<?xml version="1.0" encoding="UTF-8"?>
<oval_definitions xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-definitions-5 oval-definitions-schema.xsd http://oval.mitre.org/XMLSchema/oval-definitions-5#macos macos-definitions-schema.xsd http://oval.mitre.org/XMLSchema/oval-definitions-5#independent independent-definitions-schema.xsd http://oval.mitre.org/XMLSchema/oval-common-5 oval-common-schema.xsd http://oval.mitre.org/XMLSchema/oval-definitions-5#unix unix-definitions-schema.xsd" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:oval="http://oval.mitre.org/XMLSchema/oval-common-5" xmlns:oval-def="http://oval.mitre.org/XMLSchema/oval-definitions-5">
  <generator>
    <oval:product_name>The OVAL Repository</oval:product_name>
    <oval:schema_version>5.9</oval:schema_version>
    <oval:timestamp>2012-01-27T05:09:21.152-05:00</oval:timestamp>
  </generator>
  <definitions>
    <definition id="oval:org.mitre.oval:def:12625" version="3" class="vulnerability">
      <metadata>
        <title>Unspecified vulnerability which allows attackers to cause a denial of service or possibly execute arbitrary code in Adobe Flash Player version less than 9.0.289.0 and 10.x less than 10.1.102.64</title>
        <affected family="macos">
          <platform>Apple Mac OS X</platform>
          <product>Adobe Flash Player</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-3639" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3639"/>
        <description>Unspecified vulnerability in Adobe Flash Player before 9.0.289.0 and 10.x before 10.1.102.64 on Windows, Mac OS X, Linux, and Solaris, and 10.1.95.1 on Android, allows attackers to cause a denial of service or possibly execute arbitrary code via unknown vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2011-02-03T13:00:00">
              <contributor organization="The MITRE Corporation">Nate Przybyszewski</contributor>
            </submitted>
            <status_change date="2011-02-15T14:24:56.759-05:00">DRAFT</status_change>
            <status_change date="2011-03-07T04:00:10.492-05:00">INTERIM</status_change>
            <status_change date="2011-03-28T04:00:09.832-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Check if Adobe Flash Player is installed and version is less than 9.0.289.0">
          <extend_definition comment="Adobe Flash Player is Installed" definition_ref="oval:org.mitre.oval:def:12319"/>
          <criterion comment="Adobe Flash Player version is less than 9.0.289.0" test_ref="oval:org.mitre.oval:tst:42260"/>
        </criteria>
        <criteria operator="AND" comment="Check if Adobe Flash Player 10 is installed and version is less than 10.1.102.64">
          <extend_definition comment="Adobe Flash Player 10 is Installed" definition_ref="oval:org.mitre.oval:def:12412"/>
          <criterion comment="Adobe Flash Player version is less than 10.1.102.64" test_ref="oval:org.mitre.oval:tst:42257"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:12412" version="3" class="inventory">
      <metadata>
        <title>Adobe Flash Player 10 is Installed</title>
        <affected family="macos">
          <platform>Apple Mac OS X</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:adobe:flash_player:10"/>
        <description>Adobe Flash Player 10 has been installed on the system</description>
        <oval_repository>
          <dates>
            <submitted date="2011-02-03T13:00:00">
              <contributor organization="The MITRE Corporation">Nate Przybyszewski</contributor>
            </submitted>
            <status_change date="2011-02-15T14:24:56.518-05:00">DRAFT</status_change>
            <status_change date="2011-03-07T04:00:08.403-05:00">INTERIM</status_change>
            <status_change date="2011-03-28T04:00:06.907-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="Adobe Flash Player version 10 is installed" test_ref="oval:org.mitre.oval:tst:42145"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:12319" version="3" class="inventory">
      <metadata>
        <title>Adobe Flash Player is Installed</title>
        <affected family="macos">
          <platform>Apple Mac OS X</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:adobe:flash_player"/>
        <description>Adobe Flash Player has been installed on the system</description>
        <oval_repository>
          <dates>
            <submitted date="2011-02-03T13:00:00">
              <contributor organization="The MITRE Corporation">Nate Przybyszewski</contributor>
            </submitted>
            <status_change date="2011-02-15T14:24:56.319-05:00">DRAFT</status_change>
            <status_change date="2011-03-07T04:00:07.711-05:00">INTERIM</status_change>
            <status_change date="2011-03-28T04:00:06.235-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="The Bill of Materials (BOM) file for Adobe Flash Player is present" test_ref="oval:org.mitre.oval:tst:42437"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:12109" version="4" class="vulnerability">
      <metadata>
        <title>Snow Leopard Apple Filing Protocol (AFP) Password Bypass</title>
        <affected family="macos">
          <platform>Apple Mac OS X</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-1820" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1820"/>
        <description>Apple Filing Protocol (AFP) Server in Apple Mac OS X 10.6.x through 10.6.4 does not properly handle errors, which allows remote attackers to bypass the password requirement for shared-folder access by leveraging knowledge of a valid account name.</description>
        <oval_repository>
          <dates>
            <submitted date="2011-02-03T13:00:00">
              <contributor organization="The MITRE Corporation">Nate Przybyszewski</contributor>
            </submitted>
            <status_change date="2011-02-15T14:24:55.958-05:00">DRAFT</status_change>
            <status_change date="2011-03-07T04:00:07.147-05:00">INTERIM</status_change>
            <status_change date="2011-03-28T04:00:05.672-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="The Installed Operating System is Part of the Mac OS Family" test_ref="oval:org.mitre.oval:tst:42186"/>
        <criterion comment="Apple Mac OS X 10.6 (Snow Leopard) is Installed" test_ref="oval:org.mitre.oval:tst:41991"/>
        <criterion comment="Apple Mac OS X version is less than 10.6.5" test_ref="oval:org.mitre.oval:tst:42476"/>
        <extend_definition negate="true" comment="Apple Security Update 2010-006 is Installed" definition_ref="oval:org.mitre.oval:def:11637"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11637" version="3" class="inventory">
      <metadata>
        <title>Apple Security Update 2010-006 is Installed</title>
        <affected family="macos">
          <platform>Apple Mac OS X</platform>
        </affected>
        <description>Apple Security Update 2010-006 has been installed on the system</description>
        <oval_repository>
          <dates>
            <submitted date="2011-02-03T13:00:00">
              <contributor organization="The MITRE Corporation">Nate Przybyszewski</contributor>
            </submitted>
            <status_change date="2011-02-15T14:24:55.773-05:00">DRAFT</status_change>
            <status_change date="2011-03-07T04:00:05.491-05:00">INTERIM</status_change>
            <status_change date="2011-03-28T04:00:03.607-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="The Bill of Materials (BOM) file for the Apple Security Update 2010-006 is present" test_ref="oval:org.mitre.oval:tst:42443"/>
      </criteria>
    </definition>
  </definitions>
  <tests>
    <plist_test id="oval:org.mitre.oval:tst:42145" version="1" comment="Adobe Flash Player version 10 is installed" check_existence="only_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#macos">
      <object object_ref="oval:org.mitre.oval:obj:15971"/>
      <state state_ref="oval:org.mitre.oval:ste:12364"/>
    </plist_test>
    <file_test id="oval:org.mitre.oval:tst:42437" version="1" comment="The Bill of Materials (BOM) file for Adobe Flash Player is present" check_existence="only_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:14974"/>
    </file_test>
    <plist_test id="oval:org.mitre.oval:tst:42260" version="1" comment="Adobe Flash Player version is less than 9.0.289.0" check_existence="only_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#macos">
      <object object_ref="oval:org.mitre.oval:obj:15971"/>
      <state state_ref="oval:org.mitre.oval:ste:12327"/>
    </plist_test>
    <plist_test id="oval:org.mitre.oval:tst:42257" version="1" comment="Adobe Flash Player version is less than 10.1.102.64" check_existence="only_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#macos">
      <object object_ref="oval:org.mitre.oval:obj:15971"/>
      <state state_ref="oval:org.mitre.oval:ste:11473"/>
    </plist_test>
    <file_test id="oval:org.mitre.oval:tst:42443" version="1" comment="The Bill of Materials (BOM) file for the Apple Security Update 2010-006 is present" check_existence="only_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:15526"/>
    </file_test>
    <plist_test id="oval:org.mitre.oval:tst:42476" version="1" comment="Apple Mac OS X version is less than 10.6.5" check_existence="only_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#macos">
      <object object_ref="oval:org.mitre.oval:obj:15912"/>
      <state state_ref="oval:org.mitre.oval:ste:11632"/>
    </plist_test>
    <family_test id="oval:org.mitre.oval:tst:42186" version="1" comment="The Installed Operating System is Part of the Mac OS Family" check_existence="only_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#independent">
      <object object_ref="oval:org.mitre.oval:obj:99"/>
      <state state_ref="oval:org.mitre.oval:ste:12279"/>
    </family_test>
    <uname_test id="oval:org.mitre.oval:tst:41991" version="1" comment="Apple Mac OS X 10.6 (Snow Leopard) is Installed" check_existence="only_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:2759"/>
      <state state_ref="oval:org.mitre.oval:ste:11420"/>
    </uname_test>
  </tests>
  <objects>
    <file_object id="oval:org.mitre.oval:obj:14974" version="1" comment="The Adobe Flash bill of materials (BOM) file" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/private/var/db/receipts</path>
      <filename>com.adobe.pkg.FlashPlayer.bom</filename>
    </file_object>
    <plist_object id="oval:org.mitre.oval:obj:15971" version="1" comment="The Adobe Flash Player package version plist object." xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#macos">
      <key>PackageVersion</key>
      <filepath>/private/var/db/receipts/com.adobe.pkg.FlashPlayer.plist</filepath>
    </plist_object>
    <file_object id="oval:org.mitre.oval:obj:15526" version="1" comment="The Apple Security Update 2010-006 bill of materials (BOM) file" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/private/var/db/receipts</path>
      <filename>com.apple.pkg.update.security.2010.006.snowleopard.bom</filename>
    </file_object>
    <plist_object id="oval:org.mitre.oval:obj:15912" version="1" comment="The OSX product version plist object." xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#macos">
      <key>ProductVersion</key>
      <filepath>/System/Library/CoreServices/SystemVersion.plist</filepath>
    </plist_object>
    <family_object id="oval:org.mitre.oval:obj:99" version="1" comment="This is the default family object. Only one family object should exist." xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#independent"/>
    <uname_object id="oval:org.mitre.oval:obj:2759" version="1" comment="The single uname object." xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix"/>
  </objects>
  <states>
    <plist_state id="oval:org.mitre.oval:ste:12364" version="1" comment="The value is greater than or equal to 10" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#macos">
      <value datatype="version" operation="greater than or equal">10</value>
    </plist_state>
    <plist_state id="oval:org.mitre.oval:ste:12327" version="1" comment="The value is less than '9.0.289.0'." xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#macos">
      <value datatype="version" operation="less than">9.0.289.0</value>
    </plist_state>
    <plist_state id="oval:org.mitre.oval:ste:11473" version="1" comment="The value is less than '10.1.102.64'." xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#macos">
      <value datatype="version" operation="less than">10.1.102.64</value>
    </plist_state>
    <plist_state id="oval:org.mitre.oval:ste:11632" version="1" comment="The value is less than '10.6.5'." xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#macos">
      <value datatype="version" operation="less than">10.6.5</value>
    </plist_state>
    <family_state id="oval:org.mitre.oval:ste:12279" version="1" comment="The operating system is part of the Mac OS family." xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#independent">
      <family>macos</family>
    </family_state>
    <uname_state id="oval:org.mitre.oval:ste:11420" version="1" comment="The OS name is 'Darwin' and the OS release is '10.6.0'." xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <os_name>Darwin</os_name>
      <os_release>10.6.0</os_release>
    </uname_state>
  </states>
</oval_definitions>
