Service</title>
        <affected family="unix">
          <platform>VMWare ESX Server 3</platform>
          <platform>VMWare ESX Server 3.5</platform>
          <platform>VMWare ESX Server 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-0845" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0845"/>
        <description>The spnego_gss_accept_sec_context function in lib/gssapi/spnego/spnego_mech.c in MIT Kerberos 5 (aka krb5) 1.5 through 1.6.3, when SPNEGO is used, allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via invalid ContextFlags data in the reqFlags field in a negTokenInit token.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-09-23T15:39:02.000-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2009-09-28T06:57:28.961-04:00">DRAFT</status_change>
            <status_change date="2009-10-19T04:00:20.646-04:00">INTERIM</status_change>
            <status_change date="2009-11-09T04:01:00.504-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND">
          <extend_definition comment="VMWare ESX Server 3.0.3 is installed" definition_ref="oval:org.mitre.oval:def:6026"/>
          <criterion comment="Patch ESX303-200908403-SG is not installed" test_ref="oval:org.mitre.oval:tst:10799"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="VMware ESX Server 4.0 is installed" definition_ref="oval:org.mitre.oval:def:5506"/>
          <criterion comment="Patch ESX400-200906405-SG is not installed" test_ref="oval:org.mitre.oval:tst:10839"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="VMware ESX Server 3.5.0 is installed" definition_ref="oval:org.mitre.oval:def:5887"/>
          <criterion comment="Patch ESX350-200906407-SG is not installed" test_ref="oval:org.mitre.oval:tst:10641"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="VMWare ESX Server 3.0.2 is installed" definition_ref="oval:org.mitre.oval:def:5626"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6439" version="1" class="vulnerability">
      <metadata>
        <title>VMware Guest Virtual Device Driver Bug Lets Local Users Deny Service</title>
        <affected family="unix">
          <platform>VMWare ESX Server 3</platform>
          <platform>VMWare ESX Server 3.5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-4916" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-4916"/>
        <description>Unspecified vulnerability in a guest virtual device driver in VMware Workstation before 5.5.9 build 126128, and 6.5.1 and earlier 6.x versions; VMware Player before 1.0.9 build 126128, and 2.5.1 and earlier 2.x versions; VMware ACE before 1.0.8 build 125922, and 2.5.1 and earlier 2.x versions; VMware Server 1.x before 1.0.8 build 126538 and 2.0.x before 2.0.1 build 156745; VMware Fusion before 2.0.1; VMware ESXi 3.5; and VMware ESX 3.0.2, 3.0.3, and 3.5 allows guest OS users to cause a denial of service (host OS crash) via unknown vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-09-23T15:39:02.000-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2009-09-28T06:57:19.596-04:00">DRAFT</status_change>
            <status_change date="2009-10-19T04:00:20.375-04:00">INTERIM</status_change>
            <status_change date="2009-11-09T04:01:00.222-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND">
          <extend_definition comment="VMWare ESX Server 3.0.3 is installed" definition_ref="oval:org.mitre.oval:def:6026"/>
          <criterion comment="Patch ESX303-200811401-BG is not installed" test_ref="oval:org.mitre.oval:tst:10884"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="VMWare ESX Server 3.0.2 is installed" definition_ref="oval:org.mitre.oval:def:5613"/>
          <criterion comment="Patch ESX-1006980 is not installed" test_ref="oval:org.mitre.oval:tst:10693"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="VMware ESX Server 3.5.0 is installed" definition_ref="oval:org.mitre.oval:def:5887"/>
          <criterion comment="Patch ESX350-200811401-SG is not installed" test_ref="oval:org.mitre.oval:tst:9884"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6433" version="1" class="vulnerability">
      <metadata>
        <title>VMware authd Service Lets Remote Users Deny Service</title>
        <affected family="unix">
          <platform>VMWare ESX Server 3</platform>
          <platform>VMWare ESX Server 3.5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-0177" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0177"/>
        <description>vmwarebase.dll, as used in the vmware-authd service (aka vmware-authd.exe), in VMware Workstation 6.5.1 build 126130, 6.5.1 and earlier; VMware Player 2.5.1 build 126130, 2.5.1 and earlier; VMware ACE 2.5.1 and earlier; VMware Server 2.0.x before 2.0.1 build 156745; and VMware Fusion before 2.0.2 build 147997 allows remote attackers to cause a denial of service (daemon crash) via a long (1) USER or (2) PASS command.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-09-23T15:39:02.000-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2009-09-28T06:57:19.177-04:00">DRAFT</status_change>
            <status_change date="2009-10-19T04:00:20.106-04:00">INTERIM</status_change>
            <status_change date="2009-11-09T04:00:59.620-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND">
          <extend_definition comment="VMWare ESX Server 3.0.3 is installed" definition_ref="oval:org.mitre.oval:def:6026"/>
          <criterion comment="Patch ESX303-200811401-BG is not installed" test_ref="oval:org.mitre.oval:tst:10884"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="VMWare ESX Server 3.0.2 is installed" definition_ref="oval:org.mitre.oval:def:5613"/>
          <criterion comment="Patch ESX-1006980 is not installed" test_ref="oval:org.mitre.oval:tst:10693"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="VMware ESX Server 3.5.0 is installed" definition_ref="oval:org.mitre.oval:def:5887"/>
          <criterion comment="Patch ESX350-200811401-SG is not installed" test_ref="oval:org.mitre.oval:tst:9884"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6427" version="1" class="vulnerability">
      <metadata>
        <title>Harmoni Versions Prior to 1.6.0 Cross-Site Request Forgery and Security Bypass Vulnerabilities</title>
        <affected family="unix">
          <platform>VMWare ESX Server 3</platform>
          <platform>VMWare ESX Server 3.5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-3716" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-3716"/>
        <description>Cross-site request forgery (CSRF) vulnerability in Harmoni before 1.6.0 allows remote attackers to make administrative modifications via a (1) save or (2) delete action to an unspecified component.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-09-23T15:39:02.000-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2009-09-28T06:57:19.805-04:00">DRAFT</status_change>
            <status_change date="2009-10-19T04:00:19.714-04:00">INTERIM</status_change>
            <status_change date="2009-11-09T04:00:57.953-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND">
          <extend_definition comment="VMWare ESX Server 3.0.3 is installed" definition_ref="oval:org.mitre.oval:def:6026"/>
          <criterion comment="Patch ESX303-200811401-BG is not installed" test_ref="oval:org.mitre.oval:tst:10884"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="VMWare ESX Server 3.0.2 is installed" definition_ref="oval:org.mitre.oval:def:5613"/>
          <criterion comment="Patch ESX-1006980 is not installed" test_ref="oval:org.mitre.oval:tst:10693"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="VMware ESX Server 3.5.0 is installed" definition_ref="oval:org.mitre.oval:def:5887"/>
          <criterion comment="Patch ESX350-200811401-SG is not installed" test_ref="oval:org.mitre.oval:tst:9884"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6425" version="1" class="vulnerability">
      <metadata>
        <title>VMware ESX Administrative Directory Traversal Bug May Allow Administrators to Gain Elevated Privileges</title>
        <affected family="unix">
          <platform>VMWare ESX Server 3</platform>
          <platform>VMWare ESX Server 3.5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-4281" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-4281"/>
        <description>Directory traversal vulnerability in VMWare ESXi 3.5 before ESXe350-200810401-O-UG and ESX 3.5 before ESX350-200810201-UG allows administrators with the Datastore.FileManagement privilege to gain privileges via unknown vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-09-23T15:39:02.000-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2009-09-29T20:37:25.528-04:00">DRAFT</status_change>
            <status_change date="2009-10-19T04:00:19.451-04:00">INTERIM</status_change>
            <status_change date="2009-11-09T04:00:57.398-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND">
          <extend_definition comment="VMWare ESX Server 3.0.3 is installed" definition_ref="oval:org.mitre.oval:def:6026"/>
          <criterion comment="Patch ESX303-200810501-BG is not installed" test_ref="oval:org.mitre.oval:tst:10500"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="VMWare ESX Server 3.0.2 is installed" definition_ref="oval:org.mitre.oval:def:5626"/>
          <criterion comment="Patch ESX-1006680 is not installed" test_ref="oval:org.mitre.oval:tst:10484"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="VMware ESX Server 3.5.0 is installed" definition_ref="oval:org.mitre.oval:def:5887"/>
          <criterion comment="Patch ESX350-200810201-UG is not installed" test_ref="oval:org.mitre.oval:tst:9902"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6415" version="0" class="vulnerability">
      <metadata>
        <title>Libxml2 Integer Overflow in xmlBufferResize() Lets Remote Users Deny Service</title>
        <affected family="unix">
          <platform>VMWare ESX Server 3</platform>
          <platform>VMWare ESX Server 3.5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-4225" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-4225"/>
        <description>Integer overflow in the xmlBufferResize function in libxml2 2.7.2 allows context-dependent attackers to cause a denial of service (infinite loop) via a large XML document.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-09-23T15:39:02.000-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2009-09-29T20:37:17.106-04:00">DRAFT</status_change>
            <modified comment="Extra criteria blocks added to handle multiple patch logic in def:6415" date="2009-10-20T13:43:00.352-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </modified>
            <status_change date="2009-11-09T04:00:54.339-05:00">INTERIM</status_change>
          </dates>
          <status>INTERIM</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND">
          <extend_definition comment="VMWare ESX Server 3.0.3 is installed" definition_ref="oval:org.mitre.oval:def:6026"/>
          <criteria operator="OR" comment="All patches must be installed to not be vulnerable">
            <criterion comment="Patch ESX303-200901405-SG is not installed" test_ref="oval:org.mitre.oval:tst:10525"/>
            <criterion comment="Patch ESX303-200901406-SG is not installed" test_ref="oval:org.mitre.oval:tst:9916"/>
          </criteria>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="VMWare ESX Server 3.0.2 is installed" definition_ref="oval:org.mitre.oval:def:5626"/>
          <criteria operator="OR" comment="All patches must be installed to not be vulnerable">
            <criterion comment="Patch ESX-1007673 is not installed" test_ref="oval:org.mitre.oval:tst:10833"/>
            <criterion comment="Patch ESX-1007674 is not installed" test_ref="oval:org.mitre.oval:tst:10026"/>
          </criteria>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="VMware ESX Server 3.5.0 is installed" definition_ref="oval:org.mitre.oval:def:5887"/>
          <criteria operator="OR" comment="All patches must be installed to not be vulnerable">
            <criterion comment="Patch ESX350-200901401-SG is not installed" test_ref="oval:org.mitre.oval:tst:10671"/>
            <criterion comment="Patch ESX350-200901409-SG is not installed" test_ref="oval:org.mitre.oval:tst:10424"/>
            <criterion comment="Patch ESX350-200901410-SG is not installed" test_ref="oval:org.mitre.oval:tst:10070"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6414" version="1" class="vulnerability">
      <metadata>
        <title>Net-snmp SNMPv3 Authentication Bug Lets Remote Users Bypass Authentication</title>
        <affected family="unix">
          <platform>VMWare ESX Server 3</platform>
          <platform>VMWare ESX Server 3.5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-0960" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-0960"/>
        <description>SNMPv3 HMAC verification in (1) Net-SNMP 5.2.x before 5.2.4.1, 5.3.x before 5.3.2.1, and 5.4.x before 5.4.1.1; (2) UCD-SNMP; (3) eCos; (4) Juniper Session and Resource Control (SRC) C-series 1.0.0 through 2.0.0; (5) NetApp (aka Network Appliance) Data ONTAP 7.3RC1 and 7.3RC2; (6) SNMP Research before 16.2; (7) multiple Cisco IOS, CatOS, ACE, and Nexus products; and (8) Ingate Firewall 3.1.0 and later and SIParator 3.1.0 and later relies on the client to specify the HMAC length, which makes it easier for remote attackers to bypass SNMP authentication via a length value of 1, which only checks the first byte.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-09-23T15:39:02.000-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2009-09-29T20:37:01.401-04:00">DRAFT</status_change>
            <status_change date="2009-10-19T04:00:18.820-04:00">INTERIM</status_change>
            <status_change date="2009-11-09T04:00:53.998-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND">
          <extend_definition comment="VMWare ESX Server 3.0.3 is installed" definition_ref="oval:org.mitre.oval:def:6026"/>
          <criterion comment="Patch ESX303-200810503-SG is not installed" test_ref="oval:org.mitre.oval:tst:10758"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="VMWare ESX Server 3.0.2 is installed" definition_ref="oval:org.mitre.oval:def:5626"/>
          <criterion comment="Patch ESX-1006968 is not installed" test_ref="oval:org.mitre.oval:tst:10726"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="VMware ESX Server 3.5.0 is installed" definition_ref="oval:org.mitre.oval:def:5887"/>
          <criterion comment="Patch ESX350-200811405-SG is not installed" test_ref="oval:org.mitre.oval:tst:10390"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6399" version="1" class="vulnerability">
      <metadata>
        <title>VMware Host Guest File System Bug Lets Local Users Enable Certain Shared Folders</title>
        <affected family="unix">
          <platform>VMWare ESX Server 3</platform>
          <platform>VMWare ESX Server 3.5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-0908" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0908"/>
        <description>Unspecified vulnerability in the ACE shared folders implementation in the VMware Host Guest File System (HGFS) shared folders feature in VMware ACE 2.5.1 and earlier allows attackers to enable a disabled shared folder.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-09-23T15:39:02.000-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2009-09-28T06:57:18.950-04:00">DRAFT</status_change>
            <status_change date="2009-10-19T04:00:18.561-04:00">INTERIM</status_change>
            <status_change date="2009-11-09T04:00:52.898-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND">
          <extend_definition comment="VMWare ESX Server 3.0.3 is installed" definition_ref="oval:org.mitre.oval:def:6026"/>
          <criterion comment="Patch ESX303-200811401-BG is not installed" test_ref="oval:org.mitre.oval:tst:10884"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="VMWare ESX Server 3.0.2 is installed" definition_ref="oval:org.mitre.oval:def:5613"/>
          <criterion comment="Patch ESX-1006980 is not installed" test_ref="oval:org.mitre.oval:tst:10693"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="VMware ESX Server 3.5.0 is installed" definition_ref="oval:org.mitre.oval:def:5887"/>
          <criterion comment="Patch ESX350-200811401-SG is not installed" test_ref="oval:org.mitre.oval:tst:9884"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6380" version="0" class="vulnerability">
      <metadata>
        <title>OpenSSL DSA and ECDSA "EVP_VerifyFinal()" Spoofing Vulnerability</title>
        <affected family="unix">
          <platform>VMWare ESX Server 3</platform>
          <platform>VMWare ESX Server 3.5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-5077" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-5077"/>
        <description>OpenSSL 0.9.8i and earlier does not properly check the return value from the EVP_VerifyFinal function, which allows remote attackers to bypass validation of the certificate chain via a malformed SSL/TLS signature for DSA and ECDSA keys.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-09-23T15:39:02.000-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2009-09-28T06:56:17.688-04:00">DRAFT</status_change>
            <modified comment="Extra criteria blocks added to handle multiple patch logic in def:6380" date="2009-10-20T14:03:00.107-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </modified>
            <status_change date="2009-11-09T04:00:52.347-05:00">INTERIM</status_change>
          </dates>
          <status>INTERIM</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND">
          <extend_definition comment="VMWare ESX Server 3.0.3 is installed" definition_ref="oval:org.mitre.oval:def:6026"/>
          <criteria operator="OR" comment="All patches must be installed to not be vulnerable">
            <criterion comment="Patch ESX303-200903406-SG is not installed" test_ref="oval:org.mitre.oval:tst:10431"/>
            <criterion comment="Patch ESX303-200903405-SG is not installed" test_ref="oval:org.mitre.oval:tst:10817"/>
            <criterion comment="Patch ESX303-200903403-SG is not installed" test_ref="oval:org.mitre.oval:tst:10649"/>
          </criteria>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="VMWare ESX Server 3.0.2 is installed" definition_ref="oval:org.mitre.oval:def:5613"/>
          <criteria operator="OR" comment="All patches must be installed to not be vulnerable">
            <criterion comment="Patch ESX-1008409 is not installed" test_ref="oval:org.mitre.oval:tst:9873"/>
            <criterion comment="Patch ESX-1008408 is not installed" test_ref="oval:org.mitre.oval:tst:10772"/>
            <criterion comment="Patch ESX-1008406 is not installed" test_ref="oval:org.mitre.oval:tst:10589"/>
          </criteria>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="VMware ESX Server 3.5.0 is installed" definition_ref="oval:org.mitre.oval:def:5887"/>
          <criteria operator="OR" comment="All patches must be installed to not be vulnerable">
            <criterion comment="Patch ESX350-200904408-SG is not installed" test_ref="oval:org.mitre.oval:tst:10852"/>
            <criterion comment="Patch ESX350-200904407-SG is not installed" test_ref="oval:org.mitre.oval:tst:10730"/>
            <criterion comment="Patch ESX350-200904406-SG is not installed" test_ref="oval:org.mitre.oval:tst:10114"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6376" version="1" class="vulnerability">
      <metadata>
        <title>VMware Virtual Infrastructure Client Password Disclosure Weakness</title>
        <affected family="unix">
          <platform>VMWare ESX Server 3</platform>
          <platform>VMWare ESX Server 3.5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-0518" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0518"/>
        <description>VI Client in VMware VirtualCenter before 2.5 Update 4, VMware ESXi 3.5 before Update 4, and VMware ESX 3.5 before Update 4 retains the VirtualCenter Server password in process memory, which might allow local users to obtain this password.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-09-23T15:39:02.000-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2009-09-28T06:57:19.380-04:00">DRAFT</status_change>
            <status_change date="2009-10-19T04:00:17.518-04:00">INTERIM</status_change>
            <status_change date="2009-11-09T04:00:51.823-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND">
          <extend_definition comment="VMWare ESX Server 3.0.3 is installed" definition_ref="oval:org.mitre.oval:def:6026"/>
          <criterion comment="Patch ESX303-200811401-BG is not installed" test_ref="oval:org.mitre.oval:tst:10884"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="VMWare ESX Server 3.0.2 is installed" definition_ref="oval:org.mitre.oval:def:5613"/>
          <criterion comment="Patch ESX-1006980 is not installed" test_ref="oval:org.mitre.oval:tst:10693"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="VMware ESX Server 3.5.0 is installed" definition_ref="oval:org.mitre.oval:def:5887"/>
          <criterion comment="Patch ESX350-200811401-SG is not installed" test_ref="oval:org.mitre.oval:tst:9884"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6366" version="0" class="vulnerability">
      <metadata>
        <title>AIX NFSv4 nfs_portmon vulnerability</title>
        <affected family="unix">
          <platform>IBM AIX 5.3</platform>
          <platform>IBM AIX 6.1</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-3517" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3517"/>
        <description>nfs.ext in IBM AIX 5.3.x through 5.3.9 and 6.1.0 through 6.1.2 does not properly use the nfs_portmon setting, which allows remote attackers to bypass intended access restrictions for NFSv4 shares via unspecified vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-10-09T14:55:01.000-04:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2009-10-22T17:35:31.459-04:00">DRAFT</status_change>
            <status_change date="2009-11-09T04:00:50.517-05:00">INTERIM</status_change>
          </dates>
          <status>INTERIM</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND">
          <extend_definition comment="IBM AIX 5300-07 is installed" definition_ref="oval:org.mitre.oval:def:5707"/>
          <criterion negate="true" comment="All filesets for APAR IZ50496 are installed" test_ref="oval:org.mitre.oval:tst:10813"/>
          <criterion comment="Fileset bos.net.nfs.client is greater than or equal 5.3.7.0" test_ref="oval:org.mitre.oval:tst:10610"/>
          <criterion comment="Fileset bos.net.nfs.client is less than or equal 5.3.7.8" test_ref="oval:org.mitre.oval:tst:10136"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="IBM AIX 5300-08 is installed" definition_ref="oval:org.mitre.oval:def:5293"/>
          <criterion negate="true" comment="All filesets for APAR IZ50444 are installed" test_ref="oval:org.mitre.oval:tst:10995"/>
          <criterion comment="Fileset bos.net.nfs.client is greater than or equal 5.3.8.0" test_ref="oval:org.mitre.oval:tst:11086"/>
          <criterion comment="Fileset bos.net.nfs.client is less than or equal 5.3.8.6" test_ref="oval:org.mitre.oval:tst:10144"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="IBM AIX 5300-09 is installed" definition_ref="oval:org.mitre.oval:def:6306"/>
          <criterion negate="true" comment="All filesets for APAR IZ50399 are installed" test_ref="oval:org.mitre.oval:tst:11020"/>
          <criterion comment="Fileset bos.net.nfs.client is greater than or equal 5.3.9.0" test_ref="oval:org.mitre.oval:tst:11094"/>
          <criterion comment="Fileset bos.net.nfs.client is less than or equal 5.3.9.2" test_ref="oval:org.mitre.oval:tst:11066"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="IBM AIX 6100-00 is installed" definition_ref="oval:org.mitre.oval:def:5589"/>
          <criterion negate="true" comment="All filesets for APAR IZ49278 are installed" test_ref="oval:org.mitre.oval:tst:10801"/>
          <criterion comment="Fileset bos.net.nfs.client is greater than or equal 6.1.0.0" test_ref="oval:org.mitre.oval:tst:11068"/>
          <criterion comment="Fileset bos.net.nfs.client is less than or equal 6.1.0.8" test_ref="oval:org.mitre.oval:tst:10960"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="IBM AIX 6100-01 is installed" definition_ref="oval:org.mitre.oval:def:5959"/>
          <criterion negate="true" comment="All filesets for APAR IZ49096 are installed" test_ref="oval:org.mitre.oval:tst:10630"/>
          <criterion comment="Fileset bos.net.nfs.client is greater than or equal 6.1.1.0" test_ref="oval:org.mitre.oval:tst:11058"/>
          <criterion comment="Fileset bos.net.nfs.client is less than or equal 6.1.1.4" test_ref="oval:org.mitre.oval:tst:10606"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="IBM AIX 6100-02 is installed" definition_ref="oval:org.mitre.oval:def:5685"/>
          <criterion negate="true" comment="All filesets for APAR IZ49024 are installed" test_ref="oval:org.mitre.oval:tst:10846"/>
          <criterion comment="Fileset bos.net.nfs.client is greater than or equal 6.1.2.0" test_ref="oval:org.mitre.oval:tst:10684"/>
          <criterion comment="Fileset bos.net.nfs.client is less than or equal 6.1.2.3" test_ref="oval:org.mitre.oval:tst:10664"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6360" version="0" class="vulnerability">
      <metadata>
        <title>Libxml2 Integer Overflow in xmlSAX2Characters() May Let Remote Users Execute Arbitrary Code</title>
        <affected family="unix">
          <platform>VMWare ESX Server 3</platform>
          <platform>VMWare ESX Server 3.5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-4226" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-4226"/>
        <description>Integer overflow in the xmlSAX2Characters function in libxml2 2.7.2 allows context-dependent attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via a large XML document.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-09-23T15:39:02.000-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2009-09-29T20:37:16.823-04:00">DRAFT</status_change>
            <modified comment="Extra criteria blocks added to handle multiple patch logic in def:6360" date="2009-10-20T13:18:00.597-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </modified>
            <status_change date="2009-11-09T04:00:49.764-05:00">INTERIM</status_change>
          </dates>
          <status>INTERIM</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND">
          <extend_definition comment="VMWare ESX Server 3.0.3 is installed" definition_ref="oval:org.mitre.oval:def:6026"/>
          <criteria operator="OR" comment="All patches must be installed to not be vulnerable">
            <criterion comment="Patch ESX303-200901405-SG is not installed" test_ref="oval:org.mitre.oval:tst:10525"/>
            <criterion comment="Patch ESX303-200901406-SG is not installed" test_ref="oval:org.mitre.oval:tst:9916"/>
          </criteria>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="VMWare ESX Server 3.0.2 is installed" definition_ref="oval:org.mitre.oval:def:5626"/>
          <criteria operator="OR" comment="All patches must be installed to not be vulnerable">
            <criterion comment="Patch ESX-1007673 is not installed" test_ref="oval:org.mitre.oval:tst:10833"/>
            <criterion comment="Patch ESX-1007674 is not installed" test_ref="oval:org.mitre.oval:tst:10026"/>
          </criteria>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="VMware ESX Server 3.5.0 is installed" definition_ref="oval:org.mitre.oval:def:5887"/>
          <criteria operator="OR" comment="All patches must be installed to not be vulnerable">
            <criterion comment="Patch ESX350-200901401-SG is not installed" test_ref="oval:org.mitre.oval:tst:10671"/>
            <criterion comment="Patch ESX350-200901409-SG is not installed" test_ref="oval:org.mitre.oval:tst:10424"/>
            <criterion comment="Patch ESX350-200901410-SG is not installed" test_ref="oval:org.mitre.oval:tst:10070"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6339" version="1" class="vulnerability">
      <metadata>
        <title>MIT Kerberos SPNEGO and ASN.1 Multiple Remote Denial Of Service Vulnerabilities</title>
        <affected family="unix">
          <platform>VMWare ESX Server 3</platform>
          <platform>VMWare ESX Server 3.5</platform>
          <platform>VMWare ESX Server 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-0844" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0844"/>
        <description>The get_input_token function in the SPNEGO implementation in MIT Kerberos 5 (aka krb5) 1.5 through 1.6.3 allows remote attackers to cause a denial of service (daemon crash) and possibly obtain sensitive information via a crafted length value that triggers a buffer over-read.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-09-23T15:39:02.000-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2009-09-28T06:57:29.248-04:00">DRAFT</status_change>
            <status_change date="2009-10-19T04:00:15.316-04:00">INTERIM</status_change>
            <status_change date="2009-11-09T04:00:48.896-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND">
          <extend_definition comment="VMWare ESX Server 3.0.3 is installed" definition_ref="oval:org.mitre.oval:def:6026"/>
          <criterion comment="Patch ESX303-200908403-SG is not installed" test_ref="oval:org.mitre.oval:tst:10799"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="VMware ESX Server 4.0 is installed" definition_ref="oval:org.mitre.oval:def:5506"/>
          <criterion comment="Patch ESX400-200906405-SG is not installed" test_ref="oval:org.mitre.oval:tst:10839"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="VMware ESX Server 3.5.0 is installed" definition_ref="oval:org.mitre.oval:def:5887"/>
          <criterion comment="Patch ESX350-200906407-SG is not installed" test_ref="oval:org.mitre.oval:tst:10641"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="VMWare ESX Server 3.0.2 is installed" definition_ref="oval:org.mitre.oval:def:5626"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6318" version="0" class="vulnerability">
      <metadata>
        <title>AIX NFSv4 Kerberos vulnerability</title>
        <affected family="unix">
          <platform>IBM AIX 5.3</platform>
          <platform>IBM AIX 6.1</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-3516" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3516"/>
        <description>gssd in IBM AIX 5.3.x through 5.3.9 and 6.1.0 through 6.1.2 does not properly handle the NFSv4 Kerberos credential cache, which allows local users to bypass intended access restrictions for Kerberized NFSv4 shares via unspecified vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-10-09T14:55:01.000-04:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2009-10-22T17:35:30.977-04:00">DRAFT</status_change>
            <status_change date="2009-11-09T04:00:47.817-05:00">INTERIM</status_change>
          </dates>
          <status>INTERIM</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND">
          <extend_definition comment="IBM AIX 5300-07 is installed" definition_ref="oval:org.mitre.oval:def:5707"/>
          <criterion negate="true" comment="All filesets for APAR IZ50496 are installed" test_ref="oval:org.mitre.oval:tst:10813"/>
          <criterion comment="Fileset bos.net.nfs.client is greater than or equal 5.3.7.0" test_ref="oval:org.mitre.oval:tst:10610"/>
          <criterion comment="Fileset bos.net.nfs.client is less than or equal 5.3.7.8" test_ref="oval:org.mitre.oval:tst:10136"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="IBM AIX 5300-08 is installed" definition_ref="oval:org.mitre.oval:def:5293"/>
          <criterion negate="true" comment="All filesets for APAR IZ50444 are installed" test_ref="oval:org.mitre.oval:tst:10995"/>
          <criterion comment="Fileset bos.net.nfs.client is greater than or equal 5.3.8.0" test_ref="oval:org.mitre.oval:tst:11086"/>
          <criterion comment="Fileset bos.net.nfs.client is less than or equal 5.3.8.6" test_ref="oval:org.mitre.oval:tst:10144"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="IBM AIX 5300-09 is installed" definition_ref="oval:org.mitre.oval:def:6306"/>
          <criterion negate="true" comment="All filesets for APAR IZ50399 are installed" test_ref="oval:org.mitre.oval:tst:11020"/>
          <criterion comment="Fileset bos.net.nfs.client is greater than or equal 5.3.9.0" test_ref="oval:org.mitre.oval:tst:11094"/>
          <criterion comment="Fileset bos.net.nfs.client is less than or equal 5.3.9.2" test_ref="oval:org.mitre.oval:tst:11066"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="IBM AIX 6100-00 is installed" definition_ref="oval:org.mitre.oval:def:5589"/>
          <criterion negate="true" comment="All filesets for APAR IZ49278 are installed" test_ref="oval:org.mitre.oval:tst:10801"/>
          <criterion comment="Fileset bos.net.nfs.client is greater than or equal 6.1.0.0" test_ref="oval:org.mitre.oval:tst:11068"/>
          <criterion comment="Fileset bos.net.nfs.client is less than or equal 6.1.0.8" test_ref="oval:org.mitre.oval:tst:10960"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="IBM AIX 6100-01 is installed" definition_ref="oval:org.mitre.oval:def:5959"/>
          <criterion negate="true" comment="All filesets for APAR IZ49096 are installed" test_ref="oval:org.mitre.oval:tst:10630"/>
          <criterion comment="Fileset bos.net.nfs.client is greater than or equal 6.1.1.0" test_ref="oval:org.mitre.oval:tst:11058"/>
          <criterion comment="Fileset bos.net.nfs.client is less than or equal 6.1.1.4" test_ref="oval:org.mitre.oval:tst:10606"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="IBM AIX 6100-02 is installed" definition_ref="oval:org.mitre.oval:def:5685"/>
          <criterion negate="true" comment="All filesets for APAR IZ49024 are installed" test_ref="oval:org.mitre.oval:tst:10846"/>
          <criterion comment="Fileset bos.net.nfs.client is greater than or equal 6.1.2.0" test_ref="oval:org.mitre.oval:tst:10684"/>
          <criterion comment="Fileset bos.net.nfs.client is less than or equal 6.1.2.3" test_ref="oval:org.mitre.oval:tst:10664"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6310" version="1" class="vulnerability">
      <metadata>
        <title>VMware Bug in 'hcmon.sys' Lets Local Privileged Users Deny Service</title>
        <affected family="unix">
          <platform>VMWare ESX Server 3</platform>
          <platform>VMWare ESX Server 3.5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-1146" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1146"/>
        <description>Unspecified vulnerability in an ioctl in hcmon.sys in VMware Workstation 6.5.1 and earlier, VMware Player 2.5.1 and earlier, VMware ACE 2.5.1 and earlier, and VMware Server 1.0.x before 1.0.9 build 156507 and 2.0.x before 2.0.1 build 156745 allows local users to cause a denial of service via unknown vectors, a different vulnerability than CVE-2008-3761.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-09-23T15:39:02.000-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2009-09-28T06:57:18.168-04:00">DRAFT</status_change>
            <status_change date="2009-10-19T04:00:14.210-04:00">INTERIM</status_change>
            <status_change date="2009-11-09T04:00:47.535-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND">
          <extend_definition comment="VMWare ESX Server 3.0.3 is installed" definition_ref="oval:org.mitre.oval:def:6026"/>
          <criterion comment="Patch ESX303-200811401-BG is not installed" test_ref="oval:org.mitre.oval:tst:10884"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="VMWare ESX Server 3.0.2 is installed" definition_ref="oval:org.mitre.oval:def:5613"/>
          <criterion comment="Patch ESX-1006980 is not installed" test_ref="oval:org.mitre.oval:tst:10693"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="VMware ESX Server 3.5.0 is installed" definition_ref="oval:org.mitre.oval:def:5887"/>
          <criterion comment="Patch ESX350-200811401-SG is not installed" test_ref="oval:org.mitre.oval:tst:9884"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6309" version="1" class="vulnerability">
      <metadata>
        <title>VMware CPU Hardware Emulation Bug Lets Local Users Gain Elevated Privileges</title>
        <affected family="unix">
          <platform>VMWare ESX Server 3</platform>
          <platform>VMWare ESX Server 3.5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-4915" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-4915"/>
        <description>The CPU hardware emulation in VMware Workstation 6.0.5 and earlier and 5.5.8 and earlier; Player 2.0.x through 2.0.5 and 1.0.x through 1.0.8; ACE 2.0.x through 2.0.5 and earlier, and 1.0.x through 1.0.7; Server 1.0.x through 1.0.7; ESX 2.5.4 through 3.5; and ESXi 3.5, when running 32-bit and 64-bit guest operating systems, does not properly handle the Trap flag, which allows authenticated guest OS users to gain privileges on the guest OS.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-09-23T15:39:02.000-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2009-09-29T20:37:25.310-04:00">DRAFT</status_change>
            <status_change date="2009-10-19T04:00:13.877-04:00">INTERIM</status_change>
            <status_change date="2009-11-09T04:00:47.271-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND">
          <extend_definition comment="VMWare ESX Server 3.0.3 is installed" definition_ref="oval:org.mitre.oval:def:6026"/>
          <criterion comment="Patch ESX303-200810501-BG is not installed" test_ref="oval:org.mitre.oval:tst:10500"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="VMWare ESX Server 3.0.2 is installed" definition_ref="oval:org.mitre.oval:def:5626"/>
          <criterion comment="Patch ESX-1006680 is not installed" test_ref="oval:org.mitre.oval:tst:10484"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="VMware ESX Server 3.5.0 is installed" definition_ref="oval:org.mitre.oval:def:5887"/>
          <criterion comment="Patch ESX350-200810201-UG is not installed" test_ref="oval:org.mitre.oval:tst:9902"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6275" version="1" class="vulnerability">
      <metadata>
        <title>mimeTeX and mathTeX Buffer Overflow and Command Injection Issues</title>
        <affected family="unix">
          <platform>VMWare ESX Server 3</platform>
          <platform>VMWare ESX Server 3.5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-1382" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1382"/>
        <description>libpng 1.0.6 through 1.0.32, 1.2.0 through 1.2.26, and 1.4.0beta01 through 1.4.0beta19 allows context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via a PNG file with zero length "unknown" chunks, which trigger an access of uninitialized memory.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-09-23T15:39:02.000-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2009-09-28T06:56:27.954-04:00">DRAFT</status_change>
            <status_change date="2009-10-19T04:00:13.612-04:00">INTERIM</status_change>
            <status_change date="2009-11-09T04:00:44.197-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND">
          <extend_definition comment="VMWare ESX Server 3.0.3 is installed" definition_ref="oval:org.mitre.oval:def:6026"/>
          <criterion comment="Patch ESX303-200905401-SG is not installed" test_ref="oval:org.mitre.oval:tst:9878"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="VMWare ESX Server 3.0.2 is installed" definition_ref="oval:org.mitre.oval:def:5613"/>
          <criterion comment="Patch ESX-1008420 is not installed" test_ref="oval:org.mitre.oval:tst:10635"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="VMware ESX Server 3.5.0 is installed" definition_ref="oval:org.mitre.oval:def:5887"/>
          <criterion comment="Patch ESX350-200904401-BG is not installed" test_ref="oval:org.mitre.oval:tst:10863"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6251" version="1" class="vulnerability">
      <metadata>
        <title>VMware Heap Overflows in VNnc Codec Lets Remote Users Execute Arbitrary Code</title>
        <affected family="unix">
          <platform>VMWare ESX Server 3</platform>
          <platform>VMWare ESX Server 3.5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-0909" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0909"/>
        <description>Heap-based buffer overflow in the VNnc Codec in VMware Workstation 6.5.x before 6.5.2 build 156735, VMware Player 2.5.x before 2.5.2 build 156735, VMware ACE 2.5.x before 2.5.2 build 156735, and VMware Server 2.0.x before 2.0.1 build 156745 allows remote attackers to execute arbitrary code via a crafted web page or video file, aka ZDI-CVE-435.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-09-23T15:39:02.000-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2009-09-28T06:57:18.569-04:00">DRAFT</status_change>
            <status_change date="2009-10-19T04:00:11.817-04:00">INTERIM</status_change>
            <status_change date="2009-11-09T04:00:41.893-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND">
          <extend_definition comment="VMWare ESX Server 3.0.3 is installed" definition_ref="oval:org.mitre.oval:def:6026"/>
          <criterion comment="Patch ESX303-200811401-BG is not installed" test_ref="oval:org.mitre.oval:tst:10884"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="VMWare ESX Server 3.0.2 is installed" definition_ref="oval:org.mitre.oval:def:5613"/>
          <criterion comment="Patch ESX-1006980 is not installed" test_ref="oval:org.mitre.oval:tst:10693"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="VMware ESX Server 3.5.0 is installed" definition_ref="oval:org.mitre.oval:def:5887"/>
          <criterion comment="Patch ESX350-200811401-SG is not installed" test_ref="oval:org.mitre.oval:tst:9884"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6246" version="0" class="vulnerability">
      <metadata>
        <title>VMware ESX Virtual Hardware Memory Access Bug Lets Local Users Gain Elevated Privileges</title>
        <affected family="unix">
          <platform>VMWare ESX Server 3</platform>
          <platform>VMWare ESX Server 3.5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-4917" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-4917"/>
        <description>Unspecified vulnerability in VMware Workstation 5.5.8 and earlier, and 6.0.5 and earlier 6.x versions; VMware Player 1.0.8 and earlier, and 2.0.5 and earlier 2.x versions; VMware Server 1.0.9 and earlier; VMware ESXi 3.5; and VMware ESX 3.0.2 through 3.5 allows guest OS users to have an unknown impact by sending the virtual hardware a request that triggers an arbitrary physical-memory write operation, leading to memory corruption.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-09-23T15:39:02.000-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2009-09-29T20:37:33.913-04:00">DRAFT</status_change>
            <modified comment="Extra criteria blocks added to handle multiple patch logic in def:6246" date="2009-10-20T13:42:00.740-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </modified>
            <status_change date="2009-11-09T04:00:41.586-05:00">INTERIM</status_change>
          </dates>
          <status>INTERIM</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND">
          <extend_definition comment="VMWare ESX Server 3.0.3 is installed" definition_ref="oval:org.mitre.oval:def:6026"/>
          <criteria operator="OR" comment="All patches must be installed to not be vulnerable">
            <criterion comment="Patch ESX303-200811401-BG is not installed" test_ref="oval:org.mitre.oval:tst:10427"/>
            <criterion comment="Patch ESX303-200811404-BG is not installed" test_ref="oval:org.mitre.oval:tst:10784"/>
          </criteria>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="VMWare ESX Server 3.0.2 is installed" definition_ref="oval:org.mitre.oval:def:5626"/>
          <criteria operator="OR" comment="All patches must be installed to not be vulnerable">
            <criterion comment="Patch ESX-1006980 is not installed" test_ref="oval:org.mitre.oval:tst:10716"/>
            <criterion comment="Patch ESX-1006982 is not installed" test_ref="oval:org.mitre.oval:tst:10728"/>
          </criteria>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="VMware ESX Server 3.5.0 is installed" definition_ref="oval:org.mitre.oval:def:5887"/>
          <criteria operator="OR" comment="All patches must be installed to not be vulnerable">
            <criterion comment="Patch ESX350-200811401-SG is not installed" test_ref="oval:org.mitre.oval:tst:10834"/>
            <criterion comment="Patch ESX350-200811406-SG is not installed" test_ref="oval:org.mitre.oval:tst:10809"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6238" version="0" class="vulnerability">
      <metadata>
        <title>Vim Flaw in Quoting Vim Script Lets Remote Users Cause Arbitrary Commands to Be Executed in Certain Cases</title>
        <affected family="unix">
          <platform>VMWare ESX Server 3</platform>
          <platform>VMWare ESX Server 3.5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-2712" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-2712"/>
        <description>Vim 7.1.314, 6.4, and other versions allows user-assisted remote attackers to execute arbitrary commands via Vim scripts that do not properly sanitize inputs before invoking the execute or system functions, as demonstrated using (1) filetype.vim, (3) xpm.vim, (4) gzip_vim, and (5) netrw.  NOTE: the originally reported version was 7.1.314, but the researcher actually found this set of issues in 7.1.298.  NOTE: the zipplugin issue (originally vector 2 in this identifier) has been subsumed by CVE-2008-3075.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-09-23T15:39:02.000-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2009-09-28T06:56:17.148-04:00">DRAFT</status_change>
            <modified comment="Extra criteria blocks added to handle multiple patch logic in def:6238" date="2009-10-20T13:59:00.327-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </modified>
            <status_change date="2009-11-09T04:00:41.228-05:00">INTERIM</status_change>
          </dates>
          <status>INTERIM</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND">
          <extend_definition comment="VMWare ESX Server 3.0.3 is installed" definition_ref="oval:org.mitre.oval:def:6026"/>
          <criteria operator="OR" comment="All patches must be installed to not be vulnerable">
            <criterion comment="Patch ESX303-200903406-SG is not installed" test_ref="oval:org.mitre.oval:tst:10431"/>
            <criterion comment="Patch ESX303-200903405-SG is not installed" test_ref="oval:org.mitre.oval:tst:10817"/>
            <criterion comment="Patch ESX303-200903403-SG is not installed" test_ref="oval:org.mitre.oval:tst:10649"/>
          </criteria>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="VMWare ESX Server 3.0.2 is installed" definition_ref="oval:org.mitre.oval:def:5613"/>
          <criteria operator="OR" comment="All patches must be installed to not be vulnerable">
            <criterion comment="Patch ESX-1008409 is not installed" test_ref="oval:org.mitre.oval:tst:9873"/>
            <criterion comment="Patch ESX-1008408 is not installed" test_ref="oval:org.mitre.oval:tst:10772"/>
            <criterion comment="Patch ESX-1008406 is not installed" test_ref="oval:org.mitre.oval:tst:10589"/>
          </criteria>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="VMware ESX Server 3.5.0 is installed" definition_ref="oval:org.mitre.oval:def:5887"/>
          <criteria operator="OR" comment="All patches must be installed to not be vulnerable">
            <criterion comment="Patch ESX350-200904408-SG is not installed" test_ref="oval:org.mitre.oval:tst:10852"/>
            <criterion comment="Patch ESX350-200904407-SG is not installed" test_ref="oval:org.mitre.oval:tst:10730"/>
            <criterion comment="Patch ESX350-200904406-SG is not installed" test_ref="oval:org.mitre.oval:tst:10114"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6171" version="0" class="vulnerability">
      <metadata>
        <title>Net-snmp GETBULK Request Processing Bug Lets Remote Users Deny Service</title>
        <affected family="unix">
          <platform>VMWare ESX Server 3</platform>
          <platform>VMWare ESX Server 3.5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-4309" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-4309"/>
        <description>Integer overflow in the netsnmp_create_subtree_cache function in agent/snmp_agent.c in net-snmp 5.4 before 5.4.2.1, 5.3 before 5.3.2.3, and 5.2 before 5.2.5.1 allows remote attackers to cause a denial of service (crash) via a crafted SNMP GETBULK request, which triggers a heap-based buffer overflow,  related to the number of responses or repeats.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-09-23T15:39:02.000-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2009-09-29T20:37:16.588-04:00">DRAFT</status_change>
            <modified comment="Extra criteria blocks added to handle multiple patch logic in def:6171" date="2009-10-20T13:35:00.752-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </modified>
            <status_change date="2009-11-09T04:00:38.438-05:00">INTERIM</status_change>
          </dates>
          <status>INTERIM</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND">
          <extend_definition comment="VMWare ESX Server 3.0.3 is installed" definition_ref="oval:org.mitre.oval:def:6026"/>
          <criteria operator="OR" comment="All patches must be installed to not be vulnerable">
            <criterion comment="Patch ESX303-200901405-SG is not installed" test_ref="oval:org.mitre.oval:tst:10525"/>
            <criterion comment="Patch ESX303-200901406-SG is not installed" test_ref="oval:org.mitre.oval:tst:9916"/>
          </criteria>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="VMWare ESX Server 3.0.2 is installed" definition_ref="oval:org.mitre.oval:def:5626"/>
          <criteria operator="OR" comment="All patches must be installed to not be vulnerable">
            <criterion comment="Patch ESX-1007673 is not installed" test_ref="oval:org.mitre.oval:tst:10833"/>
            <criterion comment="Patch ESX-1007674 is not installed" test_ref="oval:org.mitre.oval:tst:10026"/>
          </criteria>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="VMware ESX Server 3.5.0 is installed" definition_ref="oval:org.mitre.oval:def:5887"/>
          <criteria operator="OR" comment="All patches must be installed to not be vulnerable">
            <criterion comment="Patch ESX350-200901401-SG is not installed" test_ref="oval:org.mitre.oval:tst:10671"/>
            <criterion comment="Patch ESX350-200901409-SG is not installed" test_ref="oval:org.mitre.oval:tst:10424"/>
            <criterion comment="Patch ESX350-200901410-SG is not installed" test_ref="oval:org.mitre.oval:tst:10070"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6130" version="1" class="vulnerability">
      <metadata>
        <title>VMware Descheduled Time Accounting Driver Bug Lets Local Users on the Guest Operating System Deny Service</title>
        <affected family="unix">
          <platform>VMWare ESX Server 3</platform>
          <platform>VMWare ESX Server 3.5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-1805" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1805"/>
        <description>Unspecified vulnerability in the VMware Descheduled Time Accounting driver in VMware Workstation 6.5.1 and earlier, VMware Player 2.5.1 and earlier, VMware ACE 2.5.1 and earlier, VMware Server 1.x before 1.0.9 build 156507 and 2.x before 2.0.1 build 156745, VMware Fusion 2.x before 2.0.2 build 147997, VMware ESXi 3.5, and VMware ESX 3.0.2, 3.0.3, and 3.5, when the Descheduled Time Accounting Service is not running, allows guest OS users on Windows to cause a denial of service via unknown vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-09-23T15:39:02.000-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2009-09-28T06:56:27.548-04:00">DRAFT</status_change>
            <status_change date="2009-10-19T04:00:09.967-04:00">INTERIM</status_change>
            <status_change date="2009-11-09T04:00:36.120-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND">
          <extend_definition comment="VMWare ESX Server 3.0.3 is installed" definition_ref="oval:org.mitre.oval:def:6026"/>
          <criterion comment="Patch ESX303-200905401-SG is not installed" test_ref="oval:org.mitre.oval:tst:9878"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="VMWare ESX Server 3.0.2 is installed" definition_ref="oval:org.mitre.oval:def:5613"/>
          <criterion comment="Patch ESX-1008420 is not installed" test_ref="oval:org.mitre.oval:tst:10635"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="VMware ESX Server 3.5.0 is installed" definition_ref="oval:org.mitre.oval:def:5887"/>
          <criterion comment="Patch ESX350-200904401-BG is not installed" test_ref="oval:org.mitre.oval:tst:10863"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6103" version="1" class="vulnerability">
      <metadata>
        <title>Libxml2 Heap Overflow in xmlParseAttValueComplex() Lets Remote Users Execute Arbitrary Code</title>
        <affected family="unix">
          <platform>VMWare ESX Server 3</platform>
          <platform>VMWare ESX Server 3.5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-3529" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-3529"/>
        <description>Heap-based buffer overflow in the xmlParseAttValueComplex function in parser.c in libxml2 before 2.7.0 allows context-dependent attackers to cause a denial of service (crash) or execute arbitrary code via a long XML entity name.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-09-23T15:39:02.000-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2009-09-29T20:37:01.834-04:00">DRAFT</status_change>
            <status_change date="2009-10-19T04:00:09.650-04:00">INTERIM</status_change>
            <status_change date="2009-11-09T04:00:35.245-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND">
          <extend_definition comment="VMWare ESX Server 3.0.3 is installed" definition_ref="oval:org.mitre.oval:def:6026"/>
          <criterion comment="Patch ESX303-200810503-SG is not installed" test_ref="oval:org.mitre.oval:tst:10758"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="VMWare ESX Server 3.0.2 is installed" definition_ref="oval:org.mitre.oval:def:5626"/>
          <criterion comment="Patch ESX-1006968 is not installed" test_ref="oval:org.mitre.oval:tst:10726"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="VMware ESX Server 3.5.0 is installed" definition_ref="oval:org.mitre.oval:def:5887"/>
          <criterion comment="Patch ESX350-200811405-SG is not installed" test_ref="oval:org.mitre.oval:tst:10390"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6074" version="0" class="vulnerability">
      <metadata>
        <title>cURL/libcURL HTTP 'Location:' Redirect Security Bypass Vulnerability</title>
        <affected family="unix">
          <platform>VMWare ESX Server 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-0037" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0037"/>
        <description>The redirect implementation in curl and libcurl 5.11 through 7.19.3, when CURLOPT_FOLLOWLOCATION is enabled, accepts arbitrary Location values, which might allow remote HTTP servers to (1) trigger arbitrary requests to intranet servers, (2) read or overwrite arbitrary files via a redirect to a file: URL, or (3) execute arbitrary commands via a redirect to an scp: URL.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-09-22T15:10:44.000-05:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2009-09-28T06:57:00.140-04:00">DRAFT</status_change>
            <modified comment="Extra criteria blocks added to handle multiple patch logic in def:6074" date="2009-10-20T14:02:00.746-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </modified>
            <status_change date="2009-11-09T04:00:34.565-05:00">INTERIM</status_change>
          </dates>
          <status>INTERIM</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="VMware ESX Server 4.0 is installed" definition_ref="oval:org.mitre.oval:def:6261"/>
        <criteria operator="OR" comment="All patches must be installed to not be vulnerable">
          <criterion comment="Patch ESX400-200906411-SG is not installed" test_ref="oval:org.mitre.oval:tst:10851"/>
          <criterion comment="Patch ESX400-200906407-SG is not installed" test_ref="oval:org.mitre.oval:tst:10872"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6261" version="1" class="inventory">
      <metadata>
        <title>VMware ESX Server 4.0 is installed</title>
        <affected family="unix">
          <platform>VMware ESX Server 4</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/o:vmware:esx:4.0"/>
        <description>The operating system installed on the system is VMware ESX Server 4.0.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-09-22T15:10:44.000-05:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2009-09-28T06:56:59.848-04:00">DRAFT</status_change>
            <status_change date="2009-10-26T04:00:05.251-04:00">INTERIM</status_change>
            <status_change date="2009-11-16T04:00:17.778-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="VMware ESX Server 4.0 is installed" test_ref="oval:org.mitre.oval:tst:10766"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6065" version="1" class="vulnerability">
      <metadata>
        <title>VMware Multiple Hosted Products Display Function Code Execution Vulnerability</title>
        <affected family="unix">
          <platform>VMWare ESX Server 3</platform>
          <platform>VMWare ESX Server 3.5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-1244" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1244"/>
        <description>Unspecified vulnerability in the virtual machine display function in VMware Workstation 6.5.1 and earlier; VMware Player 2.5.1 and earlier; VMware ACE 2.5.1 and earlier; VMware Server 1.x before 1.0.9 build 156507 and 2.x before 2.0.1 build 156745; VMware Fusion before 2.0.4 build 159196; VMware ESXi 3.5; and VMware ESX 3.0.2, 3.0.3, and 3.5 allows guest OS users to execute arbitrary code on the host OS via unknown vectors, a different vulnerability than CVE-2008-4916.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-09-23T15:39:02.000-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2009-09-28T06:56:37.015-04:00">DRAFT</status_change>
            <status_change date="2009-10-19T04:00:08.745-04:00">INTERIM</status_change>
            <status_change date="2009-11-09T04:00:34.291-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND">
          <extend_definition comment="VMWare ESX Server 3.0.3 is installed" definition_ref="oval:org.mitre.oval:def:6026"/>
          <criterion comment="Patch ESX303-200904403-SG is not installed" test_ref="oval:org.mitre.oval:tst:10327"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="VMWare ESX Server 3.0.2 is installed" definition_ref="oval:org.mitre.oval:def:5613"/>
          <criterion comment="Patch ESX-1008421 is not installed" test_ref="oval:org.mitre.oval:tst:9972"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="VMware ESX Server 3.5.0 is installed" definition_ref="oval:org.mitre.oval:def:5887"/>
          <criterion comment="Patch ESX350-200904201-SG is not installed" test_ref="oval:org.mitre.oval:tst:10724"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5987" version="0" class="vulnerability">
      <metadata>
        <title>Vim 'mch_expand_wildcards()' Heap Based Buffer Overflow Vulnerability</title>
        <affected family="unix">
          <platform>VMWare ESX Server 3</platform>
          <platform>VMWare ESX Server 3.5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-3432" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-3432"/>
        <description>Heap-based buffer overflow in the mch_expand_wildcards function in os_unix.c in Vim 6.2 and 6.3 allows user-assisted attackers to execute arbitrary code via shell metacharacters in filenames, as demonstrated by the netrw.v3 test case.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-09-23T15:39:02.000-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2009-09-28T06:56:16.847-04:00">DRAFT</status_change>
            <modified comment="Extra criteria blocks added to handle multiple patch logic in def:5987" date="2009-10-20T13:57:00.468-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </modified>
            <status_change date="2009-11-09T04:00:31.829-05:00">INTERIM</status_change>
          </dates>
          <status>INTERIM</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND">
          <extend_definition comment="VMWare ESX Server 3.0.3 is installed" definition_ref="oval:org.mitre.oval:def:6026"/>
          <criteria operator="OR" comment="All patches must be installed to not be vulnerable">
            <criterion comment="Patch ESX303-200903406-SG is not installed" test_ref="oval:org.mitre.oval:tst:10431"/>
            <criterion comment="Patch ESX303-200903405-SG is not installed" test_ref="oval:org.mitre.oval:tst:10817"/>
            <criterion comment="Patch ESX303-200903403-SG is not installed" test_ref="oval:org.mitre.oval:tst:10649"/>
          </criteria>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="VMWare ESX Server 3.0.2 is installed" definition_ref="oval:org.mitre.oval:def:5613"/>
          <criteria operator="OR" comment="All patches must be installed to not be vulnerable">
            <criterion comment="Patch ESX-1008409 is not installed" test_ref="oval:org.mitre.oval:tst:9873"/>
            <criterion comment="Patch ESX-1008408 is not installed" test_ref="oval:org.mitre.oval:tst:10772"/>
            <criterion comment="Patch ESX-1008406 is not installed" test_ref="oval:org.mitre.oval:tst:10589"/>
          </criteria>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="VMware ESX Server 3.5.0 is installed" definition_ref="oval:org.mitre.oval:def:5887"/>
          <criteria operator="OR" comment="All patches must be installed to not be vulnerable">
            <criterion comment="Patch ESX350-200904408-SG is not installed" test_ref="oval:org.mitre.oval:tst:10852"/>
            <criterion comment="Patch ESX350-200904407-SG is not installed" test_ref="oval:org.mitre.oval:tst:10730"/>
            <criterion comment="Patch ESX350-200904406-SG is not installed" test_ref="oval:org.mitre.oval:tst:10114"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5975" version="0" class="vulnerability">
      <metadata>
        <title>udev Netlink Message Validation Local Privilege Escalation Vulnerability</title>
        <affected family="unix">
          <platform>VMWare ESX Server 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-1185" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1185"/>
        <description>udev before 1.4.1 does not verify whether a NETLINK message originates from kernel space, which allows local users to gain privileges by sending a NETLINK message from user space.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-09-22T15:10:44.000-05:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2009-09-28T06:57:08.426-04:00">DRAFT</status_change>
            <modified comment="Extra criteria blocks added to handle multiple patch logic in def:5975" date="2009-10-20T14:03:00.817-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </modified>
            <status_change date="2009-11-09T04:00:31.582-05:00">INTERIM</status_change>
          </dates>
          <status>INTERIM</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition comment="VMware ESX Server 4.0 is installed" definition_ref="oval:org.mitre.oval:def:5895"/>
        <criteria operator="OR" comment="All patches must be installed to not be vulnerable">
          <criterion comment="Patch ESX400-200906411-SG is not installed" test_ref="oval:org.mitre.oval:tst:10791"/>
          <criterion comment="Patch ESX400-200906407-SG is not installed" test_ref="oval:org.mitre.oval:tst:9883"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5895" version="1" class="inventory">
      <metadata>
        <title>VMware ESX Server 4.0 is installed</title>
        <affected family="unix">
          <platform>VMware ESX Server 4</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/o:vmware:esx:4.0"/>
        <description>The operating system installed on the system is VMware ESX Server 4.0.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-09-22T15:10:44.000-05:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2009-09-28T06:57:08.157-04:00">DRAFT</status_change>
            <status_change date="2009-10-26T04:00:04.172-04:00">INTERIM</status_change>
            <status_change date="2009-11-16T04:00:15.958-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="VMware ESX Server 4.0 is installed" test_ref="oval:org.mitre.oval:tst:10667"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5909" version="0" class="vulnerability">
      <metadata>
        <title>VMware ESX Server VMDK Delta Disk Processing Lets Local Administrative Users Deny Service</title>
        <affected family="unix">
          <platform>VMWare ESX Server 3</platform>
          <platform>VMWare ESX Server 3.5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-4914" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-4914"/>
        <description>Unspecified vulnerability in VMware ESXi 3.5 before ESXe350-200901401-I-SG and ESX 3.5 before ESX350-200901401-SG allows local administrators to cause a denial of service (host crash) via a snapshot with a malformed VMDK delta disk.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-09-23T15:39:02.000-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2009-09-29T20:37:16.349-04:00">DRAFT</status_change>
            <modified comment="Extra criteria blocks added to handle multiple patch logic in def:5909" date="2009-10-20T14:04:00.516-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </modified>
            <status_change date="2009-11-09T04:00:28.768-05:00">INTERIM</status_change>
          </dates>
          <status>INTERIM</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND">
          <extend_definition comment="VMWare ESX Server 3.0.3 is installed" definition_ref="oval:org.mitre.oval:def:6026"/>
          <criteria operator="OR" comment="All patches must be installed to not be vulnerable">
            <criterion comment="Patch ESX303-200901405-SG is not installed" test_ref="oval:org.mitre.oval:tst:10525"/>
            <criterion comment="Patch ESX303-200901406-SG is not installed" test_ref="oval:org.mitre.oval:tst:9916"/>
          </criteria>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="VMWare ESX Server 3.0.2 is installed" definition_ref="oval:org.mitre.oval:def:5626"/>
          <criteria operator="OR" comment="All patches must be installed to not be vulnerable">
            <criterion comment="Patch ESX-1007673 is not installed" test_ref="oval:org.mitre.oval:tst:10833"/>
            <criterion comment="Patch ESX-1007674 is not installed" test_ref="oval:org.mitre.oval:tst:10026"/>
          </criteria>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="VMware ESX Server 3.5.0 is installed" definition_ref="oval:org.mitre.oval:def:5887"/>
          <criteria operator="OR" comment="All patches must be installed to not be vulnerable">
            <criterion comment="Patch ESX350-200901401-SG is not installed" test_ref="oval:org.mitre.oval:tst:10671"/>
            <criterion comment="Patch ESX350-200901409-SG is not installed" test_ref="oval:org.mitre.oval:tst:10424"/>
            <criterion comment="Patch ESX350-200901410-SG is not installed" test_ref="oval:org.mitre.oval:tst:10070"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5812" version="0" class="vulnerability">
      <metadata>
        <title>Vim Insufficient Shell Escaping Multiple Command Execution Vulnerability</title>
        <affected family="unix">
          <platform>VMWare ESX Server 3</platform>
          <platform>VMWare ESX Server 3.5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-4101" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-4101"/>
        <description>Vim 3.0 through 7.x before 7.2.010 does not properly escape characters, which allows user-assisted attackers to (1) execute arbitrary shell commands by entering a K keystroke on a line that contains a ";" (semicolon) followed by a command, or execute arbitrary Ex commands by entering an argument after a (2) "Ctrl-]" (control close-square-bracket) or (3) "g]" (g close-square-bracket) keystroke sequence, a different issue than CVE-2008-2712.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-09-23T15:39:02.000-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2009-09-28T06:56:16.584-04:00">DRAFT</status_change>
            <modified comment="Extra criteria blocks added to handle multiple patch logic in def:5812" date="2009-10-20T13:56:00.130-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </modified>
            <status_change date="2009-11-09T04:00:25.496-05:00">INTERIM</status_change>
          </dates>
          <status>INTERIM</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND">
          <extend_definition comment="VMWare ESX Server 3.0.3 is installed" definition_ref="oval:org.mitre.oval:def:6026"/>
          <criteria operator="OR" comment="All patches must be installed to not be vulnerable">
            <criterion comment="Patch ESX303-200903406-SG is not installed" test_ref="oval:org.mitre.oval:tst:10431"/>
            <criterion comment="Patch ESX303-200903405-SG is not installed" test_ref="oval:org.mitre.oval:tst:10817"/>
            <criterion comment="Patch ESX303-200903403-SG is not installed" test_ref="oval:org.mitre.oval:tst:10649"/>
          </criteria>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="VMWare ESX Server 3.0.2 is installed" definition_ref="oval:org.mitre.oval:def:5613"/>
          <criteria operator="OR" comment="All patches must be installed to not be vulnerable">
            <criterion comment="Patch ESX-1008409 is not installed" test_ref="oval:org.mitre.oval:tst:9873"/>
            <criterion comment="Patch ESX-1008408 is not installed" test_ref="oval:org.mitre.oval:tst:10772"/>
            <criterion comment="Patch ESX-1008406 is not installed" test_ref="oval:org.mitre.oval:tst:10589"/>
          </criteria>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="VMware ESX Server 3.5.0 is installed" definition_ref="oval:org.mitre.oval:def:5887"/>
          <criteria operator="OR" comment="All patches must be installed to not be vulnerable">
            <criterion comment="Patch ESX350-200904408-SG is not installed" test_ref="oval:org.mitre.oval:tst:10852"/>
            <criterion comment="Patch ESX350-200904407-SG is not installed" test_ref="oval:org.mitre.oval:tst:10730"/>
            <criterion comment="Patch ESX350-200904406-SG is not installed" test_ref="oval:org.mitre.oval:tst:10114"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5786" version="1" class="vulnerability">
      <metadata>
        <title>VMWare Guest Virtual Device Driver Vulnerability</title>
        <affected family="unix">
          <platform>VMWare ESX Server 3</platform>
          <platform>VMWare ESX Server 3.5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-0910" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0910"/>
        <description>Heap-based buffer overflow in the VNnc Codec in VMware Workstation 6.5.x before 6.5.2 build 156735, VMware Player 2.5.x before 2.5.2 build 156735, VMware ACE 2.5.x before 2.5.2 build 156735, and VMware Server 2.0.x before 2.0.1 build 156745 allows remote attackers to execute arbitrary code via a crafted web page or video file, aka ZDI-CVE-436.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-09-23T15:39:02.000-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2009-09-28T06:57:18.757-04:00">DRAFT</status_change>
            <status_change date="2009-10-19T04:00:05.613-04:00">INTERIM</status_change>
            <status_change date="2009-11-09T04:00:24.269-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND">
          <extend_definition comment="VMWare ESX Server 3.0.3 is installed" definition_ref="oval:org.mitre.oval:def:6026"/>
          <criterion comment="Patch ESX303-200811401-BG is not installed" test_ref="oval:org.mitre.oval:tst:10884"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="VMWare ESX Server 3.0.2 is installed" definition_ref="oval:org.mitre.oval:def:5613"/>
          <criterion comment="Patch ESX-1006980 is not installed" test_ref="oval:org.mitre.oval:tst:10693"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="VMware ESX Server 3.5.0 is installed" definition_ref="oval:org.mitre.oval:def:5887"/>
          <criterion comment="Patch ESX350-200811401-SG is not installed" test_ref="oval:org.mitre.oval:tst:9884"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5569" version="0" class="vulnerability">
      <metadata>
        <title>Avaya Solaris BIND "EVP_VerifyFinal()" Signature Spoofing Vulnerability</title>
        <affected family="unix">
          <platform>VMWare ESX Server 3</platform>
          <platform>VMWare ESX Server 3.5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-0025" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0025"/>
        <description>BIND 9.6.0, 9.5.1, 9.5.0, 9.4.3, and earlier does not properly check the return value from the OpenSSL DSA_verify function, which allows remote attackers to bypass validation of the certificate chain via a malformed SSL/TLS signature, a similar vulnerability to CVE-2008-5077.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-09-23T15:39:02.000-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2009-09-28T06:56:16.319-04:00">DRAFT</status_change>
            <modified comment="Extra criteria blocks added to handle multiple patch logic in def:5569" date="2009-10-20T13:43:00.135-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </modified>
            <status_change date="2009-11-09T04:00:20.442-05:00">INTERIM</status_change>
          </dates>
          <status>INTERIM</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND">
          <extend_definition comment="VMWare ESX Server 3.0.3 is installed" definition_ref="oval:org.mitre.oval:def:6026"/>
          <criteria operator="OR" comment="All patches must be installed to not be vulnerable">
            <criterion comment="Patch ESX303-200903406-SG is not installed" test_ref="oval:org.mitre.oval:tst:10431"/>
            <criterion comment="Patch ESX303-200903405-SG is not installed" test_ref="oval:org.mitre.oval:tst:10817"/>
            <criterion comment="Patch ESX303-200903403-SG is not installed" test_ref="oval:org.mitre.oval:tst:10649"/>
          </criteria>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="VMWare ESX Server 3.0.2 is installed" definition_ref="oval:org.mitre.oval:def:5613"/>
          <criteria operator="OR" comment="All patches must be installed to not be vulnerable">
            <criterion comment="Patch ESX-1008409 is not installed" test_ref="oval:org.mitre.oval:tst:9873"/>
            <criterion comment="Patch ESX-1008408 is not installed" test_ref="oval:org.mitre.oval:tst:10772"/>
            <criterion comment="Patch ESX-1008406 is not installed" test_ref="oval:org.mitre.oval:tst:10589"/>
          </criteria>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="VMware ESX Server 3.5.0 is installed" definition_ref="oval:org.mitre.oval:def:5887"/>
          <criteria operator="OR" comment="All patches must be installed to not be vulnerable">
            <criterion comment="Patch ESX350-200904408-SG is not installed" test_ref="oval:org.mitre.oval:tst:10852"/>
            <criterion comment="Patch ESX350-200904407-SG is not installed" test_ref="oval:org.mitre.oval:tst:10730"/>
            <criterion comment="Patch ESX350-200904406-SG is not installed" test_ref="oval:org.mitre.oval:tst:10114"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5514" version="1" class="vulnerability">
      <metadata>
        <title>LibTIFF Buffer Underflow in Decoding LZW Data Lets Remote Users Execute Arbitrary Code</title>
        <affected family="unix">
          <platform>VMWare ESX Server 3</platform>
          <platform>VMWare ESX Server 3.5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-2327" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-2327"/>
        <description>Multiple buffer underflows in the (1) LZWDecode, (2) LZWDecodeCompat, and (3) LZWDecodeVector functions in tif_lzw.c in the LZW decoder in LibTIFF 3.8.2 and earlier allow context-dependent attackers to execute arbitrary code via a crafted TIFF file, related to improper handling of the CODE_CLEAR code.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-09-23T15:39:02.000-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2009-09-29T20:37:01.632-04:00">DRAFT</status_change>
            <status_change date="2009-10-19T04:00:04.113-04:00">INTERIM</status_change>
            <status_change date="2009-11-09T04:00:18.776-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND">
          <extend_definition comment="VMWare ESX Server 3.0.3 is installed" definition_ref="oval:org.mitre.oval:def:6026"/>
          <criterion comment="Patch ESX303-200810503-SG is not installed" test_ref="oval:org.mitre.oval:tst:10758"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="VMWare ESX Server 3.0.2 is installed" definition_ref="oval:org.mitre.oval:def:5626"/>
          <criterion comment="Patch ESX-1006968 is not installed" test_ref="oval:org.mitre.oval:tst:10726"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="VMware ESX Server 3.5.0 is installed" definition_ref="oval:org.mitre.oval:def:5887"/>
          <criterion comment="Patch ESX350-200811405-SG is not installed" test_ref="oval:org.mitre.oval:tst:10390"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5483" version="1" class="vulnerability">
      <metadata>
        <title>Kerberos ASN.1 GeneralizedTime Decoder Bug Lets Remote Users Execute Arbitrary Code</title>
        <affected family="unix">
          <platform>VMWare ESX Server 3</platform>
          <platform>VMWare ESX Server 3.5</platform>
          <platform>VMWare ESX Server 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-0846" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0846"/>
        <description>The asn1_decode_generaltime function in lib/krb5/asn.1/asn1_decode.c in the ASN.1 GeneralizedTime decoder in MIT Kerberos 5 (aka krb5) before 1.6.4 allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code via vectors involving an invalid DER encoding that triggers a free of an uninitialized pointer.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-09-23T15:39:02.000-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2009-09-28T06:57:28.755-04:00">DRAFT</status_change>
            <status_change date="2009-10-19T04:00:03.599-04:00">INTERIM</status_change>
            <status_change date="2009-11-09T04:00:18.308-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND">
          <extend_definition comment="VMWare ESX Server 3.0.3 is installed" definition_ref="oval:org.mitre.oval:def:6026"/>
          <criterion comment="Patch ESX303-200908403-SG is not installed" test_ref="oval:org.mitre.oval:tst:10799"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="VMware ESX Server 4.0 is installed" definition_ref="oval:org.mitre.oval:def:5506"/>
          <criterion comment="Patch ESX400-200906405-SG is not installed" test_ref="oval:org.mitre.oval:tst:10839"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="VMware ESX Server 3.5.0 is installed" definition_ref="oval:org.mitre.oval:def:5887"/>
          <criterion comment="Patch ESX350-200906407-SG is not installed" test_ref="oval:org.mitre.oval:tst:10641"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="VMWare ESX Server 3.0.2 is installed" definition_ref="oval:org.mitre.oval:def:5626"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5506" version="1" class="inventory">
      <metadata>
        <title>VMware ESX Server 4.0 is installed</title>
        <affected family="unix">
          <platform>VMware ESX Server 4</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/o:vmware:esx:4.0"/>
        <description>The operating system installed on the system is VMware ESX Server 4.0.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-09-22T15:10:44.000-05:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2009-09-28T06:57:28.111-04:00">DRAFT</status_change>
            <status_change date="2009-10-19T04:00:03.888-04:00">INTERIM</status_change>
            <status_change date="2009-11-09T04:00:18.591-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="VMware ESX Server 4.0 is installed" test_ref="oval:org.mitre.oval:tst:10625"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5471" version="1" class="vulnerability">
      <metadata>
        <title>VMware Windows 'vmci.sys' Driver Lets Local Users Gain Elevated Privileges</title>
        <affected family="unix">
          <platform>VMWare ESX Server 3</platform>
          <platform>VMWare ESX Server 3.5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-1147" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1147"/>
        <description>Unspecified vulnerability in vmci.sys in the Virtual Machine Communication Interface (VMCI) in VMware Workstation 6.5.1 and earlier, VMware Player 2.5.1 and earlier, VMware ACE 2.5.1 and earlier, and VMware Server 2.0.x before 2.0.1 build 156745 allows local users to gain privileges via unknown vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-09-23T15:39:02.000-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2009-09-28T06:57:18.373-04:00">DRAFT</status_change>
            <status_change date="2009-10-19T04:00:03.306-04:00">INTERIM</status_change>
            <status_change date="2009-11-09T04:00:17.917-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND">
          <extend_definition comment="VMWare ESX Server 3.0.3 is installed" definition_ref="oval:org.mitre.oval:def:6026"/>
          <criterion comment="Patch ESX303-200811401-BG is not installed" test_ref="oval:org.mitre.oval:tst:10884"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="VMWare ESX Server 3.0.2 is installed" definition_ref="oval:org.mitre.oval:def:5613"/>
          <criterion comment="Patch ESX-1006980 is not installed" test_ref="oval:org.mitre.oval:tst:10693"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="VMware ESX Server 3.5.0 is installed" definition_ref="oval:org.mitre.oval:def:5887"/>
          <criterion comment="Patch ESX350-200811401-SG is not installed" test_ref="oval:org.mitre.oval:tst:9884"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5887" version="1" class="inventory">
      <metadata>
        <title>VMware ESX Server 3.5.0 is installed</title>
        <affected family="unix">
          <platform>VMware ESX Server 3.5</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/o:vmware:esx:3.5.0"/>
        <description>The operating system installed on the system is VMware ESX Server 3.5.0.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-02-06T15:10:44.000-05:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2009-02-06T16:04:27.225-05:00">DRAFT</status_change>
            <status_change date="2009-02-23T04:00:21.573-05:00">INTERIM</status_change>
            <status_change date="2009-03-16T04:00:14.681-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="VMware ESX Server 3.5.0 is installed" test_ref="oval:org.mitre.oval:tst:9598"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5780" version="1" class="vulnerability">
      <metadata>
        <title>HP-UX Running bootpd, Remote Denial of Service (DoS)</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-2679" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2679"/>
        <description>Unspecified vulnerability in bootpd in HP HP-UX B.11.11, B.11.23, and B.11.31 allows remote attackers to cause a denial of service via unknown attack vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-09-16T13:58:26.000-04:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2009-09-22T21:48:49.747-04:00">DRAFT</status_change>
            <status_change date="2009-10-12T04:00:06.852-04:00">INTERIM</status_change>
            <status_change date="2009-11-02T04:00:07.330-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02458">
          <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
          <criterion comment="InternetSrvcs.INETSVCS2-BOOT is installed" test_ref="oval:org.mitre.oval:tst:9955"/>
          <criterion negate="true" comment="Patch PHNE_39668 is installed" test_ref="oval:org.mitre.oval:tst:10775"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02458">
          <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
          <criterion comment="InternetSrvcs.INETSVCS2-BOOT is installed" test_ref="oval:org.mitre.oval:tst:9955"/>
          <criterion negate="true" comment="Patch PHNE_39700 is installed" test_ref="oval:org.mitre.oval:tst:10717"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02458">
          <criterion comment="HP-UX B.11.31" test_ref="oval:org.mitre.oval:tst:8260"/>
          <criterion comment="DHCPv4.DHCPV4-RUN is installed" test_ref="oval:org.mitre.oval:tst:10679"/>
          <criterion negate="true" comment="Patch PHNE_39443 is installed" test_ref="oval:org.mitre.oval:tst:9859"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6353" version="1" class="vulnerability">
      <metadata>
        <title>Security Vulnerability in the SNMP daemon (snmpd(1M)) May Lead to a Denial of Service (DoS) Condition</title>
        <affected family="unix">
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-4309" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-4309"/>
        <description>Integer overflow in the netsnmp_create_subtree_cache function in agent/snmp_agent.c in net-snmp 5.4 before 5.4.2.1, 5.3 before 5.3.2.3, and 5.2 before 5.2.5.1 allows remote attackers to cause a denial of service (crash) via a crafted SNMP GETBULK request, which triggers a heap-based buffer overflow,  related to the number of responses or repeats.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-09-10T11:34:43.000-04:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2009-09-10T19:37:14.283-04:00">DRAFT</status_change>
            <status_change date="2009-09-28T04:00:25.685-04:00">INTERIM</status_change>
            <status_change date="2009-10-19T04:00:16.342-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="Software Section">
          <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 262908">
            <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
            <criterion negate="true" comment="Patch 120272-25 or later installed" test_ref="oval:org.mitre.oval:tst:10802"/>
          </criteria>
          <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 262908">
            <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
            <criterion negate="true" comment="Patch 120273-27 or later installed" test_ref="oval:org.mitre.oval:tst:10754"/>
          </criteria>
        </criteria>
        <criterion comment="SUNWsmagt is installed" test_ref="oval:org.mitre.oval:tst:10650"/>
        <criterion comment="sma service is enabled" test_ref="oval:org.mitre.oval:tst:10248"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6392" version="1" class="vulnerability">
      <metadata>
        <title>Security Vulnerability in Solaris pollwakeup(9F) May Allow an Unprivileged User to Panic the System</title>
        <affected family="unix">
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-2952" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2952"/>
        <description>Unspecified vulnerability in the pollwakeup function in Sun Solaris 10, and OpenSolaris before snv_51, allows local users to cause a denial of service (panic) via unknown vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-08-25T16:38:09.000-04:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2009-08-26T08:16:49.443-04:00">DRAFT</status_change>
            <status_change date="2009-09-14T04:00:11.965-04:00">INTERIM</status_change>
            <status_change date="2009-10-05T04:00:06.640-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 265248">
          <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
          <criterion negate="true" comment="Patch 141414-09 or later installed" test_ref="oval:org.mitre.oval:tst:10377"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 265248">
          <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
          <criterion negate="true" comment="Patch 141415-09 or later installed" test_ref="oval:org.mitre.oval:tst:10060"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6225" version="1" class="vulnerability">
      <metadata>
        <title>A Security Vulnerability in the Solaris Print Service (in.lpd(1M)) May Lead to a Denial of Service (DoS) Condition</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <platform>Sun Solaris 9</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-2972" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2972"/>
        <description>in.lpd in the print service in Sun Solaris 8 and 9 allows remote attackers to cause a denial of service (memory consumption) via unspecified vectors that trigger a "fork()/exec() bomb."</description>
        <oval_repository>
          <dates>
            <submitted date="2009-08-28T12:11:40.000-04:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2009-08-28T20:32:58.712-04:00">DRAFT</status_change>
            <status_change date="2009-09-14T04:00:08.792-04:00">INTERIM</status_change>
            <status_change date="2009-10-05T04:00:05.585-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Solaris 8 (SPARC) meets Sun Alert 264608">
          <extend_definition comment="Solaris 8 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1539"/>
          <criterion negate="true" comment="Patch 109320-23 or later installed" test_ref="oval:org.mitre.oval:tst:10451"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (SPARC) meets Sun Alert 264608">
          <extend_definition comment="Solaris 9 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1457"/>
          <criterion negate="true" comment="Patch 113329-07 or later installed" test_ref="oval:org.mitre.oval:tst:10764"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 8 (x86) meets Sun Alert 264608">
          <extend_definition comment="Solaris 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:2059"/>
          <criterion negate="true" comment="Patch 109321-23 or later installed" test_ref="oval:org.mitre.oval:tst:10134"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (x86) meets Sun Alert 264608">
          <extend_definition comment="Solaris 9 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1683"/>
          <criterion negate="true" comment="Patch 114980-09 or later installed" test_ref="oval:org.mitre.oval:tst:10602"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5917" version="1" class="vulnerability">
      <metadata>
        <title>Security Vulnerability in the DNS Protocol May Lead to DNS Cache Poisoning</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <platform>Sun Solaris 9</platform>
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-1447" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1447"/>
        <description>The DNS protocol, as implemented in (1) BIND 8 and 9 before 9.5.0-P1, 9.4.2-P1, and 9.3.5-P1; (2) Microsoft DNS in Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP1 and SP2; and other implementations allow remote attackers to spoof DNS traffic via a birthday attack that uses in-bailiwick referrals to conduct cache poisoning against recursive resolvers, related to insufficient randomness of DNS transaction IDs and source ports, aka "DNS Insufficient Socket Entropy Vulnerability" or "the Kaminsky bug."</description>
        <oval_repository>
          <dates>
            <submitted date="2009-08-25T16:38:09.000-04:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2009-08-26T08:16:51.091-04:00">DRAFT</status_change>
            <status_change date="2009-09-14T04:00:06.253-04:00">INTERIM</status_change>
            <status_change date="2009-10-05T04:00:05.186-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Software Section">
          <criteria operator="AND" comment="Solaris 8 (SPARC) meets Sun Alert 239392">
            <extend_definition comment="Solaris 8 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1539"/>
            <criterion negate="true" comment="Patch 109326-23 or later installed" test_ref="oval:org.mitre.oval:tst:10663"/>
          </criteria>
          <criteria operator="AND" comment="Solaris 9 (SPARC) meets Sun Alert 239392">
            <extend_definition comment="Solaris 9 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1457"/>
            <criterion negate="true" comment="Patch 112837-15 or later installed" test_ref="oval:org.mitre.oval:tst:10777"/>
          </criteria>
          <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 239392">
            <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
            <criterion negate="true" comment="Patch 119783-06 or later installed" test_ref="oval:org.mitre.oval:tst:10241"/>
          </criteria>
          <criteria operator="AND" comment="Solaris 8 (x86) meets Sun Alert 239392">
            <extend_definition comment="Solaris 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:2059"/>
            <criterion negate="true" comment="Patch 109327-23 or later installed" test_ref="oval:org.mitre.oval:tst:10701"/>
          </criteria>
          <criteria operator="AND" comment="Solaris 9 (x86) meets Sun Alert 239392">
            <extend_definition comment="Solaris 9 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1683"/>
            <criterion negate="true" comment="Patch 114265-14 or later installed" test_ref="oval:org.mitre.oval:tst:9857"/>
          </criteria>
          <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 239392">
            <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
            <criterion negate="true" comment="Patch 119784-06 or later installed" test_ref="oval:org.mitre.oval:tst:10275"/>
          </criteria>
        </criteria>
        <criterion comment="in.named running" test_ref="oval:org.mitre.oval:tst:2624"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6152" version="1" class="vulnerability">
      <metadata>
        <title>Security Vulnerability in the Solaris Kernel Involving the Interaction of the Filesystem and Virtual Memory Subsystems</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <platform>Sun Solaris 9</platform>
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-2857" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2857"/>
        <description>The kernel in Sun Solaris 8, 9, and 10, and OpenSolaris before snv_103, does not properly handle interaction between the filesystem and virtual-memory implementations, which allows local users to cause a denial of service (deadlock and system halt) via vectors involving mmap and write operations on the same file.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-08-21T11:07:35.000-04:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2009-08-21T20:56:31.695-04:00">DRAFT</status_change>
            <status_change date="2009-09-07T04:00:11.548-04:00">INTERIM</status_change>
            <status_change date="2009-09-28T04:00:15.555-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND" comment="Solaris 8 (SPARC) meets Sun Alert 257848">
          <extend_definition comment="Solaris 8 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1539"/>
          <criterion negate="true" comment="Patch 127721-02 or later installed" test_ref="oval:org.mitre.oval:tst:10639"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (SPARC) meets Sun Alert 257848">
          <extend_definition comment="Solaris 9 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1457"/>
          <criterion negate="true" comment="Patch 122300-41 or later installed" test_ref="oval:org.mitre.oval:tst:10603"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 257848">
          <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
          <criterion negate="true" comment="Patch 139555-08 or later installed" test_ref="oval:org.mitre.oval:tst:9767"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 8 (x86) meets Sun Alert 257848">
          <extend_definition comment="Solaris 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:2059"/>
          <criterion negate="true" comment="Patch 127722-02 or later installed" test_ref="oval:org.mitre.oval:tst:10324"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (x86) meets Sun Alert 257848">
          <extend_definition comment="Solaris 9 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1683"/>
          <criterion negate="true" comment="Patch 122301-41 or later installed" test_ref="oval:org.mitre.oval:tst:10053"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 257848">
          <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
          <criterion negate="true" comment="Patch 139556-08 or later installed" test_ref="oval:org.mitre.oval:tst:10254"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5911" version="1" class="vulnerability">
      <metadata>
        <title>Untrusted search path vulnerability in chnfsmnt in IBM AIX 6.1.</title>
        <affected family="unix">
          <platform>IBM AIX 6.1</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-1710" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1710"/>
        <description>Untrusted search path vulnerability in chnfsmnt in IBM AIX 6.1 allows local users to gain privileges via a modified PATH environment variable.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-08-08T13:32:18-04:00">
              <contributor organization="DTCC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2009-08-19T14:55:18.639-04:00">DRAFT</status_change>
            <status_change date="2009-09-07T04:00:09.328-04:00">INTERIM</status_change>
            <status_change date="2009-09-28T04:00:12.316-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND" comment="IBM AIX 6100-01 meets CVE-2008-1710">
          <extend_definition comment="IBM AIX 6100-01 is installed" definition_ref="oval:org.mitre.oval:def:5959"/>
          <criterion negate="true" comment="All filesets for APAR IZ20391 are installed" test_ref="oval:org.mitre.oval:tst:10277"/>
        </criteria>
        <criteria operator="AND" comment="IBM AIX 6100-00 meets CVE-2008-1710">
          <extend_definition comment="IBM AIX 6100-00 is installed" definition_ref="oval:org.mitre.oval:def:5589"/>
          <criterion negate="true" comment="All filesets for APAR IZ23556 are installed" test_ref="oval:org.mitre.oval:tst:10575"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5692" version="1" class="vulnerability">
      <metadata>
        <title>Security Vulnerability in the Solaris sendfile(3EXT) and sendfilev(3EXT) Extended Library Functions may Result in a Denial of Service (DoS) Condition due to a System Panic</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <platform>Sun Solaris 9</platform>
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-2912" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2912"/>
        <description>The (1) sendfile and (2) sendfilev functions in Sun Solaris 8 through 10, and OpenSolaris before snv_110, allow local users to cause a denial of service (panic) via vectors related to vnode function calls.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-08-21T11:07:35.000-04:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2009-08-21T20:56:32.365-04:00">DRAFT</status_change>
            <status_change date="2009-09-07T04:00:05.294-04:00">INTERIM</status_change>
            <status_change date="2009-09-28T04:00:07.402-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND" comment="Solaris 8 (SPARC) meets Sun Alert 258588">
          <extend_definition comment="Solaris 8 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1539"/>
          <criterion negate="true" comment="Patch 127721-02 or later installed" test_ref="oval:org.mitre.oval:tst:10485"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (SPARC) meets Sun Alert 258588">
          <extend_definition comment="Solaris 9 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1457"/>
          <criterion negate="true" comment="Patch 122300-42 or later installed" test_ref="oval:org.mitre.oval:tst:10637"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 258588">
          <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
          <criterion negate="true" comment="Patch 141414-05 or later installed" test_ref="oval:org.mitre.oval:tst:10676"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 8 (x86) meets Sun Alert 258588">
          <extend_definition comment="Solaris 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:2059"/>
          <criterion negate="true" comment="Patch 127722-02 or later installed" test_ref="oval:org.mitre.oval:tst:10535"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (x86) meets Sun Alert 258588">
          <extend_definition comment="Solaris 9 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1683"/>
          <criterion negate="true" comment="Patch 122301-42 or later installed" test_ref="oval:org.mitre.oval:tst:10364"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 258588">
          <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
          <criterion negate="true" comment="Patch 141415-05 or later installed" test_ref="oval:org.mitre.oval:tst:10432"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5639" version="1" class="vulnerability">
      <metadata>
        <title>Security Vulnerability in the ACL (acl(2)) Implementation for UFS File Systems May Allow a Local User to Panic the System</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <platform>Sun Solaris 9</platform>
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-4160" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-4160"/>
        <description>Unspecified vulnerability in the UFS module in Sun Solaris 8 through 10 and OpenSolaris allows local users to cause a denial of service (NULL pointer dereference and kernel panic) via unknown vectors related to the Solaris Access Control List (ACL) implementation.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-08-19T11:48:53.000-04:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2009-08-19T14:58:28.865-04:00">DRAFT</status_change>
            <status_change date="2009-09-07T04:00:04.209-04:00">INTERIM</status_change>
            <status_change date="2009-09-28T04:00:06.168-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Software Section">
          <criteria operator="AND" comment="Solaris 8 (SPARC) meets Sun Alert 242267">
            <extend_definition comment="Solaris 8 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1539"/>
            <criterion negate="true" comment="Patch 117350-60 or later installed" test_ref="oval:org.mitre.oval:tst:10320"/>
          </criteria>
          <criteria operator="AND" comment="Solaris 9 (SPARC) meets Sun Alert 242267">
            <extend_definition comment="Solaris 9 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1457"/>
            <criterion negate="true" comment="Patch 122300-34 or later installed" test_ref="oval:org.mitre.oval:tst:10524"/>
          </criteria>
          <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 242267">
            <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
            <criterion negate="true" comment="Patch 139483-01 or later installed" test_ref="oval:org.mitre.oval:tst:10531"/>
          </criteria>
          <criteria operator="AND" comment="Solaris 8 (x86) meets Sun Alert 242267">
            <extend_definition comment="Solaris 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:2059"/>
            <criterion negate="true" comment="Patch 117351-60 or later installed" test_ref="oval:org.mitre.oval:tst:9984"/>
          </criteria>
          <criteria operator="AND" comment="Solaris 9 (x86) meets Sun Alert 242267">
            <extend_definition comment="Solaris 9 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1683"/>
            <criterion negate="true" comment="Patch 122301-34 or later installed" test_ref="oval:org.mitre.oval:tst:10020"/>
          </criteria>
          <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 242267">
            <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
            <criterion negate="true" comment="Patch 139484-01 or later installed" test_ref="oval:org.mitre.oval:tst:9621"/>
          </criteria>
        </criteria>
        <criterion comment="The system has UFS file systems mounted which are writable (read-write)" test_ref="oval:org.mitre.oval:tst:10049"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6387" version="1" class="vulnerability">
      <metadata>
        <title>HP-UX Running Kerberos, Remote Denial of Service (DoS), Execution of Arbitrary Code</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-0847" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0847"/>
        <description>The asn1buf_imbed function in the ASN.1 decoder in MIT Kerberos 5 (aka krb5) 1.6.3, when PK-INIT is used, allows remote attackers to cause a denial of service (application crash) via a crafted length value that triggers an erroneous malloc call, related to incorrect calculations with pointer arithmetic.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-08-11T16:16:36.000-04:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2009-08-12T09:50:14.604-04:00">DRAFT</status_change>
            <status_change date="2009-08-31T04:00:14.778-04:00">INTERIM</status_change>
            <status_change date="2009-09-21T04:00:08.459-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02421">
          <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="krb5client.KRB5-64SLIB-A version is less than D.1.6.2.01" test_ref="oval:org.mitre.oval:tst:10417"/>
            <criterion comment="krb5client.KRB5-64SLIB-A version is less than D.1.6.2.01" test_ref="oval:org.mitre.oval:tst:10417"/>
            <criterion comment="krb5client.KRB5-PRG-A version is less than D.1.6.2.01" test_ref="oval:org.mitre.oval:tst:9858"/>
            <criterion comment="krb5client.KRB5-RUN-A version is less than D.1.6.2.01" test_ref="oval:org.mitre.oval:tst:10546"/>
            <criterion comment="krb5client.KRB5-SHLIB-A version is less than D.1.6.2.01" test_ref="oval:org.mitre.oval:tst:9864"/>
            <criterion comment="krb5client.KRB5IA32SLIB-A version is less than D.1.6.2.01" test_ref="oval:org.mitre.oval:tst:10283"/>
            <criterion comment="krb5client.KRB5IA64SLIB-A version is less than D.1.6.2.01" test_ref="oval:org.mitre.oval:tst:10263"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02421">
          <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="krb5client.KRB5-64SLIB-A version is less than C.1.3.5.09" test_ref="oval:org.mitre.oval:tst:10041"/>
            <criterion comment="krb5client.KRB5-PRG-A version is less than C.1.3.5.09" test_ref="oval:org.mitre.oval:tst:10495"/>
            <criterion comment="krb5client.KRB5-RUN-A version is less than C.1.3.5.09" test_ref="oval:org.mitre.oval:tst:10331"/>
            <criterion comment="krb5client.KRB5-SHLIB-A version is less than C.1.3.5.09" test_ref="oval:org.mitre.oval:tst:10556"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02421">
          <criterion comment="HP-UX B.11.31" test_ref="oval:org.mitre.oval:tst:8260"/>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="krb5client.KRB5-64SLIB-A version is less than E.1.6.2.03" test_ref="oval:org.mitre.oval:tst:10551"/>
            <criterion comment="krb5client.KRB5-PRG-A version is less than E.1.6.2.03" test_ref="oval:org.mitre.oval:tst:10305"/>
            <criterion comment="krb5client.KRB5-RUN-A version is less than E.1.6.2.03" test_ref="oval:org.mitre.oval:tst:10501"/>
            <criterion comment="krb5client.KRB5-SHLIB-A version is less than E.1.6.2.03" test_ref="oval:org.mitre.oval:tst:10039"/>
            <criterion comment="krb5client.KRB5IA32SLIB-A version is less than E.1.6.2.03" test_ref="oval:org.mitre.oval:tst:10539"/>
            <criterion comment="krb5client.KRB5IA64SLIB-A version is less than E.1.6.2.03" test_ref="oval:org.mitre.oval:tst:10262"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6361" version="1" class="vulnerability">
      <metadata>
        <title>A Security Vulnerability in the Solaris IP Filter (ipf(5)) May Lead to a Denial of Service (DoS) Condition</title>
        <affected family="unix">
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-2487" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2487"/>
        <description>Use-after-free vulnerability in the frpr_icmp function in the ipfilter (aka IP Filter) subsystem in Sun Solaris 10, and OpenSolaris snv_45 through snv_110, allows remote attackers to cause a denial of service (panic) via unspecified vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-08-12T12:29:13.000-04:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2009-08-12T18:16:43.070-04:00">DRAFT</status_change>
            <status_change date="2009-08-31T04:00:14.479-04:00">INTERIM</status_change>
            <status_change date="2009-09-21T04:00:07.905-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Software Section">
          <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 260951">
            <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
            <criteria operator="OR">
              <criterion comment="Patch 125014-02 or later installed" test_ref="oval:org.mitre.oval:tst:10532"/>
              <criterion comment="Patch 120011-14 or later installed" test_ref="oval:org.mitre.oval:tst:10461"/>
            </criteria>
            <criterion negate="true" comment="Patch 141020-01 or later installed" test_ref="oval:org.mitre.oval:tst:10397"/>
          </criteria>
          <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 260951">
            <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
            <criteria>
              <criterion comment="Patch 125015-02 or later installed" test_ref="oval:org.mitre.oval:tst:10569"/>
              <criterion comment="Patch 120012-14 or later installed" test_ref="oval:org.mitre.oval:tst:10366"/>
            </criteria>
            <criterion negate="true" comment="Patch 141021-01 or later installed" test_ref="oval:org.mitre.oval:tst:10459"/>
          </criteria>
        </criteria>
        <criteria comment="Configuration Section">
          <criterion comment="ipfilter(5) is running" test_ref="oval:org.mitre.oval:tst:10149"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6349" version="1" class="vulnerability">
      <metadata>
        <title>A Security Vulnerability in the Solaris SCTP Packet Processing may Lead to a System Panic Resulting in a Denial of Service (DoS)</title>
        <affected family="unix">
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-2486" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2486"/>
        <description>Unspecified vulnerability in the SCTP implementation in Sun Solaris 10, and OpenSolaris before snv_120, allows remote attackers to cause a denial of service (panic) via unspecified packets.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-08-12T12:29:13.000-04:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2009-08-12T18:16:42.390-04:00">DRAFT</status_change>
            <status_change date="2009-08-31T04:00:14.243-04:00">INTERIM</status_change>
            <status_change date="2009-09-21T04:00:07.660-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 253608">
          <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
          <criterion negate="true" comment="Patch 141414-01 or later installed" test_ref="oval:org.mitre.oval:tst:10476"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 253608">
          <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
          <criterion negate="true" comment="Patch 141415-01 or later installed" test_ref="oval:org.mitre.oval:tst:10522"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6307" version="1" class="vulnerability">
      <metadata>
        <title>HP-UX Running XNTP, Remote Execution of Arbitrary Code</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-1252" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1252"/>
        <description>Stack-based buffer overflow in the crypto_recv function in ntp_crypto.c in ntpd in NTP before 4.2.4p7 and 4.2.5 before 4.2.5p74, when OpenSSL and autokey are enabled, allows remote attackers to execute arbitrary code via a crafted packet containing an extension field.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-08-11T16:16:37.000-04:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2009-08-12T09:50:15.432-04:00">DRAFT</status_change>
            <status_change date="2009-08-31T04:00:11.277-04:00">INTERIM</status_change>
            <status_change date="2009-09-21T04:00:07.268-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02437">
          <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
          <criterion comment="InternetSrvcs.INETSVCS2-BOOT is installed" test_ref="oval:org.mitre.oval:tst:10552"/>
          <criterion negate="true" comment="Patch PHNE_39872 is installed" test_ref="oval:org.mitre.oval:tst:9736"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02437">
          <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
          <criterion comment="InternetSrvcs.INETSVCS-BOOT is installed" test_ref="oval:org.mitre.oval:tst:10571"/>
          <criterion negate="true" comment="Patch PHNE_39871 is installed" test_ref="oval:org.mitre.oval:tst:10557"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02437">
          <criterion comment="HP-UX B.11.31" test_ref="oval:org.mitre.oval:tst:8260"/>
          <criterion comment="NTP.NTP-RUN is installed" test_ref="oval:org.mitre.oval:tst:10348"/>
          <criterion negate="true" comment="Patch PHNE_39873 is installed" test_ref="oval:org.mitre.oval:tst:10276"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6301" version="1" class="vulnerability">
      <metadata>
        <title>HP-UX Running Kerberos, Remote Denial of Service (DoS), Execution of Arbitrary Code</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-0846" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0846"/>
        <description>The asn1_decode_generaltime function in lib/krb5/asn.1/asn1_decode.c in the ASN.1 GeneralizedTime decoder in MIT Kerberos 5 (aka krb5) before 1.6.4 allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code via vectors involving an invalid DER encoding that triggers a free of an uninitialized pointer.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-08-11T16:16:36.000-04:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2009-08-12T09:50:14.263-04:00">DRAFT</status_change>
            <status_change date="2009-08-31T04:00:10.825-04:00">INTERIM</status_change>
            <status_change date="2009-09-21T04:00:06.772-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02421">
          <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="krb5client.KRB5-64SLIB-A version is less than D.1.6.2.01" test_ref="oval:org.mitre.oval:tst:10417"/>
            <criterion comment="krb5client.KRB5-64SLIB-A version is less than D.1.6.2.01" test_ref="oval:org.mitre.oval:tst:10417"/>
            <criterion comment="krb5client.KRB5-PRG-A version is less than D.1.6.2.01" test_ref="oval:org.mitre.oval:tst:9858"/>
            <criterion comment="krb5client.KRB5-RUN-A version is less than D.1.6.2.01" test_ref="oval:org.mitre.oval:tst:10546"/>
            <criterion comment="krb5client.KRB5-SHLIB-A version is less than D.1.6.2.01" test_ref="oval:org.mitre.oval:tst:9864"/>
            <criterion comment="krb5client.KRB5IA32SLIB-A version is less than D.1.6.2.01" test_ref="oval:org.mitre.oval:tst:10283"/>
            <criterion comment="krb5client.KRB5IA64SLIB-A version is less than D.1.6.2.01" test_ref="oval:org.mitre.oval:tst:10263"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02421">
          <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="krb5client.KRB5-64SLIB-A version is less than C.1.3.5.09" test_ref="oval:org.mitre.oval:tst:10041"/>
            <criterion comment="krb5client.KRB5-PRG-A version is less than C.1.3.5.09" test_ref="oval:org.mitre.oval:tst:10495"/>
            <criterion comment="krb5client.KRB5-RUN-A version is less than C.1.3.5.09" test_ref="oval:org.mitre.oval:tst:10331"/>
            <criterion comment="krb5client.KRB5-SHLIB-A version is less than C.1.3.5.09" test_ref="oval:org.mitre.oval:tst:10556"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02421">
          <criterion comment="HP-UX B.11.31" test_ref="oval:org.mitre.oval:tst:8260"/>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="krb5client.KRB5-64SLIB-A version is less than E.1.6.2.03" test_ref="oval:org.mitre.oval:tst:10551"/>
            <criterion comment="krb5client.KRB5-PRG-A version is less than E.1.6.2.03" test_ref="oval:org.mitre.oval:tst:10305"/>
            <criterion comment="krb5client.KRB5-RUN-A version is less than E.1.6.2.03" test_ref="oval:org.mitre.oval:tst:10501"/>
            <criterion comment="krb5client.KRB5-SHLIB-A version is less than E.1.6.2.03" test_ref="oval:org.mitre.oval:tst:10039"/>
            <criterion comment="krb5client.KRB5IA32SLIB-A version is less than E.1.6.2.03" test_ref="oval:org.mitre.oval:tst:10539"/>
            <criterion comment="krb5client.KRB5IA64SLIB-A version is less than E.1.6.2.03" test_ref="oval:org.mitre.oval:tst:10262"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6215" version="1" class="vulnerability">
      <metadata>
        <title>HP-UX ttrace(2), Local Denial of Service (DoS)</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-1427" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1427"/>
        <description>Unspecified vulnerability in HP-UX B.11.31 allows local users to cause a denial of service (system crash) via unknown vectors related to the ttrace system call.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-08-11T16:16:36.000-04:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2009-08-12T09:50:13.063-04:00">DRAFT</status_change>
            <status_change date="2009-08-31T04:00:09.428-04:00">INTERIM</status_change>
            <status_change date="2009-09-21T04:00:06.529-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND" comment="Criteria meets Security Bulletin HPSBUX02450">
        <criterion comment="HP-UX B.11.31" test_ref="oval:org.mitre.oval:tst:8260"/>
        <criteria operator="OR" comment="filesets tests">
          <criterion comment="ProgSupport.C-INC is installed" test_ref="oval:org.mitre.oval:tst:10434"/>
          <criterion comment="ProgSupport.PAUX-ENG-A-MAN is installed" test_ref="oval:org.mitre.oval:tst:10443"/>
          <criterion comment="OS-Core.CORE2-KRN is installed" test_ref="oval:org.mitre.oval:tst:10534"/>
        </criteria>
        <criterion negate="true" comment="Patch PHKL_40197 is installed" test_ref="oval:org.mitre.oval:tst:10541"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6198" version="1" class="vulnerability">
      <metadata>
        <title>WPAR system call implementation in the kernel in IBM AIX 6.1 denial of service.</title>
        <affected family="unix">
          <platform>IBM AIX 6.1</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-1597" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1597"/>
        <description>The WPAR system call implementation in the kernel in IBM AIX 6.1 allows local users to cause a denial of service via unknown calls that trigger "undefined behavior."</description>
        <oval_repository>
          <dates>
            <submitted date="2009-08-08T13:29:53-04:00">
              <contributor organization="DTCC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2009-08-12T18:17:13.139-04:00">DRAFT</status_change>
            <status_change date="2009-08-31T04:00:09.166-04:00">INTERIM</status_change>
            <status_change date="2009-09-21T04:00:06.272-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND" comment="IBM AIX 6100-02 meets CVE-2008-1597">
          <extend_definition comment="IBM AIX 6100-02 is installed" definition_ref="oval:org.mitre.oval:def:5685"/>
          <criterion negate="true" comment="All filesets for APAR IZ11571 are installed" test_ref="oval:org.mitre.oval:tst:10334"/>
        </criteria>
        <criteria operator="AND" comment="IBM AIX 6100-01 meets CVE-2008-1597">
          <extend_definition comment="IBM AIX 6100-01 is installed" definition_ref="oval:org.mitre.oval:def:5959"/>
          <criterion negate="true" comment="All filesets for APAR IZ09280 are installed" test_ref="oval:org.mitre.oval:tst:10173"/>
        </criteria>
        <criteria operator="AND" comment="IBM AIX 6100-00 meets CVE-2008-1597">
          <extend_definition comment="IBM AIX 6100-00 is installed" definition_ref="oval:org.mitre.oval:def:5589"/>
          <criterion negate="true" comment="All filesets for APAR IZ13392 are installed" test_ref="oval:org.mitre.oval:tst:10396"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6168" version="1" class="vulnerability">
      <metadata>
        <title>Race Condition Security Vulnerability in Solaris Auditing Related to Extended File Attributes May Allow Local Unprivileged Users to Panic the System</title>
        <affected family="unix">
          <platform>Sun Solaris 9</platform>
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-2644" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2644"/>
        <description>Race condition in the Solaris Auditing subsystem in Sun Solaris 9 and 10 and OpenSolaris before snv_121, when extended file attributes are used, allows local users to cause a denial of service (panic) via vectors related to "pathnames for invalid fds."</description>
        <oval_repository>
          <dates>
            <submitted date="2009-08-10T16:40:08.000-04:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2009-08-12T09:49:57.004-04:00">DRAFT</status_change>
            <status_change date="2009-08-31T04:00:08.660-04:00">INTERIM</status_change>
            <status_change date="2009-09-21T04:00:05.908-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="Software Section">
          <criteria operator="AND" comment="Solaris 9 (SPARC) meets Sun Alert 264429">
            <extend_definition comment="Solaris 9 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1457"/>
            <criterion negate="true" comment="Patch 122300-42 or later installed" test_ref="oval:org.mitre.oval:tst:10143"/>
          </criteria>
          <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 264429">
            <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
            <criterion negate="true" comment="Patch 140921-02 or later installed" test_ref="oval:org.mitre.oval:tst:10518"/>
          </criteria>
          <criteria operator="AND" comment="Solaris 9 (x86) meets Sun Alert 264429">
            <extend_definition comment="Solaris 9 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1683"/>
            <criterion negate="true" comment="Patch 122301-42 or later installed" test_ref="oval:org.mitre.oval:tst:10507"/>
          </criteria>
          <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 264429">
            <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
            <criterion negate="true" comment="Patch 140922-02 or later installed" test_ref="oval:org.mitre.oval:tst:9991"/>
          </criteria>
        </criteria>
        <criterion comment="Solaris Auditing is enabled" test_ref="oval:org.mitre.oval:tst:10368"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6028" version="1" class="vulnerability">
      <metadata>
        <title>Multiple unspecified vulnerabilities in IBM AIX rmsock."</title>
        <affected family="unix">
          <platform>IBM AIX 5.2</platform>
          <platform>IBM AIX 5.3</platform>
          <platform>IBM AIX 6.1</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-0370" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0370"/>
        <description>Multiple unspecified vulnerabilities in IBM AIX 5.2.0 through 6.1.2 allow local users to append data to arbitrary files, related to (1) rmsock and (2) rmsock64 not creating "secure log files."</description>
        <oval_repository>
          <dates>
            <submitted date="2009-08-07T08:18:16-04:00">
              <contributor organization="DTCC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2009-08-10T08:38:33.830-04:00">DRAFT</status_change>
            <status_change date="2009-08-31T04:00:07.513-04:00">INTERIM</status_change>
            <status_change date="2009-09-21T04:00:05.256-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="Software Section">
          <criteria operator="AND" comment="IBM AIX 5200-10 meets CVE-2009-0370">
            <extend_definition comment="IBM AIX 5200-10 is installed" definition_ref="oval:org.mitre.oval:def:5076"/>
            <criterion negate="true" comment="All filesets for APAR IZ40386 are installed" test_ref="oval:org.mitre.oval:tst:10435"/>
            <criterion comment="The level of fileset bos.net.tcp.client is greater than or equal 5.2.0.0" test_ref="oval:org.mitre.oval:tst:7050"/>
          </criteria>
          <criteria operator="AND" comment="IBM AIX 5300-00 meets CVE-2009-0370">
            <extend_definition comment="IBM AIX 5300-00 is installed" definition_ref="oval:org.mitre.oval:def:6195"/>
            <criterion negate="true" comment="All filesets for APAR IZ42785 are installed" test_ref="oval:org.mitre.oval:tst:10381"/>
            <criterion comment="The level of fileset bos.net.tcp.client is less than or equal 5.3.0.72" test_ref="oval:org.mitre.oval:tst:10478"/>
            <criterion comment="The level of fileset bos.net.tcp.client is greater than or equal 5.3.0.0" test_ref="oval:org.mitre.oval:tst:7735"/>
          </criteria>
          <criteria operator="AND" comment="IBM AIX 5300-01 through 5300-06 meets CVE-2009-0370">
            <extend_definition comment="IBM AIX 5300-01 through 5300-06 is installed" definition_ref="oval:org.mitre.oval:def:5973"/>
            <criterion comment="Fileset bos.net.tcp.client is installed" test_ref="oval:org.mitre.oval:tst:10479"/>
          </criteria>
          <criteria operator="AND" comment="IBM AIX 5300-07 meets CVE-2009-0370">
            <extend_definition comment="IBM AIX 5300-07 is installed" definition_ref="oval:org.mitre.oval:def:5707"/>
            <criterion negate="true" comment="All filesets for APAR IZ42786 are installed" test_ref="oval:org.mitre.oval:tst:10467"/>
            <criterion comment="Fileset bos.net.tcp.client is greater than or equal 5.3.7.0" test_ref="oval:org.mitre.oval:tst:10553"/>
            <criterion comment="Fileset bos.net.tcp.client is less than or equal 5.3.7.7" test_ref="oval:org.mitre.oval:tst:10423"/>
          </criteria>
          <criteria operator="AND" comment="IBM AIX 5300-08 meets CVE-2009-0370">
            <extend_definition comment="IBM AIX 5300-08 is installed" definition_ref="oval:org.mitre.oval:def:5293"/>
            <criterion negate="true" comment="All filesets for APAR IZ42787 are installed" test_ref="oval:org.mitre.oval:tst:10458"/>
            <criterion comment="Fileset bos.net.tcp.client is greater than or equal 5.3.8.0" test_ref="oval:org.mitre.oval:tst:10190"/>
            <criterion comment="Fileset bos.net.tcp.client is less than or equal 5.3.8.6" test_ref="oval:org.mitre.oval:tst:10285"/>
          </criteria>
          <criteria operator="AND" comment="IBM AIX 5300-09 meets CVE-2009-0370">
            <extend_definition comment="IBM AIX 5300-09 is installed" definition_ref="oval:org.mitre.oval:def:6306"/>
            <criterion negate="true" comment="All filesets for APAR IZ42788 are installed" test_ref="oval:org.mitre.oval:tst:9578"/>
            <criterion comment="Fileset bos.net.tcp.client is greater than or equal 5.3.9.0" test_ref="oval:org.mitre.oval:tst:10444"/>
            <criterion comment="Fileset bos.net.tcp.client is less than or equal 5.3.9.2" test_ref="oval:org.mitre.oval:tst:10464"/>
          </criteria>
          <criteria operator="AND" comment="IBM AIX 6100-00 meets CVE-2009-0370">
            <extend_definition comment="IBM AIX 6100-00 is installed" definition_ref="oval:org.mitre.oval:def:5589"/>
            <criterion negate="true" comment="All filesets for APAR IZ41599 are installed" test_ref="oval:org.mitre.oval:tst:9887"/>
            <criterion comment="Fileset bos.net.tcp.client is greater than or equal 6.1.0.0" test_ref="oval:org.mitre.oval:tst:10562"/>
            <criterion comment="Fileset bos.net.tcp.client is less than or equal 6.1.0.7" test_ref="oval:org.mitre.oval:tst:10282"/>
          </criteria>
          <criteria operator="AND" comment="IBM AIX 6100-01 meets CVE-2009-0370">
            <extend_definition comment="IBM AIX 6100-01 is installed" definition_ref="oval:org.mitre.oval:def:5959"/>
            <criterion negate="true" comment="All filesets for APAR IZ41593 are installed" test_ref="oval:org.mitre.oval:tst:10561"/>
            <criterion comment="Fileset bos.net.tcp.client is greater than or equal 6.1.1.0" test_ref="oval:org.mitre.oval:tst:10514"/>
            <criterion comment="Fileset bos.net.tcp.client is less than or equal 6.1.1.3" test_ref="oval:org.mitre.oval:tst:10497"/>
          </criteria>
          <criteria operator="AND" comment="IBM AIX 6100-02 meets CVE-2009-0370">
            <extend_definition comment="IBM AIX 6100-02 is installed" definition_ref="oval:org.mitre.oval:def:5685"/>
            <criterion negate="true" comment="All filesets for APAR IZ41510 are installed" test_ref="oval:org.mitre.oval:tst:9672"/>
            <criterion comment="Fileset bos.net.tcp.client is greater than or equal 6.1.2.0" test_ref="oval:org.mitre.oval:tst:10487"/>
            <criterion comment="Fileset bos.net.tcp.client is less than or equal 6.1.2.2" test_ref="oval:org.mitre.oval:tst:10528"/>
          </criteria>
        </criteria>
        <criteria operator="OR" comment="Configuration Section">
          <criterion comment="/usr/sbin/rmsock is suid" test_ref="oval:org.mitre.oval:tst:10496"/>
          <criterion comment="/usr/sbin/rmsock64 is suid" test_ref="oval:org.mitre.oval:tst:10491"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5838" version="1" class="vulnerability">
      <metadata>
        <title>A Security Vulnerability May Allow Popup Windows to Appear Through the Solaris XScreenSaver Program on Xorg(1) Servers</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <platform>Sun Solaris 9</platform>
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-2711" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2711"/>
        <description>XScreenSaver in Sun Solaris 9 and 10, OpenSolaris before snv_120, and X11 6.4.1 for Solaris 8, when the Xorg or Xnewt server is used, allows physically proximate attackers to obtain sensitive information by reading popup windows, which are displayed even when the screen is locked, a different vulnerability than CVE-2009-1276.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-08-10T16:40:08.000-04:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2009-08-12T09:49:58.244-04:00">DRAFT</status_change>
            <status_change date="2009-08-31T04:00:06.335-04:00">INTERIM</status_change>
            <status_change date="2009-09-21T04:00:04.819-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="Software Section">
          <criteria operator="AND" comment="Solaris 8 (SPARC) meets Sun Alert 258928">
            <extend_definition comment="Solaris 8 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1539"/>
            <criterion negate="true" comment="Patch 115298-02 or later installed" test_ref="oval:org.mitre.oval:tst:10067"/>
          </criteria>
          <criteria operator="AND" comment="Solaris 9 (SPARC) meets Sun Alert 258928">
            <extend_definition comment="Solaris 9 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1457"/>
            <criterion negate="true" comment="Patch 115158-11 or later installed" test_ref="oval:org.mitre.oval:tst:10579"/>
          </criteria>
          <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 258928">
            <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
            <criterion negate="true" comment="Patch 120094-23 or later installed" test_ref="oval:org.mitre.oval:tst:10472"/>
          </criteria>
          <criteria operator="AND" comment="Solaris 8 (x86) meets Sun Alert 258928">
            <extend_definition comment="Solaris 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:2059"/>
            <criterion negate="true" comment="Patch 115299-02 or later installed" test_ref="oval:org.mitre.oval:tst:10441"/>
          </criteria>
          <criteria operator="AND" comment="Solaris 9 (x86) meets Sun Alert 258928">
            <extend_definition comment="Solaris 9 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1683"/>
            <criterion negate="true" comment="Patch 115159-11 or later installed" test_ref="oval:org.mitre.oval:tst:10429"/>
          </criteria>
          <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 258928">
            <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
            <criterion negate="true" comment="Patch 120095-23 or later installed" test_ref="oval:org.mitre.oval:tst:10567"/>
          </criteria>
        </criteria>
        <criterion comment="SUNWxwsvr is installed" test_ref="oval:org.mitre.oval:tst:10577"/>
        <criterion comment="The Xorg X server is running" test_ref="oval:org.mitre.oval:tst:1334"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5586" version="1" class="vulnerability">
      <metadata>
        <title>Unspecified vulnerability in the NFSv4 module in the kernel in Sun Solaris 10."</title>
        <affected family="unix">
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-2488" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2488"/>
        <description>Unspecified vulnerability in the NFSv4 module in the kernel in Sun Solaris 10, and OpenSolaris snv_102 through snv_119, allows local users to cause a denial of service (client panic) via vectors involving "file operations."</description>
        <oval_repository>
          <dates>
            <submitted date="2009-08-09T17:59:08-04:00">
              <contributor organization="DTCC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2009-08-12T09:49:45.817-04:00">DRAFT</status_change>
            <status_change date="2009-08-31T04:00:04.652-04:00">INTERIM</status_change>
            <status_change date="2009-09-21T04:00:04.218-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND" comment="Solaris 10 (X86) meets Sun Alert ID 262788 criteria.">
          <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
          <criterion negate="true" comment="Patch 141734-03 or later installed" test_ref="oval:org.mitre.oval:tst:10132"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert ID 262788 criteria.">
          <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
          <criterion negate="true" comment="Patch 141733-03 or later installed" test_ref="oval:org.mitre.oval:tst:10550"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5411" version="1" class="vulnerability">
      <metadata>
        <title>HP-UX Running XNTP, Remote Execution of Arbitrary Code</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-0159" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0159"/>
        <description>Stack-based buffer overflow in the cookedprint function in ntpq/ntpq.c in ntpq in NTP before 4.2.4p7-RC2 allows remote NTP servers to execute arbitrary code via a crafted response.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-08-11T16:16:36.000-04:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2009-08-12T09:50:15.228-04:00">DRAFT</status_change>
            <status_change date="2009-08-31T04:00:02.381-04:00">INTERIM</status_change>
            <status_change date="2009-09-21T04:00:03.047-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02437">
          <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
          <criterion comment="InternetSrvcs.INETSVCS2-BOOT is installed" test_ref="oval:org.mitre.oval:tst:10552"/>
          <criterion negate="true" comment="Patch PHNE_39872 is installed" test_ref="oval:org.mitre.oval:tst:9736"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02437">
          <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
          <criterion comment="InternetSrvcs.INETSVCS-BOOT is installed" test_ref="oval:org.mitre.oval:tst:10571"/>
          <criterion negate="true" comment="Patch PHNE_39871 is installed" test_ref="oval:org.mitre.oval:tst:10557"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02437">
          <criterion comment="HP-UX B.11.31" test_ref="oval:org.mitre.oval:tst:8260"/>
          <criterion comment="NTP.NTP-RUN is installed" test_ref="oval:org.mitre.oval:tst:10348"/>
          <criterion negate="true" comment="Patch PHNE_39873 is installed" test_ref="oval:org.mitre.oval:tst:10276"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6402" version="1" class="vulnerability">
      <metadata>
        <title>Stack-based buffer overflow in muxatmd.</title>
        <affected family="unix">
          <platform>IBM AIX 5.2</platform>
          <platform>IBM AIX 5.3</platform>
          <platform>IBM AIX 6.1</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-1355" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1355"/>
        <description>Stack-based buffer overflow in muxatmd in IBM AIX 5.2, 5.3, and 6.1 allows local users to gain privileges via a long filename.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-08-01T16:26:02-04:00">
              <contributor organization="DTCC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2009-08-06T11:03:47.441-04:00">DRAFT</status_change>
            <status_change date="2009-08-24T04:00:11.640-04:00">INTERIM</status_change>
            <status_change date="2009-09-14T04:00:12.560-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND" comment="IBM AIX 5.2 meets CVE-2009-1355">
          <extend_definition comment="IBM AIX 5.2 is installed" definition_ref="oval:org.mitre.oval:def:5189"/>
          <criterion negate="true" comment="All filesets for APAR IZ48495 are installed" test_ref="oval:org.mitre.oval:tst:10554"/>
          <criterion comment="Fileset devices.common.IBM.atm.rte is greater than or equal 5.2.0.51" test_ref="oval:org.mitre.oval:tst:10505"/>
          <criterion comment="Fileset devices.common.IBM.atm.rte is less than or equal 5.2.0.97" test_ref="oval:org.mitre.oval:tst:10456"/>
        </criteria>
        <criteria operator="AND" comment="IBM AIX 5300-00 meets CVE-2009-1355">
          <extend_definition comment="IBM AIX 5300-00 is installed" definition_ref="oval:org.mitre.oval:def:6195"/>
          <criterion negate="true" comment="All filesets for APAR IZ48496 are installed" test_ref="oval:org.mitre.oval:tst:10342"/>
          <criterion comment="Fileset devices.common.IBM.atm.rte is greater than or equal 5.3.0.60" test_ref="oval:org.mitre.oval:tst:9636"/>
          <criterion comment="Fileset devices.common.IBM.atm.rte is less than or equal 5.3.0.63" test_ref="oval:org.mitre.oval:tst:10287"/>
        </criteria>
        <criteria operator="AND" comment="IBM AIX 5300-01 through 5300-06 meets CVE-2009-1355">
          <extend_definition comment="IBM AIX 5300-01 through 5300-06 is installed" definition_ref="oval:org.mitre.oval:def:5973"/>
          <criterion comment="Fileset devices.common.IBM.atm.rte is installed" test_ref="oval:org.mitre.oval:tst:10145"/>
        </criteria>
        <criteria operator="AND" comment="IBM AIX 5300-07 meets CVE-2009-1355">
          <extend_definition comment="IBM AIX 5300-07 is installed" definition_ref="oval:org.mitre.oval:def:5707"/>
          <criterion negate="true" comment="All filesets for APAR IZ48499 are installed" test_ref="oval:org.mitre.oval:tst:10228"/>
          <criterion comment="Fileset devices.common.IBM.atm.rte is greater than or equal 5.3.7.0" test_ref="oval:org.mitre.oval:tst:10182"/>
          <criterion comment="Fileset devices.common.IBM.atm.rte is less than or equal 5.3.7.2" test_ref="oval:org.mitre.oval:tst:10255"/>
        </criteria>
        <criteria operator="AND" comment="IBM AIX 5300-08 meets CVE-2009-1355">
          <extend_definition comment="IBM AIX 5300-08 is installed" definition_ref="oval:org.mitre.oval:def:5293"/>
          <criterion negate="true" comment="All filesets for APAR IZ48500 are installed" test_ref="oval:org.mitre.oval:tst:10225"/>
          <criterion comment="Fileset devices.common.IBM.atm.rte is equal to 5.3.8.0" test_ref="oval:org.mitre.oval:tst:10533"/>
        </criteria>
        <criteria operator="AND" comment="IBM AIX 5300-09 meets CVE-2009-1355">
          <extend_definition comment="IBM AIX 5300-09 is installed" definition_ref="oval:org.mitre.oval:def:6306"/>
          <criterion negate="true" comment="All filesets for APAR IZ48501 are installed" test_ref="oval:org.mitre.oval:tst:10515"/>
          <criterion comment="Fileset devices.common.IBM.atm.rte is equal to 5.3.9.0" test_ref="oval:org.mitre.oval:tst:10508"/>
        </criteria>
        <criteria operator="AND" comment="IBM AIX 6100-00 meets CVE-2009-1355">
          <extend_definition comment="IBM AIX 6100-00 is installed" definition_ref="oval:org.mitre.oval:def:5589"/>
          <criterion negate="true" comment="All filesets for APAR IZ48502 are installed" test_ref="oval:org.mitre.oval:tst:10140"/>
          <criterion comment="Fileset devices.common.IBM.atm.rte is greater than or equal 6.1.0.0" test_ref="oval:org.mitre.oval:tst:9677"/>
          <criterion comment="Fileset devices.common.IBM.atm.rte is less than or equal 6.1.0.1" test_ref="oval:org.mitre.oval:tst:10201"/>
        </criteria>
        <criteria operator="AND" comment="IBM AIX 6100-01 meets CVE-2009-1355">
          <extend_definition comment="IBM AIX 6100-01 is installed" definition_ref="oval:org.mitre.oval:def:5959"/>
          <criterion negate="true" comment="All filesets for APAR IZ48561 are installed" test_ref="oval:org.mitre.oval:tst:10449"/>
          <criterion comment="Fileset devices.common.IBM.atm.rte is equal to 6.1.1.0" test_ref="oval:org.mitre.oval:tst:9925"/>
        </criteria>
        <criteria operator="AND" comment="IBM AIX 6100-02 meets CVE-2009-1355">
          <extend_definition comment="IBM AIX 6100-02 is installed" definition_ref="oval:org.mitre.oval:def:5685"/>
          <criterion negate="true" comment="All filesets for APAR IZ48562 are installed" test_ref="oval:org.mitre.oval:tst:10486"/>
          <criterion comment="Fileset devices.common.IBM.atm.rte is equal to 6.1.2.0" test_ref="oval:org.mitre.oval:tst:10294"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6303" version="1" class="vulnerability">
      <metadata>
        <title>Buffer overflow in autoconf6.</title>
        <affected family="unix">
          <platform>IBM AIX 5.3</platform>
          <platform>IBM AIX 6.1</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-5387" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-5387"/>
        <description>Buffer overflow in autoconf6 in IBM AIX 6.1.0 through 6.1.2, when Role-Based Access Control is enabled, allows local users with aix.network.config.tcpip authorization to gain privileges via unspecified vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-08-02T14:02:44-04:00">
              <contributor organization="DTCC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2009-08-06T10:44:06.771-04:00">DRAFT</status_change>
            <status_change date="2009-08-24T04:00:08.925-04:00">INTERIM</status_change>
            <status_change date="2009-09-14T04:00:09.374-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND" comment="IBM AIX 5300-00 through 5300-05 meets CVE-2008-5387">
          <extend_definition comment="IBM AIX 5300-00 through 5300-05 is installed" definition_ref="oval:org.mitre.oval:def:6368"/>
        </criteria>
        <criteria operator="AND" comment="IBM AIX 5300-06 meets CVE-2008-5387">
          <extend_definition comment="IBM AIX 5300-06 is installed" definition_ref="oval:org.mitre.oval:def:4813"/>
          <criterion negate="true" comment="All filesets for APAR IZ32172 are installed" test_ref="oval:org.mitre.oval:tst:10259"/>
        </criteria>
        <criteria operator="AND" comment="IBM AIX 5300-07 meets CVE-2008-5387">
          <extend_definition comment="IBM AIX 5300-07 is installed" definition_ref="oval:org.mitre.oval:def:5707"/>
          <criterion negate="true" comment="All filesets for APAR IZ32051 are installed" test_ref="oval:org.mitre.oval:tst:9861"/>
        </criteria>
        <criteria operator="AND" comment="IBM AIX 5300-08 meets CVE-2008-5387">
          <extend_definition comment="IBM AIX 5300-08 is installed" definition_ref="oval:org.mitre.oval:def:5293"/>
          <criterion negate="true" comment="All filesets for APAR IZ32016 are installed" test_ref="oval:org.mitre.oval:tst:10527"/>
        </criteria>
        <criteria operator="AND" comment="IBM AIX 5300-09 meets CVE-2008-5387">
          <extend_definition comment="IBM AIX 5300-09 is installed" definition_ref="oval:org.mitre.oval:def:6306"/>
          <criterion negate="true" comment="All filesets for APAR IZ30238 are installed" test_ref="oval:org.mitre.oval:tst:10466"/>
        </criteria>
        <criteria operator="AND" comment="IBM AIX 6100-00 meets CVE-2008-5387">
          <extend_definition comment="IBM AIX 6100-00 is installed" definition_ref="oval:org.mitre.oval:def:5589"/>
          <criterion negate="true" comment="All filesets for APAR IZ34753 are installed" test_ref="oval:org.mitre.oval:tst:10410"/>
        </criteria>
        <criteria operator="AND" comment="IBM AIX 6100-01 meets CVE-2008-5387">
          <extend_definition comment="IBM AIX 6100-01 is installed" definition_ref="oval:org.mitre.oval:def:5959"/>
          <criterion negate="true" comment="All filesets for APAR IZ34393 are installed" test_ref="oval:org.mitre.oval:tst:10180"/>
        </criteria>
        <criteria operator="AND" comment="IBM AIX 6100-02 meets CVE-2008-5387">
          <extend_definition comment="IBM AIX 6100-02 is installed" definition_ref="oval:org.mitre.oval:def:5685"/>
          <criterion negate="true" comment="All filesets for APAR IZ30231 are installed" test_ref="oval:org.mitre.oval:tst:10011"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6368" version="1" class="inventory">
      <metadata>
        <title>IBM AIX 5300-00 through 5300-05 is installed</title>
        <affected family="unix">
          <platform>IBM AIX 5.3</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/o:ibm:aix:5.3"/>
        <description>The operating system installed on the system is IBM AIX version 5300-00 through 5300-06.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-08-02T12:00:00.000-04:00">
              <contributor organization="DTCC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2009-08-06T10:44:04.622-04:00">DRAFT</status_change>
            <status_change date="2009-08-24T04:00:11.165-04:00">INTERIM</status_change>
            <status_change date="2009-09-14T04:00:11.758-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="IBM AIX version is greater than or equal 5.3.0.0" test_ref="oval:org.mitre.oval:tst:7973"/>
        <criterion comment="IBM AIX version is less than or equal 5300-05" test_ref="oval:org.mitre.oval:tst:10250"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6155" version="1" class="vulnerability">
      <metadata>
        <title>at allows local users to read arbitrary files.</title>
        <affected family="unix">
          <platform>IBM AIX 5.2</platform>
          <platform>IBM AIX 5.3</platform>
          <platform>IBM AIX 6.1</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-0536" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0536"/>
        <description>at in bos.rte.cron on IBM AIX 5.2.0, 5.3.0 through 5.3.9, and 6.1.0 through 6.1.2 allows local users to read arbitrary files via unspecified vectors, related to failure to drop root privileges.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-08-01T16:42:25-04:00">
              <contributor organization="DTCC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2009-08-04T10:38:30.325-04:00">DRAFT</status_change>
            <status_change date="2009-08-24T04:00:08.002-04:00">INTERIM</status_change>
            <status_change date="2009-09-14T04:00:07.840-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND" comment="IBM AIX 5200-10 meets CVE-2009-0536">
          <extend_definition comment="IBM AIX 5200-10 is installed" definition_ref="oval:org.mitre.oval:def:5076"/>
          <criterion negate="true" comment="All filesets for APAR IZ43452 are installed" test_ref="oval:org.mitre.oval:tst:10346"/>
          <criterion comment="Fileset bos.rte.cron is greater than or equal 5.2.0.0" test_ref="oval:org.mitre.oval:tst:10266"/>
          <criterion comment="Fileset bos.rte.cron is less than or equal 5.2.0.106" test_ref="oval:org.mitre.oval:tst:10308"/>
        </criteria>
        <criteria operator="AND" comment="IBM AIX 5300-00 meets CVE-2009-0536">
          <extend_definition comment="IBM AIX 5300-00 is installed" definition_ref="oval:org.mitre.oval:def:6195"/>
          <criterion negate="true" comment="All filesets for APAR IZ43453 are installed" test_ref="oval:org.mitre.oval:tst:9585"/>
          <criterion comment="Fileset bos.rte.cron is greater than or equal 5.3.0.0" test_ref="oval:org.mitre.oval:tst:10468"/>
          <criterion comment="Fileset bos.rte.cron is less than or equal 5.3.0.63" test_ref="oval:org.mitre.oval:tst:9900"/>
        </criteria>
        <criteria operator="AND" comment="IBM AIX 5300-01 through 5300-06 meets CVE-2009-0536">
          <extend_definition comment="IBM AIX 5300-01 through 5300-06 is installed" definition_ref="oval:org.mitre.oval:def:5973"/>
          <criterion comment="Fileset bos.rte.cron is installed" test_ref="oval:org.mitre.oval:tst:10547"/>
        </criteria>
        <criteria operator="AND" comment="IBM AIX 5300-07 meets CVE-2009-0536">
          <extend_definition comment="IBM AIX 5300-07 is installed" definition_ref="oval:org.mitre.oval:def:5707"/>
          <criterion negate="true" comment="All filesets for APAR IZ43454 are installed" test_ref="oval:org.mitre.oval:tst:9728"/>
          <criterion comment="Fileset bos.rte.cron is greater than or equal 5.3.7.0" test_ref="oval:org.mitre.oval:tst:10447"/>
          <criterion comment="Fileset bos.rte.cron is less than or equal 5.3.7.1" test_ref="oval:org.mitre.oval:tst:10301"/>
        </criteria>
        <criteria operator="AND" comment="IBM AIX 5300-08 meets CVE-2009-0536">
          <extend_definition comment="IBM AIX 5300-08 is installed" definition_ref="oval:org.mitre.oval:def:5293"/>
          <criterion negate="true" comment="All filesets for APAR IZ43455 are installed" test_ref="oval:org.mitre.oval:tst:10513"/>
          <criterion comment="Fileset bos.rte.cron is greater than or equal 5.3.8.0" test_ref="oval:org.mitre.oval:tst:10222"/>
          <criterion comment="Fileset bos.rte.cron is less than or equal 5.3.8.1" test_ref="oval:org.mitre.oval:tst:10374"/>
        </criteria>
        <criteria operator="AND" comment="IBM AIX 5300-09 meets CVE-2009-0536">
          <extend_definition comment="IBM AIX 5300-09 is installed" definition_ref="oval:org.mitre.oval:def:6306"/>
          <criterion negate="true" comment="All filesets for APAR IZ43456 are installed" test_ref="oval:org.mitre.oval:tst:9949"/>
          <criterion comment="Fileset bos.rte.cron is equal to 5.3.9.0" test_ref="oval:org.mitre.oval:tst:10185"/>
        </criteria>
        <criteria operator="AND" comment="IBM AIX 6100-00 meets CVE-2009-0536">
          <extend_definition comment="IBM AIX 6100-00 is installed" definition_ref="oval:org.mitre.oval:def:5589"/>
          <criterion negate="true" comment="All filesets for APAR IZ43457 are installed" test_ref="oval:org.mitre.oval:tst:9561"/>
          <criterion comment="Fileset bos.rte.cron is greater than or equal 6.1.0.0" test_ref="oval:org.mitre.oval:tst:10376"/>
          <criterion comment="Fileset bos.rte.cron is less than or equal 6.1.0.1" test_ref="oval:org.mitre.oval:tst:10315"/>
        </criteria>
        <criteria operator="AND" comment="IBM AIX 6100-01 meets CVE-2009-0536">
          <extend_definition comment="IBM AIX 6100-01 is installed" definition_ref="oval:org.mitre.oval:def:5959"/>
          <criterion negate="true" comment="All filesets for APAR IZ43458 are installed" test_ref="oval:org.mitre.oval:tst:9866"/>
          <criterion comment="Fileset bos.rte.cron is greater than or equal 6.1.1.0" test_ref="oval:org.mitre.oval:tst:10517"/>
          <criterion comment="Fileset bos.rte.cron is less than or equal 6.1.1.2" test_ref="oval:org.mitre.oval:tst:9829"/>
        </criteria>
        <criteria operator="AND" comment="IBM AIX 6100-02 meets CVE-2009-0536">
          <extend_definition comment="IBM AIX 6100-02 is installed" definition_ref="oval:org.mitre.oval:def:5685"/>
          <criterion negate="true" comment="All filesets for APAR IZ43459 are installed" test_ref="oval:org.mitre.oval:tst:10436"/>
          <criterion comment="Fileset bos.rte.cron is equal to 6.1.2.0" test_ref="oval:org.mitre.oval:tst:10521"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5612" version="1" class="vulnerability">
      <metadata>
        <title>crontab allows local users to gain privileges by launching an editor.</title>
        <affected family="unix">
          <platform>IBM AIX 6.1</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-5384" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-5384"/>
        <description>crontab in bos.rte.cron in IBM AIX 6.1.0 through 6.1.2 allows local users with aix.system.config.cron authorization to gain privileges by launching an editor.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-08-02T10:33:29-04:00">
              <contributor organization="DTCC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2009-08-04T10:38:13.330-04:00">DRAFT</status_change>
            <status_change date="2009-08-24T04:00:04.841-04:00">INTERIM</status_change>
            <status_change date="2009-09-14T04:00:04.742-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND" comment="IBM AIX 6100-02 meets CVE-2008-5384">
          <extend_definition comment="IBM AIX 6100-02 is installed" definition_ref="oval:org.mitre.oval:def:5685"/>
          <criterion negate="true" comment="All filesets for APAR IZ30248 are installed" test_ref="oval:org.mitre.oval:tst:10034"/>
          <criterion comment="Fileset bos.rte.cron is greater than or equal 6.1.2.0" test_ref="oval:org.mitre.oval:tst:10167"/>
          <criterion comment="Fileset bos.rte.cron is less than or equal 6.1.2.1" test_ref="oval:org.mitre.oval:tst:10096"/>
        </criteria>
        <criteria operator="AND" comment="IBM AIX 6100-01 meets CVE-2008-5384">
          <extend_definition comment="IBM AIX 6100-01 is installed" definition_ref="oval:org.mitre.oval:def:5959"/>
          <criterion negate="true" comment="All filesets for APAR IZ34478 are installed" test_ref="oval:org.mitre.oval:tst:10387"/>
          <criterion comment="Fileset bos.rte.cron is greater than or equal 6.1.1.0" test_ref="oval:org.mitre.oval:tst:10080"/>
          <criterion comment="Fileset bos.rte.cron is less than or equal 6.1.1.1" test_ref="oval:org.mitre.oval:tst:9994"/>
        </criteria>
        <criteria operator="AND" comment="IBM AIX 6100-00 meets CVE-2008-5384">
          <extend_definition comment="IBM AIX 6100-00 is installed" definition_ref="oval:org.mitre.oval:def:5589"/>
          <criterion negate="true" comment="All filesets for APAR IZ34783 are installed" test_ref="oval:org.mitre.oval:tst:9496"/>
          <criterion comment="Fileset bos.rte.cron is equal to 6.1.0.0" test_ref="oval:org.mitre.oval:tst:10430"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6252" version="1" class="vulnerability">
      <metadata>
        <title>Security Vulnerability in PostgreSQL Shipped with Solaris may Allow a Denial of Service (DoS)</title>
        <affected family="unix">
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-0922" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0922"/>
        <description>PostgreSQL before 8.3.7, 8.2.13, 8.1.17, 8.0.21, and 7.4.25 allows remote authenticated users to cause a denial of service (stack consumption and crash) by triggering a failure in the conversion of a localized error message to a client-specified encoding, as demonstrated using mismatched encoding conversion requests.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-07-28T11:46:34.000-04:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2009-07-30T17:45:07.723-04:00">DRAFT</status_change>
            <status_change date="2009-08-17T04:00:03.670-04:00">INTERIM</status_change>
            <status_change date="2009-09-07T04:00:13.826-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="Software Section">
          <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 258808">
            <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
            <criterion negate="true" comment="Patch 123590-10 or later installed" test_ref="oval:org.mitre.oval:tst:10235"/>
            <criterion comment="SUNWpostgr is installed" test_ref="oval:org.mitre.oval:tst:10073"/>
          </criteria>
          <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 258808">
            <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
            <criterion negate="true" comment="Patch 136998-06 or later installed" test_ref="oval:org.mitre.oval:tst:10133"/>
            <criterion comment="SUNWpostgr-82* is installed" test_ref="oval:org.mitre.oval:tst:10339"/>
          </criteria>
          <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 258808">
            <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
            <criterion negate="true" comment="Patch 138826-04 or later installed" test_ref="oval:org.mitre.oval:tst:10362"/>
            <criterion comment="SUNWpostgr-83* is installed" test_ref="oval:org.mitre.oval:tst:10361"/>
          </criteria>
          <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 258808">
            <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
            <criterion negate="true" comment="Patch 123591-10 or later installed" test_ref="oval:org.mitre.oval:tst:10129"/>
            <criterion comment="SUNWpostgr is installed" test_ref="oval:org.mitre.oval:tst:10073"/>
          </criteria>
          <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 258808">
            <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
            <criterion negate="true" comment="Patch 136999-06 or later installed" test_ref="oval:org.mitre.oval:tst:10164"/>
            <criterion comment="SUNWpostgr-82* is installed" test_ref="oval:org.mitre.oval:tst:10339"/>
          </criteria>
          <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 258808">
            <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
            <criterion negate="true" comment="Patch 138827-04 or later installed" test_ref="oval:org.mitre.oval:tst:10385"/>
            <criterion comment="SUNWpostgr-83* is installed" test_ref="oval:org.mitre.oval:tst:10361"/>
          </criteria>
        </criteria>
        <criterion comment="Patch 136999-06 or later installed" test_ref="oval:org.mitre.oval:tst:10409"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6136" version="1" class="vulnerability">
      <metadata>
        <title>Security Vulnerability in the Simple Authentication and Security Layer (SASL) Library Bundled with the Java Enterprise System (JES) may Allow Unprivileged Users to Crash Applications Using the sasl_encode64 Function</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <platform>Sun Solaris 9</platform>
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-0688" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0688"/>
        <description>Multiple buffer overflows in the CMU Cyrus SASL library before 2.1.23 might allow remote attackers to execute arbitrary code or cause a denial of service (application crash) via strings that are used as input to the sasl_encode64 function in lib/saslutil.c.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-07-28T11:14:39.000-04:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2009-07-30T17:45:06.789-04:00">DRAFT</status_change>
            <status_change date="2009-08-17T04:00:03.181-04:00">INTERIM</status_change>
            <status_change date="2009-09-07T04:00:11.189-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="Software Section">
          <criteria operator="AND" comment="Solaris 8 (SPARC) meets Sun Alert 264248">
            <extend_definition comment="Solaris 8 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1539"/>
            <criterion negate="true" comment="Patch 115328-08 or later installed" test_ref="oval:org.mitre.oval:tst:10445"/>
          </criteria>
          <criteria operator="AND" comment="Solaris 9 (SPARC) meets Sun Alert 264248">
            <extend_definition comment="Solaris 9 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1457"/>
            <criterion negate="true" comment="Patch 115342-08 or later installed" test_ref="oval:org.mitre.oval:tst:10367"/>
          </criteria>
          <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 264248">
            <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
            <criterion negate="true" comment="Patch 119345-07 or later installed" test_ref="oval:org.mitre.oval:tst:10193"/>
          </criteria>
          <criteria operator="AND" comment="Solaris 9 (x86) meets Sun Alert 264248">
            <extend_definition comment="Solaris 9 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1683"/>
            <criterion negate="true" comment="Patch 115343-08 or later installed" test_ref="oval:org.mitre.oval:tst:10455"/>
          </criteria>
          <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 264248">
            <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
            <criterion negate="true" comment="Patch 119346-07 or later installed" test_ref="oval:org.mitre.oval:tst:9898"/>
          </criteria>
        </criteria>
        <criterion comment="SUNWsasl is installed" test_ref="oval:org.mitre.oval:tst:9482"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:12575" version="1" class="vulnerability">
      <metadata>
        <title>Buffer overflow in the drmgr command in IBM AIX 5.2 and 5.3 allows local users to cause a denial of service (crash) and possibly execute arbitrary code via a long path name.</title>
        <affected family="unix">
          <platform>IBM AIX 5.3</platform>
          <platform>IBM AIX 5.2</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-1798" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1798"/>
        <description>Buffer overflow in the drmgr command in IBM AIX 5.2 and 5.3 allows local users to cause a denial of service (crash) and possibly execute arbitrary code via a long path name.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-07-27T10:12:07-04:00">
              <contributor organization="DTCC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2009-07-30T17:45:34.504-04:00">DRAFT</status_change>
            <status_change date="2009-08-17T04:00:02.039-04:00">INTERIM</status_change>
            <status_change date="2009-09-07T04:00:02.807-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IBM AIX 5200-10 meets CVE-2007-1798">
          <extend_definition comment="IBM AIX 5200-10 is installed" definition_ref="oval:org.mitre.oval:def:5076"/>
          <criterion negate="true" comment="All filesets for APAR IY96772 are installed" test_ref="oval:org.mitre.oval:tst:10209"/>
        </criteria>
        <criteria operator="AND" comment="IBM AIX 5300-00 through 5300-05 always meets CVE-2007-1798">
          <extend_definition comment="IBM AIX 5300-00 through 5300-05 is installed" definition_ref="oval:org.mitre.oval:def:6123"/>
        </criteria>
        <criteria operator="AND" comment="IBM AIX 5300-06 meets CVE-2007-1798">
          <extend_definition comment="IBM AIX 5300-06 is installed" definition_ref="oval:org.mitre.oval:def:4813"/>
          <criterion negate="true" comment="All filesets for APAR IY96753 are installed" test_ref="oval:org.mitre.oval:tst:10265"/>
        </criteria>
        <criteria operator="AND" comment="IBM AIX 5300-07 meets CVE-2007-1798">
          <extend_definition comment="IBM AIX 5300-07 is installed" definition_ref="oval:org.mitre.oval:def:5707"/>
          <criterion negate="true" comment="All filesets for APAR IY95054 are installed" test_ref="oval:org.mitre.oval:tst:10048"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6276" version="1" class="vulnerability">
      <metadata>
        <title>Malloc subsystem in libc in IBM AIX 5.3 and 6.1 vulnerability.</title>
        <affected family="unix">
          <platform>IBM AIX 5.3</platform>
          <platform>IBM AIX 6.1</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-1786" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1786"/>
        <description>The malloc subsystem in libc in IBM AIX 5.3 and 6.1 allows local users to create or overwrite arbitrary files via a symlink attack on the log file associated with the MALLOCDEBUG environment variable.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-07-18T15:10:44.000-05:00">
              <contributor organization="DTCC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2009-07-20T22:24:02.312-04:00">DRAFT</status_change>
            <status_change date="2009-08-10T04:00:07.163-04:00">INTERIM</status_change>
            <status_change date="2009-08-31T04:00:09.685-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="IBM AIX 5300-00 meets CVE-2009-1786">
          <extend_definition comment="IBM AIX 5300-00 is installed" definition_ref="oval:org.mitre.oval:def:6195"/>
          <criterion comment="The level of fileset bos.rte.libc is greater than or equal 5.3.0.0" test_ref="oval:org.mitre.oval:tst:9865"/>
          <criterion comment="The level of fileset bos.rte.libc is less than or equal 5.3.0.71" test_ref="oval:org.mitre.oval:tst:10347"/>
          <criterion comment="The level of fileset bos.adt.prof is greater than or equal 5.3.0.0" test_ref="oval:org.mitre.oval:tst:10232"/>
          <criterion comment="The level of fileset bos.adt.prof is less than or equal 5.3.0.71" test_ref="oval:org.mitre.oval:tst:10072"/>
          <criterion negate="true" comment="All filesets for APAR IZ50500 are installed" test_ref="oval:org.mitre.oval:tst:10208"/>
        </criteria>
        <criteria operator="AND" comment="IBM AIX 5300-01 through 5300-06 always meets CVE-2009-1786">
          <extend_definition comment="IBM AIX 5300-01 through 5300-06 is installed" definition_ref="oval:org.mitre.oval:def:5973"/>
          <criterion comment="Fileset bos.rte.libc is installed" test_ref="oval:org.mitre.oval:tst:10148"/>
          <criterion comment="Fileset bos.adt.prof is installed" test_ref="oval:org.mitre.oval:tst:9915"/>
        </criteria>
        <criteria operator="AND" comment="IBM AIX 5300-07 meets CVE-2009-1786">
          <extend_definition comment="IBM AIX 5300-07 is installed" definition_ref="oval:org.mitre.oval:def:5707"/>
          <criterion comment="The level of fileset bos.rte.libc is greater than or equal 5.3.7.0" test_ref="oval:org.mitre.oval:tst:10091"/>
          <criterion comment="The level of fileset bos.rte.libc is less than or equal 5.3.7.8" test_ref="oval:org.mitre.oval:tst:9830"/>
          <criterion comment="The level of fileset bos.adt.prof is greater than or equal 5.3.7.0" test_ref="oval:org.mitre.oval:tst:10412"/>
          <criterion comment="The level of fileset bos.adt.prof is less than or equal 5.3.7.8" test_ref="oval:org.mitre.oval:tst:10386"/>
          <criterion negate="true" comment="All filesets for APAR IZ50517 are installed" test_ref="oval:org.mitre.oval:tst:10103"/>
        </criteria>
        <criteria operator="AND" comment="IBM AIX 5300-08 meets CVE-2009-1786">
          <extend_definition comment="IBM AIX 5300-08 is installed" definition_ref="oval:org.mitre.oval:def:5293"/>
          <criterion comment="The level of fileset bos.rte.libc is greater than or equal 5.3.8.0" test_ref="oval:org.mitre.oval:tst:10088"/>
          <criterion comment="The level of fileset bos.rte.libc is less than or equal 5.3.8.5" test_ref="oval:org.mitre.oval:tst:10404"/>
          <criterion comment="The level of fileset bos.adt.prof is greater than or equal 5.3.8.0" test_ref="oval:org.mitre.oval:tst:10108"/>
          <criterion comment="The level of fileset bos.adt.prof is less than or equal 5.3.8.5" test_ref="oval:org.mitre.oval:tst:9768"/>
          <criterion negate="true" comment="All filesets for APAR IZ50447 are installed" test_ref="oval:org.mitre.oval:tst:10205"/>
        </criteria>
        <criteria operator="AND" comment="IBM AIX 5300-09 meets CVE-2009-1786">
          <extend_definition comment="IBM AIX 5300-09 is installed" definition_ref="oval:org.mitre.oval:def:6306"/>
          <criterion comment="The level of fileset bos.rte.libc is greater than or equal 5.3.9.0" test_ref="oval:org.mitre.oval:tst:9956"/>
          <criterion comment="The level of fileset bos.rte.libc is less than or equal 5.3.9.2" test_ref="oval:org.mitre.oval:tst:9470"/>
          <criterion comment="The level of fileset bos.adt.prof is greater than or equal 5.3.9.0" test_ref="oval:org.mitre.oval:tst:10233"/>
          <criterion comment="The level of fileset bos.adt.prof is less than or equal 5.3.9.2" test_ref="oval:org.mitre.oval:tst:10394"/>
          <criterion negate="true" comment="All filesets for APAR IZ50445 are installed" test_ref="oval:org.mitre.oval:tst:10321"/>
        </criteria>
        <criteria operator="AND" comment="IBM AIX 6100-00 meets CVE-2009-1786">
          <extend_definition comment="IBM AIX 6100-00 is installed" definition_ref="oval:org.mitre.oval:def:5589"/>
          <criterion comment="The level of fileset bos.rte.libc is greater than or equal 6.1.0.0" test_ref="oval:org.mitre.oval:tst:10156"/>
          <criterion comment="The level of fileset bos.rte.libc is less than or equal 6.1.0.9" test_ref="oval:org.mitre.oval:tst:9908"/>
          <criterion comment="The level of fileset bos.adt.prof is greater than or equal 6.1.0.0" test_ref="oval:org.mitre.oval:tst:10298"/>
          <criterion comment="The level of fileset bos.adt.prof is less than or equal 6.1.0.9" test_ref="oval:org.mitre.oval:tst:10426"/>
          <criterion negate="true" comment="All filesets for APAR IZ50139 are installed" test_ref="oval:org.mitre.oval:tst:10384"/>
        </criteria>
        <criteria operator="AND" comment="IBM AIX 6100-01 meets CVE-2009-1786">
          <extend_definition comment="IBM AIX 6100-01 is installed" definition_ref="oval:org.mitre.oval:def:5959"/>
          <criterion comment="The level of fileset bos.rte.libc is greater than or equal 6.1.1.0" test_ref="oval:org.mitre.oval:tst:9918"/>
          <criterion comment="The level of fileset bos.rte.libc is less than or equal 6.1.1.4" test_ref="oval:org.mitre.oval:tst:9935"/>
          <criterion comment="The level of fileset bos.adt.prof is greater than or equal 6.1.1.0" test_ref="oval:org.mitre.oval:tst:9872"/>
          <criterion comment="The level of fileset bos.adt.prof is less than or equal 6.1.1.4" test_ref="oval:org.mitre.oval:tst:10117"/>
          <criterion negate="true" comment="All filesets for APAR IZ50129 are installed" test_ref="oval:org.mitre.oval:tst:10403"/>
        </criteria>
        <criteria operator="AND" comment="IBM AIX 6100-02 meets CVE-2009-1786">
          <extend_definition comment="IBM AIX 6100-02 is installed" definition_ref="oval:org.mitre.oval:def:5685"/>
          <criterion comment="The level of fileset bos.rte.libc is greater than or equal 6.1.2.0" test_ref="oval:org.mitre.oval:tst:10419"/>
          <criterion comment="The level of fileset bos.rte.libc is less than or equal 6.1.2.3" test_ref="oval:org.mitre.oval:tst:10335"/>
          <criterion comment="The level of fileset bos.adt.prof is greater than or equal 6.1.2.0" test_ref="oval:org.mitre.oval:tst:10105"/>
          <criterion comment="The level of fileset bos.adt.prof is less than or equal 6.1.2.3" test_ref="oval:org.mitre.oval:tst:10322"/>
          <criterion negate="true" comment="All filesets for APAR IZ50121 are installed" test_ref="oval:org.mitre.oval:tst:10343"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6195" version="1" class="inventory">
      <metadata>
        <title>IBM AIX 5300-00 is installed</title>
        <affected family="unix">
          <platform>IBM AIX 5.3</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/o:ibm:aix:5.3"/>
        <description>The operating system installed on the system is IBM AIX version 5300-00.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-07-20T12:00:00.000-04:00">
              <contributor organization="DTCC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2009-07-20T22:24:00.441-04:00">DRAFT</status_change>
            <status_change date="2009-08-17T04:00:03.501-04:00">INTERIM</status_change>
            <status_change date="2009-09-07T04:00:12.484-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="Version of IBM AIX installed is 5300-00" test_ref="oval:org.mitre.oval:tst:10391"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5973" version="1" class="inventory">
      <metadata>
        <title>IBM AIX 5300-01 through 5300-06 is installed</title>
        <affected family="unix">
          <platform>IBM AIX 5.3</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/o:ibm:aix:5.3"/>
        <description>The operating system installed on the system is IBM AIX version 5300-01 through 5300-06.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-07-20T12:00:00.000-04:00">
              <contributor organization="DTCC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2009-07-20T22:24:00.911-04:00">DRAFT</status_change>
            <status_change date="2009-08-17T04:00:02.775-04:00">INTERIM</status_change>
            <status_change date="2009-09-07T04:00:10.298-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="IBM AIX version is greater than or equal 5300-01" test_ref="oval:org.mitre.oval:tst:9727"/>
        <criterion comment="IBM AIX version is less than or equal 5300-06" test_ref="oval:org.mitre.oval:tst:10071"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5616" version="2" class="vulnerability">
      <metadata>
        <title>AIX pioout buffer overflow</title>
        <affected family="unix">
          <platform>IBM AIX 5.2</platform>
          <platform>IBM AIX 5.3</platform>
          <platform>IBM AIX 6.1</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-5764" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5764"/>
        <description>Buffer overflow in the pioout program in printers.rte in IBM AIX 5.2, 5.3, and 6.1 allows local users to gain privileges via a long command line option.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-04-18T15:10:44.000-05:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2008-07-08T13:06:06.549-04:00">DRAFT</status_change>
            <status_change date="2008-07-28T04:00:17.548-04:00">INTERIM</status_change>
            <status_change date="2008-08-18T04:00:43.597-04:00">ACCEPTED</status_change>
            <modified comment="Added more versions, more fixes, and a configuration section." date="2009-07-30T17:17:00.261-04:00">
              <contributor organization="DTCC">Aharon Chernin</contributor>
            </modified>
            <status_change date="2009-08-03T04:00:06.917-04:00">INTERIM</status_change>
            <status_change date="2009-08-24T04:00:05.202-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="Software Section">
          <criteria operator="AND" comment="IBM AIX 5200-10 meets CVE-2007-5764">
            <extend_definition comment="IBM AIX 5200-10 is installed" definition_ref="oval:org.mitre.oval:def:5076"/>
            <criterion negate="true" comment="All filesets for APAR IZ10840 are installed" test_ref="oval:org.mitre.oval:tst:8298"/>
            <criterion comment="Fileset printers.rte is installed" test_ref="oval:org.mitre.oval:tst:10395"/>
          </criteria>
          <criteria operator="AND" comment="IBM AIX 5300-00 through 5300-05 always meets CVE-2007-5764">
            <extend_definition comment="IBM AIX 5300-00 through 5300-05 is installed" definition_ref="oval:org.mitre.oval:def:6123"/>
            <criterion comment="Fileset printers.rte is installed" test_ref="oval:org.mitre.oval:tst:10395"/>
          </criteria>
          <criteria operator="AND" comment="IBM AIX 5300-06 meets CVE-2007-5764">
            <extend_definition comment="IBM AIX 5300-06 is installed" definition_ref="oval:org.mitre.oval:def:4813"/>
            <criterion negate="true" comment="All filesets for APAR IZ10841 are installed" test_ref="oval:org.mitre.oval:tst:8425"/>
            <criterion comment="Fileset printers.rte is installed" test_ref="oval:org.mitre.oval:tst:10395"/>
          </criteria>
          <criteria operator="AND" comment="IBM AIX 5300-07 meets CVE-2007-5764">
            <extend_definition comment="IBM AIX 5300-07 is installed" definition_ref="oval:org.mitre.oval:def:5707"/>
            <criterion negate="true" comment="All filesets for APAR IZ10842 are installed" test_ref="oval:org.mitre.oval:tst:8183"/>
            <criterion comment="Fileset printers.rte is installed" test_ref="oval:org.mitre.oval:tst:10395"/>
          </criteria>
          <criteria operator="AND" comment="IBM AIX 5300-08 meets CVE-2007-5764">
            <extend_definition comment="IBM AIX 5300-08 is installed" definition_ref="oval:org.mitre.oval:def:5293"/>
            <criterion negate="true" comment="All filesets for APAR IZ10843 are installed" test_ref="oval:org.mitre.oval:tst:8415"/>
            <criterion comment="Fileset printers.rte is installed" test_ref="oval:org.mitre.oval:tst:10395"/>
          </criteria>
          <criteria operator="AND" comment="IBM AIX 5300-09 meets CVE-2007-5764">
            <extend_definition comment="IBM AIX 5300-09 is installed" definition_ref="oval:org.mitre.oval:def:6306"/>
            <criterion negate="true" comment="All filesets for APAR IZ11328 are installed" test_ref="oval:org.mitre.oval:tst:10453"/>
            <criterion comment="Fileset printers.rte is installed" test_ref="oval:org.mitre.oval:tst:10395"/>
          </criteria>
          <criteria operator="AND" comment="IBM AIX 6100-00 meets CVE-2007-5764">
            <extend_definition comment="IBM AIX 6100-00 is installed" definition_ref="oval:org.mitre.oval:def:5589"/>
            <criterion negate="true" comment="All filesets for APAR IZ10844 are installed" test_ref="oval:org.mitre.oval:tst:8429"/>
            <criterion comment="Fileset printers.rte is installed" test_ref="oval:org.mitre.oval:tst:10395"/>
          </criteria>
          <criteria operator="AND" comment="IBM AIX 6100-01 meets CVE-2007-5764">
            <extend_definition comment="IBM AIX 6100-01 is installed" definition_ref="oval:org.mitre.oval:def:5959"/>
            <criterion negate="true" comment="All filesets for APAR IZ11214 are installed" test_ref="oval:org.mitre.oval:tst:10197"/>
            <criterion comment="Fileset printers.rte is installed" test_ref="oval:org.mitre.oval:tst:10395"/>
          </criteria>
          <criteria operator="AND" comment="IBM AIX 6100-02 meets CVE-2007-5764">
            <extend_definition comment="IBM AIX 6100-02 is installed" definition_ref="oval:org.mitre.oval:def:5685"/>
            <criterion negate="true" comment="All filesets for APAR IZ11687 are installed" test_ref="oval:org.mitre.oval:tst:10418"/>
            <criterion comment="Fileset printers.rte is installed" test_ref="oval:org.mitre.oval:tst:10395"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Configuration section">
          <criterion comment="/usr/lib/lpd/pio/etc/pioout is setuid" test_ref="oval:org.mitre.oval:tst:10452"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6306" version="1" class="inventory">
      <metadata>
        <title>IBM AIX 5300-09 is installed</title>
        <affected family="unix">
          <platform>IBM AIX 5.3</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/o:ibm:aix:5.3"/>
        <description>The operating system installed on the system is IBM AIX version 5300-09.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-07-20T12:00:00.000-04:00">
              <contributor organization="DTCC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2009-07-20T22:24:01.613-04:00">DRAFT</status_change>
            <status_change date="2009-08-17T04:00:03.981-04:00">INTERIM</status_change>
            <status_change date="2009-09-07T04:00:16.981-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="Version of IBM AIX installed is 5300-09" test_ref="oval:org.mitre.oval:tst:10388"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6123" version="1" class="inventory">
      <metadata>
        <title>IBM AIX 5300-00 through 5300-05 is installed</title>
        <affected family="unix">
          <platform>IBM AIX 5.3</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/o:ibm:aix:5.3"/>
        <description>The operating system installed on the system is IBM AIX version 5300-00 through 5300-05.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-07-27T12:00:00.000-04:00">
              <contributor organization="DTCC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2009-07-30T17:45:33.847-04:00">DRAFT</status_change>
            <status_change date="2009-08-17T04:00:02.955-04:00">INTERIM</status_change>
            <status_change date="2009-09-07T04:00:10.924-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="IBM AIX version is greater than or equal 5.3.0.0" test_ref="oval:org.mitre.oval:tst:7973"/>
        <criterion comment="IBM AIX version is less than or equal 5300-5" test_ref="oval:org.mitre.oval:tst:10062"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5959" version="1" class="inventory">
      <metadata>
        <title>IBM AIX 6100-01 is installed</title>
        <affected family="unix">
          <platform>IBM AIX 6.1</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/o:ibm:aix:6.1"/>
        <description>The operating system installed on the system is IBM AIX version 6100-01.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-07-20T12:00:00.000-04:00">
              <contributor organization="DTCC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2009-07-20T22:24:02.045-04:00">DRAFT</status_change>
            <modified comment="changed the operation from less than or equal to equals." date="2009-07-30T17:17:00.992-04:00">
              <contributor organization="DTCC">Aharon Chernin</contributor>
            </modified>
            <status_change date="2009-08-24T04:00:06.749-04:00">INTERIM</status_change>
            <status_change date="2009-09-14T04:00:06.624-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="Version of IBM AIX installed is 6100-01" test_ref="oval:org.mitre.oval:tst:9809"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5685" version="1" class="inventory">
      <metadata>
        <title>IBM AIX 6100-02 is installed</title>
        <affected family="unix">
          <platform>IBM AIX 6.1</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/o:ibm:aix:6.1"/>
        <description>The operating system installed on the system is IBM AIX version 6100-02.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-07-20T12:00:00.000-04:00">
              <contributor organization="DTCC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2009-07-20T22:24:02.200-04:00">DRAFT</status_change>
            <modified comment="changed the operation from less than or equal to equals." date="2009-07-30T17:17:00.261-04:00">
              <contributor organization="DTCC">Aharon Chernin</contributor>
            </modified>
            <status_change date="2009-08-17T04:00:02.415-04:00">INTERIM</status_change>
            <status_change date="2009-09-07T04:00:05.088-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="Version of IBM AIX installed is 6100-02" test_ref="oval:org.mitre.oval:tst:10023"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6331" version="1" class="vulnerability">
      <metadata>
        <title>A Security Vulnerability in the Solaris rpc.nisd(1M) Daemon may Cause a Denial of Service (DoS) Condition to a NIS+ Server</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <platform>Sun Solaris 9</platform>
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-2029" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2029"/>
        <description>Unspecified vulnerability in rpc.nisd in Sun Solaris 8 through 10, and OpenSolaris before snv_104, allows remote authenticated users to cause a denial of service (NIS+ daemon hang) via unspecified vectors related to NIS+ callbacks.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-06-23T12:21:57.000-04:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2009-06-30T10:48:13.719-04:00">DRAFT</status_change>
            <status_change date="2009-07-20T04:00:44.613-04:00">INTERIM</status_change>
            <status_change date="2009-08-10T04:00:08.560-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Solaris 8 and 9">
          <criteria operator="OR" comment="Solaris 8 and 9 software section">
            <criteria operator="AND" comment="Solaris 8 (SPARC) meets Sun Alert 256748">
              <extend_definition comment="Solaris 8 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1539"/>
              <criterion negate="true" comment="Patch 128624-09 or later installed" test_ref="oval:org.mitre.oval:tst:9596"/>
            </criteria>
            <criteria operator="AND" comment="Solaris 9 (SPARC) meets Sun Alert 256748">
              <extend_definition comment="Solaris 9 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1457"/>
              <criterion negate="true" comment="Patch 112960-65 or later installed" test_ref="oval:org.mitre.oval:tst:9856"/>
            </criteria>
            <criteria operator="AND" comment="Solaris 8 (x86) meets Sun Alert 256748">
              <extend_definition comment="Solaris 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:2059"/>
              <criterion negate="true" comment="Patch 128625-09 or later installed" test_ref="oval:org.mitre.oval:tst:10082"/>
            </criteria>
            <criteria operator="AND" comment="Solaris 9 (x86) meets Sun Alert 256748">
              <extend_definition comment="Solaris 9 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1683"/>
              <criterion negate="true" comment="Patch 114242-50 or later installed" test_ref="oval:org.mitre.oval:tst:9784"/>
            </criteria>
          </criteria>
          <criterion comment="rpc.nisd service is running" test_ref="oval:org.mitre.oval:tst:10097"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10">
          <criteria operator="OR" comment="Solaris 10 software section">
            <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 256748">
              <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
              <criterion negate="true" comment="Patch 140917-01 or later installed" test_ref="oval:org.mitre.oval:tst:10226"/>
            </criteria>
            <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 256748">
              <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
              <criterion negate="true" comment="Patch 140918-01 or later installed" test_ref="oval:org.mitre.oval:tst:10054"/>
            </criteria>
          </criteria>
          <criterion comment="rpc.nisd service is running" test_ref="oval:org.mitre.oval:tst:10027"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5906" version="1" class="vulnerability">
      <metadata>
        <title>Two Race Condition Vulnerabilities in the Solaris Event Port API May Allow Local Users to Panic the System, Causing a Denial of Service (DoS)</title>
        <affected family="unix">
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-2135" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2135"/>
        <description>Multiple race conditions in the Solaris Event Port API in Sun Solaris 10 and OpenSolaris before snv_107 allow local users to cause a denial of service (panic) via unspecified vectors related to a race between the port_dissociate and close functions.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-06-23T12:21:57.000-04:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2009-06-30T10:48:14.002-04:00">DRAFT</status_change>
            <status_change date="2009-07-20T04:00:39.553-04:00">INTERIM</status_change>
            <status_change date="2009-08-10T04:00:05.339-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 260449">
          <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
          <criterion negate="true" comment="Patch 141414-01 or later installed" test_ref="oval:org.mitre.oval:tst:9911"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 260449">
          <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
          <criterion negate="true" comment="Patch 141415-01 or later installed" test_ref="oval:org.mitre.oval:tst:9619"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1252" version="2" class="vulnerability">
      <metadata>
        <title>Format string vulnerability in Sun Java Web Console</title>
        <affected family="unix">
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-1681" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1681"/>
        <description>Format string vulnerability in libwebconsole_services.so in Sun Java Web Console 2.2.2 through 2.2.5 allows remote attackers to cause a denial of service (application crash), obtain sensitive information, and possibly execute arbitrary code via unspecified vectors during a failed login attempt, related to syslog.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-06-15T09:00:00.000-04:00">
              <contributor organization="Opsware, Inc.">Pai Peng</contributor>
            </submitted>
            <status_change date="2007-06-15T11:20:00.000-04:00">DRAFT</status_change>
            <status_change date="2007-07-03T14:05:54.056-04:00">INTERIM</status_change>
            <status_change date="2007-07-18T15:57:48.718-04:00">ACCEPTED</status_change>
            <modified comment="Add criteria to check for affected version of Sun Java Web Console" date="2009-07-20T21:58:00.890-04:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </modified>
            <status_change date="2009-07-21T07:46:12.813-04:00">INTERIM</status_change>
            <status_change date="2009-08-10T04:00:02.535-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Sun Alert 201387 for Solaris 10 (SPARC)">
          <criterion comment="Solaris 10 Installed" test_ref="oval:org.mitre.oval:tst:3680"/>
          <criterion comment="sparc architecture" test_ref="oval:org.mitre.oval:tst:3237"/>
          <criterion negate="true" comment="Patch 121211-02 or later installed" test_ref="oval:org.mitre.oval:tst:3537"/>
          <criterion comment="Sun Java Web Console version is 2.2.2, 2.2.3, 2.2.4 or 2.2.5" test_ref="oval:org.mitre.oval:tst:10318"/>
        </criteria>
        <criteria operator="AND" comment="Sun Alert 201387 for Solaris 10 (x86)">
          <criterion comment="Solaris 10 Installed" test_ref="oval:org.mitre.oval:tst:3680"/>
          <criterion comment="ix86 architecture" test_ref="oval:org.mitre.oval:tst:3912"/>
          <criterion negate="true" comment="Patch 121212-02 or later installed" test_ref="oval:org.mitre.oval:tst:3315"/>
          <criterion comment="Sun Java Web Console version is 2.2.2, 2.2.3, 2.2.4 or 2.2.5" test_ref="oval:org.mitre.oval:tst:10318"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:881" version="2" class="vulnerability">
      <metadata>
        <title>Bourne Shell Local-DoS Vulnerability</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <platform>Sun Solaris 9</platform>
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-1780" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1780"/>
        <description>The Bourne shell (sh) in Solaris 8, 9, and 10 allows local users to cause a denial of service (sh crash) via an unspecified attack vector that causes sh processes to crash during creation of temporary files.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-04-14T06:41:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-04-19T10:08:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-05-10T08:33:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-05-31T09:45:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Changed criterion to check for the patch or later being installed instead of simply checking if the patch is installed." date="2009-07-17T11:04:00.601-04:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </modified>
            <status_change date="2009-07-17T11:07:21.610-04:00">INTERIM</status_change>
            <status_change date="2009-08-03T04:00:04.542-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Solaris 8 (SPARC) meets Sun Alert ID 102282 criteria.">
          <criterion comment="Solaris 8 Installed" test_ref="oval:org.mitre.oval:tst:3145"/>
          <criterion comment="sparc architecture" test_ref="oval:org.mitre.oval:tst:2465"/>
          <criterion comment="Patch 109324-09 or later is installed" negate="true" test_ref="oval:org.mitre.oval:tst:1520"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (SPARC) meets Sun Alert ID 102282 criteria.">
          <criterion comment="Solaris 9 Installed" test_ref="oval:org.mitre.oval:tst:3051"/>
          <criterion comment="sparc architecture" test_ref="oval:org.mitre.oval:tst:2465"/>
          <criterion comment="Patch 118535-03 or later is installed" negate="true" test_ref="oval:org.mitre.oval:tst:1519"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert ID 102282 criteria.">
          <criterion comment="Solaris 10 Installed" test_ref="oval:org.mitre.oval:tst:2459"/>
          <criterion comment="sparc architecture" test_ref="oval:org.mitre.oval:tst:2465"/>
          <criterion comment="Patch 121004-01 or later is installed" negate="true" test_ref="oval:org.mitre.oval:tst:1518"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 8 (x86) meets Sun Alert ID 102282 criteria.">
          <criterion comment="Solaris 8 Installed" test_ref="oval:org.mitre.oval:tst:3145"/>
          <criterion comment="ix86 architecture" test_ref="oval:org.mitre.oval:tst:2463"/>
          <criterion comment="Patch 109325-09 or later is installed" negate="true" test_ref="oval:org.mitre.oval:tst:1517"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (x86) meets Sun Alert ID 102282 criteria.">
          <criterion comment="Solaris 9 Installed" test_ref="oval:org.mitre.oval:tst:3051"/>
          <criterion comment="ix86 architecture" test_ref="oval:org.mitre.oval:tst:2463"/>
          <criterion comment="Patch 118536-03 or later is installed" negate="true" test_ref="oval:org.mitre.oval:tst:1516"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert ID 102282 criteria.">
          <criterion comment="Solaris 10 Installed" test_ref="oval:org.mitre.oval:tst:2459"/>
          <criterion comment="ix86 architecture" test_ref="oval:org.mitre.oval:tst:2463"/>
          <criterion comment="Patch 121005-01 or later is installed" negate="true" test_ref="oval:org.mitre.oval:tst:1515"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:765" version="3" class="vulnerability">
      <metadata>
        <title>GNU GZip CHMod File Permission Modification Race ConditionWeakness</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <platform>Sun Solaris 9</platform>
          <platform>Sun Solaris 10</platform>
          <product>gzip</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0988" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0988"/>
        <description>Race condition in gzip 1.2.4, 1.3.3, and earlier, when decompressing a gzipped file, allows local users to modify permissions of arbitrary files via a hard link attack on a file while it is being decompressed, whose permissions are changed by gzip after the decompression is complete.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-09-22T05:52:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-09-22T20:15:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-07T09:15:53.441-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:16:00.590-04:00">ACCEPTED</status_change>
            <modified comment="Added title. Implemented by Jon Baker of The MITRE Corporation." date="2007-02-13T14:47:00.641-05:00">
              <contributor organization="Security-Database">Nabil Ouchn</contributor>
            </modified>
            <status_change date="2007-02-13T14:48:04.662-05:00">INTERIM</status_change>
            <status_change date="2007-03-21T16:17:27.180-04:00">ACCEPTED</status_change>
            <modified comment="Corrected sparc criterion that was intended to be x86." date="2009-07-17T11:09:00.290-04:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </modified>
            <status_change date="2009-07-17T11:19:33.298-04:00">INTERIM</status_change>
            <status_change date="2009-08-03T04:00:04.095-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Solaris 8 (SPARC) meets Sun Alert ID 101816 criteria.">
          <criterion comment="Solaris 8 Installed" test_ref="oval:org.mitre.oval:tst:3437"/>
          <criterion comment="sparc architecture" test_ref="oval:org.mitre.oval:tst:3237"/>
          <criterion comment="Patch 112668-03 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:4005"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 8 (x86) meets Sun Alert ID 101816 criteria.">
          <criterion comment="Solaris 8 Installed" test_ref="oval:org.mitre.oval:tst:3437"/>
          <criterion comment="ix86 architecture" test_ref="oval:org.mitre.oval:tst:3912"/>
          <criterion comment="Patch 112669-03 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:4070"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (SPARC) meets Sun Alert ID 101816 criteria.">
          <criterion comment="Solaris 9 Installed" test_ref="oval:org.mitre.oval:tst:3172"/>
          <criterion comment="sparc architecture" test_ref="oval:org.mitre.oval:tst:3237"/>
          <criterion comment="Patch 116340-04 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:3666"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (x86) meets Sun Alert ID 101816 criteria.">
          <criterion comment="Solaris 9 Installed" test_ref="oval:org.mitre.oval:tst:3172"/>
          <criterion comment="ix86 architecture" test_ref="oval:org.mitre.oval:tst:3912"/>
          <criterion comment="Patch 116341-04 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:3778"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert ID 101816 criteria.">
          <criterion comment="Solaris 10 Installed" test_ref="oval:org.mitre.oval:tst:3680"/>
          <criterion comment="sparc architecture" test_ref="oval:org.mitre.oval:tst:3237"/>
          <criterion comment="Patch 120719-01 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:3295"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert ID 101816 criteria.">
          <criterion comment="Solaris 10 Installed" test_ref="oval:org.mitre.oval:tst:3680"/>
          <criterion comment="ix86 architecture" test_ref="oval:org.mitre.oval:tst:3912"/>
          <criterion comment="Patch 120720-01 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:3621"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:3270" version="2" class="vulnerability">
      <metadata>
        <title>Security Vulnerability in the Solaris 10 Internet Protocol (ip(7P)) may Lead to a Denial of Service (DoS) Condition</title>
        <affected family="unix">
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-5716" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5716"/>
        <description>Unspecified vulnerability in the Internet Protocol (IP) functionality in Sun Solaris 10 allows local users to cause a denial of service (panic) via unspecified vectors, probably related to a UDP packet.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-11-05T11:19:05.000-05:00">
              <contributor organization="Opsware, Inc.">Pai Peng</contributor>
            </submitted>
            <status_change date="2007-11-06T13:03:43.139-05:00">DRAFT</status_change>
            <status_change date="2007-11-26T04:00:04.347-05:00">INTERIM</status_change>
            <status_change date="2007-12-17T04:00:05.181-05:00">ACCEPTED</status_change>
            <modified comment="Changed criterion to check for the patch or later being installed instead of simply checking if the patch is installed." date="2009-07-17T11:04:00.761-04:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </modified>
            <status_change date="2009-07-17T11:09:04.768-04:00">INTERIM</status_change>
            <status_change date="2009-08-03T04:00:03.743-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 103087">
          <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
          <criterion comment="Patch 118833-04 or later installed" test_ref="oval:org.mitre.oval:tst:5394"/>
          <criterion negate="true" comment="Patch 127111-02 or later installed" test_ref="oval:org.mitre.oval:tst:5429"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 103087">
          <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
          <criterion comment="Patch 118855-03 or later installed" test_ref="oval:org.mitre.oval:tst:5577"/>
          <criterion negate="true" comment="Patch 127112-02 or later installed" test_ref="oval:org.mitre.oval:tst:5048"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:170" version="3" class="vulnerability">
      <metadata>
        <title>Sun Solaris Gzip Race condition and Directory Traversal Issues</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <platform>Sun Solaris 9</platform>
          <platform>Sun Solaris 10</platform>
          <product>gzip</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1228" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1228"/>
        <description>Directory traversal vulnerability in gunzip -N in gzip 1.2.4 through 1.3.5 allows remote attackers to write to arbitrary directories via a .. (dot dot) in the original filename within a compressed file.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-09-22T05:52:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-09-22T20:15:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-07T09:15:27.272-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:15:16.282-04:00">ACCEPTED</status_change>
            <modified comment="Added title. Implemented by Jon Baker of The MITRE Corporation." date="2007-02-13T14:05:00.064-05:00">
              <contributor organization="Security-Database">Nabil Ouchn</contributor>
            </modified>
            <status_change date="2007-02-13T14:07:07.091-05:00">INTERIM</status_change>
            <status_change date="2007-03-21T16:17:00.447-04:00">ACCEPTED</status_change>
            <modified comment="Corrected sparc criterion that was intended to be x86." date="2009-07-17T11:09:00.287-04:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </modified>
            <status_change date="2009-07-17T11:27:44.296-04:00">INTERIM</status_change>
            <status_change date="2009-08-03T04:00:02.600-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Solaris 8 (SPARC) meets Sun Alert ID 101816 criteria.">
          <criterion comment="Solaris 8 Installed" test_ref="oval:org.mitre.oval:tst:3437"/>
          <criterion comment="sparc architecture" test_ref="oval:org.mitre.oval:tst:3237"/>
          <criterion comment="Patch 112668-03 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:4005"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 8 (x86) meets Sun Alert ID 101816 criteria.">
          <criterion comment="Solaris 8 Installed" test_ref="oval:org.mitre.oval:tst:3437"/>
          <criterion comment="ix86 architecture" test_ref="oval:org.mitre.oval:tst:3912"/>
          <criterion comment="Patch 112669-03 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:4070"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (SPARC) meets Sun Alert ID 101816 criteria.">
          <criterion comment="Solaris 9 Installed" test_ref="oval:org.mitre.oval:tst:3172"/>
          <criterion comment="sparc architecture" test_ref="oval:org.mitre.oval:tst:3237"/>
          <criterion comment="Patch 116340-04 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:3666"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (x86) meets Sun Alert ID 101816 criteria.">
          <criterion comment="Solaris 9 Installed" test_ref="oval:org.mitre.oval:tst:3172"/>
          <criterion comment="ix86 architecture" test_ref="oval:org.mitre.oval:tst:3912"/>
          <criterion comment="Patch 116341-04 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:3778"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert ID 101816 criteria.">
          <criterion comment="Solaris 10 Installed" test_ref="oval:org.mitre.oval:tst:3680"/>
          <criterion comment="sparc architecture" test_ref="oval:org.mitre.oval:tst:3237"/>
          <criterion comment="Patch 120719-01 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:3295"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert ID 101816 criteria.">
          <criterion comment="Solaris 10 Installed" test_ref="oval:org.mitre.oval:tst:3680"/>
          <criterion comment="ix86 architecture" test_ref="oval:org.mitre.oval:tst:3912"/>
          <criterion comment="Patch 120720-01 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:3621"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1707" version="2" class="vulnerability">
      <metadata>
        <title>Enterprise Storage Manager 2.1 SAN Manager management station patch</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <platform>Sun Solaris 9</platform>
          <product>Sun Enterprise Storage Manager (ESM)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-1345" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1345"/>
        <description>Unknown vulnerability in Sun StorEdge Enterprise Storage Manager (ESM) 2.1 for Solaris 8 and Solaris 9 allows local users with the "ESMUser" role to gain root access.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-01-19T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Brian Soby</contributor>
            </submitted>
            <status_change date="2005-01-24T03:40:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-02-16T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-03-09T07:56:00.000-04:00">ACCEPTED</status_change>
            <modified date="2009-06-15T12:00:00.000-04:00" comment="Added CVE Reference. Added solaris 9 as an affected platform.">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2009-06-22T04:00:51.071-04:00">INTERIM</status_change>
            <status_change date="2009-07-13T04:00:30.181-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Solaris 8 or 9 installed">
          <criterion comment="Solaris 8 Installed" test_ref="oval:org.mitre.oval:tst:3145"/>
          <criterion comment="Solaris 9 Installed" test_ref="oval:org.mitre.oval:tst:3051"/>
        </criteria>
        <criterion comment="Sun Enterprise Storage Manager installed" test_ref="oval:org.mitre.oval:tst:762"/>
        <criterion negate="true" comment="Patch 117367-01 or later installed" test_ref="oval:org.mitre.oval:tst:761"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5347" version="1" class="vulnerability">
      <metadata>
        <title>Heap-based Buffer Overflow Vulnerability in the Solaris 8 and 9 sadmind(1M) Daemon May Lead to Arbitrary Code Execution</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <platform>Sun Solaris 9</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-3869" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-3869"/>
        <description>Heap-based buffer overflow in sadmind in Sun Solaris 8 and 9 allows remote attackers to execute arbitrary code via a crafted RPC request, related to improper decoding of request parameters.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-05-28T13:34:47.000-04:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2009-06-05T14:12:44.460-04:00">DRAFT</status_change>
            <status_change date="2009-06-22T04:00:19.512-04:00">INTERIM</status_change>
            <status_change date="2009-07-13T04:00:31.941-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="Software Section">
          <criteria operator="AND" comment="Solaris 8 (SPARC) meets Sun Alert 259468">
            <extend_definition comment="Solaris 8 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1539"/>
            <criterion negate="true" comment="Patch 116455-02 or later installed" test_ref="oval:org.mitre.oval:tst:9833"/>
          </criteria>
          <criteria operator="AND" comment="Solaris 9 (SPARC) meets Sun Alert 259468">
            <extend_definition comment="Solaris 9 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1457"/>
            <criterion negate="true" comment="Patch 116453-03 or later installed" test_ref="oval:org.mitre.oval:tst:9695"/>
          </criteria>
          <criteria operator="AND" comment="Solaris 8 (x86) meets Sun Alert 259468">
            <extend_definition comment="Solaris 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:2059"/>
            <criterion negate="true" comment="Patch 116442-02 or later installed" test_ref="oval:org.mitre.oval:tst:10038"/>
          </criteria>
          <criteria operator="AND" comment="Solaris 9 (x86) meets Sun Alert 259468">
            <extend_definition comment="Solaris 9 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1683"/>
            <criterion negate="true" comment="Patch 116454-03 or later installed" test_ref="oval:org.mitre.oval:tst:10171"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Configuration Section">
          <criterion comment="inetd running" test_ref="oval:org.mitre.oval:tst:3135"/>
          <criterion comment="inetd.conf contains sadmind" test_ref="oval:org.mitre.oval:tst:1023"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5543" version="1" class="vulnerability">
      <metadata>
        <title>A Buffer Overflow Security Vulnerability in the Solaris sadmind(1M) Daemon May Lead to Execution of Arbitrary Code</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <platform>Sun Solaris 9</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-4556" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-4556"/>
        <description>Stack-based buffer overflow in the adm_build_path function in sadmind in Sun Solstice AdminSuite on Solaris 8 and 9 allows remote attackers to execute arbitrary code via a crafted request.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-05-26T13:34:47.000-04:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2009-05-27T17:29:51.085-04:00">DRAFT</status_change>
            <status_change date="2009-06-15T04:00:44.279-04:00">INTERIM</status_change>
            <status_change date="2009-07-06T04:00:22.228-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="Software Section">
          <criteria operator="AND" comment="Solaris 8 (SPARC) meets Sun Alert 245806">
            <extend_definition comment="Solaris 8 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1539"/>
            <criterion negate="true" comment="Patch 116455-02 or later installed" test_ref="oval:org.mitre.oval:tst:9833"/>
          </criteria>
          <criteria operator="AND" comment="Solaris 9 (SPARC) meets Sun Alert 245806">
            <extend_definition comment="Solaris 9 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1457"/>
            <criterion negate="true" comment="Patch 116453-03 or later installed" test_ref="oval:org.mitre.oval:tst:9695"/>
          </criteria>
          <criteria operator="AND" comment="Solaris 8 (x86) meets Sun Alert 245806">
            <extend_definition comment="Solaris 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:2059"/>
            <criterion negate="true" comment="Patch 116442-02 or later installed" test_ref="oval:org.mitre.oval:tst:10038"/>
          </criteria>
          <criteria operator="AND" comment="Solaris 9 (x86) meets Sun Alert 245806">
            <extend_definition comment="Solaris 9 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1683"/>
            <criterion negate="true" comment="Patch 116454-03 or later installed" test_ref="oval:org.mitre.oval:tst:10171"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Configuration Section">
          <criterion comment="inetd running" test_ref="oval:org.mitre.oval:tst:3135"/>
          <criterion comment="inetd.conf contains sadmind" test_ref="oval:org.mitre.oval:tst:1023"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6092" version="1" class="vulnerability">
      <metadata>
        <title>Integer Overflow Vulnerability in the Solaris 8 and 9 sadmind(1M) Daemon May Lead to Arbitrary Code Execution</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <platform>Sun Solaris 9</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-3870" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-3870"/>
        <description>Integer overflow in sadmind in Sun Solaris 8 and 9 allows remote attackers to execute arbitrary code via a crafted RPC request that triggers a heap-based buffer overflow, related to improper memory allocation.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-05-28T13:34:47.000-04:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2009-06-05T14:12:44.849-04:00">DRAFT</status_change>
            <status_change date="2009-06-22T04:00:27.049-04:00">INTERIM</status_change>
            <status_change date="2009-07-13T04:00:47.597-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="Software Section">
          <criteria operator="AND" comment="Solaris 8 (SPARC) meets Sun Alert 259468">
            <extend_definition comment="Solaris 8 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1539"/>
            <criterion negate="true" comment="Patch 116455-02 or later installed" test_ref="oval:org.mitre.oval:tst:9833"/>
          </criteria>
          <criteria operator="AND" comment="Solaris 9 (SPARC) meets Sun Alert 259468">
            <extend_definition comment="Solaris 9 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1457"/>
            <criterion negate="true" comment="Patch 116453-03 or later installed" test_ref="oval:org.mitre.oval:tst:9695"/>
          </criteria>
          <criteria operator="AND" comment="Solaris 8 (x86) meets Sun Alert 259468">
            <extend_definition comment="Solaris 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:2059"/>
            <criterion negate="true" comment="Patch 116442-02 or later installed" test_ref="oval:org.mitre.oval:tst:10038"/>
          </criteria>
          <criteria operator="AND" comment="Solaris 9 (x86) meets Sun Alert 259468">
            <extend_definition comment="Solaris 9 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1683"/>
            <criterion negate="true" comment="Patch 116454-03 or later installed" test_ref="oval:org.mitre.oval:tst:10171"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Configuration Section">
          <criterion comment="inetd running" test_ref="oval:org.mitre.oval:tst:3135"/>
          <criterion comment="inetd.conf contains sadmind" test_ref="oval:org.mitre.oval:tst:1023"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6256" version="1" class="vulnerability">
      <metadata>
        <title>Security Vulnerability in Solaris 9 fstat(2) System Call May Lead to a System Panic, Resulting in a Denial of Service (DoS)</title>
        <affected family="unix">
          <platform>Sun Solaris 9</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-1673" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1673"/>
        <description>The kernel in Sun Solaris 9 allows local users to cause a denial of service (panic) by calling fstat with a first argument of AT_FDCWD.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-05-20T10:58:53.000-04:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2009-05-27T17:29:30.743-04:00">DRAFT</status_change>
            <status_change date="2009-06-15T04:01:13.061-04:00">INTERIM</status_change>
            <status_change date="2009-07-06T04:00:49.860-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Solaris 9 (SPARC) meets Sun Alert 257988">
          <extend_definition comment="Solaris 9 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1457"/>
          <criterion negate="true" comment="Patch 122300-40 or later installed" test_ref="oval:org.mitre.oval:tst:9907"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (x86) meets Sun Alert 257988">
          <extend_definition comment="Solaris 9 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1683"/>
          <criterion negate="true" comment="Patch 122301-40 or later installed" test_ref="oval:org.mitre.oval:tst:10040"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6094" version="1" class="vulnerability">
      <metadata>
        <title>Security Vulnerability in GNU tar May Lead to Arbitrary Code Execution or Denial of Service (DoS)</title>
        <affected family="unix">
          <platform>Sun Solaris 9</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-0300" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0300"/>
        <description>Buffer overflow in tar 1.14 through 1.15.90 allows user-assisted attackers to cause a denial of service (application crash) and possibly execute code via unspecified vectors involving PAX extended headers.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-04-30T11:23:00.000-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2009-05-07T11:17:30.107-04:00">DRAFT</status_change>
            <status_change date="2009-05-25T04:01:59.363-04:00">INTERIM</status_change>
            <status_change date="2009-06-15T04:01:00.185-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND" comment="Solaris 9 (x86) meets Sun Alert 241646">
          <extend_definition comment="Solaris 9 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1683"/>
          <criterion negate="true" comment="Patch 118192-02 or later installed" test_ref="oval:org.mitre.oval:tst:10043"/>
          <criterion comment="Patch 118192-01 or later installed" test_ref="oval:org.mitre.oval:tst:10160"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5993" version="1" class="vulnerability">
      <metadata>
        <title>Security Vulnerability in GNU tar May Lead to Arbitrary Code Execution or Denial of Service (DoS)</title>
        <affected family="unix">
          <platform>Sun Solaris 9</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-0300" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0300"/>
        <description>Buffer overflow in tar 1.14 through 1.15.90 allows user-assisted attackers to cause a denial of service (application crash) and possibly execute code via unspecified vectors involving PAX extended headers.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-04-30T11:23:00.000-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2009-05-07T11:17:32.738-04:00">DRAFT</status_change>
            <status_change date="2009-05-25T04:01:52.639-04:00">INTERIM</status_change>
            <status_change date="2009-06-15T04:00:54.861-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND" comment="Solaris 9 (SPARC) meets Sun Alert 241646">
          <extend_definition comment="Solaris 9 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1457"/>
          <criterion negate="true" comment="Patch 118191-02 or later installed" test_ref="oval:org.mitre.oval:tst:9793"/>
          <criterion comment="Patch 118191-01 or later installed" test_ref="oval:org.mitre.oval:tst:9763"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5978" version="1" class="vulnerability">
      <metadata>
        <title>Security Vulnerability in GNU tar May Lead to Arbitrary Code Execution or Denial of Service (DoS)</title>
        <affected family="unix">
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-0300" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0300"/>
        <description>Buffer overflow in tar 1.14 through 1.15.90 allows user-assisted attackers to cause a denial of service (application crash) and possibly execute code via unspecified vectors involving PAX extended headers.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-04-30T11:23:00.000-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2009-05-07T11:17:33.789-04:00">DRAFT</status_change>
            <status_change date="2009-05-25T04:01:51.856-04:00">INTERIM</status_change>
            <status_change date="2009-06-15T04:00:53.458-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 241646">
          <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
          <criterion negate="true" comment="Patch 139099-01 or later installed" test_ref="oval:org.mitre.oval:tst:9629"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5791" version="1" class="vulnerability">
      <metadata>
        <title>HPUX Running useradd(1M), Local Unauthorized Access</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-0719" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0719"/>
        <description>Unspecified vulnerability in useradd in HP HP-UX B.11.11, B.11.23, and B.11.31 allows local users to access arbitrary files and directories via unknown vectors, a different issue than CVE-2008-1660.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-04-29T14:29:56.000-04:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2009-05-07T11:17:41.618-04:00">DRAFT</status_change>
            <status_change date="2009-05-25T04:01:46.634-04:00">INTERIM</status_change>
            <status_change date="2009-06-15T04:00:48.178-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02366">
          <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
          <criterion comment="OS-Core.UX2-CORE is installed" test_ref="oval:org.mitre.oval:tst:10095"/>
          <criterion negate="true" comment="Patch PHCO_38481 is installed" test_ref="oval:org.mitre.oval:tst:9730"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02366">
          <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
          <criterion comment="OS-Core.UX2-CORE is installed" test_ref="oval:org.mitre.oval:tst:10095"/>
          <criterion negate="true" comment="Patch PHCO_38490 is installed" test_ref="oval:org.mitre.oval:tst:9687"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02366">
          <criterion comment="HP-UX B.11.31" test_ref="oval:org.mitre.oval:tst:8260"/>
          <criterion comment="OS-Core.UX2-CORE is installed" test_ref="oval:org.mitre.oval:tst:10095"/>
          <criterion negate="true" comment="Patch PHCO_38482 is installed" test_ref="oval:org.mitre.oval:tst:9928"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5698" version="1" class="vulnerability">
      <metadata>
        <title>The Solaris rpc.metad(1M) Daemon is Vulnerable to a Denial of Service (DoS) Attack</title>
        <affected family="unix">
          <platform>Sun Solaris 9</platform>
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-1480" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1480"/>
        <description>rpc.metad in Sun Solaris 10 allows remote attackers to cause a denial of service (daemon crash) via a malformed RPC request.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-05-06T17:15:10.000-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2009-05-07T11:17:43.220-04:00">DRAFT</status_change>
            <status_change date="2009-05-25T04:01:43.025-04:00">INTERIM</status_change>
            <status_change date="2009-06-15T04:00:46.835-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND" comment="Solaris 9 (SPARC) meets Sun Alert 249146">
          <extend_definition comment="Solaris 9 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1457"/>
          <criterion negate="true" comment="Patch 116669-34 or later installed" test_ref="oval:org.mitre.oval:tst:9832"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 249146">
          <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
          <criterion negate="true" comment="Patch 138632-03 or later installed" test_ref="oval:org.mitre.oval:tst:9259"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (x86) meets Sun Alert 249146">
          <extend_definition comment="Solaris 9 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1683"/>
          <criterion negate="true" comment="Patch 138574-01 or later installed" test_ref="oval:org.mitre.oval:tst:9628"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 249146">
          <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
          <criterion negate="true" comment="Patch 138882-02 or later installed" test_ref="oval:org.mitre.oval:tst:9974"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5252" version="1" class="vulnerability">
      <metadata>
        <title>Security Vulnerability in GNU tar May Lead to Arbitrary Code Execution or Denial of Service (DoS)</title>
        <affected family="unix">
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-0300" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0300"/>
        <description>Buffer overflow in tar 1.14 through 1.15.90 allows user-assisted attackers to cause a denial of service (application crash) and possibly execute code via unspecified vectors involving PAX extended headers.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-04-30T11:23:00.000-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2009-05-07T11:17:46.363-04:00">DRAFT</status_change>
            <status_change date="2009-05-25T04:01:32.862-04:00">INTERIM</status_change>
            <status_change date="2009-06-15T04:00:39.412-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 241646">
          <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
          <criterion negate="true" comment="Patch 139100-01 or later installed" test_ref="oval:org.mitre.oval:tst:9899"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:868" version="1" class="vulnerability">
      <metadata>
        <title>Linux Kernel eflags Checking Privilege Escalation Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <product>Linux kernel</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0001" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0001"/>
        <description>Unknown vulnerability in the eflags checking in the 32-bit ptrace emulation for the Linux kernel on AMD64 systems allows local users to gain privileges.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-03-20T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Matt Busby</contributor>
            </submitted>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="The MITRE Corporation">Matt Busby</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-06-16T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Red Hat Enterprise 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2861"/>
        <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:1547"/>
        <criterion comment="kernel version is less than 2.4.21-9.EL" negate="false" test_ref="oval:org.mitre.oval:tst:1546"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7" version="1" class="vulnerability">
      <metadata>
        <title>Solaris 8 kcms_configure Command-Line Buffer Overflow</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <product>kcms_configure</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2001-0594" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-0594"/>
        <description>kcms_configure as included with Solaris 7 and 8 allows a local attacker to gain additional privileges via a buffer overflow in a command line argument.</description>
        <oval_repository>
          <dates>
            <submitted date="2002-09-17T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">David Proulx</contributor>
            </submitted>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3145"/>
          <criterion comment="File kcms_configure exists" negate="false" test_ref="oval:org.mitre.oval:tst:3144"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="AND" comment="File kcms_configure executable and SUID or SGID">
            <criterion comment="File kcms_configure executable and SUID or SGID" negate="false" test_ref="oval:org.mitre.oval:tst:3143"/>
            <criteria operator="OR" comment="File kcms_configure executable and SUID or SGID">
              <criterion comment="File kcms_configure executable and SUID or SGID" negate="false" test_ref="oval:org.mitre.oval:tst:3142"/>
              <criterion comment="File kcms_configure executable and SUID or SGID" negate="false" test_ref="oval:org.mitre.oval:tst:3141"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:10" version="1" class="vulnerability">
      <metadata>
        <title>Heap Overflow in Solaris 8 xlock</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <product>xlock</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2001-0652" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-0652"/>
        <description>Heap overflow in xlock in Solaris 2.6 through 8 allows local users to gain root privileges via a long (1) XFILESEARCHPATH or (2) XUSERFILESEARCHPATH environmental variable.</description>
        <oval_repository>
          <dates>
            <submitted date="2002-09-17T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">David Proulx</contributor>
            </submitted>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3145"/>
          <criterion comment="File xlock exists" negate="false" test_ref="oval:org.mitre.oval:tst:3130"/>
          <criterion comment="Patch 108652-38 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:3129"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="AND" comment="File xlock SUID and executable">
            <criterion comment="File xlock SUID and executable" negate="false" test_ref="oval:org.mitre.oval:tst:3128"/>
            <criterion comment="File xlock SUID and executable" negate="false" test_ref="oval:org.mitre.oval:tst:3127"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11" version="1" class="vulnerability">
      <metadata>
        <title>String Format Vulnerability in Solaris 8 snmpdx</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <product>snmpdx</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-0796" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0796"/>
        <description>Format string vulnerability in the logging component of snmpdx for Solaris 5.6 through 8 allows remote attackers to gain root privileges.</description>
        <oval_repository>
          <dates>
            <submitted date="2002-09-25T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">David Proulx</contributor>
            </submitted>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3145"/>
          <criterion comment="File snmpdx exists" negate="false" test_ref="oval:org.mitre.oval:tst:3126"/>
          <criterion comment="Patch 108869-16 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:3125"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="snmpdx running" negate="false" test_ref="oval:org.mitre.oval:tst:3124"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:14" version="1" class="vulnerability">
      <metadata>
        <title>Sun Solaris 8 XSun Color Database File Heap Overflow</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <product>Xsun</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-0158" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0158"/>
        <description>Buffer overflow in Xsun on Solaris 2.6 through 8 allows local users to gain root privileges via a long -co (color database) command line argument.</description>
        <oval_repository>
          <dates>
            <submitted date="2002-08-23T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">David Proulx</contributor>
            </submitted>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3145"/>
          <criterion comment="File Xsun exists" negate="false" test_ref="oval:org.mitre.oval:tst:3109"/>
          <criterion comment="Patch 108652-52 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:3108"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="AND" comment="File Xsun SGID and executable">
            <criterion comment="File Xsun SGID and executable" negate="false" test_ref="oval:org.mitre.oval:tst:3107"/>
            <criterion comment="File Xsun SGID and executable" negate="false" test_ref="oval:org.mitre.oval:tst:3106"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:33" version="1" class="vulnerability">
      <metadata>
        <title>Sun Solaris 7 XSun Color Database File Heap Overflow</title>
        <affected family="unix">
          <platform>Sun Solaris 7</platform>
          <product>Xsun</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-0158" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0158"/>
        <description>Buffer overflow in Xsun on Solaris 2.6 through 8 allows local users to gain root privileges via a long -co (color database) command line argument.</description>
        <oval_repository>
          <dates>
            <submitted date="2002-10-17T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">David Proulx</contributor>
            </submitted>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Solaris 7 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3045"/>
          <criterion comment="File Xsun exists" negate="false" test_ref="oval:org.mitre.oval:tst:3109"/>
          <criterion comment="Patch 108376-38 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:3044"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="AND" comment="File Xsun SGID and executable">
            <criterion comment="File Xsun SGID and executable" negate="false" test_ref="oval:org.mitre.oval:tst:3107"/>
            <criterion comment="File Xsun SGID and executable" negate="false" test_ref="oval:org.mitre.oval:tst:3106"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:56" version="1" class="vulnerability">
      <metadata>
        <title>Solaris 8 rpc.yppasswdd Buffer Overrun Vulnerability</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <product>rpc.yppasswdd</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2001-0779" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-0779"/>
        <description>Buffer overflow in rpc.yppasswdd (yppasswd server) in Solaris 2.6, 7 and 8 allows remote attackers to gain root access via a long username.</description>
        <oval_repository>
          <dates>
            <submitted date="2002-08-30T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">David Proulx</contributor>
            </submitted>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3145"/>
          <criterion comment="File rpc.yppasswdd exists" negate="false" test_ref="oval:org.mitre.oval:tst:3006"/>
          <criterion comment="Patch 111596-02 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:3005"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="rpc.yppasswdd running" negate="false" test_ref="oval:org.mitre.oval:tst:3004"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:62" version="1" class="vulnerability">
      <metadata>
        <title>Solaris 7 mibiisa Remote Buffer Overflow Vulnerability</title>
        <affected family="unix">
          <platform>Sun Solaris 7</platform>
          <product>mibiisa</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-0797" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0797"/>
        <description>Buffer overflow in the MIB parsing component of mibiisa for Solaris 5.6 through 8 allows remote attackers to gain root privileges.</description>
        <oval_repository>
          <dates>
            <submitted date="2002-10-17T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">David Proulx</contributor>
            </submitted>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Solaris 7 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3045"/>
          <criterion comment="File mibiisa exists" negate="false" test_ref="oval:org.mitre.oval:tst:2995"/>
          <criterion comment="Patch 107709-19 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:2994"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="mibiisa running" negate="false" test_ref="oval:org.mitre.oval:tst:2993"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:65" version="1" class="vulnerability">
      <metadata>
        <title>Solaris 7 kcms_configure Command-Line Buffer Overflow</title>
        <affected family="unix">
          <platform>Sun Solaris 7</platform>
          <product>kcms_configure</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2001-0594" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-0594"/>
        <description>kcms_configure as included with Solaris 7 and 8 allows a local attacker to gain additional privileges via a buffer overflow in a command line argument.</description>
        <oval_repository>
          <dates>
            <submitted date="2002-09-17T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">David Proulx</contributor>
            </submitted>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Solaris 7 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3045"/>
          <criterion comment="File kcms_configure exists" negate="false" test_ref="oval:org.mitre.oval:tst:3144"/>
          <criterion comment="Patch 107337-02 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:2989"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="AND" comment="File kcms_configure executable and SUID or SGID">
            <criterion comment="File kcms_configure executable and SUID or SGID" negate="false" test_ref="oval:org.mitre.oval:tst:3143"/>
            <criteria operator="OR" comment="File kcms_configure executable and SUID or SGID">
              <criterion comment="File kcms_configure executable and SUID or SGID" negate="false" test_ref="oval:org.mitre.oval:tst:3142"/>
              <criterion comment="File kcms_configure executable and SUID or SGID" negate="false" test_ref="oval:org.mitre.oval:tst:3141"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:86" version="1" class="vulnerability">
      <metadata>
        <title>Solaris 8 LBXProxy Display Name Buffer Overflow</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <product>lbxproxy</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-0090" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0090"/>
        <description>Buffer overflow in Low BandWidth X proxy (lbxproxy) in Solaris 8 allows local users to execute arbitrary code via a long display command line option.</description>
        <oval_repository>
          <dates>
            <submitted date="2002-08-30T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">David Proulx</contributor>
            </submitted>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3145"/>
          <criterion comment="File lbxproxy exists" negate="false" test_ref="oval:org.mitre.oval:tst:2964"/>
          <criterion comment="Patch 108652-51 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:2963"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="AND" comment="File lbxproxy SGID and executable">
            <criterion comment="File lbxproxy SGID and executable" negate="false" test_ref="oval:org.mitre.oval:tst:2962"/>
            <criterion comment="File lbxproxy SGID and executable" negate="false" test_ref="oval:org.mitre.oval:tst:2961"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:94" version="1" class="vulnerability">
      <metadata>
        <title>Solaris 8 mibiisa Remote Buffer Overflow Vulnerability</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <product>mibiisa</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-0797" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0797"/>
        <description>Buffer overflow in the MIB parsing component of mibiisa for Solaris 5.6 through 8 allows remote attackers to gain root privileges.</description>
        <oval_repository>
          <dates>
            <submitted date="2002-09-25T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">David Proulx</contributor>
            </submitted>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3145"/>
          <criterion comment="File mibiisa exists" negate="false" test_ref="oval:org.mitre.oval:tst:2995"/>
          <criterion comment="Patch 108869-16 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:3125"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="mibiisa running" negate="false" test_ref="oval:org.mitre.oval:tst:2993"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:102" version="1" class="vulnerability">
      <metadata>
        <title>Solaris 7 rpc.yppasswdd Buffer Overrun Vulnerability</title>
        <affected family="unix">
          <platform>Sun Solaris 7</platform>
          <product>rpc.yppasswdd</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2001-0779" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-0779"/>
        <description>Buffer overflow in rpc.yppasswdd (yppasswd server) in Solaris 2.6, 7 and 8 allows remote attackers to gain root access via a long username.</description>
        <oval_repository>
          <dates>
            <submitted date="2002-10-17T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">David Proulx</contributor>
            </submitted>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Solaris 7 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3045"/>
          <criterion comment="File rpc.yppasswdd exists" negate="false" test_ref="oval:org.mitre.oval:tst:3006"/>
          <criterion comment="Patch 111590-02 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:2943"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="rpc.yppasswdd running" negate="false" test_ref="oval:org.mitre.oval:tst:3004"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:114" version="1" class="vulnerability">
      <metadata>
        <title>String Format Vulnerability in Solaris 7 snmpdx</title>
        <affected family="unix">
          <platform>Sun Solaris 7</platform>
          <product>snmpdx</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-0796" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0796"/>
        <description>Format string vulnerability in the logging component of snmpdx for Solaris 5.6 through 8 allows remote attackers to gain root privileges.</description>
        <oval_repository>
          <dates>
            <submitted date="2002-10-17T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">David Proulx</contributor>
            </submitted>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Solaris 7 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3045"/>
          <criterion comment="File snmpdx exists" negate="false" test_ref="oval:org.mitre.oval:tst:3126"/>
          <criterion comment="Patch 107709-19 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:2994"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="snmpdx running" negate="false" test_ref="oval:org.mitre.oval:tst:3124"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:131" version="1" class="vulnerability">
      <metadata>
        <title>Heap Overflow in Solaris 7 xlock</title>
        <affected family="unix">
          <platform>Sun Solaris 7</platform>
          <product>xlock</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2001-0652" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-0652"/>
        <description>Heap overflow in xlock in Solaris 2.6 through 8 allows local users to gain root privileges via a long (1) XFILESEARCHPATH or (2) XUSERFILESEARCHPATH environmental variable.</description>
        <oval_repository>
          <dates>
            <submitted date="2002-10-17T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">David Proulx</contributor>
            </submitted>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Solaris 7 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3045"/>
          <criterion comment="File xlock exists" negate="false" test_ref="oval:org.mitre.oval:tst:3130"/>
          <criterion comment="Patch 108376-30 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:2912"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="AND" comment="File xlock SUID and executable">
            <criterion comment="File xlock SUID and executable" negate="false" test_ref="oval:org.mitre.oval:tst:3128"/>
            <criterion comment="File xlock SUID and executable" negate="false" test_ref="oval:org.mitre.oval:tst:3127"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:179" version="1" class="vulnerability">
      <metadata>
        <title>Solaris 7 LBXProxy Display Name Buffer Overflow</title>
        <affected family="unix">
          <platform>Sun Solaris 7</platform>
          <product>lbxproxy</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-0090" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0090"/>
        <description>Buffer overflow in Low BandWidth X proxy (lbxproxy) in Solaris 8 allows local users to execute arbitrary code via a long display command line option.</description>
        <oval_repository>
          <dates>
            <submitted date="2002-10-17T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">David Proulx</contributor>
            </submitted>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Solaris 7 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3045"/>
          <criterion comment="File lbxproxy exists" negate="false" test_ref="oval:org.mitre.oval:tst:2964"/>
          <criterion comment="Patch 107654-10 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:2848"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="AND" comment="File lbxproxy SGID and executable">
            <criterion comment="File lbxproxy SGID and executable" negate="false" test_ref="oval:org.mitre.oval:tst:2962"/>
            <criterion comment="File lbxproxy SGID and executable" negate="false" test_ref="oval:org.mitre.oval:tst:2961"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1982" version="1" class="vulnerability">
      <metadata>
        <title>Apache Connection Blocking Denial Of Service Vulnerability</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <platform>Sun Solaris 9</platform>
          <product>Apache</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0174" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0174"/>
        <description>Apache 1.4.x before 1.3.30, and 2.0.x before 2.0.49, when using multiple listening sockets on certain platforms, allows remote attackers to cause a denial of service (blocked new connections) via a "short-lived connection on a rarely-accessed listening socket."</description>
        <oval_repository>
          <dates>
            <submitted date="2004-10-14T01:13:00.000-04:00">
              <contributor organization="The MITRE Corporation">Brian Soby</contributor>
            </submitted>
            <modified date="2004-10-18T03:12:00.000-04:00" comment="Changed apache test to file test">
              <contributor organization="The MITRE Corporation">Brian Soby</contributor>
            </modified>
            <modified date="2004-10-19T11:17:00.000-04:00" comment="Changed apache test to package test">
              <contributor organization="The MITRE Corporation">Brian Soby</contributor>
            </modified>
            <status_change date="2004-10-20T02:35:00.000-04:00">DRAFT</status_change>
            <status_change date="2004-11-03T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-12-09T08:46:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criteria operator="OR" comment="Solaris 8 or 9 installed">
            <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3145"/>
            <criterion comment="Solaris 9 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3051"/>
          </criteria>
          <criterion comment="Patch 116973-01 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:656"/>
          <criterion comment="Patch 113146-05 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:655"/>
          <criterion comment="Apache (SUNWapchu) installed" negate="false" test_ref="oval:org.mitre.oval:tst:653"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="Apache running (httpd)" negate="false" test_ref="oval:org.mitre.oval:tst:654"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:2621" version="1" class="vulnerability">
      <metadata>
        <title>OpenSSL Denial of Service Vulnerabilities</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <product>Sun Crypto Accelerator 4000</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0079" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0079"/>
        <description>The do_change_cipher_spec function in OpenSSL 0.9.6c to 0.9.6k, and 0.9.7a to 0.9.7c, allows remote attackers to cause a denial of service (crash) via a crafted SSL/TLS handshake that triggers a null dereference.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-10-12T09:44:00.000-04:00">
              <contributor organization="The MITRE Corporation">Brian Soby</contributor>
            </submitted>
            <status_change date="2004-10-13T01:15:00.000-04:00">DRAFT</status_change>
            <status_change date="2004-10-27T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-11-17T10:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criteria operator="OR" comment="Solaris 8 or 9 installed">
            <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3145"/>
            <criterion comment="Solaris 9 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3051"/>
          </criteria>
          <criterion comment="Patch 114796-04 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:501"/>
          <criterion comment="Sun Crypto Accelerator 4000 software installed" negate="false" test_ref="oval:org.mitre.oval:tst:500"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="Apache running (httpd)" negate="false" test_ref="oval:org.mitre.oval:tst:654"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:3799" version="1" class="vulnerability">
      <metadata>
        <title>Apache Web Server Multiple Module Local Buffer Overflow</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <platform>Sun Solaris 9</platform>
          <product>Apache</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0542" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0542"/>
        <description>Multiple stack-based buffer overflows in (1) mod_alias and (2) mod_rewrite for Apache before 1.3.29 allow attackers to create configuration files to cause a denial of service (crash) or execute arbitrary code via a regular expression with more than 9 captures.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-10-19T03:08:00.000-04:00">
              <contributor organization="The MITRE Corporation">Brian Soby</contributor>
            </submitted>
            <status_change date="2004-10-20T02:35:00.000-04:00">DRAFT</status_change>
            <status_change date="2004-11-03T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-12-09T08:46:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criteria operator="OR" comment="Solaris 8 or 9 installed">
            <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3145"/>
            <criterion comment="Solaris 9 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3051"/>
          </criteria>
          <criterion comment="Patch 113146-03 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:383"/>
          <criterion comment="Patch 116973-01 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:656"/>
          <criterion comment="Apache (SUNWapchu) installed" negate="false" test_ref="oval:org.mitre.oval:tst:653"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="Apache running (httpd)" negate="false" test_ref="oval:org.mitre.oval:tst:654"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:4030" version="1" class="vulnerability">
      <metadata>
        <title>DtMail Local Command Line Format String Vulnerability</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <platform>Sun Solaris 9</platform>
          <product>DtMail</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0800" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0800"/>
        <description>Format string vulnerability in CDE Mailer (dtmail) on Solaris 8 and 9 allows local users to gain privileges via format strings in the argv[0] value.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-10-19T03:09:00.000-04:00">
              <contributor organization="The MITRE Corporation">Brian Soby</contributor>
            </submitted>
            <status_change date="2004-10-20T02:35:00.000-04:00">DRAFT</status_change>
            <status_change date="2004-11-03T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-12-09T08:46:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="Solaris 8 or 9 installed">
          <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3145"/>
          <criterion comment="Solaris 9 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3051"/>
        </criteria>
        <criterion comment="Patch 109613-07 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:365"/>
        <criterion comment="Patch 112810-06 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:364"/>
        <criterion comment="CDE Desktop Applications (SUNWdtdst) installed" negate="false" test_ref="oval:org.mitre.oval:tst:363"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:4114" version="1" class="vulnerability">
      <metadata>
        <title>Apache Error Log Escape Sequence Injection Vulnerability</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <platform>Sun Solaris 9</platform>
          <product>Apache</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0020" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0020"/>
        <description>Apache does not filter terminal escape sequences from its error logs, which could make it easier for attackers to insert those sequences into terminal emulators containing vulnerabilities related to escape sequences.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-10-14T01:14:00.000-04:00">
              <contributor organization="The MITRE Corporation">Brian Soby</contributor>
            </submitted>
            <modified date="2004-10-18T03:14:00.000-04:00" comment="Change apache test to file test">
              <contributor organization="The MITRE Corporation">Brian Soby</contributor>
            </modified>
            <modified date="2004-10-19T11:18:00.000-04:00" comment="Changed apache test to package test">
              <contributor organization="The MITRE Corporation">Brian Soby</contributor>
            </modified>
            <status_change date="2004-10-20T02:35:00.000-04:00">DRAFT</status_change>
            <status_change date="2004-11-03T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-12-09T08:46:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criteria operator="OR" comment="Solaris 8 or 9 installed">
            <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3145"/>
            <criterion comment="Solaris 9 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3051"/>
          </criteria>
          <criterion comment="Patch 116973-01 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:656"/>
          <criterion comment="Patch 113146-05 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:655"/>
          <criterion comment="Apache (SUNWapchu) installed" negate="false" test_ref="oval:org.mitre.oval:tst:653"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="Apache running (httpd)" negate="false" test_ref="oval:org.mitre.oval:tst:654"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:4254" version="1" class="vulnerability">
      <metadata>
        <title>OpenSSL Integer Overflow Vulnerability</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <platform>Sun Solaris 9</platform>
          <product>Sun Cluster</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0543" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0543"/>
        <description>Integer overflow in OpenSSL 0.9.6 and 0.9.7 allows remote attackers to cause a denial of service (crash) via an SSL client certificate with certain ASN.1 tag values.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-10-19T03:10:00.000-04:00">
              <contributor organization="The MITRE Corporation">Brian Soby</contributor>
            </submitted>
            <status_change date="2004-10-20T02:35:00.000-04:00">DRAFT</status_change>
            <status_change date="2004-11-03T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-12-09T08:46:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criteria operator="OR" comment="Solaris 8 or 9 installed">
            <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3145"/>
            <criterion comment="Solaris 9 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3051"/>
          </criteria>
          <criterion comment="Patch 113505-02 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:511"/>
          <criterion comment="Patch 113508-02 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:510"/>
          <criterion comment="Patch 115054-01 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:509"/>
          <criterion comment="Patch 115055-01 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:508"/>
          <criterion comment="SunCluster Component SUNWscvw installed" negate="false" test_ref="oval:org.mitre.oval:tst:507"/>
          <criterion comment="Apache (SUNWapchu) installed" negate="false" test_ref="oval:org.mitre.oval:tst:653"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="Apache running with SunPlex Manager config" negate="false" test_ref="oval:org.mitre.oval:tst:506"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:4416" version="1" class="vulnerability">
      <metadata>
        <title>Apache mod_digest Nonce Verification Vulnerability</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <platform>Sun Solaris 9</platform>
          <product>Apache</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0987" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0987"/>
        <description>mod_digest for Apache before 1.3.31 does not properly verify the nonce of a client response by using a AuthNonce secret.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-10-14T01:14:00.000-04:00">
              <contributor organization="The MITRE Corporation">Brian Soby</contributor>
            </submitted>
            <modified date="2004-10-18T03:15:00.000-04:00" comment="Change apache test to file test">
              <contributor organization="The MITRE Corporation">Brian Soby</contributor>
            </modified>
            <modified date="2004-10-19T11:19:00.000-04:00" comment="Changed apache test to package test">
              <contributor organization="The MITRE Corporation">Brian Soby</contributor>
            </modified>
            <status_change date="2004-10-20T02:35:00.000-04:00">DRAFT</status_change>
            <status_change date="2004-11-03T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-12-09T08:46:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criteria operator="OR" comment="Solaris 8 or 9 installed">
            <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3145"/>
            <criterion comment="Solaris 9 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3051"/>
          </criteria>
          <criterion comment="Patch 116973-01 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:656"/>
          <criterion comment="Patch 113146-05 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:655"/>
          <criterion comment="Apache (SUNWapchu) installed" negate="false" test_ref="oval:org.mitre.oval:tst:653"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="Apache running (httpd)" negate="false" test_ref="oval:org.mitre.oval:tst:654"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:4574" version="1" class="vulnerability">
      <metadata>
        <title>OpenSSL ASN.1 Inputs Character Tracking Vulnerability</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <platform>Sun Solaris 9</platform>
          <product>Sun Cluster</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0544" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0544"/>
        <description>OpenSSL 0.9.6 and 0.9.7 does not properly track the number of characters in certain ASN.1 inputs, which allows remote attackers to cause a denial of service (crash) via an SSL client certificate that causes OpenSSL to read past the end of a buffer when the long form is used.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-10-19T03:10:00.000-04:00">
              <contributor organization="The MITRE Corporation">Brian Soby</contributor>
            </submitted>
            <status_change date="2004-10-20T02:35:00.000-04:00">DRAFT</status_change>
            <status_change date="2004-11-03T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-12-09T08:46:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criteria operator="OR" comment="Solaris 8 or 9 installed">
            <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3145"/>
            <criterion comment="Solaris 9 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3051"/>
          </criteria>
          <criterion comment="Patch 113505-02 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:511"/>
          <criterion comment="Patch 113508-02 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:510"/>
          <criterion comment="Patch 115054-01 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:509"/>
          <criterion comment="Patch 115055-01 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:508"/>
          <criterion comment="SunCluster Component SUNWscvw installed" negate="false" test_ref="oval:org.mitre.oval:tst:507"/>
          <criterion comment="Apache (SUNWapchu) installed" negate="false" test_ref="oval:org.mitre.oval:tst:653"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="Apache running with SunPlex Manager config" negate="false" test_ref="oval:org.mitre.oval:tst:506"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:4670" version="1" class="vulnerability">
      <metadata>
        <title>Apache Mod_Access Access Control Rule Bypass Vulnerability</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <platform>Sun Solaris 9</platform>
          <product>Apache</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0993" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0993"/>
        <description>mod_access in Apache 1.3 before 1.3.30, when running big-endian 64-bit platforms, does not properly parse Allow/Deny rules using IP addresses without a netmask, which could allow remote attackers to bypass intended access restrictions.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-10-14T01:13:00.000-04:00">
              <contributor organization="The MITRE Corporation">Brian Soby</contributor>
            </submitted>
            <modified date="2004-10-18T03:16:00.000-04:00" comment="Changes apache test to file test">
              <contributor organization="The MITRE Corporation">Brian Soby</contributor>
            </modified>
            <modified date="2004-10-19T11:19:00.000-04:00" comment="Changed apache test to package test">
              <contributor organization="The MITRE Corporation">Brian Soby</contributor>
            </modified>
            <status_change date="2004-10-20T02:35:00.000-04:00">DRAFT</status_change>
            <status_change date="2004-11-03T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-12-09T08:46:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criteria operator="OR" comment="Solaris 8 or 9 installed">
            <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3145"/>
            <criterion comment="Solaris 9 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3051"/>
          </criteria>
          <criterion comment="Patch 116973-01 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:656"/>
          <criterion comment="Patch 113146-05 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:655"/>
          <criterion comment="Apache (SUNWapchu) installed" negate="false" test_ref="oval:org.mitre.oval:tst:653"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="Apache running (httpd)" negate="false" test_ref="oval:org.mitre.oval:tst:654"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:4863" version="1" class="vulnerability">
      <metadata>
        <title>Apache Mod_Proxy Remote Negative Content-Length Buffer Overflow</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <platform>Sun Solaris 9</platform>
          <product>Apache</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0492" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0492"/>
        <description>Heap-based buffer overflow in proxy_util.c for mod_proxy in Apache 1.3.25 to 1.3.31 allows remote attackers to cause a denial of service (process crash) and possibly execute arbitrary code via a negative Content-Length HTTP header field, which causes a large amount of data to be copied.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-10-14T01:12:00.000-04:00">
              <contributor organization="The MITRE Corporation">Brian Soby</contributor>
            </submitted>
            <modified date="2004-10-18T03:16:00.000-04:00" comment="Changed apache test to file test">
              <contributor organization="The MITRE Corporation">Brian Soby</contributor>
            </modified>
            <modified date="2004-10-19T11:20:00.000-04:00" comment="Changed apache test to package test">
              <contributor organization="The MITRE Corporation">Brian Soby</contributor>
            </modified>
            <status_change date="2004-10-20T02:35:00.000-04:00">DRAFT</status_change>
            <status_change date="2004-11-03T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-12-09T08:46:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criteria operator="OR" comment="Solaris 8 or 9 installed">
            <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3145"/>
            <criterion comment="Solaris 9 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3051"/>
          </criteria>
          <criterion comment="Patch 116973-01 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:656"/>
          <criterion comment="Patch 113146-05 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:655"/>
          <criterion comment="Apache (SUNWapchu) installed" negate="false" test_ref="oval:org.mitre.oval:tst:653"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="Apache running (httpd)" negate="false" test_ref="oval:org.mitre.oval:tst:654"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:449" version="1" class="vulnerability">
      <metadata>
        <title>Bind OPT Resource Record DoS Vulnerability</title>
        <affected family="unix">
          <platform>Sun Solaris 9</platform>
          <product>Bind</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-1220" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-1220"/>
        <description>BIND 8.3.x through 8.3.3 allows remote attackers to cause a denial of service (termination due to assertion failure) via a request for a subdomain that does not exist, with an OPT resource record with a large UDP payload size.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-01-19T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Brian Soby</contributor>
            </submitted>
            <status_change date="2005-01-24T03:40:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-02-16T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-03-09T07:56:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Solaris 9 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3051"/>
          <criterion comment="Internet Domain Name Server (BIND, SUNWinamd) installed" negate="false" test_ref="oval:org.mitre.oval:tst:2626"/>
          <criterion comment="Patch 112970-03 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:2625"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="in.named running" negate="false" test_ref="oval:org.mitre.oval:tst:2624"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:555" version="1" class="vulnerability">
      <metadata>
        <title>Xsun Buffer Overflow via HOME Envvar</title>
        <affected family="unix">
          <platform>Sun Solaris 7</platform>
          <product>Xsun</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2001-0422" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-0422"/>
        <description>Buffer overflow in Xsun in Solaris 8 and earlier allows local users to execute arbitrary commands via a long HOME environmental variable.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-12-28T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Brian Soby</contributor>
            </submitted>
            <status_change date="2005-01-12T12:41:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-02-02T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-02-23T09:25:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="Solaris 7 or 8 installed">
          <criterion comment="Solaris 7 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3045"/>
          <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3145"/>
        </criteria>
        <criterion comment="Patch 108376-25 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:2562"/>
        <criterion comment="Patch 108652-30 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:2561"/>
        <criterion comment="X Window System platform software (SUNWxwplt) installed" negate="false" test_ref="oval:org.mitre.oval:tst:2560"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1048" version="1" class="vulnerability">
      <metadata>
        <title>SNMP Trap Handling Vulnerability</title>
        <affected family="unix">
          <platform>Sun Solaris 7</platform>
          <platform>Sun Solaris 8</platform>
          <product>snmpdx</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-0012" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0012"/>
        <description>Vulnerabilities in a large number of SNMP implementations allow remote attackers to cause a denial of service or gain privileges via SNMPv1 trap handling, as demonstrated by the PROTOS c06-SNMPv1 test suite.  NOTE: It is highly likely that this candidate will be SPLIT into multiple candidates, one or more for each vendor.  This and other SNMP-related candidates will be updated when more accurate information is available.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-02-01T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Brian Soby</contributor>
            </submitted>
            <status_change date="2005-02-01T08:41:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-02-16T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-03-09T07:56:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criteria operator="OR" comment="Solaris 7 or 8 installed">
            <criterion comment="Solaris 7 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3045"/>
            <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3145"/>
          </criteria>
          <criterion comment="Solstice Enterprise Agents SNMP (SUNWsasnm) installed" negate="false" test_ref="oval:org.mitre.oval:tst:1243"/>
          <criterion comment="Patch 107709-18 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:1242"/>
          <criterion comment="Patch 108869-15 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:1241"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="snmpdx running" negate="false" test_ref="oval:org.mitre.oval:tst:3124"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1227" version="1" class="vulnerability">
      <metadata>
        <title>Mozilla FTP URI MIME Type Exploit Vulnerability</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <product>mozilla</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0760" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0760"/>
        <description>Mozilla allows remote attackers to cause Mozilla to open a URI as a different MIME type than expected via a null character (%00) in an FTP URI.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-01-19T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Brian Soby</contributor>
            </submitted>
            <status_change date="2005-01-24T03:40:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-02-16T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-03-09T07:56:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="Solaris 8 or 9 installed">
          <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3145"/>
          <criterion comment="Solaris 9 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3051"/>
        </criteria>
        <criteria operator="OR" comment="Mozilla components (any SUNWmoznav/SUNWmozmail) installed">
          <criterion comment="Mozilla (SUNWmoznav) installed" negate="false" test_ref="oval:org.mitre.oval:tst:1070"/>
          <criterion comment="Mozilla Mail (SUNWmozmail) installed" negate="false" test_ref="oval:org.mitre.oval:tst:1069"/>
        </criteria>
        <criterion comment="Patch 117765-02 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:1068"/>
        <criterion comment="Patch 117767-02 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:1067"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1467" version="1" class="vulnerability">
      <metadata>
        <title>Samba Encrypted Password DoS</title>
        <affected family="unix">
          <platform>Sun Solaris 9</platform>
          <product>Samba</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-1318" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-1318"/>
        <description>Buffer overflow in samba 2.2.2 through 2.2.6 allows remote attackers to cause a denial of service and possibly execute arbitrary code via an encrypted password that causes the overflow during decryption in which a DOS codepage string is converted to a little-endian UCS2 unicode string.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-01-19T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Brian Soby</contributor>
            </submitted>
            <status_change date="2005-01-24T03:40:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-02-16T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-03-09T07:56:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Solaris 9 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3051"/>
          <criterion comment="Samba - Usr (SUNWsmbau) installed" negate="false" test_ref="oval:org.mitre.oval:tst:914"/>
          <criterion comment="Patch 114684-01 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:913"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="smbd running" negate="false" test_ref="oval:org.mitre.oval:tst:912"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1479" version="1" class="vulnerability">
      <metadata>
        <title>Integer Overflow in libpng via Malformed PNG Image</title>
        <affected family="unix">
          <platform>Sun Solaris 7</platform>
          <product>libpng</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0599" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0599"/>
        <description>Multiple integer overflows in the (1) png_read_png in pngread.c or (2) png_handle_sPLT functions in pngrutil.c or (3) progressive display image reading capability in libpng 1.2.5 and earlier allow remote attackers to cause a denial of service (application crash) via a malformed PNG image.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-12-12T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Brian Soby</contributor>
            </submitted>
            <status_change date="2005-01-24T12:04:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-02-16T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-03-09T07:56:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="Solaris 7,8,or 9 installed">
          <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3145"/>
          <criterion comment="Solaris 7 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3045"/>
          <criterion comment="Solaris 9 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3051"/>
        </criteria>
        <criterion comment="Netscape installed" negate="false" test_ref="oval:org.mitre.oval:tst:901"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1844" version="1" class="vulnerability">
      <metadata>
        <title>ypbind Daemon Buffer Overflow</title>
        <affected family="unix">
          <platform>Sun Solaris 7</platform>
          <product>NIS</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2001-1328" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-1328"/>
        <description>Buffer overflow in ypbind daemon in Solaris 5.4 through 8 allows remote attackers to execute arbitrary code.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-12-29T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Brian Soby</contributor>
            </submitted>
            <status_change date="2005-01-12T12:41:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-02-02T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-02-23T09:25:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criteria operator="OR" comment="Solaris 7 or 8 installed">
            <criterion comment="Solaris 7 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3045"/>
            <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3145"/>
          </criteria>
          <criterion comment="NIS/NIS+ Utilities installed (SUNWnisu)" negate="false" test_ref="oval:org.mitre.oval:tst:690"/>
          <criterion comment="Patch 108750-02 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:689"/>
          <criterion comment="Patch 110322-01 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:688"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="ypbind running" negate="false" test_ref="oval:org.mitre.oval:tst:687"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1880" version="1" class="vulnerability">
      <metadata>
        <title>CDE dtspcd Daemon Symlink Vulnerability</title>
        <affected family="unix">
          <platform>Sun Solaris 7</platform>
          <product>dtspcd</product>
        </affected>
        <reference source="CVE" ref_id="CVE-1999-0689" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-0689"/>
        <description>The CDE dtspcd daemon allows local users to execute arbitrary commands via a symlink attack.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-02-01T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Brian Soby</contributor>
            </submitted>
            <status_change date="2005-02-01T08:41:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-02-16T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-03-09T07:56:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Solaris 7 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3045"/>
        <criterion comment="CDE Daemons (SUNWdtdmn) installed" negate="false" test_ref="oval:org.mitre.oval:tst:680"/>
        <criterion comment="Patch 108221-01 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:679"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1905" version="1" class="vulnerability">
      <metadata>
        <title>dtsession Buffer Overflow via HOME Envvar</title>
        <affected family="unix">
          <platform>Sun Solaris 7</platform>
          <platform>Sun Solaris 8</platform>
          <platform>Sun Solaris 9</platform>
          <product>Common Desktop Environment</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0092" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0092"/>
        <description>Heap-based buffer overflow in dtsession for Solaris 2.5.1 through Solaris 9 allows local users to gain root privileges via a long HOME environment variable.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-02-01T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Brian Soby</contributor>
            </submitted>
            <status_change date="2005-02-01T08:41:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-02-16T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-03-09T07:56:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="Solaris 7,8,or 9 installed">
          <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3145"/>
          <criterion comment="Solaris 7 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3045"/>
          <criterion comment="Solaris 9 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3051"/>
        </criteria>
        <criterion comment="CDE Desktop Window Manager (SUNWdtwm) installed" negate="false" test_ref="oval:org.mitre.oval:tst:675"/>
        <criterion comment="Patch 107702-12 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:674"/>
        <criterion comment="Patch 109354-19 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:673"/>
        <criterion comment="Patch 114497-01 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:672"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:2065" version="1" class="vulnerability">
      <metadata>
        <title>Kerberos Client Plaintext Password Vulnerability</title>
        <affected family="unix">
          <platform>Sun Solaris 9</platform>
          <product>pam_krb5</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0653" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0653"/>
        <description>Solaris 9, when configured as a Kerberos client with patch 112908-12 or 115168-03 and using pam_krb5 as an "auth" module with the debug feature enabled, records passwords in plaintext, which could allow local users to gain other user's passwords by reading log files.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-10-12T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Brian Soby</contributor>
            </submitted>
            <status_change date="2004-10-13T12:00:00.000-04:00">DRAFT</status_change>
            <modified date="2005-01-14T12:00:00.000-04:00" comment="Changed all unknown tests to solaris file contents tests">
              <contributor organization="The MITRE Corporation">Brian Soby</contributor>
            </modified>
            <status_change date="2005-02-02T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-02-23T09:25:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Solaris 9 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3051"/>
          <criterion comment="Kerberos 5 installed" negate="false" test_ref="oval:org.mitre.oval:tst:648"/>
          <criterion comment="Patch 112908-13 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:630"/>
          <criterion comment="Patch 112908-12 installed" negate="false" test_ref="oval:org.mitre.oval:tst:629"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="/etc/pam.conf is configured to use pam_krb5 as an 'auth' module and the debug feature of pam_krb5 is enabled" negate="false" test_ref="oval:org.mitre.oval:tst:628"/>
          <criterion comment="/etc/krb5/krb5.conf is configured with a kerberos domain" negate="false" test_ref="oval:org.mitre.oval:tst:1153"/>
          <criterion comment="/etc/syslog.conf is configured to log &quot;debug&quot; level messages for at least daemon" negate="false" test_ref="oval:org.mitre.oval:tst:627"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:2094" version="1" class="vulnerability">
      <metadata>
        <title>BIND DoS via SIG RR Elements</title>
        <affected family="unix">
          <platform>Sun Solaris 7</platform>
          <product>Bind</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-1221" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-1221"/>
        <description>BIND 8.x through 8.3.3 allows remote attackers to cause a denial of service (crash) via SIG RR elements with invalid expiry times, which are removed from the internal BIND database and later cause a null dereference.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-01-19T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Brian Soby</contributor>
            </submitted>
            <status_change date="2005-01-24T03:40:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-02-16T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-03-09T07:56:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criteria operator="OR" comment="Solaris 7,8,or 9 installed">
            <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3145"/>
            <criterion comment="Solaris 7 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3045"/>
            <criterion comment="Solaris 9 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3051"/>
          </criteria>
          <criterion comment="Internet Domain Name Server (BIND, SUNWinamd) installed" negate="false" test_ref="oval:org.mitre.oval:tst:2626"/>
          <criterion comment="Patch 106938-07 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:623"/>
          <criterion comment="Patch 109326-10 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:622"/>
          <criterion comment="Patch 112970-03 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:2625"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="in.named running" negate="false" test_ref="oval:org.mitre.oval:tst:2624"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:2139" version="1" class="vulnerability">
      <metadata>
        <title>Kerberos 5 ASN.1 Library DoS</title>
        <affected family="unix">
          <platform>Sun Solaris 9</platform>
          <product>Kerberos5</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0644" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0644"/>
        <description>The asn1buf_skiptail function in the ASN.1 decoder library for MIT Kerberos 5 (krb5) 1.2.2 through 1.3.4 allows remote attackers to cause a denial of service (infinite loop) via a certain BER encoding.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-10-12T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Brian Soby</contributor>
            </submitted>
            <status_change date="2004-10-13T12:00:00.000-04:00">DRAFT</status_change>
            <modified date="2005-01-14T12:00:00.000-04:00" comment="Changed kerberos unknown test to solaris file contents test">
              <contributor organization="The MITRE Corporation">Brian Soby</contributor>
            </modified>
            <status_change date="2005-02-02T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-02-23T09:25:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Solaris 9 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3051"/>
          <criterion comment="Kerberos 5 installed" negate="false" test_ref="oval:org.mitre.oval:tst:648"/>
          <criterion comment="Patch 112908-15 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:616"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="/etc/krb5/krb5.conf is configured with a kerberos domain" negate="false" test_ref="oval:org.mitre.oval:tst:1153"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:2183" version="1" class="vulnerability">
      <metadata>
        <title>Sendmail Custom DNS Map Buffer Overflow</title>
        <affected family="unix">
          <platform>Sun Solaris 9</platform>
          <product>Sendmail</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-0906" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0906"/>
        <description>Buffer overflow in Sendmail before 8.12.5, when configured to use a custom DNS map to query TXT records, allows remote attackers to cause a denial of service and possibly execute arbitrary code via a malicious DNS server.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-12-22T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Brian Soby</contributor>
            </submitted>
            <status_change date="2005-01-12T12:00:00.000-04:00">DRAFT</status_change>
            <modified date="2005-01-27T12:00:00.000-04:00" comment="Removed &quot;Sendmail running&quot; configuration test.  Sendmail installs as SUID root">
              <contributor organization="The MITRE Corporation">Brian Soby</contributor>
            </modified>
            <status_change date="2005-04-20T12:13:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-05-11T05:41:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Solaris 9 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3051"/>
        <criterion comment="Sendmail - root (SUNWsndmr) installed" negate="false" test_ref="oval:org.mitre.oval:tst:608"/>
        <criterion comment="Patch 113575-01 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:607"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:2378" version="1" class="vulnerability">
      <metadata>
        <title>Multiple Buffer Overflows in libpng</title>
        <affected family="unix">
          <platform>Sun Solaris 7</platform>
          <product>libpng</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0597" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0597"/>
        <description>Multiple buffer overflows in libpng 1.2.5 and earlier, as used in multiple products, allow remote attackers to execute arbitrary code via malformed PNG images in which (1) the png_handle_tRNS function does not properly validate the length of transparency chunk (tRNS) data, or the (2) png_handle_sBIT or (3) png_handle_hIST functions do not perform sufficient bounds checking.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-12-12T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Brian Soby</contributor>
            </submitted>
            <status_change date="2005-01-24T12:04:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-02-16T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-03-09T07:56:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="Solaris 7,8,or 9 installed">
          <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3145"/>
          <criterion comment="Solaris 7 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3045"/>
          <criterion comment="Solaris 9 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3051"/>
        </criteria>
        <criterion comment="Netscape installed" negate="false" test_ref="oval:org.mitre.oval:tst:901"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:2418" version="1" class="vulnerability">
      <metadata>
        <title>Mozilla, Firefox, Thunderbird User Interface Hijacking Vulnerability</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <product>mozilla</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0764" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0764"/>
        <description>Mozilla before 1.7, Firefox before 0.9, and Thunderbird before 0.7, allow remote web sites to hijack the user interface via the "chrome" flag and XML User Interface Language (XUL) files.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-01-19T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Brian Soby</contributor>
            </submitted>
            <status_change date="2005-01-24T03:40:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-02-16T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-03-09T07:56:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="Solaris 8 or 9 installed">
          <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3145"/>
          <criterion comment="Solaris 9 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3051"/>
        </criteria>
        <criteria operator="OR" comment="Mozilla components (any SUNWmoznav/SUNWmozmail) installed">
          <criterion comment="Mozilla (SUNWmoznav) installed" negate="false" test_ref="oval:org.mitre.oval:tst:1070"/>
          <criterion comment="Mozilla Mail (SUNWmozmail) installed" negate="false" test_ref="oval:org.mitre.oval:tst:1069"/>
        </criteria>
        <criterion comment="Patch 117765-02 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:1068"/>
        <criterion comment="Patch 117767-02 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:1067"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:2423" version="1" class="vulnerability">
      <metadata>
        <title>ypxfrd File Disclosure Vulnerability</title>
        <affected family="unix">
          <platform>Sun Solaris 7</platform>
          <product>NIS</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-1199" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-1199"/>
        <description>The getdbm procedure in ypxfrd allows local users to read arbitrary files, and remote attackers to read databases outside /var/yp, via a directory traversal and symlink attack on the domain and map arguments.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-01-19T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Brian Soby</contributor>
            </submitted>
            <status_change date="2005-01-24T03:40:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-02-16T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-03-09T07:56:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criteria operator="OR" comment="Solaris 7,8,or 9 installed">
            <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3145"/>
            <criterion comment="Solaris 7 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3045"/>
            <criterion comment="Solaris 9 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3051"/>
          </criteria>
          <criterion comment="NIS Server - User (SUNWypu) installed" negate="false" test_ref="oval:org.mitre.oval:tst:547"/>
          <criterion comment="Patch 106541-24 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:546"/>
          <criterion comment="Patch 109328-03 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:545"/>
          <criterion comment="Patch 113579-01 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:544"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="ypxfrd running" negate="false" test_ref="oval:org.mitre.oval:tst:543"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:2539" version="1" class="vulnerability">
      <metadata>
        <title>BIND SIG Resource Records Buffer Overflow</title>
        <affected family="unix">
          <platform>Sun Solaris 7</platform>
          <product>Bind</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-1219" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-1219"/>
        <description>Buffer overflow in named in BIND 4 versions 4.9.10 and earlier, and 8 versions 8.3.3 and earlier, allows remote attackers to execute arbitrary code via a certain DNS server response containing SIG resource records (RR).</description>
        <oval_repository>
          <dates>
            <submitted date="2005-01-19T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Brian Soby</contributor>
            </submitted>
            <status_change date="2005-01-24T03:40:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-02-16T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-03-09T07:56:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criteria operator="OR" comment="Solaris 7,8,or 9 installed">
            <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3145"/>
            <criterion comment="Solaris 7 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3045"/>
            <criterion comment="Solaris 9 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3051"/>
          </criteria>
          <criterion comment="Internet Domain Name Server (BIND, SUNWinamd) installed" negate="false" test_ref="oval:org.mitre.oval:tst:2626"/>
          <criterion comment="Patch 106938-07 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:623"/>
          <criterion comment="Patch 109326-10 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:622"/>
          <criterion comment="Patch 112970-03 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:2625"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="in.named running" negate="false" test_ref="oval:org.mitre.oval:tst:2624"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:2572" version="1" class="vulnerability">
      <metadata>
        <title>DoS Vulnerability in libpng function png_handle_iCCP()</title>
        <affected family="unix">
          <platform>Sun Solaris 7</platform>
          <product>libpng</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0598" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0598"/>
        <description>The png_handle_iCCP function in libpng 1.2.5 and earlier allows remote attackers to cause a denial of service (application crash) via a certain PNG image that triggers a null dereference.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-12-12T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Brian Soby</contributor>
            </submitted>
            <status_change date="2005-01-24T12:04:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-02-16T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-03-09T07:56:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="Solaris 7,8,or 9 installed">
          <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3145"/>
          <criterion comment="Solaris 7 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3045"/>
          <criterion comment="Solaris 9 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3051"/>
        </criteria>
        <criterion comment="Netscape installed" negate="false" test_ref="oval:org.mitre.oval:tst:901"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:2719" version="1" class="vulnerability">
      <metadata>
        <title>Buffer Management Error in OpenSSH</title>
        <affected family="unix">
          <platform>Sun Solaris 9</platform>
          <product>OpenSSH</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0693" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0693"/>
        <description>A "buffer management error" in buffer_append_space of buffer.c for OpenSSH before 3.7 may allow remote attackers to execute arbitrary code by causing an incorrect amount of memory to be freed and corrupting the heap, a different vulnerability than CVE-2003-0695.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-12-30T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Brian Soby</contributor>
            </submitted>
            <status_change date="2005-01-12T12:41:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-02-02T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-02-23T09:25:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Solaris 9 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3051"/>
          <criterion comment="Patch 113273-04 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:485"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="sshd running" negate="false" test_ref="oval:org.mitre.oval:tst:484"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:2975" version="1" class="vulnerability">
      <metadata>
        <title>Sendmail prescan function Buffer Overflow</title>
        <affected family="unix">
          <platform>Sun Solaris 7</platform>
          <product>Sendmail</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0694" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0694"/>
        <description>The prescan function in Sendmail 8.12.9 allows remote attackers to execute arbitrary code via buffer overflow attacks, as demonstrated using the parseaddr function in parseaddr.c.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-12-29T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Brian Soby</contributor>
            </submitted>
            <status_change date="2005-01-12T12:41:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-02-02T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-02-23T09:25:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="Solaris 7,8,or 9 installed">
          <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3145"/>
          <criterion comment="Solaris 7 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3045"/>
          <criterion comment="Solaris 9 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3051"/>
        </criteria>
        <criterion comment="Sendmail - user (SUNWsndmu) installed" negate="false" test_ref="oval:org.mitre.oval:tst:587"/>
        <criterion comment="Patch 107684-10 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:466"/>
        <criterion comment="Patch 110615-10 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:465"/>
        <criterion comment="Patch 113575-05 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:464"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:3078" version="1" class="vulnerability">
      <metadata>
        <title>CDE AddSuLog Function Buffer Overflow</title>
        <affected family="unix">
          <platform>Sun Solaris 7</platform>
          <product>Common Desktop Environment</product>
        </affected>
        <reference source="CVE" ref_id="CVE-1999-0691" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-0691"/>
        <description>Buffer overflow in the AddSuLog function of the CDE dtaction utility allows local users to gain root privileges via a long user name.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-02-01T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Brian Soby</contributor>
            </submitted>
            <status_change date="2005-02-01T08:41:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-02-16T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-03-09T07:56:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Solaris 7 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3045"/>
        <criterion comment="CDE application basic runtime environment (SUNWdtbas/SUNWdtbax) installed" negate="false" test_ref="oval:org.mitre.oval:tst:459"/>
        <criterion comment="Patch 108219-01 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:458"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:3134" version="1" class="vulnerability">
      <metadata>
        <title>Mozilla CA Certificate DoS</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <product>mozilla</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0758" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0758"/>
        <description>Mozilla 1.5 through 1.7 allows a CA certificate to be imported even when their DN is the same as that of the built-in CA root certificate, which allows remote attackers to cause a denial of service to SSL pages because the malicious certificate is treated as invalid.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-01-19T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Brian Soby</contributor>
            </submitted>
            <status_change date="2005-01-24T03:40:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-02-16T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-03-09T07:56:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="Solaris 8 or 9 installed">
          <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3145"/>
          <criterion comment="Solaris 9 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3051"/>
        </criteria>
        <criteria operator="OR" comment="Mozilla components (any SUNWmoznav/SUNWmozmail) installed">
          <criterion comment="Mozilla (SUNWmoznav) installed" negate="false" test_ref="oval:org.mitre.oval:tst:1070"/>
          <criterion comment="Mozilla Mail (SUNWmozmail) installed" negate="false" test_ref="oval:org.mitre.oval:tst:1069"/>
        </criteria>
        <criterion comment="Patch 117765-02 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:1068"/>
        <criterion comment="Patch 117767-02 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:1067"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:3250" version="1" class="vulnerability">
      <metadata>
        <title>Mozilla, Firefox, Thunderbird POP3 SendUidl Buffer Overflow</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <product>mozilla</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0757" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0757"/>
        <description>Heap-based buffer overflow in the SendUidl in the POP3 capability for Mozilla before 1.7, Firefox before 0.9, and Thunderbird before 0.7, may allow remote POP3 mail servers to execute arbitrary code.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-01-19T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Brian Soby</contributor>
            </submitted>
            <status_change date="2005-01-24T03:40:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-02-16T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-03-09T07:56:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="Solaris 8 or 9 installed">
          <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3145"/>
          <criterion comment="Solaris 9 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3051"/>
        </criteria>
        <criteria operator="OR" comment="Mozilla components (any SUNWmoznav/SUNWmozmail) installed">
          <criterion comment="Mozilla (SUNWmoznav) installed" negate="false" test_ref="oval:org.mitre.oval:tst:1070"/>
          <criterion comment="Mozilla Mail (SUNWmozmail) installed" negate="false" test_ref="oval:org.mitre.oval:tst:1069"/>
        </criteria>
        <criterion comment="Patch 117765-02 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:1068"/>
        <criterion comment="Patch 117767-02 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:1067"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:3601" version="1" class="vulnerability">
      <metadata>
        <title>Runtime linker, ld.so.1 LD_PRELOAD Envvar Buffer Overflow</title>
        <affected family="unix">
          <platform>Sun Solaris 7</platform>
          <product>Solaris Runtime Linker</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0609" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0609"/>
        <description>Stack-based buffer overflow in the runtime linker, ld.so.1, on Solaris 2.6 through 9 allows local users to gain root privileges via a long LD_PRELOAD environment variable.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-12-29T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Brian Soby</contributor>
            </submitted>
            <status_change date="2005-01-12T12:41:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-02-02T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-02-23T09:25:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="Solaris 7,8,or 9 installed">
          <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3145"/>
          <criterion comment="Solaris 7 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3045"/>
          <criterion comment="Solaris 9 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3051"/>
        </criteria>
        <criteria operator="OR" comment="Solaris 9 OR Patch 106950-14+ OR Patch 109147-07+ installed">
          <criterion comment="Patch 106950-14 or later installed" negate="false" test_ref="oval:org.mitre.oval:tst:397"/>
          <criterion comment="Patch 109147-07 or later installed" negate="false" test_ref="oval:org.mitre.oval:tst:396"/>
          <criterion comment="Solaris 9 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3051"/>
        </criteria>
        <criterion comment="Patch 106950-14 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:397"/>
        <criterion comment="Patch 109147-07 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:396"/>
        <criterion comment="Patch 112963-09 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:395"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:3603" version="1" class="vulnerability">
      <metadata>
        <title>Mozilla, Firefox, Thunderbird Security Lock Icon Spoof Vulnerability</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <product>mozilla</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0761" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0761"/>
        <description>Mozilla before 1.7, Firefox before 0.9, and Thunderbird before 0.7, allow remote attackers to use certain redirect sequences to spoof the security lock icon that makes a web page appear to be encrypted.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-01-19T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Brian Soby</contributor>
            </submitted>
            <status_change date="2005-01-24T03:40:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-02-16T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-03-09T07:56:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="Solaris 8 or 9 installed">
          <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3145"/>
          <criterion comment="Solaris 9 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3051"/>
        </criteria>
        <criteria operator="OR" comment="Mozilla components (any SUNWmoznav/SUNWmozmail) installed">
          <criterion comment="Mozilla (SUNWmoznav) installed" negate="false" test_ref="oval:org.mitre.oval:tst:1070"/>
          <criterion comment="Mozilla Mail (SUNWmozmail) installed" negate="false" test_ref="oval:org.mitre.oval:tst:1069"/>
        </criteria>
        <criterion comment="Patch 117765-02 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:1068"/>
        <criterion comment="Patch 117767-02 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:1067"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:3637" version="1" class="vulnerability">
      <metadata>
        <title>priocntl Directory Traversal Vulnerability</title>
        <affected family="unix">
          <platform>Sun Solaris 7</platform>
          <platform>Sun Solaris 8</platform>
          <platform>Sun Solaris 9</platform>
          <product>priocntl()</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-1296" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-1296"/>
        <description>Directory traversal vulnerability in priocntl system call in Solaris does allows local users to execute arbitrary code via ".." sequences in the pc_clname field of a pcinfo_t structure, which cause priocntl to load a malicious kernel module.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-02-01T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Brian Soby</contributor>
            </submitted>
            <status_change date="2005-02-01T08:41:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-02-16T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-03-09T07:56:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="Solaris 7,8,or 9 installed">
          <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3145"/>
          <criterion comment="Solaris 7 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3045"/>
          <criterion comment="Solaris 9 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3051"/>
        </criteria>
        <criterion comment="Patch 106541-24 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:546"/>
        <criterion comment="Patch 108528-18 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:390"/>
        <criterion comment="Patch 112233-04 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:389"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:3989" version="1" class="vulnerability">
      <metadata>
        <title>Mozilla Firefox Certificate Spoofing Vulnerability</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <product>mozilla</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0763" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0763"/>
        <description>Mozilla Firefox 0.9.1 and 0.9.2 allows remote web sites to spoof certificates of trusted web sites via redirects and Javascript that uses the "onunload" method.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-01-19T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Brian Soby</contributor>
            </submitted>
            <status_change date="2005-01-24T03:40:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-02-16T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-03-09T07:56:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="Solaris 8 or 9 installed">
          <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3145"/>
          <criterion comment="Solaris 9 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3051"/>
        </criteria>
        <criteria operator="OR" comment="Mozilla components (any SUNWmoznav/SUNWmozmail) installed">
          <criterion comment="Mozilla (SUNWmoznav) installed" negate="false" test_ref="oval:org.mitre.oval:tst:1070"/>
          <criterion comment="Mozilla Mail (SUNWmozmail) installed" negate="false" test_ref="oval:org.mitre.oval:tst:1069"/>
        </criteria>
        <criterion comment="Patch 117765-02 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:1068"/>
        <criterion comment="Patch 117767-02 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:1067"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:4098" version="1" class="vulnerability">
      <metadata>
        <title>Multiple Vulnerabilities in lpstat and libprint</title>
        <affected family="unix">
          <platform>Sun Solaris 7</platform>
          <product>lpstat, libprint</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0999" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0999"/>
        <description>Unknown multiple vulnerabilities in (1) lpstat and (2) the libprint library in Solaris 2.6 through 9 may allow attackers to execute arbitrary code or read or write arbitrary files.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-01-19T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Brian Soby</contributor>
            </submitted>
            <status_change date="2005-01-24T03:40:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-02-16T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-03-09T07:56:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="Solaris 7,8,or 9 installed">
          <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3145"/>
          <criterion comment="Solaris 7 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3045"/>
          <criterion comment="Solaris 9 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3051"/>
        </criteria>
        <criteria operator="OR" comment="Solaris Printing Services installed (any SUNWpcr/SUNWpcu/SUNWpsr/SUNWpsu)">
          <criterion comment="Solaris Print - Client - Root (SUNWpcr) installed" negate="false" test_ref="oval:org.mitre.oval:tst:352"/>
          <criterion comment="Solaris Print - Client - Usr (SUNWpcu) installed" negate="false" test_ref="oval:org.mitre.oval:tst:351"/>
          <criterion comment="Solaris Print - LP Server - Root (SUNWpsr) installed" negate="false" test_ref="oval:org.mitre.oval:tst:350"/>
          <criterion comment="Solaris Print - LP Server - Usr (SUNWpsu) installed" negate="false" test_ref="oval:org.mitre.oval:tst:349"/>
        </criteria>
        <criterion comment="Patch 107115-13 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:348"/>
        <criterion comment="Patch 109320-07 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:347"/>
        <criterion comment="Patch 113329-02 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:346"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:4190" version="1" class="vulnerability">
      <metadata>
        <title>Buffer Overflow in DNS Resolver Library</title>
        <affected family="unix">
          <platform>Sun Solaris 7</platform>
          <product>Bind</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-0651" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0651"/>
        <description>Buffer overflow in the DNS resolver code used in libc, glibc, and libbind, as derived from ISC BIND, allows remote malicious DNS servers to cause a denial of service and possibly execute arbitrary code via the stub resolvers.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-01-19T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Brian Soby</contributor>
            </submitted>
            <status_change date="2005-01-24T03:40:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-02-16T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-03-09T07:56:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criteria operator="OR" comment="Solaris 7,8,or 9 installed">
            <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3145"/>
            <criterion comment="Solaris 7 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3045"/>
            <criterion comment="Solaris 9 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3051"/>
          </criteria>
          <criterion comment="Patch 106938-06 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:345"/>
          <criterion comment="Patch 109326-09 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:344"/>
          <criterion comment="Patch 112970-02 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:343"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="/etc/nsswitch.conf configured to resolve hosts through DNS" negate="false" test_ref="oval:org.mitre.oval:tst:342"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:4374" version="1" class="vulnerability">
      <metadata>
        <title>ToolTalk Buffer Overflow via TT_SESSION Envvar</title>
        <affected family="unix">
          <platform>Sun Solaris 7</platform>
          <product>Common Desktop Environment</product>
        </affected>
        <reference source="CVE" ref_id="CVE-1999-0693" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-0693"/>
        <description>Buffer overflow in TT_SESSION environment variable in ToolTalk shared library allows local users to gain root privileges.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-02-01T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Brian Soby</contributor>
            </submitted>
            <status_change date="2005-02-01T08:41:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-02-16T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-03-09T07:56:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Solaris 7 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3045"/>
        <criterion comment="CDE Desktop Window Manager (SUNWdtwm) installed" negate="false" test_ref="oval:org.mitre.oval:tst:675"/>
        <criterion comment="Patch 107893-05 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:331"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:4383" version="1" class="vulnerability">
      <metadata>
        <title>lpq Buffer Overflow in bsd_queue()</title>
        <affected family="unix">
          <platform>Sun Solaris 7</platform>
          <product>lpstat</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0091" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0091"/>
        <description>Stack-based buffer overflow in the bsd_queue() function for lpq on Solaris 2.6 and 7 allows local users to gain root privilege.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-02-01T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Brian Soby</contributor>
            </submitted>
            <status_change date="2005-02-01T08:41:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-02-16T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-03-09T07:56:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Solaris 7 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3045"/>
        <criterion comment="SunSoft Print - Client - Usr (SUNWpcu) installed" negate="false" test_ref="oval:org.mitre.oval:tst:753"/>
        <criterion comment="Patch 107115-12 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:330"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:4403" version="1" class="vulnerability">
      <metadata>
        <title>Mozilla, Firefox, Thunderbird XPInstall Security Vulnerability</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <product>mozilla</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0762" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0762"/>
        <description>Mozilla before 1.7, Firefox before 0.9, and Thunderbird before 0.7, allow remote web sites to install arbitrary extensions by using interactive events to manipulate the XPInstall Security dialog box.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-01-19T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Brian Soby</contributor>
            </submitted>
            <status_change date="2005-01-24T03:40:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-02-16T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-03-09T07:56:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="Solaris 8 or 9 installed">
          <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3145"/>
          <criterion comment="Solaris 9 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3051"/>
        </criteria>
        <criteria operator="OR" comment="Mozilla components (any SUNWmoznav/SUNWmozmail) installed">
          <criterion comment="Mozilla (SUNWmoznav) installed" negate="false" test_ref="oval:org.mitre.oval:tst:1070"/>
          <criterion comment="Mozilla Mail (SUNWmozmail) installed" negate="false" test_ref="oval:org.mitre.oval:tst:1069"/>
        </criteria>
        <criterion comment="Patch 117765-02 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:1068"/>
        <criterion comment="Patch 117767-02 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:1067"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:4629" version="1" class="vulnerability">
      <metadata>
        <title>Mozilla, Netscape SOAPParameter Integer Overflow</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <product>mozilla</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0722" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0722"/>
        <description>Integer overflow in the SOAPParameter object constructor in (1) Netscape version 7.0 and 7.1 and (2) Mozilla 1.6, and possibly earlier versions, allows remote attackers to execute arbitrary code.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-01-19T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Brian Soby</contributor>
            </submitted>
            <status_change date="2005-01-24T03:40:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-02-16T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-03-09T07:56:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="Solaris 8 or 9 installed">
          <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3145"/>
          <criterion comment="Solaris 9 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3051"/>
        </criteria>
        <criteria operator="OR" comment="Mozilla components (any SUNWmoznav/SUNWmozmail) installed">
          <criterion comment="Mozilla (SUNWmoznav) installed" negate="false" test_ref="oval:org.mitre.oval:tst:1070"/>
          <criterion comment="Mozilla Mail (SUNWmozmail) installed" negate="false" test_ref="oval:org.mitre.oval:tst:1069"/>
        </criteria>
        <criterion comment="Patch 117765-02 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:1068"/>
        <criterion comment="Patch 117767-02 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:1067"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:4756" version="1" class="vulnerability">
      <metadata>
        <title>Mozilla, Firebird, Firefox Frame Injection Vulnerability</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <product>mozilla</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0718" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0718"/>
        <description>The (1) Mozilla 1.6, (2) Firebird 0.7, (3) Firefox 0.8, and (4) Netscape 7.1 web browsers do not properly prevent a frame in one domain from injecting content into a frame that belongs to another domain, which facilitates web site spoofing and other attacks, aka the frame injection vulnerability.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-01-19T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Brian Soby</contributor>
            </submitted>
            <status_change date="2005-01-24T03:40:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-02-16T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-03-09T07:56:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="Solaris 8 or 9 installed">
          <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3145"/>
          <criterion comment="Solaris 9 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3051"/>
        </criteria>
        <criteria operator="OR" comment="Mozilla components (any SUNWmoznav/SUNWmozmail) installed">
          <criterion comment="Mozilla (SUNWmoznav) installed" negate="false" test_ref="oval:org.mitre.oval:tst:1070"/>
          <criterion comment="Mozilla Mail (SUNWmozmail) installed" negate="false" test_ref="oval:org.mitre.oval:tst:1069"/>
        </criteria>
        <criterion comment="Patch 117765-02 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:1068"/>
        <criterion comment="Patch 117767-02 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:1067"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:592" version="1" class="vulnerability">
      <metadata>
        <title>rwho daemon Code Execution Vulnerability</title>
        <affected family="unix">
          <platform>Sun Solaris 7</platform>
          <platform>Sun Solaris 8</platform>
          <platform>Sun Solaris 9</platform>
          <product>Licence Logging Service</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-1351" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1351"/>
        <description>Unknown vulnerability in the rwho daemon (in.rwhod) for Solaris 7 through 9 allows remote attackers to execute arbitrary code.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-04-13T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Brian Soby</contributor>
            </submitted>
            <status_change date="2005-04-20T12:13:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-05-11T05:41:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-06-01T03:30:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criteria operator="OR" comment="Solaris 7 or 8 OR Solaris 9 and Remote Network Server Commands (SUNWrcmds) installed">
            <criteria operator="OR" comment="Solaris 7 or 8 installed">
              <criterion comment="Solaris 7 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3045"/>
              <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3145"/>
            </criteria>
            <criteria operator="AND" comment="Solaris 9 and Remote Network Server Commands (SUNWrcmds) installed">
              <criterion comment="Solaris 9 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3051"/>
              <criterion comment="Remote Network Server Commands - Usr (SUNWrcmds) installed" negate="false" test_ref="oval:org.mitre.oval:tst:2525"/>
            </criteria>
          </criteria>
          <criterion comment="Patch 118239-01 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:2524"/>
          <criterion comment="Patch 116984-01 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:2523"/>
          <criterion comment="Patch 117455-01 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:2522"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="in.rwhod is running" negate="false" test_ref="oval:org.mitre.oval:tst:2521"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1654" version="1" class="vulnerability">
      <metadata>
        <title>gzip -force File Permission Alteration Vulnerability</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <product>Licence Logging Service</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-1349" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1349"/>
        <description>gzip before 1.3 in Solaris 8, when called with the -f or -force flags, will change the permissions of files that are hard linked to the target files, which allows local users to view or modify these files.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-04-13T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Brian Soby</contributor>
            </submitted>
            <status_change date="2005-04-20T12:13:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-05-11T05:41:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-06-01T03:30:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3145"/>
        <criterion comment="GNU Zip (gzip, SUNWgzip) installed" negate="false" test_ref="oval:org.mitre.oval:tst:790"/>
        <criterion comment="Patch 112668-02 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:789"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:2222" version="1" class="vulnerability">
      <metadata>
        <title>Sendmail Address Processor Buffer Overflow</title>
        <affected family="unix">
          <platform>Sun Solaris 7</platform>
          <platform>Sun Solaris 8</platform>
          <platform>Sun Solaris 9</platform>
          <product>Sendmail</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-1337" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-1337"/>
        <description>Buffer overflow in Sendmail 5.79 to 8.12.7 allows remote attackers to execute arbitrary code via certain formatted address fields, related to sender and recipient header comments as processed by the crackaddr function of headers.c.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-04-13T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Brian Soby</contributor>
            </submitted>
            <status_change date="2005-04-20T12:13:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-05-11T05:41:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-06-01T03:30:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criteria operator="OR" comment="Solaris 7,8,or 9 installed">
            <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3145"/>
            <criterion comment="Solaris 7 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3045"/>
            <criterion comment="Solaris 9 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3051"/>
          </criteria>
          <criterion comment="Sendmail - user (SUNWsndmu) installed" negate="false" test_ref="oval:org.mitre.oval:tst:587"/>
          <criterion comment="Patch 107684-08 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:586"/>
          <criterion comment="Patch 110615-08 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:585"/>
          <criterion comment="Patch 113575-03 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:584"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="Sendmail running" negate="false" test_ref="oval:org.mitre.oval:tst:583"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:2248" version="1" class="vulnerability">
      <metadata>
        <title>Sun RPC No Timeout Denial of Service on TCP Ports</title>
        <affected family="unix">
          <platform>Sun Solaris 7</platform>
          <product>libc</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-1265" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-1265"/>
        <description>The Sun RPC functionality in multiple libc implementations does not provide a time-out mechanism when reading data from TCP connections, which allows remote attackers to cause a denial of service (hang).</description>
        <oval_repository>
          <dates>
            <submitted date="2005-04-13T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Brian Soby</contributor>
            </submitted>
            <status_change date="2005-04-20T12:13:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-05-11T05:41:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-06-01T03:30:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Solaris 7 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3045"/>
          <criteria operator="AND" comment="All RPC w/TCP patches installed - CVE-2002-1265">
            <criterion comment="Patch 108748-01 or later installed" negate="false" test_ref="oval:org.mitre.oval:tst:581"/>
            <criterion comment="Patch 108750-01 or later installed" negate="false" test_ref="oval:org.mitre.oval:tst:580"/>
            <criteria operator="OR" comment="Patches 108752-01 or 106541-14 installed">
              <criterion comment="Patch 108752-01 or later installed" negate="false" test_ref="oval:org.mitre.oval:tst:579"/>
              <criterion comment="Patch 106541-14 or later installed" negate="false" test_ref="oval:org.mitre.oval:tst:578"/>
            </criteria>
            <criterion comment="Patch 106942-09 or later installed" negate="false" test_ref="oval:org.mitre.oval:tst:577"/>
            <criterion comment="Patch 107477-03 or later installed" negate="false" test_ref="oval:org.mitre.oval:tst:576"/>
            <criterion comment="Patch 108551-03 or later installed" negate="false" test_ref="oval:org.mitre.oval:tst:575"/>
            <criterion comment="Patch 108754-01 or later installed" negate="false" test_ref="oval:org.mitre.oval:tst:574"/>
            <criterion comment="Patch 108756-01 or later installed" negate="false" test_ref="oval:org.mitre.oval:tst:573"/>
            <criterion comment="Patch 108758-01 or later installed" negate="false" test_ref="oval:org.mitre.oval:tst:572"/>
            <criterion comment="Patch 108760-01 or later installed" negate="false" test_ref="oval:org.mitre.oval:tst:571"/>
            <criterion comment="Patch 108762-01 or later installed" negate="false" test_ref="oval:org.mitre.oval:tst:570"/>
            <criterion comment="Patch 108764-01 or later installed" negate="false" test_ref="oval:org.mitre.oval:tst:569"/>
          </criteria>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="rpcbind running" negate="false" test_ref="oval:org.mitre.oval:tst:568"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:3400" version="1" class="vulnerability">
      <metadata>
        <title>Buffer Overflow in Solaris ping Daemon</title>
        <affected family="unix">
          <platform>Sun Solaris 7</platform>
          <platform>Sun Solaris 8</platform>
          <platform>Sun Solaris 9</platform>
          <product>Licence Logging Service</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-1352" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1352"/>
        <description>Buffer overflow in the ping daemon of Sun Solaris 7 through 9 may allow local users to execute arbitrary code.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-04-13T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Brian Soby</contributor>
            </submitted>
            <status_change date="2005-04-20T12:13:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-05-11T05:41:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-06-01T03:30:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="Solaris 7 or 8 OR Solaris 9 and Solaris Basic IP Commands (SUNWbip) installed">
          <criteria operator="OR" comment="Solaris 7 or 8 installed">
            <criterion comment="Solaris 7 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3045"/>
            <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3145"/>
          </criteria>
          <criteria operator="AND" comment="Solaris 9 and Solaris Basic IP Commands (SUNWbip) installed">
            <criterion comment="Solaris 9 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3051"/>
            <criterion comment="Solaris Basic IP Commands (SUNWbip) installed" negate="false" test_ref="oval:org.mitre.oval:tst:433"/>
          </criteria>
        </criteria>
        <criterion comment="Patch 118313-01 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:432"/>
        <criterion comment="Patch 116986-02 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:431"/>
        <criterion comment="Patch 116774-03 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:430"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:3567" version="1" class="vulnerability">
      <metadata>
        <title>Patches Disable Basic Security Module Auditing Functionality</title>
        <affected family="unix">
          <platform>Sun Solaris 9</platform>
          <product>Basic Security Module</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-1358" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1358"/>
        <description>The patches (1) 114332-08 and (2) 114929-06 for Sun Solaris 9 disable the auditing functionality of the Basic Security Module (BSM), which allows attackers to avoid having their activity logged.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-04-13T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Brian Soby</contributor>
            </submitted>
            <status_change date="2005-04-20T12:13:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-05-11T05:41:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-06-01T03:30:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Solaris 9 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3051"/>
          <criterion comment="Patch 114332-08 installed" negate="false" test_ref="oval:org.mitre.oval:tst:406"/>
          <criterion comment="Patch 114332-10 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:405"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="/etc/system has BSM enabled" negate="false" test_ref="oval:org.mitre.oval:tst:404"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:3831" version="1" class="vulnerability">
      <metadata>
        <title>Buffer Overflow in ntp Daemon via readvar</title>
        <affected family="unix">
          <platform>Sun Solaris 7</platform>
          <platform>Sun Solaris 8</platform>
          <product>sendfilev()</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2001-0414" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-0414"/>
        <description>Buffer overflow in ntpd ntp daemon 4.0.99k and earlier (aka xntpd and xntp3) allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long readvar argument.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-04-13T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Brian Soby</contributor>
            </submitted>
            <status_change date="2005-04-20T12:13:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-05-11T05:41:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-06-01T03:30:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criteria operator="OR" comment="Solaris 7 or 8 installed">
            <criterion comment="Solaris 7 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3045"/>
            <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3145"/>
          </criteria>
          <criterion comment="NTP daemon - Usr (SUNWntpu) installed" negate="false" test_ref="oval:org.mitre.oval:tst:379"/>
          <criterion comment="Patch 109409-04 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:378"/>
          <criterion comment="Patch 109667-04 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:377"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="xntpd running" negate="false" test_ref="oval:org.mitre.oval:tst:376"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:3960" version="1" class="vulnerability">
      <metadata>
        <title>in.named Process Crash Vulnerability</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <product>Bind</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-1348" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1348"/>
        <description>Unknown vulnerability in in.named on Solaris 8 allows remote attackers to cause a denial of service (process crash).</description>
        <oval_repository>
          <dates>
            <submitted date="2005-04-13T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Brian Soby</contributor>
            </submitted>
            <status_change date="2005-04-20T12:13:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-05-11T05:41:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-06-01T03:30:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3145"/>
          <criterion comment="Internet Domain Name Server (BIND, SUNWinamd) installed" negate="false" test_ref="oval:org.mitre.oval:tst:2626"/>
          <criterion comment="Patch 109326-16 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:372"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="File /etc/named.conf exists" negate="false" test_ref="oval:org.mitre.oval:tst:371"/>
          <criterion comment="in.named running" negate="false" test_ref="oval:org.mitre.oval:tst:2624"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:2002" version="2" class="vulnerability">
      <metadata>
        <title>Multiple Buffer Overflows in Kerberos 5 (krb5_aname_to_localname)</title>
        <affected family="unix">
          <platform>Sun Solaris 7</platform>
          <product>Solaris Enterprise Authentication Mechanism (SEAM)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0523" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0523"/>
        <description>Multiple buffer overflows in krb5_aname_to_localname for MIT Kerberos 5 (krb5) 1.3.3 and earlier allow remote attackers to execute arbitrary code as root.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-10-11T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Brian Soby</contributor>
            </submitted>
            <status_change date="2004-10-13T12:00:00.000-04:00">DRAFT</status_change>
            <modified date="2005-01-14T12:00:00.000-04:00" comment="Changed two unknown tests for kerberos configuration to Solaris text file contents tests">
              <contributor organization="The MITRE Corporation">Brian Soby</contributor>
            </modified>
            <status_change date="2005-02-02T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-02-23T09:25:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-07-03T12:56:00.000-04:00" comment="Added negate=true attribute to criteria sub-block to fix conversion error from OVAL 4.2 to OVAL 5.0">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2006-07-03T12:56:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-09-27T12:29:12.225-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Kerberos 5 installed" negate="false" test_ref="oval:org.mitre.oval:tst:648"/>
          <criteria operator="OR" comment="Solaris 7,8,or 9 installed">
            <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3145"/>
            <criterion comment="Solaris 7 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3045"/>
            <criterion comment="Solaris 9 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3051"/>
          </criteria>
          <criterion comment="Patch 112908-16 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:647"/>
          <criterion comment="Patch 112536-05 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:646"/>
          <criteria operator="AND" comment="Patches 112237-11 and 112390-09 or greater installed" negate="true">
            <criterion comment="Patch 112237-11 or later installed" negate="false" test_ref="oval:org.mitre.oval:tst:645"/>
            <criterion comment="Patch 112390-09 or later installed" negate="false" test_ref="oval:org.mitre.oval:tst:644"/>
          </criteria>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="/etc/krb5/krb5.conf is configured with a kerberos domain" negate="false" test_ref="oval:org.mitre.oval:tst:1153"/>
          <criterion comment="/etc/krb5/krb5.conf is configured with explicit or rules-based mapping" negate="false" test_ref="oval:org.mitre.oval:tst:643"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:2536" version="2" class="vulnerability">
      <metadata>
        <title>Kerberos 5 KDC Heap Corruption Vulnerability</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <product>Kerberos5</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0082" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0082"/>
        <description>The Key Distribution Center (KDC) in Kerberos 5 (krb5) 1.2.7 and earlier allows remote, authenticated attackers to cause a denial of service (crash) on KDCs within the same realm using a certain protocol request that causes the KDC to corrupt its heap (aka "buffer underrun").</description>
        <oval_repository>
          <dates>
            <submitted date="2005-01-19T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Brian Soby</contributor>
            </submitted>
            <status_change date="2005-01-24T03:40:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-02-16T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-03-09T07:56:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-07-03T12:56:00.000-04:00" comment="Added negate=true attribute to criteria sub-block to fix conversion error from OVAL 4.2 to OVAL 5.0">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2006-07-03T12:56:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-09-27T12:29:18.623-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <notes>
        <note>Vulnerability exists in standard Solaris kerberos and SEAM.  This definition only covers Solaris kerberos</note>
      </notes>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criteria operator="OR" comment="Solaris 8 or 9 installed">
            <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3145"/>
            <criterion comment="Solaris 9 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3051"/>
          </criteria>
          <criteria operator="OR" comment="Kerberos v5 (any SUNWkrbr/SUNWkrbu/SUNWkrbux) installed">
            <criterion comment="Kerberos v5 - Root (SUNWkrbr) installed" negate="false" test_ref="oval:org.mitre.oval:tst:527"/>
            <criterion comment="Kerberos v5 - Usr (SUNWkrbu/SUNWkrbux) installed" negate="false" test_ref="oval:org.mitre.oval:tst:526"/>
          </criteria>
          <criteria operator="AND" comment="Patches 112237-09 and 112390-08 or later installed" negate="true">
            <criterion comment="Patch 112237-09 or later installed" negate="false" test_ref="oval:org.mitre.oval:tst:525"/>
            <criterion comment="Patch 112390-08 or later installed" negate="false" test_ref="oval:org.mitre.oval:tst:524"/>
          </criteria>
          <criteria operator="AND" comment="Patches 112925-03,112923-03,112921-02, and 112908-10 or later installed" negate="true">
            <criterion comment="Patch 112925-03 or later installed" negate="false" test_ref="oval:org.mitre.oval:tst:523"/>
            <criterion comment="Patch 112923-03 or later installed" negate="false" test_ref="oval:org.mitre.oval:tst:522"/>
            <criterion comment="Patch 112921-02 or later installed" negate="false" test_ref="oval:org.mitre.oval:tst:521"/>
            <criterion comment="Patch 112908-10 or later installed" negate="false" test_ref="oval:org.mitre.oval:tst:520"/>
          </criteria>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="/etc/krb5/krb5.conf is configured with a kerberos domain" negate="false" test_ref="oval:org.mitre.oval:tst:1153"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:4430" version="2" class="vulnerability">
      <metadata>
        <title>Kerberos 5 KDC Buffer Underrun in Principle Name Handling</title>
        <affected family="unix">
          <platform>Sun Solaris 7</platform>
          <product>Solaris Enterprise Authentication Mechanism (SEAM)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0082" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0082"/>
        <description>The Key Distribution Center (KDC) in Kerberos 5 (krb5) 1.2.7 and earlier allows remote, authenticated attackers to cause a denial of service (crash) on KDCs within the same realm using a certain protocol request that causes the KDC to corrupt its heap (aka "buffer underrun").</description>
        <oval_repository>
          <dates>
            <submitted date="2005-01-19T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Brian Soby</contributor>
            </submitted>
            <status_change date="2005-01-24T03:40:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-02-16T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-03-09T07:56:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-07-03T12:56:00.000-04:00" comment="Added negate=true attribute to criteria sub-block to fix conversion error from OVAL 4.2 to OVAL 5.0">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2006-07-03T12:56:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-09-27T12:29:26.851-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <notes>
        <note>Vulnerability exists in standard Solaris kerberos and SEAM.  This definition only covers SEAM</note>
      </notes>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="Solaris 7,8,or 9 installed">
          <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3145"/>
          <criterion comment="Solaris 7 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3045"/>
          <criterion comment="Solaris 9 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3051"/>
        </criteria>
        <criterion comment="Sun Enterprise Authentication Mechanism (SEAM, SUNWkr5sv) installed" negate="false" test_ref="oval:org.mitre.oval:tst:1161"/>
        <criteria operator="AND" comment="Patches 112536-04 and 110057-07 or later installed" negate="true">
          <criterion comment="Patch 112536-04 or later installed" negate="false" test_ref="oval:org.mitre.oval:tst:325"/>
          <criterion comment="Patch 110057-07 or later installed" negate="false" test_ref="oval:org.mitre.oval:tst:324"/>
        </criteria>
        <criterion comment="Patch 110060-04 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:323"/>
        <criterion comment="Patch 116462-01 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:322"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:4728" version="2" class="vulnerability">
      <metadata>
        <title>SunRPC xdr_array Function Integer Overflow</title>
        <affected family="unix">
          <platform>Sun Solaris 7</platform>
          <product>Sun RPC</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-0391" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0391"/>
        <description>Integer overflow in xdr_array function in RPC servers for operating systems that use libc, glibc, or other code based on SunRPC including dietlibc, allows remote attackers to execute arbitrary code by passing a large number of arguments to xdr_array through RPC services such as rpc.cmsd and dmispd.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-01-19T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Brian Soby</contributor>
            </submitted>
            <status_change date="2005-01-24T03:40:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-02-16T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-03-09T07:56:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-07-03T12:56:00.000-04:00" comment="Added negate=true attribute to criteria sub-block to fix conversion error from OVAL 4.2 to OVAL 5.0">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2006-07-03T12:56:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-09-27T12:29:27.565-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <notes>
        <note>Specific applications using this library are not tested for because Suns advisory only provides a sample of known vulnerable applications and states that they are still investigating.</note>
      </notes>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="Solaris 7,8,or 9 installed">
          <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3145"/>
          <criterion comment="Solaris 7 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3045"/>
          <criterion comment="Solaris 9 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3051"/>
        </criteria>
        <criteria operator="AND" comment="Patches 106942-22 and 108451-06 or later installed" negate="true">
          <criterion comment="Patch 106942-22 or later installed" negate="false" test_ref="oval:org.mitre.oval:tst:3026"/>
          <criterion comment="Patch 108451-06 or later installed" negate="false" test_ref="oval:org.mitre.oval:tst:310"/>
        </criteria>
        <criteria operator="AND" comment="Patches 108827-30 and 108901-06" negate="true">
          <criterion comment="Patch 108827-30 or later installed" negate="false" test_ref="oval:org.mitre.oval:tst:3138"/>
          <criterion comment="Patch 108901-06 or later installed" negate="false" test_ref="oval:org.mitre.oval:tst:3137"/>
        </criteria>
        <criteria operator="AND" comment="Patches 113319-01 and 112233-02 or later installed" negate="true">
          <criterion comment="Patch 113319-01 or later installed" negate="false" test_ref="oval:org.mitre.oval:tst:309"/>
          <criterion comment="Patch 112233-02 or later installed" negate="false" test_ref="oval:org.mitre.oval:tst:308"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:4047" version="2" class="vulnerability">
      <metadata>
        <title>Shell Redirect Symlink Attack Vulnerability</title>
        <affected family="unix">
          <platform>Sun Solaris 7</platform>
          <platform>Sun Solaris 8</platform>
          <product>Bourne Shell (sh)</product>
          <product>Bourne Again Shell (bash)</product>
          <product>TENEX C Shell (tcsh)</product>
          <product>C Shell (csh)</product>
          <product>Korn Shell (ksh)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2000-1134" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2000-1134"/>
        <description>Multiple shell programs on various Unix systems, including (1) tcsh, (2) csh, (3) sh, and (4) bash, follow symlinks when processing &lt;&lt; redirects (aka here-documents or in-here documents), which allows local users to overwrite files of other users via a symlink attack.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-01-19T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Brian Soby</contributor>
            </submitted>
            <status_change date="2005-01-24T03:40:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-02-16T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-03-09T07:56:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-06-13T03:18:00.000-04:00" comment="Added Sun Solaris 8 to list of platforms in Affected metadata.">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2006-06-14T07:41:00.000-04:00">INTERIM</status_change>
            <modified date="2006-07-03T12:56:00.000-04:00" comment="Added negate=true attribute to criteria sub-block to fix conversion error from OVAL 4.2 to OVAL 5.0">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2006-09-27T12:29:23.796-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="Solaris 7 or 8 installed">
          <criterion comment="Solaris 7 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3045"/>
          <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3145"/>
        </criteria>
        <criteria operator="AND" comment="Patches 108574-03, 108162-04, and 108416-02 or later installed" negate="true">
          <criterion comment="Patch 108574-03 or later installed" negate="false" test_ref="oval:org.mitre.oval:tst:358"/>
          <criterion comment="Patch 108162-04 or later installed" negate="false" test_ref="oval:org.mitre.oval:tst:357"/>
          <criterion comment="Patch 108416-02 or later installed" negate="false" test_ref="oval:org.mitre.oval:tst:356"/>
        </criteria>
        <criteria operator="AND" comment="Patches 110943-01, 110898-02, and 109324-03 or later installed" negate="true">
          <criterion comment="Patch 110943-01 or later installed" negate="false" test_ref="oval:org.mitre.oval:tst:355"/>
          <criterion comment="Patch 110898-02 or later installed" negate="false" test_ref="oval:org.mitre.oval:tst:354"/>
          <criterion comment="Patch 109324-03 or later installed" negate="false" test_ref="oval:org.mitre.oval:tst:353"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:2025" version="1" class="vulnerability">
      <metadata>
        <title>System V login Buffer Overflow</title>
        <affected family="unix">
          <platform>Sun Solaris 7</platform>
          <product>login</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2001-0797" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-0797"/>
        <description>Buffer overflow in login in various System V based operating systems allows remote attackers to execute arbitrary commands via a large number of arguments through services such as telnet and rlogin.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-12-29T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Brian Soby</contributor>
            </submitted>
            <status_change date="2005-01-12T12:41:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-02-02T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-02-23T09:25:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="Solaris 7 or 8 installed">
          <criterion comment="Solaris 7 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3045"/>
          <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3145"/>
        </criteria>
        <criterion comment="Patch 112300-01 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:635"/>
        <criterion comment="Patch 111085-02 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:634"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1110" version="1" class="vulnerability">
      <metadata>
        <title>Kerberos V5 Null Pointer DoS Vulnerability</title>
        <affected family="unix">
          <platform>Sun Solaris 7</platform>
          <platform>Sun Solaris 8</platform>
          <platform>Sun Solaris 9</platform>
          <product>Solaris Enterprise Authentication Mechanism (SEAM)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0058" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0058"/>
        <description>MIT Kerberos V5 Key Distribution Center (KDC) before 1.2.5 allows remote authenticated attackers to cause a denial of service (crash) on KDCs within the same realm via a certain protocol request that causes a null dereference.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-02-01T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Brian Soby</contributor>
            </submitted>
            <status_change date="2005-02-01T08:41:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-02-16T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-03-09T07:56:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criteria operator="OR" comment="Solaris 7 and Solaris Enterprise Authentication Mechanism OR Solaris 8 or 9 installed">
            <criteria operator="AND" comment="Solaris 7 AND Solaris Enterprise Authentication Mechanism installed">
              <criterion comment="Solaris 7 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3045"/>
              <criteria operator="OR" comment="Solaris Enterprise Authentication Mechanism (ANY SUNWkr5sl/SUNWkr5sv/SUNWkrgdo/SUNWkrggl)">
                <criterion comment="Sun Enterprise Authentication Mechanism (SEAM, SUNWkr5sv) installed" negate="false" test_ref="oval:org.mitre.oval:tst:1161"/>
                <criterion comment=" Sun Enterprise Authentication Mechanism (SEAM, SUNWkr5sl) installed" negate="false" test_ref="oval:org.mitre.oval:tst:1160"/>
                <criterion comment=" Sun Enterprise Authentication Mechanism (SEAM, SUNWkrgdo) installed" negate="false" test_ref="oval:org.mitre.oval:tst:1159"/>
                <criterion comment=" Sun Enterprise Authentication Mechanism (SEAM, SUNWkrggl) installed" negate="false" test_ref="oval:org.mitre.oval:tst:1158"/>
              </criteria>
            </criteria>
            <criteria operator="OR" comment="Solaris 8 or 9 installed">
              <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3145"/>
              <criterion comment="Solaris 9 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3051"/>
            </criteria>
          </criteria>
          <criterion comment="Patch 112536-02 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:1157"/>
          <criterion comment="Patch 112908-04 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:1156"/>
          <criterion comment="Patch 112237-07 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:1155"/>
          <criterion comment="Patch 112390-07 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:1154"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="/etc/krb5/krb5.conf is configured with a kerberos domain" negate="false" test_ref="oval:org.mitre.oval:tst:1153"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1840" version="1" class="vulnerability">
      <metadata>
        <title>LDAP rootDN Password Disclosure Vulnerability</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <platform>Sun Solaris 9</platform>
          <product>LDAP</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-1782" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1782"/>
        <description>Unspecified vulnerability in Solaris 8 and 9 allows local users to obtain the LDAP Directory Server root Distinguished Name (rootDN) password when a privileged user (1) runs idsconfig; or "insecurely" runs LDAP2 commands with the -w option, including (2) ldapadd, (3) ldapdelete, (4) ldapmodify, (5) ldapmodrdn, and (6) ldapsearch.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-04-14T06:41:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-04-19T10:08:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-05-10T08:33:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-05-31T09:45:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="OR">
        <criteria operator="AND" comment="Solaris 8 (SPARC) meets Sun Alert ID 102113 criteria.">
          <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3145"/>
          <criterion comment="sparc architecture" negate="false" test_ref="oval:org.mitre.oval:tst:2465"/>
          <criterion comment="Patch 108993-14 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:700"/>
          <criterion comment="Patch 108993-51 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:699"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (SPARC) meets Sun Alert ID 102113 criteria.">
          <criterion comment="Solaris 9 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3051"/>
          <criterion comment="sparc architecture" negate="false" test_ref="oval:org.mitre.oval:tst:2465"/>
          <criterion comment="Patch 115677-02 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:698"/>
          <criterion comment="Patch 121321-01 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:697"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 8 (x86) meets Sun Alert ID 102113 criteria.">
          <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3145"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:2463"/>
          <criterion comment="Patch 108994-14 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:696"/>
          <criterion comment="Patch 108994-51 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:695"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (x86) meets Sun Alert ID 102113 criteria.">
          <criterion comment="Solaris 9 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3051"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:2463"/>
          <criterion comment="Patch 115678-02 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:694"/>
          <criterion comment="Patch 121322-01 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:693"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1786" version="1" class="vulnerability">
      <metadata>
        <title>XPM Image Decoder Malicious Color String Vulnerability</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <platform>Sun Solaris 9</platform>
          <product>Operating System</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0783" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0783"/>
        <description>Stack-based buffer overflow in xpm_extract_color (io-xpm.c) in the XPM image decoder for gtk+ 2.4.4 (gtk2) and earlier, and gdk-pixbuf before 0.22, may allow remote attackers to execute arbitrary code via a certain color string.  NOTE: this identifier is ONLY for gtk+.  It was incorrectly referenced in an advisory for a different issue (CVE-2004-0688).</description>
        <oval_repository>
          <dates>
            <submitted date="2006-03-21T04:03:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-03-22T11:10:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-04-06T06:31:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-05-03T10:06:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="OR">
        <criteria operator="AND" comment="GNOME 2.0 Solaris 8 (SPARC) meets Sun Alert ID 101776 criteria.">
          <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3145"/>
          <criterion comment="sparc architecture" negate="false" test_ref="oval:org.mitre.oval:tst:2465"/>
          <criterion comment="Gnome 2.0.0 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:818"/>
          <criterion comment="Patch 114644-03 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:817"/>
        </criteria>
        <criteria operator="AND" comment="GNOME 2.0 Solaris 8 (x86) meets Sun Alert ID 101776 criteria.">
          <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3145"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:2463"/>
          <criterion comment="Gnome 2.0.0 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:818"/>
          <criterion comment="Patch 114645-03 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:816"/>
        </criteria>
        <criteria operator="AND" comment="GNOME 2.0 Solaris 9 (SPARC) meets Sun Alert ID 101776 criteria.">
          <criterion comment="Solaris 9 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3051"/>
          <criterion comment="sparc architecture" negate="false" test_ref="oval:org.mitre.oval:tst:2465"/>
          <criterion comment="Gnome 2.0.0 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:818"/>
          <criterion comment="Patch 114686-03 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:815"/>
        </criteria>
        <criteria operator="AND" comment="GNOME 2.0.2 Solaris 9 (SPARC) meets Sun Alert ID 101776 criteria.">
          <criterion comment="Solaris 9 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3051"/>
          <criterion comment="sparc architecture" negate="false" test_ref="oval:org.mitre.oval:tst:2465"/>
          <criterion comment="Gnome 2.0.2 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:814"/>
          <criterion comment="Patch 115738-04 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:813"/>
        </criteria>
        <criteria operator="AND" comment="GNOME 2.0 Solaris 9 (x86) meets Sun Alert ID 101776 criteria.">
          <criterion comment="Solaris 9 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3051"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:2463"/>
          <criterion comment="Gnome 2.0.0 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:818"/>
          <criterion comment="Patch 114687-03 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:812"/>
        </criteria>
        <criteria operator="AND" comment="GNOME 2.0.2 Solaris 9 (x86) meets Sun Alert ID 101776 criteria.">
          <criterion comment="Solaris 9 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3051"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:2463"/>
          <criterion comment="Gnome 2.0.2 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:814"/>
          <criterion comment="Patch 115739-04 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:811"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (x86) with JDS release 2 meets Sun Alert ID 101776 criteria.">
          <criterion comment="Solaris 9 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3051"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:2463"/>
          <criterion comment="JDS release 2 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:810"/>
          <criterion comment="Patch 121092-01 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:809"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1617" version="1" class="vulnerability">
      <metadata>
        <title>XPM Image Decoder Buffer Overflow</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <platform>Sun Solaris 9</platform>
          <product>Operating System</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0782" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0782"/>
        <description>Integer overflow in pixbuf_create_from_xpm (io-xpm.c) in the XPM image decoder for gtk+ 2.4.4 (gtk2) and earlier, and gdk-pixbuf before 0.22, allows remote attackers to execute arbitrary code via certain n_col and cpp values that enable a heap-based buffer overflow.  NOTE: this identifier is ONLY for gtk+.  It was incorrectly referenced in an advisory for a different issue (CVE-2004-0687).</description>
        <oval_repository>
          <dates>
            <submitted date="2006-03-21T04:03:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-03-22T11:10:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-04-06T06:31:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-05-03T10:06:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="OR">
        <criteria operator="AND" comment="GNOME 2.0 Solaris 8 (SPARC) meets Sun Alert ID 101776 criteria.">
          <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3145"/>
          <criterion comment="sparc architecture" negate="false" test_ref="oval:org.mitre.oval:tst:2465"/>
          <criterion comment="Gnome 2.0.0 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:818"/>
          <criterion comment="Patch 114644-03 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:817"/>
        </criteria>
        <criteria operator="AND" comment="GNOME 2.0 Solaris 8 (x86) meets Sun Alert ID 101776 criteria.">
          <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3145"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:2463"/>
          <criterion comment="Gnome 2.0.0 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:818"/>
          <criterion comment="Patch 114645-03 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:816"/>
        </criteria>
        <criteria operator="AND" comment="GNOME 2.0 Solaris 9 (SPARC) meets Sun Alert ID 101776 criteria.">
          <criterion comment="Solaris 9 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3051"/>
          <criterion comment="sparc architecture" negate="false" test_ref="oval:org.mitre.oval:tst:2465"/>
          <criterion comment="Gnome 2.0.0 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:818"/>
          <criterion comment="Patch 114686-03 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:815"/>
        </criteria>
        <criteria operator="AND" comment="GNOME 2.0.2 Solaris 9 (SPARC) meets Sun Alert ID 101776 criteria.">
          <criterion comment="Solaris 9 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3051"/>
          <criterion comment="sparc architecture" negate="false" test_ref="oval:org.mitre.oval:tst:2465"/>
          <criterion comment="Gnome 2.0.2 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:814"/>
          <criterion comment="Patch 115738-04 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:813"/>
        </criteria>
        <criteria operator="AND" comment="GNOME 2.0 Solaris 9 (x86) meets Sun Alert ID 101776 criteria.">
          <criterion comment="Solaris 9 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3051"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:2463"/>
          <criterion comment="Gnome 2.0.0 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:818"/>
          <criterion comment="Patch 114687-03 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:812"/>
        </criteria>
        <criteria operator="AND" comment="GNOME 2.0.2 Solaris 9 (x86) meets Sun Alert ID 101776 criteria.">
          <criterion comment="Solaris 9 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3051"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:2463"/>
          <criterion comment="Gnome 2.0.2 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:814"/>
          <criterion comment="Patch 115739-04 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:811"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (x86) with JDS release 2 meets Sun Alert ID 101776 criteria.">
          <criterion comment="Solaris 9 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3051"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:2463"/>
          <criterion comment="JDS release 2 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:810"/>
          <criterion comment="Patch 121092-01 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:809"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1697" version="1" class="vulnerability">
      <metadata>
        <title>X.Org Privilege Escalation Vulnerability in X11R6.9, X11R7.0</title>
        <affected family="unix">
          <platform>Sun Solaris 10</platform>
          <product>Operating System</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-0745" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0745"/>
        <description>X.Org server (xorg-server) 1.0.0 and later, X11R6.9.0, and X11R7.0 inadvertently treats the address of the geteuid function as if it is the return value of a call to geteuid, which allows local users to bypass intended restrictions and (1) execute arbitrary code via the -modulepath command line option or (2) overwrite arbitrary files via -logfile.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-03-21T04:03:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-03-22T11:10:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-04-06T06:31:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-05-03T10:06:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Solaris 10 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:2459"/>
        <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:2463"/>
        <criteria operator="AND" comment="Patch 118966-14 through 118966-16 is installed.">
          <criterion comment="Patch 118966-14 or later installed" negate="false" test_ref="oval:org.mitre.oval:tst:765"/>
          <criterion comment="Patch 118966-17 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:764"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1074" version="1" class="vulnerability">
      <metadata>
        <title>Perl Format String Integer Overflow Vulnerability</title>
        <affected family="unix">
          <platform>Sun Solaris 10</platform>
          <product>Perl</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-3962" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-3962"/>
        <description>Integer overflow in the format string functionality (Perl_sv_vcatpvfn) in Perl 5.9.2 and 5.8.6 Perl allows attackers to overwrite arbitrary memory and possibly execute arbitrary code via format string specifiers with large values, which causes an integer wrap and leads to a buffer overflow, as demonstrated using format string vulnerabilities in Perl applications.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-03-02T02:05:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-03-09T12:19:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-04-06T06:30:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-05-03T10:06:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="OR">
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert ID 102192 criteria.">
          <criterion comment="Solaris 10 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:2459"/>
          <criterion comment="sparc architecture" negate="false" test_ref="oval:org.mitre.oval:tst:2465"/>
          <criterion comment="Patch 119985-02 or later installed (SPARC-10)" negate="true" test_ref="oval:org.mitre.oval:tst:1197"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert ID 102192 criteria.">
          <criterion comment="Solaris 10 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:2459"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:2463"/>
          <criterion comment="Patch 122082-01 or later installed (x86-10)" negate="true" test_ref="oval:org.mitre.oval:tst:1196"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1628" version="1" class="vulnerability">
      <metadata>
        <title>CD Drive DoS Vulnerability</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <platform>Sun Solaris 9</platform>
          <platform>Sun Solaris 10</platform>
          <product>Operating System</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-0901" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0901"/>
        <description>Unspecified vulnerability in the hsfs filesystem in Solaris 8, 9, and 10 allows unspecified attackers to cause a denial of service (panic) or execute arbitrary code.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-02-26T12:31:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-03-09T12:19:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-04-06T06:30:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-05-03T10:06:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="OR">
        <criteria operator="AND" comment="Solaris 8 (SPARC) meets Sun Alert ID 102161 criteria.">
          <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3145"/>
          <criterion comment="sparc architecture" negate="false" test_ref="oval:org.mitre.oval:tst:2465"/>
          <criterion comment="Patch 109764-06 or later installed (SPARC-8)" negate="true" test_ref="oval:org.mitre.oval:tst:801"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (SPARC) meets Sun Alert ID 102161 criteria.">
          <criterion comment="Solaris 9 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3051"/>
          <criterion comment="sparc architecture" negate="false" test_ref="oval:org.mitre.oval:tst:2465"/>
          <criterion comment="Patch 116047-03 or later installed (SPARC-9)" negate="true" test_ref="oval:org.mitre.oval:tst:800"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert ID 102161 criteria.">
          <criterion comment="Solaris 10 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:2459"/>
          <criterion comment="sparc architecture" negate="false" test_ref="oval:org.mitre.oval:tst:2465"/>
          <criterion comment="Patch 119596-03 or later installed (SPARC-10)" negate="true" test_ref="oval:org.mitre.oval:tst:799"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 8 (x86) meets Sun Alert ID 102161 criteria.">
          <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3145"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:2463"/>
          <criterion comment="Patch 109765-06 or later installed (x86-8)" negate="true" test_ref="oval:org.mitre.oval:tst:798"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (x86) meets Sun Alert ID 102161 criteria.">
          <criterion comment="Solaris 9 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3051"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:2463"/>
          <criterion comment="Patch 121995-01 or later installed (x86-9)" negate="true" test_ref="oval:org.mitre.oval:tst:797"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert ID 102161 criteria.">
          <criterion comment="Solaris 10 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:2459"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:2463"/>
          <criterion comment="Patch 118813-03 or later installed (x86-10)" negate="true" test_ref="oval:org.mitre.oval:tst:796"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1580" version="1" class="vulnerability">
      <metadata>
        <title>Kerberos Command Execution Vulnerability rexec Daemon</title>
        <affected family="unix">
          <platform>Sun Solaris 10</platform>
          <product>X</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-0769" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0769"/>
        <description>Unspecified vulnerability in in.rexecd in Solaris 10 allows local users to gain privileges on Kerberos systems via unknown attack vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-02-19T05:38:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-02-22T08:27:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-03-09T12:19:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-04-06T06:30:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="OR">
          <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert ID 102186 criteria.">
            <criterion comment="Solaris 10 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:2459"/>
            <criterion comment="sparc architecture" negate="false" test_ref="oval:org.mitre.oval:tst:2465"/>
            <criterion comment="Patch 120329-02 or later installed (SPARC-10)" negate="true" test_ref="oval:org.mitre.oval:tst:845"/>
          </criteria>
          <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert ID 102186 criteria.">
            <criterion comment="Solaris 10 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:2459"/>
            <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:2463"/>
            <criterion comment="Patch 120330-02 or later installed (SPARC-10)" negate="true" test_ref="oval:org.mitre.oval:tst:844"/>
          </criteria>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="Target is configured to reference pam_krb5" negate="false" test_ref="oval:org.mitre.oval:tst:843"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1608" version="1" class="vulnerability">
      <metadata>
        <title>Solaris 10 find on /proc panic DoS Vulnerability</title>
        <affected family="unix">
          <platform>Sun Solaris 10</platform>
          <product>Operating System</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-0191" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0191"/>
        <description>Unspecified vulnerability in Sun Solaris 10 allows local users to cause a denial of service (null dereference) via unspecified vectors involving the use of the find command on the "/proc" filesystem. NOTE: due to the vagueness of the vendor advisory, it is not clear whether this is related to CVE-2005-3250.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-01-12T11:25:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-01-25T07:30:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-02-22T08:27:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-03-09T12:19:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="OR">
        <criteria operator="AND" comment="Solaris 10 (sparc) meets Sun Alert ID 102108 criteria.">
          <criterion comment="Solaris 10 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:2459"/>
          <criterion comment="sparc architecture" negate="false" test_ref="oval:org.mitre.oval:tst:2465"/>
          <criterion comment="Patch 118822-24 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:822"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert ID 102066 and 102108 criteria.">
          <criterion comment="Solaris 10 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:2459"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:2463"/>
          <criterion comment="Patch 118844-24 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:2409"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:702" version="1" class="vulnerability">
      <metadata>
        <title>Solaris Privilege Escalation/DoS Vulnerability (6293270)</title>
        <affected family="unix">
          <platform>Sun Solaris 9</platform>
          <platform>Sun Solaris 10</platform>
          <product>Operating System</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-0190" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0190"/>
        <description>Unspecified vulnerability in Sun Solaris 9 and 10 for the x86 platform allows local users to gain privileges or cause a denial of service (panic) via unspecified vectors, possibly involving functions from the mm driver.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-01-12T11:25:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-01-25T07:30:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-02-22T08:27:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-03-09T12:19:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="OR">
        <criteria operator="AND" comment="Solaris 9 (x86) meets Sun Alert ID 102066 criteria.">
          <criterion comment="Solaris 9 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3051"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:2463"/>
          <criteria operator="OR" comment="Contributing factors for Solaris 9, Sun Alert ID 102066 criteria.">
            <criterion comment="Patch 112234-11 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2413"/>
            <criterion comment="Patch 112234-12 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2412"/>
            <criterion comment="Patch 117172-16 or later installed" negate="false" test_ref="oval:org.mitre.oval:tst:2411"/>
          </criteria>
          <criterion comment="Patch 118559-19 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:2410"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert ID 102066 and 102108 criteria.">
          <criterion comment="Solaris 10 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:2459"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:2463"/>
          <criterion comment="Patch 118844-24 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:2409"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1534" version="1" class="vulnerability">
      <metadata>
        <title>uucp/uustat Privilege Escalation Vulnerability</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <platform>Sun Solaris 9</platform>
          <product>Operating System</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-0161" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0161"/>
        <description>Unspecified vulnerability in uucp in Sun Solaris 8 and 9 has unknown impact and attack vectors.  NOTE: due to the vagueness of the vendor advisory, it is not clear whether this is related to CVE-2004-0780.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-01-11T12:56:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-01-12T09:18:00.000-04:00">DRAFT</status_change>
            <modified date="2006-01-17T01:07:00.000-04:00" comment="Updated reference to CVE-2006-0161, per Rob Hollis.">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2006-02-01T09:08:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-02-22T08:27:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="OR">
        <criteria operator="AND" comment="Solaris 8 (SPARC) meets Sun Alert ID 101933 criteria.">
          <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3145"/>
          <criterion comment="sparc architecture" negate="false" test_ref="oval:org.mitre.oval:tst:2465"/>
          <criterion comment="Patch 111570-04 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:878"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 8 (x86) meets Sun Alert ID 101933 criteria.">
          <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3145"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:2463"/>
          <criterion comment="Patch 111571-04 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:877"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (SPARC) meets Sun Alert ID 101933 criteria.">
          <criterion comment="Solaris 9 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3051"/>
          <criterion comment="sparc architecture" negate="false" test_ref="oval:org.mitre.oval:tst:2465"/>
          <criterion comment="Patch 113322-03 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:876"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (x86) meets Sun Alert ID 101933 criteria.">
          <criterion comment="Solaris 9 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3051"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:2463"/>
          <criterion comment="Patch 115880-02 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:875"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1409" version="1" class="vulnerability">
      <metadata>
        <title>PC Netlink 2.0 Privilege Escalation Vulnerability</title>
        <affected family="unix">
          <platform>Sun Solaris 7</platform>
          <platform>Sun Solaris 8</platform>
          <platform>Sun Solaris 9</platform>
          <product>Solaris Management Console</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-4552" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-4552"/>
        <description>The (1) slsmgr and (2) slsadmin programs in Sun Solaris PC NetLink 2.0 create temporary files insecurely, which allows local users to gain privileges.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-01-11T12:56:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-01-12T09:18:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-02-01T09:08:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-02-22T08:27:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="Solaris 7,8,or 9 installed">
          <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3145"/>
          <criterion comment="Solaris 7 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3045"/>
          <criterion comment="Solaris 9 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3051"/>
        </criteria>
        <criterion comment="sparc architecture" negate="false" test_ref="oval:org.mitre.oval:tst:2465"/>
        <criterion comment="the SUNWlzas package (for slsadmin) is installed" negate="false" test_ref="oval:org.mitre.oval:tst:963"/>
        <criterion comment="Patch 121332-01 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:962"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1445" version="1" class="vulnerability">
      <metadata>
        <title>SMC TRACE HTTP Vulnerability</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <platform>Sun Solaris 9</platform>
          <platform>Sun Solaris 10</platform>
          <product>Solaris Management Console</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-3398" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-3398"/>
        <description>The default configuration of the web server for the Solaris Management Console (SMC) in Solaris 8, 9, and 10 enables the HTTP TRACE method, which could allow remote attackers to obtain sensitive information such as cookies and authentication data from HTTP headers.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-01-11T12:56:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-01-12T09:18:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-02-01T09:08:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-02-22T08:27:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="OR">
        <criteria operator="AND" comment="Solaris 8 (SPARC) meets Sun Alert ID 102016 criteria.">
          <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3145"/>
          <criterion comment="sparc architecture" negate="false" test_ref="oval:org.mitre.oval:tst:2465"/>
          <criterion comment="Patch 111313-03 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:933"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 8 (x86) meets Sun Alert ID 102016 criteria.">
          <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3145"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:2463"/>
          <criterion comment="Patch 111314-03 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:932"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (SPARC) meets Sun Alert ID 102016 criteria.">
          <criterion comment="Solaris 9 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3051"/>
          <criterion comment="sparc architecture" negate="false" test_ref="oval:org.mitre.oval:tst:2465"/>
          <criterion comment="Patch 116807-02 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:931"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (x86) meets Sun Alert ID 102016 criteria.">
          <criterion comment="Solaris 9 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3051"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:2463"/>
          <criterion comment="Patch 116808-02 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:930"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert ID 102016 criteria.">
          <criterion comment="Solaris 10 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:2459"/>
          <criterion comment="sparc architecture" negate="false" test_ref="oval:org.mitre.oval:tst:2465"/>
          <criterion comment="Patch 121308-01 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:929"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert ID 102016 criteria.">
          <criterion comment="Solaris 10 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:2459"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:2463"/>
          <criterion comment="Patch 121309-01 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:928"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:100117" version="1" class="vulnerability">
      <metadata>
        <title>libtiff Directory Entry Count Integer Overflow Vulnerability</title>
        <affected family="unix">
          <platform>Sun Solaris 7</platform>
          <platform>Sun Solaris 8</platform>
          <platform>Sun Solaris 9</platform>
          <platform>Sun Solaris 10</platform>
          <product>libtiff</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-1308" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1308"/>
        <description>Integer overflow in (1) tif_dirread.c and (2) tif_fax3.c for libtiff 3.5.7 and 3.7.0 allows remote attackers to execute arbitrary code via a TIFF file containing a TIFF_ASCII or TIFF_UNDEFINED directory entry with a -1 entry count, which leads to a heap-based buffer overflow.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-08-16T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-09-21T01:33:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-11-16T08:02:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="OR">
        <criteria operator="AND" comment="Solaris 7 (SPARC) meets Sun Alert ID 101677 criteria.">
          <criterion comment="Solaris 7 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3045"/>
          <criterion comment="sparc architecture" negate="false" test_ref="oval:org.mitre.oval:tst:2465"/>
          <criterion comment="Patch 118953-02 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:209"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 7 (x86) meets Sun Alert ID 101677 criteria.">
          <criterion comment="Solaris 7 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3045"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:2463"/>
          <criterion comment="Patch 118954-02 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:208"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 8 (SPARC) meets Sun Alert ID 101677 criteria.">
          <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3145"/>
          <criterion comment="sparc architecture" negate="false" test_ref="oval:org.mitre.oval:tst:2465"/>
          <criterion comment="Patch 109931-10 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:207"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 8 (x86) meets Sun Alert ID 101677 criteria.">
          <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3145"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:2463"/>
          <criterion comment="Patch 109932-10 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:206"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (SPARC) meets Sun Alert ID 101677 criteria.">
          <criterion comment="Solaris 9 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3051"/>
          <criterion comment="sparc architecture" negate="false" test_ref="oval:org.mitre.oval:tst:2465"/>
          <criteria operator="OR" comment="Solaris 9 (SPARC) supporting criteria for Sun Alert ID 101677.">
            <criteria operator="AND" comment="Solaris 9 (SPARC) supporting CDE criteria for Sun Alert ID 101677.">
              <criterion comment="CDE Desktop Window Manager (SUNWdtwm) installed" negate="false" test_ref="oval:org.mitre.oval:tst:675"/>
              <criterion comment="Patch 114219-11 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:205"/>
            </criteria>
            <criterion comment="Pkg SUNWTiff is installed" negate="false" test_ref="oval:org.mitre.oval:tst:204"/>
            <criterion comment="Pkg SUNWTiffx is installed" negate="false" test_ref="oval:org.mitre.oval:tst:203"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (x86) meets Sun Alert ID 101677 criteria.">
          <criterion comment="Solaris 9 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3051"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:2463"/>
          <criteria operator="OR" comment="Solaris 9 (x86) supporting criteria for Sun Alert ID 101677.">
            <criteria operator="AND" comment="Solaris 9 (x86) supporting CDE criteria for Sun Alert ID 101677.">
              <criterion comment="CDE Desktop Window Manager (SUNWdtwm) installed" negate="false" test_ref="oval:org.mitre.oval:tst:675"/>
              <criterion comment="Patch 114220-11 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:202"/>
            </criteria>
            <criterion comment="Pkg SUNWTiff is installed" negate="false" test_ref="oval:org.mitre.oval:tst:204"/>
            <criterion comment="Pkg SUNWTiffx is installed" negate="false" test_ref="oval:org.mitre.oval:tst:203"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert ID 101677 criteria.">
          <criterion comment="Solaris 10 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:2459"/>
          <criterion comment="sparc architecture" negate="false" test_ref="oval:org.mitre.oval:tst:2465"/>
          <criterion comment="Pkg SUNWTiff is installed" negate="false" test_ref="oval:org.mitre.oval:tst:204"/>
          <criterion comment="Patch 119900-01 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:201"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert ID 101677 criteria.">
          <criterion comment="Solaris 10 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:2459"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:2463"/>
          <criterion comment="Pkg SUNWTiff is installed" negate="false" test_ref="oval:org.mitre.oval:tst:204"/>
          <criterion comment="Patch 119901-01 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:200"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:100116" version="1" class="vulnerability">
      <metadata>
        <title>libtiff Malloc Error Denial of Service</title>
        <affected family="unix">
          <platform>Sun Solaris 7</platform>
          <platform>Sun Solaris 8</platform>
          <platform>Sun Solaris 9</platform>
          <platform>Sun Solaris 10</platform>
          <product>libtiff</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0886" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0886"/>
        <description>Multiple integer overflows in libtiff 3.6.1 and earlier allow remote attackers to cause a denial of service (crash or memory corruption) via TIFF images that lead to incorrect malloc calls.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-08-16T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-09-21T01:33:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-11-16T08:02:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="OR">
        <criteria operator="AND" comment="Solaris 7 (SPARC) meets Sun Alert ID 101677 criteria.">
          <criterion comment="Solaris 7 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3045"/>
          <criterion comment="sparc architecture" negate="false" test_ref="oval:org.mitre.oval:tst:2465"/>
          <criterion comment="Patch 118953-02 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:209"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 7 (x86) meets Sun Alert ID 101677 criteria.">
          <criterion comment="Solaris 7 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3045"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:2463"/>
          <criterion comment="Patch 118954-02 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:208"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 8 (SPARC) meets Sun Alert ID 101677 criteria.">
          <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3145"/>
          <criterion comment="sparc architecture" negate="false" test_ref="oval:org.mitre.oval:tst:2465"/>
          <criterion comment="Patch 109931-10 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:207"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 8 (x86) meets Sun Alert ID 101677 criteria.">
          <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3145"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:2463"/>
          <criterion comment="Patch 109932-10 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:206"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (SPARC) meets Sun Alert ID 101677 criteria.">
          <criterion comment="Solaris 9 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3051"/>
          <criterion comment="sparc architecture" negate="false" test_ref="oval:org.mitre.oval:tst:2465"/>
          <criteria operator="OR" comment="Solaris 9 (SPARC) supporting criteria for Sun Alert ID 101677.">
            <criteria operator="AND" comment="Solaris 9 (SPARC) supporting CDE criteria for Sun Alert ID 101677.">
              <criterion comment="CDE Desktop Window Manager (SUNWdtwm) installed" negate="false" test_ref="oval:org.mitre.oval:tst:675"/>
              <criterion comment="Patch 114219-11 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:205"/>
            </criteria>
            <criterion comment="Pkg SUNWTiff is installed" negate="false" test_ref="oval:org.mitre.oval:tst:204"/>
            <criterion comment="Pkg SUNWTiffx is installed" negate="false" test_ref="oval:org.mitre.oval:tst:203"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (x86) meets Sun Alert ID 101677 criteria.">
          <criterion comment="Solaris 9 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3051"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:2463"/>
          <criteria operator="OR" comment="Solaris 9 (x86) supporting criteria for Sun Alert ID 101677.">
            <criteria operator="AND" comment="Solaris 9 (x86) supporting CDE criteria for Sun Alert ID 101677.">
              <criterion comment="CDE Desktop Window Manager (SUNWdtwm) installed" negate="false" test_ref="oval:org.mitre.oval:tst:675"/>
              <criterion comment="Patch 114220-11 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:202"/>
            </criteria>
            <criterion comment="Pkg SUNWTiff is installed" negate="false" test_ref="oval:org.mitre.oval:tst:204"/>
            <criterion comment="Pkg SUNWTiffx is installed" negate="false" test_ref="oval:org.mitre.oval:tst:203"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert ID 101677 criteria.">
          <criterion comment="Solaris 10 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:2459"/>
          <criterion comment="sparc architecture" negate="false" test_ref="oval:org.mitre.oval:tst:2465"/>
          <criterion comment="Pkg SUNWTiff is installed" negate="false" test_ref="oval:org.mitre.oval:tst:204"/>
          <criterion comment="Patch 119900-01 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:201"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert ID 101677 criteria.">
          <criterion comment="Solaris 10 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:2459"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:2463"/>
          <criterion comment="Pkg SUNWTiff is installed" negate="false" test_ref="oval:org.mitre.oval:tst:204"/>
          <criterion comment="Patch 119901-01 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:200"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:100115" version="1" class="vulnerability">
      <metadata>
        <title>libtiff tif_dirread divide-by-zero Denial of Service</title>
        <affected family="unix">
          <platform>Sun Solaris 7</platform>
          <platform>Sun Solaris 8</platform>
          <platform>Sun Solaris 9</platform>
          <platform>Sun Solaris 10</platform>
          <product>libtiff</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0804" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0804"/>
        <description>Vulnerability in tif_dirread.c for libtiff allows remote attackers to cause a denial of service (application crash) via a TIFF image that causes a divide-by-zero error when the number of row bytes is zero, a different vulnerability than CVE-2005-2452.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-08-16T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-09-21T01:33:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-11-16T08:02:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="OR">
        <criteria operator="AND" comment="Solaris 7 (SPARC) meets Sun Alert ID 101677 criteria.">
          <criterion comment="Solaris 7 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3045"/>
          <criterion comment="sparc architecture" negate="false" test_ref="oval:org.mitre.oval:tst:2465"/>
          <criterion comment="Patch 118953-02 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:209"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 7 (x86) meets Sun Alert ID 101677 criteria.">
          <criterion comment="Solaris 7 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3045"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:2463"/>
          <criterion comment="Patch 118954-02 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:208"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 8 (SPARC) meets Sun Alert ID 101677 criteria.">
          <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3145"/>
          <criterion comment="sparc architecture" negate="false" test_ref="oval:org.mitre.oval:tst:2465"/>
          <criterion comment="Patch 109931-10 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:207"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 8 (x86) meets Sun Alert ID 101677 criteria