<?xml version="1.0" encoding="UTF-8"?>
<oval_definitions xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-definitions-5 oval-definitions-schema.xsd http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux hpux-definitions-schema.xsd http://oval.mitre.org/XMLSchema/oval-common-5 oval-common-schema.xsd http://oval.mitre.org/XMLSchema/oval-definitions-5#unix unix-definitions-schema.xsd" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:oval="http://oval.mitre.org/XMLSchema/oval-common-5" xmlns:oval-def="http://oval.mitre.org/XMLSchema/oval-definitions-5">
  <generator>
    <oval:product_name>The OVAL Repository</oval:product_name>
    <oval:schema_version>5.6</oval:schema_version>
    <oval:timestamp>2009-11-20T04:31:59.182-05:00</oval:timestamp>
  </generator>
  <definitions>
    <definition id="oval:org.mitre.oval:def:5855" version="1" class="vulnerability">
      <metadata>
        <title>HP-UX Using libc, Remote Denial of Service (DoS)</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-1664" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1664"/>
        <description>Unspecified vulnerability in libc on HP HP-UX B.11.23 and B.11.31 allows remote attackers to cause a denial of service via unknown vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-08-07T10:53:22.000-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2008-08-11T11:11:29.603-04:00">DRAFT</status_change>
            <status_change date="2008-09-01T04:01:11.754-04:00">INTERIM</status_change>
            <status_change date="2008-09-22T04:00:34.470-04:00">ACCEPTED</status_change>
            <modified comment="Corrected the patch number for HP-UX B.11.31 based on the modification on HPSBUX02355" date="2009-11-16T17:18:00.073-05:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </modified>
            <status_change date="2009-11-16T17:19:30.081-05:00">INTERIM</status_change>
          </dates>
          <status>INTERIM</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02355">
          <criterion comment="HP-UX B.11.31" test_ref="oval:org.mitre.oval:tst:8260"/>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="ProgSupport.PROG-MIN is installed" test_ref="oval:org.mitre.oval:tst:8906"/>
            <criterion comment="OS-Core.CORE-64SLIB is installed" test_ref="oval:org.mitre.oval:tst:8378"/>
            <criterion comment="OS-Core.CORE-SHLIBS is installed" test_ref="oval:org.mitre.oval:tst:8981"/>
            <criterion comment="OS-Core.C-MIN is installed" test_ref="oval:org.mitre.oval:tst:8917"/>
            <criterion comment="OS-Core.C-MIN-64ALIB is installed" test_ref="oval:org.mitre.oval:tst:8551"/>
            <criterion comment="OS-Core.CORE2-64SLIB is installed" test_ref="oval:org.mitre.oval:tst:8680"/>
            <criterion comment="OS-Core.CORE2-SHLIBS is installed" test_ref="oval:org.mitre.oval:tst:9084"/>
            <criterion comment="ProgSupport.PROG2-AUX is installed" test_ref="oval:org.mitre.oval:tst:8594"/>
            <criterion comment="ProgSupport.PROG-AX-64ALIB is installed" test_ref="oval:org.mitre.oval:tst:8703"/>
          </criteria>
          <criterion negate="true" comment="Patch PHCO_38048 is installed" test_ref="oval:org.mitre.oval:tst:8563"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02355">
          <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="OS-Core.C-MIN is installed" test_ref="oval:org.mitre.oval:tst:8917"/>
            <criterion comment="OS-Core.C-MIN-64ALIB is installed" test_ref="oval:org.mitre.oval:tst:8551"/>
            <criterion comment="OS-Core.CORE2-64SLIB is installed" test_ref="oval:org.mitre.oval:tst:8680"/>
            <criterion comment="OS-Core.CORE2-SHLIBS is installed" test_ref="oval:org.mitre.oval:tst:9084"/>
            <criterion comment="ProgSupport.PROG2-AUX is installed" test_ref="oval:org.mitre.oval:tst:8594"/>
            <criterion comment="ProgSupport.PROG-AX-64ALIB is installed" test_ref="oval:org.mitre.oval:tst:8703"/>
            <criterion comment="ProgSupport.PROG-MIN is installed" test_ref="oval:org.mitre.oval:tst:8906"/>
          </criteria>
          <criterion negate="true" comment="Patch PHCO_38273 is installed" test_ref="oval:org.mitre.oval:tst:8692"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6328" version="1" class="vulnerability">
      <metadata>
        <title>HP-UX Running Role-Based Access Control (RBAC), Local Unauthorized Access</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-2682" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2682"/>
        <description>Unspecified vulnerability in Role-Based Access Control (RBAC) in HP HP-UX B.11.23 and B.11.31 allows local users to bypass intended access restrictions via unknown vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-10-07T11:33:53.000-04:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2009-10-09T14:07:00.581-04:00">DRAFT</status_change>
            <status_change date="2009-10-26T04:00:05.422-04:00">INTERIM</status_change>
            <status_change date="2009-11-16T04:00:19.006-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02457">
          <criterion comment="HP-UX B.11.31" test_ref="oval:org.mitre.oval:tst:8260"/>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="RBAC.RBAC-CONF is installed" test_ref="oval:org.mitre.oval:tst:10651"/>
            <criterion comment="RBAC.RBAC-RUN is installed" test_ref="oval:org.mitre.oval:tst:10540"/>
          </criteria>
          <criterion negate="true" comment="Patch PHCO_40131 is installed" test_ref="oval:org.mitre.oval:tst:10732"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02457">
          <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="RBAC.RBAC-CONF version is less than B.11.23.06" test_ref="oval:org.mitre.oval:tst:9940"/>
            <criterion comment="RBAC.RBAC-RUN version is less than B.11.23.06" test_ref="oval:org.mitre.oval:tst:10583"/>
            <criterion comment="RBAC.RBAC-WEB version is less than B.11.23.06" test_ref="oval:org.mitre.oval:tst:10906"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5780" version="1" class="vulnerability">
      <metadata>
        <title>HP-UX Running bootpd, Remote Denial of Service (DoS)</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-2679" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2679"/>
        <description>Unspecified vulnerability in bootpd in HP HP-UX B.11.11, B.11.23, and B.11.31 allows remote attackers to cause a denial of service via unknown attack vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-09-16T13:58:26.000-04:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2009-09-22T21:48:49.747-04:00">DRAFT</status_change>
            <status_change date="2009-10-12T04:00:06.852-04:00">INTERIM</status_change>
            <status_change date="2009-11-02T04:00:07.330-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02458">
          <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
          <criterion comment="InternetSrvcs.INETSVCS2-BOOT is installed" test_ref="oval:org.mitre.oval:tst:9955"/>
          <criterion negate="true" comment="Patch PHNE_39668 is installed" test_ref="oval:org.mitre.oval:tst:10775"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02458">
          <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
          <criterion comment="InternetSrvcs.INETSVCS2-BOOT is installed" test_ref="oval:org.mitre.oval:tst:9955"/>
          <criterion negate="true" comment="Patch PHNE_39700 is installed" test_ref="oval:org.mitre.oval:tst:10717"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02458">
          <criterion comment="HP-UX B.11.31" test_ref="oval:org.mitre.oval:tst:8260"/>
          <criterion comment="DHCPv4.DHCPV4-RUN is installed" test_ref="oval:org.mitre.oval:tst:10679"/>
          <criterion negate="true" comment="Patch PHNE_39443 is installed" test_ref="oval:org.mitre.oval:tst:9859"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6387" version="1" class="vulnerability">
      <metadata>
        <title>HP-UX Running Kerberos, Remote Denial of Service (DoS), Execution of Arbitrary Code</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-0847" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0847"/>
        <description>The asn1buf_imbed function in the ASN.1 decoder in MIT Kerberos 5 (aka krb5) 1.6.3, when PK-INIT is used, allows remote attackers to cause a denial of service (application crash) via a crafted length value that triggers an erroneous malloc call, related to incorrect calculations with pointer arithmetic.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-08-11T16:16:36.000-04:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2009-08-12T09:50:14.604-04:00">DRAFT</status_change>
            <status_change date="2009-08-31T04:00:14.778-04:00">INTERIM</status_change>
            <status_change date="2009-09-21T04:00:08.459-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02421">
          <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="krb5client.KRB5-64SLIB-A version is less than D.1.6.2.01" test_ref="oval:org.mitre.oval:tst:10417"/>
            <criterion comment="krb5client.KRB5-64SLIB-A version is less than D.1.6.2.01" test_ref="oval:org.mitre.oval:tst:10417"/>
            <criterion comment="krb5client.KRB5-PRG-A version is less than D.1.6.2.01" test_ref="oval:org.mitre.oval:tst:9858"/>
            <criterion comment="krb5client.KRB5-RUN-A version is less than D.1.6.2.01" test_ref="oval:org.mitre.oval:tst:10546"/>
            <criterion comment="krb5client.KRB5-SHLIB-A version is less than D.1.6.2.01" test_ref="oval:org.mitre.oval:tst:9864"/>
            <criterion comment="krb5client.KRB5IA32SLIB-A version is less than D.1.6.2.01" test_ref="oval:org.mitre.oval:tst:10283"/>
            <criterion comment="krb5client.KRB5IA64SLIB-A version is less than D.1.6.2.01" test_ref="oval:org.mitre.oval:tst:10263"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02421">
          <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="krb5client.KRB5-64SLIB-A version is less than C.1.3.5.09" test_ref="oval:org.mitre.oval:tst:10041"/>
            <criterion comment="krb5client.KRB5-PRG-A version is less than C.1.3.5.09" test_ref="oval:org.mitre.oval:tst:10495"/>
            <criterion comment="krb5client.KRB5-RUN-A version is less than C.1.3.5.09" test_ref="oval:org.mitre.oval:tst:10331"/>
            <criterion comment="krb5client.KRB5-SHLIB-A version is less than C.1.3.5.09" test_ref="oval:org.mitre.oval:tst:10556"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02421">
          <criterion comment="HP-UX B.11.31" test_ref="oval:org.mitre.oval:tst:8260"/>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="krb5client.KRB5-64SLIB-A version is less than E.1.6.2.03" test_ref="oval:org.mitre.oval:tst:10551"/>
            <criterion comment="krb5client.KRB5-PRG-A version is less than E.1.6.2.03" test_ref="oval:org.mitre.oval:tst:10305"/>
            <criterion comment="krb5client.KRB5-RUN-A version is less than E.1.6.2.03" test_ref="oval:org.mitre.oval:tst:10501"/>
            <criterion comment="krb5client.KRB5-SHLIB-A version is less than E.1.6.2.03" test_ref="oval:org.mitre.oval:tst:10039"/>
            <criterion comment="krb5client.KRB5IA32SLIB-A version is less than E.1.6.2.03" test_ref="oval:org.mitre.oval:tst:10539"/>
            <criterion comment="krb5client.KRB5IA64SLIB-A version is less than E.1.6.2.03" test_ref="oval:org.mitre.oval:tst:10262"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6307" version="1" class="vulnerability">
      <metadata>
        <title>HP-UX Running XNTP, Remote Execution of Arbitrary Code</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-1252" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1252"/>
        <description>Stack-based buffer overflow in the crypto_recv function in ntp_crypto.c in ntpd in NTP before 4.2.4p7 and 4.2.5 before 4.2.5p74, when OpenSSL and autokey are enabled, allows remote attackers to execute arbitrary code via a crafted packet containing an extension field.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-08-11T16:16:37.000-04:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2009-08-12T09:50:15.432-04:00">DRAFT</status_change>
            <status_change date="2009-08-31T04:00:11.277-04:00">INTERIM</status_change>
            <status_change date="2009-09-21T04:00:07.268-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02437">
          <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
          <criterion comment="InternetSrvcs.INETSVCS2-BOOT is installed" test_ref="oval:org.mitre.oval:tst:10552"/>
          <criterion negate="true" comment="Patch PHNE_39872 is installed" test_ref="oval:org.mitre.oval:tst:9736"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02437">
          <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
          <criterion comment="InternetSrvcs.INETSVCS-BOOT is installed" test_ref="oval:org.mitre.oval:tst:10571"/>
          <criterion negate="true" comment="Patch PHNE_39871 is installed" test_ref="oval:org.mitre.oval:tst:10557"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02437">
          <criterion comment="HP-UX B.11.31" test_ref="oval:org.mitre.oval:tst:8260"/>
          <criterion comment="NTP.NTP-RUN is installed" test_ref="oval:org.mitre.oval:tst:10348"/>
          <criterion negate="true" comment="Patch PHNE_39873 is installed" test_ref="oval:org.mitre.oval:tst:10276"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6301" version="1" class="vulnerability">
      <metadata>
        <title>HP-UX Running Kerberos, Remote Denial of Service (DoS), Execution of Arbitrary Code</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-0846" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0846"/>
        <description>The asn1_decode_generaltime function in lib/krb5/asn.1/asn1_decode.c in the ASN.1 GeneralizedTime decoder in MIT Kerberos 5 (aka krb5) before 1.6.4 allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code via vectors involving an invalid DER encoding that triggers a free of an uninitialized pointer.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-08-11T16:16:36.000-04:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2009-08-12T09:50:14.263-04:00">DRAFT</status_change>
            <status_change date="2009-08-31T04:00:10.825-04:00">INTERIM</status_change>
            <status_change date="2009-09-21T04:00:06.772-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02421">
          <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="krb5client.KRB5-64SLIB-A version is less than D.1.6.2.01" test_ref="oval:org.mitre.oval:tst:10417"/>
            <criterion comment="krb5client.KRB5-64SLIB-A version is less than D.1.6.2.01" test_ref="oval:org.mitre.oval:tst:10417"/>
            <criterion comment="krb5client.KRB5-PRG-A version is less than D.1.6.2.01" test_ref="oval:org.mitre.oval:tst:9858"/>
            <criterion comment="krb5client.KRB5-RUN-A version is less than D.1.6.2.01" test_ref="oval:org.mitre.oval:tst:10546"/>
            <criterion comment="krb5client.KRB5-SHLIB-A version is less than D.1.6.2.01" test_ref="oval:org.mitre.oval:tst:9864"/>
            <criterion comment="krb5client.KRB5IA32SLIB-A version is less than D.1.6.2.01" test_ref="oval:org.mitre.oval:tst:10283"/>
            <criterion comment="krb5client.KRB5IA64SLIB-A version is less than D.1.6.2.01" test_ref="oval:org.mitre.oval:tst:10263"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02421">
          <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="krb5client.KRB5-64SLIB-A version is less than C.1.3.5.09" test_ref="oval:org.mitre.oval:tst:10041"/>
            <criterion comment="krb5client.KRB5-PRG-A version is less than C.1.3.5.09" test_ref="oval:org.mitre.oval:tst:10495"/>
            <criterion comment="krb5client.KRB5-RUN-A version is less than C.1.3.5.09" test_ref="oval:org.mitre.oval:tst:10331"/>
            <criterion comment="krb5client.KRB5-SHLIB-A version is less than C.1.3.5.09" test_ref="oval:org.mitre.oval:tst:10556"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02421">
          <criterion comment="HP-UX B.11.31" test_ref="oval:org.mitre.oval:tst:8260"/>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="krb5client.KRB5-64SLIB-A version is less than E.1.6.2.03" test_ref="oval:org.mitre.oval:tst:10551"/>
            <criterion comment="krb5client.KRB5-PRG-A version is less than E.1.6.2.03" test_ref="oval:org.mitre.oval:tst:10305"/>
            <criterion comment="krb5client.KRB5-RUN-A version is less than E.1.6.2.03" test_ref="oval:org.mitre.oval:tst:10501"/>
            <criterion comment="krb5client.KRB5-SHLIB-A version is less than E.1.6.2.03" test_ref="oval:org.mitre.oval:tst:10039"/>
            <criterion comment="krb5client.KRB5IA32SLIB-A version is less than E.1.6.2.03" test_ref="oval:org.mitre.oval:tst:10539"/>
            <criterion comment="krb5client.KRB5IA64SLIB-A version is less than E.1.6.2.03" test_ref="oval:org.mitre.oval:tst:10262"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6215" version="1" class="vulnerability">
      <metadata>
        <title>HP-UX ttrace(2), Local Denial of Service (DoS)</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-1427" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1427"/>
        <description>Unspecified vulnerability in HP-UX B.11.31 allows local users to cause a denial of service (system crash) via unknown vectors related to the ttrace system call.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-08-11T16:16:36.000-04:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2009-08-12T09:50:13.063-04:00">DRAFT</status_change>
            <status_change date="2009-08-31T04:00:09.428-04:00">INTERIM</status_change>
            <status_change date="2009-09-21T04:00:06.529-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND" comment="Criteria meets Security Bulletin HPSBUX02450">
        <criterion comment="HP-UX B.11.31" test_ref="oval:org.mitre.oval:tst:8260"/>
        <criteria operator="OR" comment="filesets tests">
          <criterion comment="ProgSupport.C-INC is installed" test_ref="oval:org.mitre.oval:tst:10434"/>
          <criterion comment="ProgSupport.PAUX-ENG-A-MAN is installed" test_ref="oval:org.mitre.oval:tst:10443"/>
          <criterion comment="OS-Core.CORE2-KRN is installed" test_ref="oval:org.mitre.oval:tst:10534"/>
        </criteria>
        <criterion negate="true" comment="Patch PHKL_40197 is installed" test_ref="oval:org.mitre.oval:tst:10541"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5411" version="1" class="vulnerability">
      <metadata>
        <title>HP-UX Running XNTP, Remote Execution of Arbitrary Code</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-0159" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0159"/>
        <description>Stack-based buffer overflow in the cookedprint function in ntpq/ntpq.c in ntpq in NTP before 4.2.4p7-RC2 allows remote NTP servers to execute arbitrary code via a crafted response.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-08-11T16:16:36.000-04:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2009-08-12T09:50:15.228-04:00">DRAFT</status_change>
            <status_change date="2009-08-31T04:00:02.381-04:00">INTERIM</status_change>
            <status_change date="2009-09-21T04:00:03.047-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02437">
          <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
          <criterion comment="InternetSrvcs.INETSVCS2-BOOT is installed" test_ref="oval:org.mitre.oval:tst:10552"/>
          <criterion negate="true" comment="Patch PHNE_39872 is installed" test_ref="oval:org.mitre.oval:tst:9736"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02437">
          <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
          <criterion comment="InternetSrvcs.INETSVCS-BOOT is installed" test_ref="oval:org.mitre.oval:tst:10571"/>
          <criterion negate="true" comment="Patch PHNE_39871 is installed" test_ref="oval:org.mitre.oval:tst:10557"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02437">
          <criterion comment="HP-UX B.11.31" test_ref="oval:org.mitre.oval:tst:8260"/>
          <criterion comment="NTP.NTP-RUN is installed" test_ref="oval:org.mitre.oval:tst:10348"/>
          <criterion negate="true" comment="Patch PHNE_39873 is installed" test_ref="oval:org.mitre.oval:tst:10276"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5791" version="1" class="vulnerability">
      <metadata>
        <title>HPUX Running useradd(1M), Local Unauthorized Access</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-0719" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0719"/>
        <description>Unspecified vulnerability in useradd in HP HP-UX B.11.11, B.11.23, and B.11.31 allows local users to access arbitrary files and directories via unknown vectors, a different issue than CVE-2008-1660.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-04-29T14:29:56.000-04:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2009-05-07T11:17:41.618-04:00">DRAFT</status_change>
            <status_change date="2009-05-25T04:01:46.634-04:00">INTERIM</status_change>
            <status_change date="2009-06-15T04:00:48.178-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02366">
          <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
          <criterion comment="OS-Core.UX2-CORE is installed" test_ref="oval:org.mitre.oval:tst:10095"/>
          <criterion negate="true" comment="Patch PHCO_38481 is installed" test_ref="oval:org.mitre.oval:tst:9730"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02366">
          <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
          <criterion comment="OS-Core.UX2-CORE is installed" test_ref="oval:org.mitre.oval:tst:10095"/>
          <criterion negate="true" comment="Patch PHCO_38490 is installed" test_ref="oval:org.mitre.oval:tst:9687"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02366">
          <criterion comment="HP-UX B.11.31" test_ref="oval:org.mitre.oval:tst:8260"/>
          <criterion comment="OS-Core.UX2-CORE is installed" test_ref="oval:org.mitre.oval:tst:10095"/>
          <criterion negate="true" comment="Patch PHCO_38482 is installed" test_ref="oval:org.mitre.oval:tst:9928"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:840" version="1" class="vulnerability">
      <metadata>
        <title>Apache HTTP Request Smuggling</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
          <product>Apache</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2088" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2088"/>
        <description>The Apache HTTP server before 1.3.34, and 2.0.x before 2.0.55, when acting as an HTTP proxy, allows remote attackers to poison the web cache, bypass web application firewall protection, and conduct XSS attacks via an HTTP request with both a "Transfer-Encoding: chunked" header and a Content-Length header, which causes Apache to incorrectly handle and forward the body of the request in a way that causes the receiving server to process it as a separate HTTP request, aka "HTTP Request Smuggling."</description>
        <oval_repository>
          <dates>
            <submitted date="2005-11-30T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-12-20T11:03:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-01-04T08:04:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-01-25T07:30:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.00, 11.11, or 11.23">
          <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.11">
            <criteria operator="AND" comment="700 Series OS Release 11.11">
              <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2515"/>
              <criterion comment="HP Release B.11.11" negate="false" test_ref="oval:org.mitre.oval:tst:2514"/>
            </criteria>
            <criteria operator="AND" comment="800 Series OS Release 11.11">
              <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2513"/>
              <criterion comment="HP Release B.11.11" negate="false" test_ref="oval:org.mitre.oval:tst:2514"/>
            </criteria>
          </criteria>
          <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.00">
            <criteria operator="AND" comment="700 Series OS Release 11.00">
              <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2515"/>
              <criterion comment="HP Release B.11.00" negate="false" test_ref="oval:org.mitre.oval:tst:2512"/>
            </criteria>
            <criteria operator="AND" comment="800 Series OS Release 11.00">
              <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2513"/>
              <criterion comment="HP Release B.11.00" negate="false" test_ref="oval:org.mitre.oval:tst:2512"/>
            </criteria>
          </criteria>
          <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.23">
            <criteria operator="AND" comment="700 Series OS Release 11.23">
              <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2515"/>
              <criterion comment="HP Release B.11.23" negate="false" test_ref="oval:org.mitre.oval:tst:2511"/>
            </criteria>
            <criteria operator="AND" comment="800 Series OS Release 11.23">
              <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2513"/>
              <criterion comment="HP Release B.11.23" negate="false" test_ref="oval:org.mitre.oval:tst:2511"/>
            </criteria>
          </criteria>
        </criteria>
        <criterion comment="hpuxwsAPACHE is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2388"/>
        <criterion comment="hpuxwsAPACHE has a version greater than or equal (A|B).2.0.55.0" negate="true" test_ref="oval:org.mitre.oval:tst:2387"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:772" version="2" class="vulnerability">
      <metadata>
        <title>HP-UX Usermod Local Unauthorized Access Vulnerability instead of usermod Recursive Ownership Error.</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
          <product>Apache</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-1248" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1248"/>
        <description>Unspecified vulnerability in usermod in HP-UX B.11.00, B.11.11, and B.11.23, when run with certain options that involve a new home directory, might cause usermod to change the ownership of all directories and files under the new directory, which might result in less secure permissions than intended.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-03-18T07:24:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-03-22T11:10:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-04-06T06:31:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-05-03T10:06:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Added CVE reference. Implemented by Jon Baker of The MITRE Corporation." date="2007-03-19T20:27:00.650-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2007-03-19T20:42:53.692-04:00">INTERIM</status_change>
            <modified comment="Updated definition title. Implemented by Jon Baker of The MITRE Corporation." date="2007-03-19T20:42:00.035-04:00">
              <contributor organization="Security-Database">Nabil Ouchn</contributor>
            </modified>
            <status_change date="2007-04-10T13:44:28.730-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.00">
          <criteria operator="AND" comment="700 Series OS Release 11.00">
            <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2515"/>
            <criterion comment="HP Release B.11.00" negate="false" test_ref="oval:org.mitre.oval:tst:2512"/>
          </criteria>
          <criteria operator="AND" comment="800 Series OS Release 11.00">
            <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2513"/>
            <criterion comment="HP Release B.11.00" negate="false" test_ref="oval:org.mitre.oval:tst:2512"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:760" version="1" class="vulnerability">
      <metadata>
        <title>Apache HTTP Byte-range DoS Vulnerability</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
          <product>Apache</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2728" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2728"/>
        <description>The byte-range filter in Apache 2.0 before 2.0.54 allows remote attackers to cause a denial of service (memory consumption) via an HTTP header with a large Range field.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-11-30T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-12-20T11:03:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-01-04T08:04:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-01-25T07:30:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.00, 11.11, or 11.23">
          <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.11">
            <criteria operator="AND" comment="700 Series OS Release 11.11">
              <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2515"/>
              <criterion comment="HP Release B.11.11" negate="false" test_ref="oval:org.mitre.oval:tst:2514"/>
            </criteria>
            <criteria operator="AND" comment="800 Series OS Release 11.11">
              <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2513"/>
              <criterion comment="HP Release B.11.11" negate="false" test_ref="oval:org.mitre.oval:tst:2514"/>
            </criteria>
          </criteria>
          <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.00">
            <criteria operator="AND" comment="700 Series OS Release 11.00">
              <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2515"/>
              <criterion comment="HP Release B.11.00" negate="false" test_ref="oval:org.mitre.oval:tst:2512"/>
            </criteria>
            <criteria operator="AND" comment="800 Series OS Release 11.00">
              <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2513"/>
              <criterion comment="HP Release B.11.00" negate="false" test_ref="oval:org.mitre.oval:tst:2512"/>
            </criteria>
          </criteria>
          <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.23">
            <criteria operator="AND" comment="700 Series OS Release 11.23">
              <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2515"/>
              <criterion comment="HP Release B.11.23" negate="false" test_ref="oval:org.mitre.oval:tst:2511"/>
            </criteria>
            <criteria operator="AND" comment="800 Series OS Release 11.23">
              <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2513"/>
              <criterion comment="HP Release B.11.23" negate="false" test_ref="oval:org.mitre.oval:tst:2511"/>
            </criteria>
          </criteria>
        </criteria>
        <criterion comment="hpuxwsAPACHE is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2388"/>
        <criterion comment="hpuxwsAPACHE has a version greater than or equal (A|B).2.0.55.0" negate="true" test_ref="oval:org.mitre.oval:tst:2387"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:735" version="1" class="vulnerability">
      <metadata>
        <title>Apache Integer Overflow in pcre_compile.c</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
          <product>Apache</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2491" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2491"/>
        <description>Integer overflow in pcre_compile.c in Perl Compatible Regular Expressions (PCRE) before 6.2, as used in multiple products such as Python, Ethereal, and PHP, allows attackers to execute arbitrary code via quantifier values in regular expressions, which leads to a heap-based buffer overflow.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-11-30T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-12-20T11:03:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-01-04T08:04:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-01-25T07:30:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.00, 11.11, or 11.23">
          <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.11">
            <criteria operator="AND" comment="700 Series OS Release 11.11">
              <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2515"/>
              <criterion comment="HP Release B.11.11" negate="false" test_ref="oval:org.mitre.oval:tst:2514"/>
            </criteria>
            <criteria operator="AND" comment="800 Series OS Release 11.11">
              <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2513"/>
              <criterion comment="HP Release B.11.11" negate="false" test_ref="oval:org.mitre.oval:tst:2514"/>
            </criteria>
          </criteria>
          <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.00">
            <criteria operator="AND" comment="700 Series OS Release 11.00">
              <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2515"/>
              <criterion comment="HP Release B.11.00" negate="false" test_ref="oval:org.mitre.oval:tst:2512"/>
            </criteria>
            <criteria operator="AND" comment="800 Series OS Release 11.00">
              <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2513"/>
              <criterion comment="HP Release B.11.00" negate="false" test_ref="oval:org.mitre.oval:tst:2512"/>
            </criteria>
          </criteria>
          <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.23">
            <criteria operator="AND" comment="700 Series OS Release 11.23">
              <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2515"/>
              <criterion comment="HP Release B.11.23" negate="false" test_ref="oval:org.mitre.oval:tst:2511"/>
            </criteria>
            <criteria operator="AND" comment="800 Series OS Release 11.23">
              <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2513"/>
              <criterion comment="HP Release B.11.23" negate="false" test_ref="oval:org.mitre.oval:tst:2511"/>
            </criteria>
          </criteria>
        </criteria>
        <criterion comment="hpuxwsAPACHE is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2388"/>
        <criterion comment="hpuxwsAPACHE has a version greater than or equal (A|B).2.0.55.0" negate="true" test_ref="oval:org.mitre.oval:tst:2387"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:728" version="2" class="vulnerability">
      <metadata>
        <title>HP-UX 11 Perl rmtree Race Condition</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
          <product>Perl</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0448" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0448"/>
        <description>Race condition in the rmtree function in File::Path.pm in Perl before 5.8.4 allows local users to create arbitrary setuid binaries in the tree being deleted, a different vulnerability than CVE-2004-0452.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-09-22T05:48:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-09-22T20:15:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-07T09:15:52.495-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:15:59.663-04:00">ACCEPTED</status_change>
            <modified comment="Added title." date="2007-02-22T17:48:00.580-05:00">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2007-02-22T17:49:04.605-05:00">INTERIM</status_change>
            <status_change date="2007-03-21T16:17:25.449-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="OR">
        <criteria operator="AND" comment="Perl 5.6 or 5.8 vulnerable on 11.00, 11.11, or 11.23" negate="false">
          <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.00, 11.11, or 11.23" negate="false">
            <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.11" negate="false">
              <criteria operator="AND" comment="700 Series OS Release 11.11" negate="false">
                <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:3443"/>
                <criterion comment="HP Release B.11.11" negate="false" test_ref="oval:org.mitre.oval:tst:3704"/>
              </criteria>
              <criteria operator="AND" comment="800 Series OS Release 11.11" negate="false">
                <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:4124"/>
                <criterion comment="HP Release B.11.11" negate="false" test_ref="oval:org.mitre.oval:tst:3704"/>
              </criteria>
            </criteria>
            <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.00" negate="false">
              <criteria operator="AND" comment="700 Series OS Release 11.00" negate="false">
                <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:3443"/>
                <criterion comment="HP Release B.11.00" negate="false" test_ref="oval:org.mitre.oval:tst:3571"/>
              </criteria>
              <criteria operator="AND" comment="800 Series OS Release 11.00" negate="false">
                <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:4124"/>
                <criterion comment="HP Release B.11.00" negate="false" test_ref="oval:org.mitre.oval:tst:3571"/>
              </criteria>
            </criteria>
            <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.23" negate="false">
              <criteria operator="AND" comment="700 Series OS Release 11.23" negate="false">
                <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:3443"/>
                <criterion comment="HP Release B.11.23" negate="false" test_ref="oval:org.mitre.oval:tst:3901"/>
              </criteria>
              <criteria operator="AND" comment="800 Series OS Release 11.23" negate="false">
                <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:4124"/>
                <criterion comment="HP Release B.11.23" negate="false" test_ref="oval:org.mitre.oval:tst:3901"/>
              </criteria>
            </criteria>
          </criteria>
          <criteria operator="OR" comment="Perl version 5.6.0 is installed or 5.8.0 without revision G or later is installed" negate="false">
            <criterion comment="Perl 5.6.0 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3419"/>
            <criterion comment="Perl 5.8.0 (revision F or earlier) is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3902"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Perl 5.8.2 vulnerable on 11.00 or 11.11" negate="false">
          <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.00 or 11.11" negate="false">
            <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.11" negate="false">
              <criteria operator="AND" comment="700 Series OS Release 11.11" negate="false">
                <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:3443"/>
                <criterion comment="HP Release B.11.11" negate="false" test_ref="oval:org.mitre.oval:tst:3704"/>
              </criteria>
              <criteria operator="AND" comment="800 Series OS Release 11.11" negate="false">
                <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:4124"/>
                <criterion comment="HP Release B.11.11" negate="false" test_ref="oval:org.mitre.oval:tst:3704"/>
              </criteria>
            </criteria>
            <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.00" negate="false">
              <criteria operator="AND" comment="700 Series OS Release 11.00" negate="false">
                <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:3443"/>
                <criterion comment="HP Release B.11.00" negate="false" test_ref="oval:org.mitre.oval:tst:3571"/>
              </criteria>
              <criteria operator="AND" comment="800 Series OS Release 11.00" negate="false">
                <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:4124"/>
                <criterion comment="HP Release B.11.00" negate="false" test_ref="oval:org.mitre.oval:tst:3571"/>
              </criteria>
            </criteria>
          </criteria>
          <criterion comment="Perl 5.8.2,revision C or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3226"/>
        </criteria>
        <criteria operator="AND" comment="Perl 5.8.2 vulnerable on 11.23" negate="false">
          <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.23" negate="false">
            <criteria operator="AND" comment="700 Series OS Release 11.23" negate="false">
              <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:3443"/>
              <criterion comment="HP Release B.11.23" negate="false" test_ref="oval:org.mitre.oval:tst:3901"/>
            </criteria>
            <criteria operator="AND" comment="800 Series OS Release 11.23" negate="false">
              <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:4124"/>
              <criterion comment="HP Release B.11.23" negate="false" test_ref="oval:org.mitre.oval:tst:3901"/>
            </criteria>
          </criteria>
          <criterion comment="Perl 5.8.2,revision E or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3635"/>
        </criteria>
        <criteria operator="AND" comment="Perl 5.8.3 vulnerable on 11.0, 11.11, or 11.23" negate="false">
          <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.00, 11.11, or 11.23" negate="false">
            <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.11" negate="false">
              <criteria operator="AND" comment="700 Series OS Release 11.11" negate="false">
                <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:3443"/>
                <criterion comment="HP Release B.11.11" negate="false" test_ref="oval:org.mitre.oval:tst:3704"/>
              </criteria>
              <criteria operator="AND" comment="800 Series OS Release 11.11" negate="false">
                <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:4124"/>
                <criterion comment="HP Release B.11.11" negate="false" test_ref="oval:org.mitre.oval:tst:3704"/>
              </criteria>
            </criteria>
            <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.00" negate="false">
              <criteria operator="AND" comment="700 Series OS Release 11.00" negate="false">
                <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:3443"/>
                <criterion comment="HP Release B.11.00" negate="false" test_ref="oval:org.mitre.oval:tst:3571"/>
              </criteria>
              <criteria operator="AND" comment="800 Series OS Release 11.00" negate="false">
                <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:4124"/>
                <criterion comment="HP Release B.11.00" negate="false" test_ref="oval:org.mitre.oval:tst:3571"/>
              </criteria>
            </criteria>
            <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.23" negate="false">
              <criteria operator="AND" comment="700 Series OS Release 11.23" negate="false">
                <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:3443"/>
                <criterion comment="HP Release B.11.23" negate="false" test_ref="oval:org.mitre.oval:tst:3901"/>
              </criteria>
              <criteria operator="AND" comment="800 Series OS Release 11.23" negate="false">
                <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:4124"/>
                <criterion comment="HP Release B.11.23" negate="false" test_ref="oval:org.mitre.oval:tst:3901"/>
              </criteria>
            </criteria>
          </criteria>
          <criterion comment="Perl 5.8.3,revision A is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3847"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:651" version="2" class="vulnerability">
      <metadata>
        <title>HP-UX 11.11 or 11.23 Path MTU Discovery Attack Vulnerability</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
          <product>Operating System</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-1060" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1060"/>
        <description>Multiple TCP/IP and ICMP implementations, when using Path MTU (PMTU) discovery (PMTUD), allow remote attackers to cause a denial of service (network throughput reduction for TCP connections) via forged ICMP ("Fragmentation Needed and Don't Fragment was Set") packets with a low next-hop MTU value, aka the "Path MTU discovery attack."  NOTE: CVE-2004-0790, CVE-2004-0791, and CVE-2004-1060 have been SPLIT based on different attacks; CVE-2005-0065, CVE-2005-0066, CVE-2005-0067, and CVE-2005-0068 are related identifiers that are SPLIT based on the underlying vulnerability.  While CVE normally SPLITs based on vulnerability, the attack-based identifiers exist due to the variety and number of affected implementations and solutions that address the attacks instead of the underlying vulnerabilities.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-09-22T05:48:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-09-22T20:15:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-07T09:15:51.103-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:15:58.450-04:00">ACCEPTED</status_change>
            <modified comment="Added title." date="2007-02-22T17:43:00.954-05:00">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2007-02-22T17:44:10.985-05:00">INTERIM</status_change>
            <status_change date="2007-03-21T16:17:23.230-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="An HPUX 11.11 or 11.23 is installed" negate="false">
          <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.11" negate="false">
            <criteria operator="AND" comment="700 Series OS Release 11.11" negate="false">
              <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:3443"/>
              <criterion comment="HP Release B.11.11" negate="false" test_ref="oval:org.mitre.oval:tst:3704"/>
            </criteria>
            <criteria operator="AND" comment="800 Series OS Release 11.11" negate="false">
              <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:4124"/>
              <criterion comment="HP Release B.11.11" negate="false" test_ref="oval:org.mitre.oval:tst:3704"/>
            </criteria>
          </criteria>
          <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.23" negate="false">
            <criteria operator="AND" comment="700 Series OS Release 11.23" negate="false">
              <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:3443"/>
              <criterion comment="HP Release B.11.23" negate="false" test_ref="oval:org.mitre.oval:tst:3901"/>
            </criteria>
            <criteria operator="AND" comment="800 Series OS Release 11.23" negate="false">
              <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:4124"/>
              <criterion comment="HP Release B.11.23" negate="false" test_ref="oval:org.mitre.oval:tst:3901"/>
            </criteria>
          </criteria>
        </criteria>
        <criterion comment="TOUR_PRODUCT.T-NET2-KRN with version less than A.03.00 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3415"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:642" version="1" class="vulnerability">
      <metadata>
        <title>HP-Samba DACL Remote Integer Overflow Vulnerability (CIFS A.02)</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
          <product>Samba</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-1154" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1154"/>
        <description>Integer overflow in the Samba daemon (smbd) in Samba 2.x and 3.0.x through 3.0.9 allows remote authenticated users to cause a denial of service (application crash) and possibly execute arbitrary code via a Samba request with a large number of security descriptors that triggers a heap-based buffer overflow.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-01-13T02:24:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-01-25T07:30:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-02-22T08:27:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-03-09T12:19:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="An HPUX 11.11 or 11.23 is installed">
          <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.11">
            <criteria operator="AND" comment="700 Series OS Release 11.11">
              <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2515"/>
              <criterion comment="HP Release B.11.11" negate="false" test_ref="oval:org.mitre.oval:tst:2514"/>
            </criteria>
            <criteria operator="AND" comment="800 Series OS Release 11.11">
              <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2513"/>
              <criterion comment="HP Release B.11.11" negate="false" test_ref="oval:org.mitre.oval:tst:2514"/>
            </criteria>
          </criteria>
          <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.23">
            <criteria operator="AND" comment="700 Series OS Release 11.23">
              <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2515"/>
              <criterion comment="HP Release B.11.23" negate="false" test_ref="oval:org.mitre.oval:tst:2511"/>
            </criteria>
            <criteria operator="AND" comment="800 Series OS Release 11.23">
              <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2513"/>
              <criterion comment="HP Release B.11.23" negate="false" test_ref="oval:org.mitre.oval:tst:2511"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="OR" comment="Any of the CIFS components has a version equal to A.02.01">
          <criterion comment="CIFS-Server.CIFS-RUN with version equal A.02.01 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2481"/>
          <criterion comment="CIFS-Server.CIFS-UTIL with version equal A.02.01 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2480"/>
          <criterion comment="CIFS-Server.CIFS-ADMIN with version equal A.02.01 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2479"/>
          <criterion comment="CIFS-Server.CIFS-LIB with version equal A.02.01 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2478"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:615" version="2" class="vulnerability">
      <metadata>
        <title>HP-UX ftpd Remote Unauthorized Data Access (B.11.11)</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
          <product>ftpd</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-3296" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-3296"/>
        <description>The FTP server in HP-UX 10.20, B.11.00, and B.11.11, allows remote attackers to list arbitrary directories as root by running the LIST command before logging in.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-09-22T05:48:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-09-22T20:15:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-07T09:15:49.969-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:15:57.625-04:00">ACCEPTED</status_change>
            <modified comment="Added title." date="2007-02-25T23:52:00.850-05:00">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2007-02-25T23:52:49.873-05:00">INTERIM</status_change>
            <status_change date="2007-03-21T16:17:22.517-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.11" negate="false">
          <criteria operator="AND" comment="700 Series OS Release 11.11" negate="false">
            <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:3443"/>
            <criterion comment="HP Release B.11.11" negate="false" test_ref="oval:org.mitre.oval:tst:3704"/>
          </criteria>
          <criteria operator="AND" comment="800 Series OS Release 11.11" negate="false">
            <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:4124"/>
            <criterion comment="HP Release B.11.11" negate="false" test_ref="oval:org.mitre.oval:tst:3704"/>
          </criteria>
        </criteria>
        <criterion comment="WUFTP-26.INETSVCS-FTP with version less than B.11.11.01.006 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3641"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:596" version="2" class="vulnerability">
      <metadata>
        <title>HP-UX 11.11 or 11.23 ICMP Source Quench Attack Vulnerability</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
          <product>Operating System</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0791" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0791"/>
        <description>Multiple TCP/IP and ICMP implementations allow remote attackers to cause a denial of service (network throughput reduction for TCP connections) via a blind throughput-reduction attack using spoofed Source Quench packets, aka the "ICMP Source Quench attack."  NOTE: CVE-2004-0790, CVE-2004-0791, and CVE-2004-1060 have been SPLIT based on different attacks; CVE-2005-0065, CVE-2005-0066, CVE-2005-0067, and CVE-2005-0068 are related identifiers that are SPLIT based on the underlying vulnerability.  While CVE normally SPLITs based on vulnerability, the attack-based identifiers exist due to the variety and number of affected implementations and solutions that address the attacks instead of the underlying vulnerabilities.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-09-22T05:48:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-09-22T20:15:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-07T09:15:49.438-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:15:56.897-04:00">ACCEPTED</status_change>
            <modified comment="Added title." date="2007-02-23T12:53:00.683-05:00">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2007-02-23T12:54:12.704-05:00">INTERIM</status_change>
            <status_change date="2007-03-21T16:17:21.919-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="An HPUX 11.11 or 11.23 is installed" negate="false">
          <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.11" negate="false">
            <criteria operator="AND" comment="700 Series OS Release 11.11" negate="false">
              <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:3443"/>
              <criterion comment="HP Release B.11.11" negate="false" test_ref="oval:org.mitre.oval:tst:3704"/>
            </criteria>
            <criteria operator="AND" comment="800 Series OS Release 11.11" negate="false">
              <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:4124"/>
              <criterion comment="HP Release B.11.11" negate="false" test_ref="oval:org.mitre.oval:tst:3704"/>
            </criteria>
          </criteria>
          <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.23" negate="false">
            <criteria operator="AND" comment="700 Series OS Release 11.23" negate="false">
              <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:3443"/>
              <criterion comment="HP Release B.11.23" negate="false" test_ref="oval:org.mitre.oval:tst:3901"/>
            </criteria>
            <criteria operator="AND" comment="800 Series OS Release 11.23" negate="false">
              <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:4124"/>
              <criterion comment="HP Release B.11.23" negate="false" test_ref="oval:org.mitre.oval:tst:3901"/>
            </criteria>
          </criteria>
        </criteria>
        <criterion comment="TOUR_PRODUCT.T-NET2-KRN with version less than A.03.00 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3415"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:514" version="2" class="vulnerability">
      <metadata>
        <title>HP-UX 11.11, 11.23 Blind Connection Reset Attack Vulnerability</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
          <product>Operating System</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0790" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0790"/>
        <description>Multiple TCP/IP and ICMP implementations allow remote attackers to cause a denial of service (reset TCP connections) via spoofed ICMP error messages, aka the "blind connection-reset attack."  NOTE: CVE-2004-0790, CVE-2004-0791, and CVE-2004-1060 have been SPLIT based on different attacks; CVE-2005-0065, CVE-2005-0066, CVE-2005-0067, and CVE-2005-0068 are related identifiers that are SPLIT based on the underlying vulnerability.  While CVE normally SPLITs based on vulnerability, the attack-based identifiers exist due to the variety and number of affected implementations and solutions that address the attacks instead of the underlying vulnerabilities.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-09-22T05:48:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-09-22T20:15:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-07T09:15:48.503-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:15:56.136-04:00">ACCEPTED</status_change>
            <modified comment="Added title." date="2007-02-26T01:00:00.030-05:00">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2007-02-26T01:00:42.054-05:00">INTERIM</status_change>
            <status_change date="2007-03-21T16:17:19.700-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="An HPUX 11.11 or 11.23 is installed" negate="false">
          <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.11" negate="false">
            <criteria operator="AND" comment="700 Series OS Release 11.11" negate="false">
              <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:3443"/>
              <criterion comment="HP Release B.11.11" negate="false" test_ref="oval:org.mitre.oval:tst:3704"/>
            </criteria>
            <criteria operator="AND" comment="800 Series OS Release 11.11" negate="false">
              <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:4124"/>
              <criterion comment="HP Release B.11.11" negate="false" test_ref="oval:org.mitre.oval:tst:3704"/>
            </criteria>
          </criteria>
          <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.23" negate="false">
            <criteria operator="AND" comment="700 Series OS Release 11.23" negate="false">
              <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:3443"/>
              <criterion comment="HP Release B.11.23" negate="false" test_ref="oval:org.mitre.oval:tst:3901"/>
            </criteria>
            <criteria operator="AND" comment="800 Series OS Release 11.23" negate="false">
              <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:4124"/>
              <criterion comment="HP Release B.11.23" negate="false" test_ref="oval:org.mitre.oval:tst:3901"/>
            </criteria>
          </criteria>
        </criteria>
        <criterion comment="TOUR_PRODUCT.T-NET2-KRN with version less than A.03.00 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3415"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:438" version="2" class="vulnerability">
      <metadata>
        <title>HP-UX ftpd Remote Unauthorized Data Access (B.11.00)</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
          <product>ftpd</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-3296" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-3296"/>
        <description>The FTP server in HP-UX 10.20, B.11.00, and B.11.11, allows remote attackers to list arbitrary directories as root by running the LIST command before logging in.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-09-22T05:48:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-09-22T20:15:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-07T09:15:47.606-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:15:55.094-04:00">ACCEPTED</status_change>
            <modified comment="Added title." date="2007-02-25T23:51:00.539-05:00">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2007-02-25T23:52:03.561-05:00">INTERIM</status_change>
            <status_change date="2007-03-21T16:17:19.299-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.00" negate="false">
          <criteria operator="AND" comment="700 Series OS Release 11.00" negate="false">
            <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:3443"/>
            <criterion comment="HP Release B.11.00" negate="false" test_ref="oval:org.mitre.oval:tst:3571"/>
          </criteria>
          <criteria operator="AND" comment="800 Series OS Release 11.00" negate="false">
            <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:4124"/>
            <criterion comment="HP Release B.11.00" negate="false" test_ref="oval:org.mitre.oval:tst:3571"/>
          </criteria>
        </criteria>
        <criterion comment="WUFTP-26.INETSVCS-FTP with version less than B.11.00.01.005 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3962"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1637" version="1" class="vulnerability">
      <metadata>
        <title>HP-UX wuftpd Privilege Escalation Vulnerability (B.11.00)</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
          <product>ftpd</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0148" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0148"/>
        <description>wu-ftpd 2.6.2 and earlier, with the restricted-gid option enabled, allows local users to bypass access restrictions by changing the permissions to prevent access to their home directory, which causes wu-ftpd to use the root directory instead.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-01-30T07:20:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-02-01T09:08:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-02-22T08:27:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-03-09T12:19:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.00">
          <criteria operator="AND" comment="700 Series OS Release 11.00">
            <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2515"/>
            <criterion comment="HP Release B.11.00" negate="false" test_ref="oval:org.mitre.oval:tst:2512"/>
          </criteria>
          <criteria operator="AND" comment="800 Series OS Release 11.00">
            <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2513"/>
            <criterion comment="HP Release B.11.00" negate="false" test_ref="oval:org.mitre.oval:tst:2512"/>
          </criteria>
        </criteria>
        <criterion comment="WUFTP-26.INETSVCS-FTP with version less than B.11.00.01.004 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1124"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1582" version="1" class="vulnerability">
      <metadata>
        <title>HP-UX SIM Hangs MS-IE Due to MS04-025 Changes</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
          <product>Operating System</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-3983" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-3983"/>
        <description>Unknown vulnerability in the login page for HP Systems Insight Manager (SIM) 4.0 and 4.1, when accessed by Microsoft Internet Explorer with the MS04-025 patch, leads to a denial of service (browser hang). NOTE: although the advisory is vague, this issue does not appear to involve an attacker at all.  If not, then this issue is not a vulnerability.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-01-30T07:20:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-02-01T09:08:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-02-22T08:27:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-03-09T12:19:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="OR">
        <criterion comment="SysMgmtServer.MX-PORTAL (C.04.00.00.00) is installed" negate="false" test_ref="oval:org.mitre.oval:tst:841"/>
        <criterion comment="SysMgmtServer.MX-PORTAL (C.04.01.00.00) is installed" negate="false" test_ref="oval:org.mitre.oval:tst:840"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1566" version="1" class="vulnerability">
      <metadata>
        <title>Leaking GSSAPI Credentials Vulnerability (B.11.00/B.11.11)</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
          <product>SecureShell</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2798" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2798"/>
        <description>sshd in OpenSSH before 4.2, when GSSAPIDelegateCredentials is enabled, allows GSSAPI credentials to be delegated to clients who log in using non-GSSAPI methods, which could cause those credentials to be exposed to untrusted users or hosts.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-01-11T12:55:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-01-12T09:18:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-02-01T09:08:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-02-22T08:27:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.00 or 11.11">
          <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.11">
            <criteria operator="AND" comment="700 Series OS Release 11.11">
              <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2515"/>
              <criterion comment="HP Release B.11.11" negate="false" test_ref="oval:org.mitre.oval:tst:2514"/>
            </criteria>
            <criteria operator="AND" comment="800 Series OS Release 11.11">
              <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2513"/>
              <criterion comment="HP Release B.11.11" negate="false" test_ref="oval:org.mitre.oval:tst:2514"/>
            </criteria>
          </criteria>
          <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.00">
            <criteria operator="AND" comment="700 Series OS Release 11.00">
              <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2515"/>
              <criterion comment="HP Release B.11.00" negate="false" test_ref="oval:org.mitre.oval:tst:2512"/>
            </criteria>
            <criteria operator="AND" comment="800 Series OS Release 11.00">
              <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2513"/>
              <criterion comment="HP Release B.11.00" negate="false" test_ref="oval:org.mitre.oval:tst:2512"/>
            </criteria>
          </criteria>
        </criteria>
        <criterion comment="Secure_Shell.SECURE_SHELL is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1033"/>
        <criterion comment="Secure_Shell.SECURE_SHELL with version less than A.04.20.004 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:869"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1552" version="1" class="vulnerability">
      <metadata>
        <title>HP-UX PMTUD Remote DoS (B.11.22)</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
          <product>Operating System</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1192" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1192"/>
        <description>Unknown vulnerability in HP-UX B.11.00, B.11.04, B.11.11, B.11.22, and B.11.23, when running TCP/IP on IPv4, allows remote attackers to cause a denial of service via certain packets, related to the PMTU, a different vulnerability than CVE-2004-1060.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-02-01T11:45:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-03-09T12:19:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-04-06T06:30:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-05-03T10:06:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="AND" comment="700 Series OS Release 11.22">
          <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2515"/>
          <criterion comment="HP Release B.11.22" negate="false" test_ref="oval:org.mitre.oval:tst:1015"/>
        </criteria>
        <criterion comment="Networking.NET2-KRN is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1442"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1542" version="1" class="vulnerability">
      <metadata>
        <title>zlib Compression Remote DoS Vulnerability (B.11.00/B.11.11)</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
          <product>SecureShell</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2096" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2096"/>
        <description>zlib 1.2 and later versions allows remote attackers to cause a denial of service (crash) via a crafted compressed stream with an incomplete code description of a length greater than 1, which leads to a buffer overflow, as demonstrated using a crafted PNG file.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-01-11T12:55:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-01-12T09:18:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-02-01T09:08:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-02-22T08:27:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.00 or 11.11">
          <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.11">
            <criteria operator="AND" comment="700 Series OS Release 11.11">
              <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2515"/>
              <criterion comment="HP Release B.11.11" negate="false" test_ref="oval:org.mitre.oval:tst:2514"/>
            </criteria>
            <criteria operator="AND" comment="800 Series OS Release 11.11">
              <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2513"/>
              <criterion comment="HP Release B.11.11" negate="false" test_ref="oval:org.mitre.oval:tst:2514"/>
            </criteria>
          </criteria>
          <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.00">
            <criteria operator="AND" comment="700 Series OS Release 11.00">
              <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2515"/>
              <criterion comment="HP Release B.11.00" negate="false" test_ref="oval:org.mitre.oval:tst:2512"/>
            </criteria>
            <criteria operator="AND" comment="800 Series OS Release 11.00">
              <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2513"/>
              <criterion comment="HP Release B.11.00" negate="false" test_ref="oval:org.mitre.oval:tst:2512"/>
            </criteria>
          </criteria>
        </criteria>
        <criterion comment="Secure_Shell.SECURE_SHELL is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1033"/>
        <criterion comment="Secure_Shell.SECURE_SHELL with version less than A.04.20.004 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:869"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1533" version="1" class="vulnerability">
      <metadata>
        <title>HP-UX PMTUD Remote DoS (B.11.11-IPSEC)</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
          <product>Operating System</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1192" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1192"/>
        <description>Unknown vulnerability in HP-UX B.11.00, B.11.04, B.11.11, B.11.22, and B.11.23, when running TCP/IP on IPv4, allows remote attackers to cause a denial of service via certain packets, related to the PMTU, a different vulnerability than CVE-2004-1060.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-02-01T11:45:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-03-09T12:19:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-04-06T06:30:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-05-03T10:06:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.11">
          <criteria operator="AND" comment="700 Series OS Release 11.11">
            <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2515"/>
            <criterion comment="HP Release B.11.11" negate="false" test_ref="oval:org.mitre.oval:tst:2514"/>
          </criteria>
          <criteria operator="AND" comment="800 Series OS Release 11.11">
            <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2513"/>
            <criterion comment="HP Release B.11.11" negate="false" test_ref="oval:org.mitre.oval:tst:2514"/>
          </criteria>
        </criteria>
        <criterion comment="IPSec.IPSEC2-KRN is installed" negate="false" test_ref="oval:org.mitre.oval:tst:966"/>
        <criteria operator="OR" comment="IPSec.IPSEC2-KRN version is under A.2.00.01 or TOUR version is under 3.0">
          <criterion comment="IPSec.IPSEC2-KRN with version less than A.2.00.01 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:965"/>
          <criterion comment="TOUR_PRODUCT.T-NET2-KRN with version less than A.03.00 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:964"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1459" version="1" class="vulnerability">
      <metadata>
        <title>HP-Samba DACL Remote Integer Overflow Vulnerability (CIFS A.01)</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
          <product>Samba</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-1154" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1154"/>
        <description>Integer overflow in the Samba daemon (smbd) in Samba 2.x and 3.0.x through 3.0.9 allows remote authenticated users to cause a denial of service (application crash) and possibly execute arbitrary code via a Samba request with a large number of security descriptors that triggers a heap-based buffer overflow.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-01-13T02:24:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-01-25T07:30:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-02-22T08:27:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-03-09T12:19:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.00, 11.11, 11.22, or 11.23">
          <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.00">
            <criteria operator="AND" comment="700 Series OS Release 11.00">
              <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2515"/>
              <criterion comment="HP Release B.11.00" negate="false" test_ref="oval:org.mitre.oval:tst:2512"/>
            </criteria>
            <criteria operator="AND" comment="800 Series OS Release 11.00">
              <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2513"/>
              <criterion comment="HP Release B.11.00" negate="false" test_ref="oval:org.mitre.oval:tst:2512"/>
            </criteria>
          </criteria>
          <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.11">
            <criteria operator="AND" comment="700 Series OS Release 11.11">
              <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2515"/>
              <criterion comment="HP Release B.11.11" negate="false" test_ref="oval:org.mitre.oval:tst:2514"/>
            </criteria>
            <criteria operator="AND" comment="800 Series OS Release 11.11">
              <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2513"/>
              <criterion comment="HP Release B.11.11" negate="false" test_ref="oval:org.mitre.oval:tst:2514"/>
            </criteria>
          </criteria>
          <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.22">
            <criteria operator="AND" comment="700 Series OS Release 11.22">
              <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2515"/>
              <criterion comment="HP Release B.11.22" negate="false" test_ref="oval:org.mitre.oval:tst:1015"/>
            </criteria>
            <criteria operator="AND" comment="800 Series OS Release 11.22">
              <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2513"/>
              <criterion comment="HP Release B.11.22" negate="false" test_ref="oval:org.mitre.oval:tst:1015"/>
            </criteria>
          </criteria>
          <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.23">
            <criteria operator="AND" comment="700 Series OS Release 11.23">
              <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2515"/>
              <criterion comment="HP Release B.11.23" negate="false" test_ref="oval:org.mitre.oval:tst:2511"/>
            </criteria>
            <criteria operator="AND" comment="800 Series OS Release 11.23">
              <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2513"/>
              <criterion comment="HP Release B.11.23" negate="false" test_ref="oval:org.mitre.oval:tst:2511"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="OR" comment="Any of the CIFS components has a version less than A.01.11.04">
          <criterion comment="CIFS-Server.CIFS-RUN with version less than A.01.11.04 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:920"/>
          <criterion comment="CIFS-Server.CIFS-UTIL with version less than A.01.11.04 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:919"/>
          <criterion comment="CIFS-Server.CIFS-ADMIN with version less than A.01.11.04 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:918"/>
          <criterion comment="CIFS-Server.CIFS-LIB with version less than A.01.11.04 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:917"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1346" version="1" class="vulnerability">
      <metadata>
        <title>Apache mod_ssl CRL off-by-one DoS</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
          <product>Apache</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1268" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1268"/>
        <description>Off-by-one error in the mod_ssl Certificate Revocation List (CRL) verification callback in Apache, when configured to use a CRL, allows remote attackers to cause a denial of service (child process crash) via a CRL that causes a buffer overflow of one null byte.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-11-30T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-12-20T11:03:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-01-04T08:04:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-01-25T07:30:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.00, 11.11, or 11.23">
          <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.11">
            <criteria operator="AND" comment="700 Series OS Release 11.11">
              <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2515"/>
              <criterion comment="HP Release B.11.11" negate="false" test_ref="oval:org.mitre.oval:tst:2514"/>
            </criteria>
            <criteria operator="AND" comment="800 Series OS Release 11.11">
              <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2513"/>
              <criterion comment="HP Release B.11.11" negate="false" test_ref="oval:org.mitre.oval:tst:2514"/>
            </criteria>
          </criteria>
          <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.00">
            <criteria operator="AND" comment="700 Series OS Release 11.00">
              <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2515"/>
              <criterion comment="HP Release B.11.00" negate="false" test_ref="oval:org.mitre.oval:tst:2512"/>
            </criteria>
            <criteria operator="AND" comment="800 Series OS Release 11.00">
              <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2513"/>
              <criterion comment="HP Release B.11.00" negate="false" test_ref="oval:org.mitre.oval:tst:2512"/>
            </criteria>
          </criteria>
          <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.23">
            <criteria operator="AND" comment="700 Series OS Release 11.23">
              <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2515"/>
              <criterion comment="HP Release B.11.23" negate="false" test_ref="oval:org.mitre.oval:tst:2511"/>
            </criteria>
            <criteria operator="AND" comment="800 Series OS Release 11.23">
              <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2513"/>
              <criterion comment="HP Release B.11.23" negate="false" test_ref="oval:org.mitre.oval:tst:2511"/>
            </criteria>
          </criteria>
        </criteria>
        <criterion comment="hpuxwsAPACHE is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2388"/>
        <criterion comment="hpuxwsAPACHE has a version greater than or equal (A|B).2.0.55.0" negate="true" test_ref="oval:org.mitre.oval:tst:2387"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1345" version="1" class="vulnerability">
      <metadata>
        <title>Leaking GSSAPI Credentials Vulnerability (B.11.23)</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
          <product>SecureShell</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2798" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2798"/>
        <description>sshd in OpenSSH before 4.2, when GSSAPIDelegateCredentials is enabled, allows GSSAPI credentials to be delegated to clients who log in using non-GSSAPI methods, which could cause those credentials to be exposed to untrusted users or hosts.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-01-11T12:55:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-01-12T09:18:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-02-01T09:08:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-02-22T08:27:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.23">
          <criteria operator="AND" comment="700 Series OS Release 11.23">
            <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2515"/>
            <criterion comment="HP Release B.11.23" negate="false" test_ref="oval:org.mitre.oval:tst:2511"/>
          </criteria>
          <criteria operator="AND" comment="800 Series OS Release 11.23">
            <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2513"/>
            <criterion comment="HP Release B.11.23" negate="false" test_ref="oval:org.mitre.oval:tst:2511"/>
          </criteria>
        </criteria>
        <criterion comment="Secure_Shell.SECURE_SHELL is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1033"/>
        <criterion comment="Secure_Shell.SECURE_SHELL with version less than A.04.20.005 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:1032"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1287" version="1" class="vulnerability">
      <metadata>
        <title>Mozilla IDN heap overrun using soft-hyphens</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
          <product>mozilla</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2871" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2871"/>
        <description>Buffer overflow in the International Domain Name (IDN) support in Mozilla Firefox 1.0.6 and earlier, and Netscape 8.0.3.3 and 7.2, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a hostname with all "soft" hyphens (character 0xAD), which is not properly handled by the NormalizeIDN call in nsStandardURL::BuildNormalizedSpec.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-11-30T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-12-27T08:49:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-01-12T08:59:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-02-01T09:08:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.00, 11.11, 11.22, or 11.23">
          <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.00">
            <criteria operator="AND" comment="700 Series OS Release 11.00">
              <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2515"/>
              <criterion comment="HP Release B.11.00" negate="false" test_ref="oval:org.mitre.oval:tst:2512"/>
            </criteria>
            <criteria operator="AND" comment="800 Series OS Release 11.00">
              <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2513"/>
              <criterion comment="HP Release B.11.00" negate="false" test_ref="oval:org.mitre.oval:tst:2512"/>
            </criteria>
          </criteria>
          <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.11">
            <criteria operator="AND" comment="700 Series OS Release 11.11">
              <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2515"/>
              <criterion comment="HP Release B.11.11" negate="false" test_ref="oval:org.mitre.oval:tst:2514"/>
            </criteria>
            <criteria operator="AND" comment="800 Series OS Release 11.11">
              <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2513"/>
              <criterion comment="HP Release B.11.11" negate="false" test_ref="oval:org.mitre.oval:tst:2514"/>
            </criteria>
          </criteria>
          <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.22">
            <criteria operator="AND" comment="700 Series OS Release 11.22">
              <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2515"/>
              <criterion comment="HP Release B.11.22" negate="false" test_ref="oval:org.mitre.oval:tst:1015"/>
            </criteria>
            <criteria operator="AND" comment="800 Series OS Release 11.22">
              <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2513"/>
              <criterion comment="HP Release B.11.22" negate="false" test_ref="oval:org.mitre.oval:tst:1015"/>
            </criteria>
          </criteria>
          <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.23">
            <criteria operator="AND" comment="700 Series OS Release 11.23">
              <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2515"/>
              <criterion comment="HP Release B.11.23" negate="false" test_ref="oval:org.mitre.oval:tst:2511"/>
            </criteria>
            <criteria operator="AND" comment="800 Series OS Release 11.23">
              <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2513"/>
              <criterion comment="HP Release B.11.23" negate="false" test_ref="oval:org.mitre.oval:tst:2511"/>
            </criteria>
          </criteria>
        </criteria>
        <criterion comment="Mozilla is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1014"/>
        <criterion comment="Mozilla v1.7.12 (1.7.12.0.00) or later is installed" negate="true" test_ref="oval:org.mitre.oval:tst:1013"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1262" version="1" class="vulnerability">
      <metadata>
        <title>zlib Compression Remote DoS Vulnerability (B.11.23)</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
          <product>SecureShell</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2096" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2096"/>
        <description>zlib 1.2 and later versions allows remote attackers to cause a denial of service (crash) via a crafted compressed stream with an incomplete code description of a length greater than 1, which leads to a buffer overflow, as demonstrated using a crafted PNG file.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-01-11T12:55:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-01-12T09:18:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-02-01T09:08:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-02-22T08:27:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.23">
          <criteria operator="AND" comment="700 Series OS Release 11.23">
            <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2515"/>
            <criterion comment="HP Release B.11.23" negate="false" test_ref="oval:org.mitre.oval:tst:2511"/>
          </criteria>
          <criteria operator="AND" comment="800 Series OS Release 11.23">
            <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2513"/>
            <criterion comment="HP Release B.11.23" negate="false" test_ref="oval:org.mitre.oval:tst:2511"/>
          </criteria>
        </criteria>
        <criterion comment="Secure_Shell.SECURE_SHELL is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1033"/>
        <criterion comment="Secure_Shell.SECURE_SHELL with version less than A.04.20.005 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:1032"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1147" version="1" class="vulnerability">
      <metadata>
        <title>HP-UX wuftpd Privilege Escalation Vulnerability (B.11.11)</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
          <product>ftpd</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0148" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0148"/>
        <description>wu-ftpd 2.6.2 and earlier, with the restricted-gid option enabled, allows local users to bypass access restrictions by changing the permissions to prevent access to their home directory, which causes wu-ftpd to use the root directory instead.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-01-30T07:20:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-02-01T09:08:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-02-22T08:27:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-03-09T12:19:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.11">
          <criteria operator="AND" comment="700 Series OS Release 11.11">
            <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2515"/>
            <criterion comment="HP Release B.11.11" negate="false" test_ref="oval:org.mitre.oval:tst:2514"/>
          </criteria>
          <criteria operator="AND" comment="800 Series OS Release 11.11">
            <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2513"/>
            <criterion comment="HP Release B.11.11" negate="false" test_ref="oval:org.mitre.oval:tst:2514"/>
          </criteria>
        </criteria>
        <criterion comment="WUFTP-26.INETSVCS-FTP with version less than B.11.00.01.004 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1124"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1098" version="2" class="vulnerability">
      <metadata>
        <title>usermod Recursive Ownership Error (B.11.23)</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-1248" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1248"/>
        <description>Unspecified vulnerability in usermod in HP-UX B.11.00, B.11.11, and B.11.23, when run with certain options that involve a new home directory, might cause usermod to change the ownership of all directories and files under the new directory, which might result in less secure permissions than intended.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-03-18T07:24:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-03-22T11:10:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-04-06T06:31:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-05-03T10:06:00.000-04:00">ACCEPTED</status_change>
            <modified comment="added CVE reference" date="2007-02-05T10:23:00.400-05:00">
              <contributor organization="Security-Database">Nabil Ouchn</contributor>
            </modified>
            <status_change date="2007-02-05T10:25:21.449-05:00">INTERIM</status_change>
            <status_change date="2007-02-20T13:39:29.984-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.23">
          <criteria operator="AND" comment="700 Series OS Release 11.23">
            <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2515"/>
            <criterion comment="HP Release B.11.23" negate="false" test_ref="oval:org.mitre.oval:tst:2511"/>
          </criteria>
          <criteria operator="AND" comment="800 Series OS Release 11.23">
            <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2513"/>
            <criterion comment="HP Release B.11.23" negate="false" test_ref="oval:org.mitre.oval:tst:2511"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:935" version="2" class="vulnerability">
      <metadata>
        <title>HP-UX PMTUD Remote DoS (B.11.23)</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
          <product>Operating System</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1192" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1192"/>
        <description>Unknown vulnerability in HP-UX B.11.00, B.11.04, B.11.11, B.11.22, and B.11.23, when running TCP/IP on IPv4, allows remote attackers to cause a denial of service via certain packets, related to the PMTU, a different vulnerability than CVE-2004-1060.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-02-01T11:45:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-03-09T12:19:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-04-06T06:30:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-05-03T10:06:00.000-04:00">ACCEPTED</status_change>
            <modified comment="modified patch test to only check for specific patch, checking for supersedence was incorrect and need a language change" date="2007-09-13T00:00:00.000-05:00">
              <contributor organization="Opsware, Inc.">Todd Dolinsky</contributor>
            </modified>
            <status_change date="2007-09-13T14:05:31.649-04:00">INTERIM</status_change>
            <status_change date="2007-10-02T08:08:13.897-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.23">
          <criteria operator="AND" comment="700 Series OS Release 11.23">
            <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2515"/>
            <criterion comment="HP Release B.11.23" negate="false" test_ref="oval:org.mitre.oval:tst:2511"/>
          </criteria>
          <criteria operator="AND" comment="800 Series OS Release 11.23">
            <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2513"/>
            <criterion comment="HP Release B.11.23" negate="false" test_ref="oval:org.mitre.oval:tst:2511"/>
          </criteria>
        </criteria>
        <criterion comment="Networking.NET2-KRN is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1442"/>
        <criterion comment="Patch PHNE_32606 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:1441"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:899" version="3" class="vulnerability">
      <metadata>
        <title>HP-UX 11.04 Path MTU Discovery Attack Vulnerability</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
          <product>Operating System</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-1060" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1060"/>
        <description>Multiple TCP/IP and ICMP implementations, when using Path MTU (PMTU) discovery (PMTUD), allow remote attackers to cause a denial of service (network throughput reduction for TCP connections) via forged ICMP ("Fragmentation Needed and Don't Fragment was Set") packets with a low next-hop MTU value, aka the "Path MTU discovery attack."  NOTE: CVE-2004-0790, CVE-2004-0791, and CVE-2004-1060 have been SPLIT based on different attacks; CVE-2005-0065, CVE-2005-0066, CVE-2005-0067, and CVE-2005-0068 are related identifiers that are SPLIT based on the underlying vulnerability.  While CVE normally SPLITs based on vulnerability, the attack-based identifiers exist due to the variety and number of affected implementations and solutions that address the attacks instead of the underlying vulnerabilities.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-09-22T05:48:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-09-22T20:15:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-07T09:15:54.417-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:16:01.065-04:00">ACCEPTED</status_change>
            <modified comment="Added title." date="2007-02-22T17:23:00.955-05:00">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2007-02-22T17:23:41.998-05:00">INTERIM</status_change>
            <status_change date="2007-03-21T16:17:28.351-04:00">ACCEPTED</status_change>
            <modified comment="modified patch test to only check for specific patch, checking for supersedence was incorrect and need a language change" date="2007-09-13T00:00:00.000-05:00">
              <contributor organization="Opsware, Inc.">Todd Dolinsky</contributor>
            </modified>
            <status_change date="2007-09-13T14:05:31.562-04:00">INTERIM</status_change>
            <status_change date="2007-10-02T08:08:13.792-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.04" negate="false">
          <criteria operator="AND" comment="700 Series OS Release 11.04" negate="false">
            <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:3443"/>
            <criterion comment="HP Release B.11.04" negate="false" test_ref="oval:org.mitre.oval:tst:3294"/>
          </criteria>
          <criteria operator="AND" comment="800 Series OS Release 11.04" negate="false">
            <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:4124"/>
            <criterion comment="HP Release B.11.04" negate="false" test_ref="oval:org.mitre.oval:tst:3294"/>
          </criteria>
        </criteria>
        <criterion comment="Patch PHNE_33427 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:3468"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:726" version="3" class="vulnerability">
      <metadata>
        <title>HP-UX 11.00 ICMP Source Quench Attack Vulnerability</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
          <product>Operating System</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0791" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0791"/>
        <description>Multiple TCP/IP and ICMP implementations allow remote attackers to cause a denial of service (network throughput reduction for TCP connections) via a blind throughput-reduction attack using spoofed Source Quench packets, aka the "ICMP Source Quench attack."  NOTE: CVE-2004-0790, CVE-2004-0791, and CVE-2004-1060 have been SPLIT based on different attacks; CVE-2005-0065, CVE-2005-0066, CVE-2005-0067, and CVE-2005-0068 are related identifiers that are SPLIT based on the underlying vulnerability.  While CVE normally SPLITs based on vulnerability, the attack-based identifiers exist due to the variety and number of affected implementations and solutions that address the attacks instead of the underlying vulnerabilities.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-09-22T05:48:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-09-22T20:15:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-07T09:15:52.288-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:15:59.492-04:00">ACCEPTED</status_change>
            <modified comment="Added title." date="2007-02-23T12:52:00.826-05:00">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2007-02-23T12:53:23.849-05:00">INTERIM</status_change>
            <status_change date="2007-03-21T16:17:25.287-04:00">ACCEPTED</status_change>
            <modified comment="modified patch test to only check for specific patch, checking for supersedence was incorrect and need a language change" date="2007-09-13T00:00:00.000-05:00">
              <contributor organization="Opsware, Inc.">Todd Dolinsky</contributor>
            </modified>
            <status_change date="2007-09-13T14:05:31.157-04:00">INTERIM</status_change>
            <status_change date="2007-10-02T08:08:13.290-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.00" negate="false">
          <criteria operator="AND" comment="700 Series OS Release 11.00" negate="false">
            <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:3443"/>
            <criterion comment="HP Release B.11.00" negate="false" test_ref="oval:org.mitre.oval:tst:3571"/>
          </criteria>
          <criteria operator="AND" comment="800 Series OS Release 11.00" negate="false">
            <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:4124"/>
            <criterion comment="HP Release B.11.00" negate="false" test_ref="oval:org.mitre.oval:tst:3571"/>
          </criteria>
        </criteria>
        <criterion comment="Patch PHNE_33395 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:3393"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:688" version="3" class="vulnerability">
      <metadata>
        <title>HP-UX 11.23 ICMP Source Quench Attack Vulnerability</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
          <product>Operating System</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0791" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0791"/>
        <description>Multiple TCP/IP and ICMP implementations allow remote attackers to cause a denial of service (network throughput reduction for TCP connections) via a blind throughput-reduction attack using spoofed Source Quench packets, aka the "ICMP Source Quench attack."  NOTE: CVE-2004-0790, CVE-2004-0791, and CVE-2004-1060 have been SPLIT based on different attacks; CVE-2005-0065, CVE-2005-0066, CVE-2005-0067, and CVE-2005-0068 are related identifiers that are SPLIT based on the underlying vulnerability.  While CVE normally SPLITs based on vulnerability, the attack-based identifiers exist due to the variety and number of affected implementations and solutions that address the attacks instead of the underlying vulnerabilities.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-09-22T05:48:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-09-22T20:15:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-07T09:15:51.358-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:15:58.763-04:00">ACCEPTED</status_change>
            <modified comment="Added title." date="2007-02-23T12:53:00.978-05:00">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2007-02-23T12:53:50.998-05:00">INTERIM</status_change>
            <status_change date="2007-03-21T16:17:24.308-04:00">ACCEPTED</status_change>
            <modified comment="modified patch test to only check for specific patch, checking for supersedence was incorrect and need a language change" date="2007-09-13T00:00:00.000-05:00">
              <contributor organization="Opsware, Inc.">Todd Dolinsky</contributor>
            </modified>
            <status_change date="2007-09-13T14:05:31.069-04:00">INTERIM</status_change>
            <status_change date="2007-10-02T08:08:13.145-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.23" negate="false">
          <criteria operator="AND" comment="700 Series OS Release 11.23" negate="false">
            <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:3443"/>
            <criterion comment="HP Release B.11.23" negate="false" test_ref="oval:org.mitre.oval:tst:3901"/>
          </criteria>
          <criteria operator="AND" comment="800 Series OS Release 11.23" negate="false">
            <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:4124"/>
            <criterion comment="HP Release B.11.23" negate="false" test_ref="oval:org.mitre.oval:tst:3901"/>
          </criteria>
        </criteria>
        <criterion comment="Patch PHNE_32606 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:3439"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:648" version="3" class="vulnerability">
      <metadata>
        <title>HP-UX wuftpd Privilege Escalation Vulnerability (B.11.23)</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
          <product>ftpd</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0148" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0148"/>
        <description>wu-ftpd 2.6.2 and earlier, with the restricted-gid option enabled, allows local users to bypass access restrictions by changing the permissions to prevent access to their home directory, which causes wu-ftpd to use the root directory instead.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-01-30T07:20:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-02-01T09:08:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-02-22T08:27:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-03-09T12:19:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-07-03T12:56:00.000-04:00" comment="Added negate=true attribute to criteria sub-block to fix conversion error from OVAL 4.2 to OVAL 5.0">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2006-07-03T12:56:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-10-07T09:15:50.907-04:00">ACCEPTED</status_change>
            <modified comment="modified patch test to only check for specific patch, checking for supersedence was incorrect and need a language change" date="2007-09-13T00:00:00.000-05:00">
              <contributor organization="Opsware, Inc.">Todd Dolinsky</contributor>
            </modified>
            <status_change date="2007-09-13T14:05:30.972-04:00">INTERIM</status_change>
            <status_change date="2007-10-02T08:08:13.030-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.23">
          <criteria operator="AND" comment="700 Series OS Release 11.23">
            <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2515"/>
            <criterion comment="HP Release B.11.23" negate="false" test_ref="oval:org.mitre.oval:tst:2511"/>
          </criteria>
          <criteria operator="AND" comment="800 Series OS Release 11.23">
            <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2513"/>
            <criterion comment="HP Release B.11.23" negate="false" test_ref="oval:org.mitre.oval:tst:2511"/>
          </criteria>
        </criteria>
        <criterion comment="InternetSrvcs.INETSVCS2-RUN is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2472"/>
        <criteria operator="OR" comment="Either PHNE_30983 or PHNE_31732 is installed" negate="true">
          <criterion comment="Patch PHNE_30983 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2471"/>
          <criterion comment="Patch PHNE_31732 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2470"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:616" version="3" class="vulnerability">
      <metadata>
        <title>HP-UX 11.11 swagentd Denial of Service</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
          <product>swagentd</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-1389" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1389"/>
        <description>Unspecified vulnerability in swagentd in HP-UX B.11.00, B.11.04, and B.11.11 allows remote attackers to cause a denial of service (application crash) via unspecified vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-09-22T05:48:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-09-22T20:15:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-07T09:15:50.134-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:15:57.789-04:00">ACCEPTED</status_change>
            <modified comment="Added title and CVE reference." date="2007-02-23T16:06:00.705-05:00">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2007-02-23T16:06:46.731-05:00">INTERIM</status_change>
            <status_change date="2007-03-21T16:17:22.697-04:00">ACCEPTED</status_change>
            <modified comment="modified patch test to only check for specific patch, checking for supersedence was incorrect and need a language change" date="2007-09-13T00:00:00.000-05:00">
              <contributor organization="Opsware, Inc.">Todd Dolinsky</contributor>
            </modified>
            <status_change date="2007-09-13T14:05:30.876-04:00">INTERIM</status_change>
            <status_change date="2007-10-02T08:08:12.891-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.11" negate="false">
          <criteria operator="AND" comment="700 Series OS Release 11.11" negate="false">
            <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:3443"/>
            <criterion comment="HP Release B.11.11" negate="false" test_ref="oval:org.mitre.oval:tst:3704"/>
          </criteria>
          <criteria operator="AND" comment="800 Series OS Release 11.11" negate="false">
            <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:4124"/>
            <criterion comment="HP Release B.11.11" negate="false" test_ref="oval:org.mitre.oval:tst:3704"/>
          </criteria>
        </criteria>
        <criteria operator="OR" comment="Installed B.11.11 software has not been patched for c00622788" negate="false">
          <criteria operator="AND" comment="DCE-Core.DCE-CORE-SHLIB is installed without PHSS_29964 or subsequent" negate="false">
            <criterion comment="DCE-Core.DCE-CORE-SHLIB is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3858"/>
            <criterion comment="Patch PHSS_29964 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:3974"/>
          </criteria>
          <criteria operator="AND" comment="SW-DIST.SD-AGENT is installed without PHCO_28848 or subsequent" negate="false">
            <criterion comment="SW-DIST.SD-AGENT is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3857"/>
            <criterion comment="Patch PHCO_28848 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:3831"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:593" version="3" class="vulnerability">
      <metadata>
        <title>HP-UX ftpd Remote Unauthorized Data Access (B.11.23)</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
          <product>ftpd</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-3296" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-3296"/>
        <description>The FTP server in HP-UX 10.20, B.11.00, and B.11.11, allows remote attackers to list arbitrary directories as root by running the LIST command before logging in.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-09-22T05:48:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-09-22T20:15:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-07T09:15:49.302-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:15:56.734-04:00">ACCEPTED</status_change>
            <modified comment="Added title." date="2007-02-25T23:52:00.734-05:00">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2007-02-25T23:52:28.751-05:00">INTERIM</status_change>
            <status_change date="2007-03-21T16:17:21.562-04:00">ACCEPTED</status_change>
            <modified comment="modified patch test to only check for specific patch, checking for supersedence was incorrect and need a language change" date="2007-09-13T00:00:00.000-05:00">
              <contributor organization="Opsware, Inc.">Todd Dolinsky</contributor>
            </modified>
            <status_change date="2007-09-13T14:05:30.589-04:00">INTERIM</status_change>
            <status_change date="2007-10-02T08:08:12.534-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.23" negate="false">
          <criteria operator="AND" comment="700 Series OS Release 11.23" negate="false">
            <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:3443"/>
            <criterion comment="HP Release B.11.23" negate="false" test_ref="oval:org.mitre.oval:tst:3901"/>
          </criteria>
          <criteria operator="AND" comment="800 Series OS Release 11.23" negate="false">
            <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:4124"/>
            <criterion comment="HP Release B.11.23" negate="false" test_ref="oval:org.mitre.oval:tst:3901"/>
          </criteria>
        </criteria>
        <criterion comment="InternetSrvcs.INETSVCS-RUN for B.11.23 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3687"/>
        <criterion comment="Patch PHNE_33414 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:3428"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:421" version="3" class="vulnerability">
      <metadata>
        <title>HP-UX ftpd Remote Unauthorized Data Access (B.11.11)</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
          <product>ftpd</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-3296" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-3296"/>
        <description>The FTP server in HP-UX 10.20, B.11.00, and B.11.11, allows remote attackers to list arbitrary directories as root by running the LIST command before logging in.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-09-22T05:48:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-09-22T20:15:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-07T09:15:47.099-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:15:54.727-04:00">ACCEPTED</status_change>
            <modified comment="Added title." date="2007-02-25T23:51:00.595-05:00">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2007-02-25T23:51:38.615-05:00">INTERIM</status_change>
            <status_change date="2007-03-21T16:17:19.052-04:00">ACCEPTED</status_change>
            <modified comment="modified patch test to only check for specific patch, checking for supersedence was incorrect and need a language change" date="2007-09-13T00:00:00.000-05:00">
              <contributor organization="Opsware, Inc.">Todd Dolinsky</contributor>
            </modified>
            <status_change date="2007-09-13T14:05:30.502-04:00">INTERIM</status_change>
            <status_change date="2007-10-02T08:08:12.418-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.11" negate="false">
          <criteria operator="AND" comment="700 Series OS Release 11.11" negate="false">
            <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:3443"/>
            <criterion comment="HP Release B.11.11" negate="false" test_ref="oval:org.mitre.oval:tst:3704"/>
          </criteria>
          <criteria operator="AND" comment="800 Series OS Release 11.11" negate="false">
            <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:4124"/>
            <criterion comment="HP Release B.11.11" negate="false" test_ref="oval:org.mitre.oval:tst:3704"/>
          </criteria>
        </criteria>
        <criterion comment="InternetSrvcs.INETSVCS-RUN for B.11.23 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3193"/>
        <criterion comment="Patch PHNE_33412 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:4132"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:412" version="3" class="vulnerability">
      <metadata>
        <title>HP-UX 11.04 Blind Connection Reset Attack Vulnerability</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
          <product>Operating System</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0790" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0790"/>
        <description>Multiple TCP/IP and ICMP implementations allow remote attackers to cause a denial of service (reset TCP connections) via spoofed ICMP error messages, aka the "blind connection-reset attack."  NOTE: CVE-2004-0790, CVE-2004-0791, and CVE-2004-1060 have been SPLIT based on different attacks; CVE-2005-0065, CVE-2005-0066, CVE-2005-0067, and CVE-2005-0068 are related identifiers that are SPLIT based on the underlying vulnerability.  While CVE normally SPLITs based on vulnerability, the attack-based identifiers exist due to the variety and number of affected implementations and solutions that address the attacks instead of the underlying vulnerabilities.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-09-22T05:48:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-09-22T20:15:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-07T09:15:46.966-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:15:54.574-04:00">ACCEPTED</status_change>
            <modified comment="Added title." date="2007-02-26T00:59:00.221-05:00">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2007-02-26T01:00:20.244-05:00">INTERIM</status_change>
            <status_change date="2007-03-21T16:17:18.872-04:00">ACCEPTED</status_change>
            <modified comment="modified patch test to only check for specific patch, checking for supersedence was incorrect and need a language change" date="2007-09-13T00:00:00.000-05:00">
              <contributor organization="Opsware, Inc.">Todd Dolinsky</contributor>
            </modified>
            <status_change date="2007-09-13T14:05:30.416-04:00">INTERIM</status_change>
            <status_change date="2007-10-02T08:08:12.318-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.04" negate="false">
          <criteria operator="AND" comment="700 Series OS Release 11.04" negate="false">
            <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:3443"/>
            <criterion comment="HP Release B.11.04" negate="false" test_ref="oval:org.mitre.oval:tst:3294"/>
          </criteria>
          <criteria operator="AND" comment="800 Series OS Release 11.04" negate="false">
            <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:4124"/>
            <criterion comment="HP Release B.11.04" negate="false" test_ref="oval:org.mitre.oval:tst:3294"/>
          </criteria>
        </criteria>
        <criterion comment="Patch PHNE_33427 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:3468"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:410" version="3" class="vulnerability">
      <metadata>
        <title>HP-UX ftpd Remote Unauthorized Data Access (B.11.04)</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
          <product>ftpd</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-3296" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-3296"/>
        <description>The FTP server in HP-UX 10.20, B.11.00, and B.11.11, allows remote attackers to list arbitrary directories as root by running the LIST command before logging in.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-09-22T05:48:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-09-22T20:15:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-07T09:15:46.831-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:15:54.395-04:00">ACCEPTED</status_change>
            <modified comment="Added title." date="2007-02-25T23:50:00.337-05:00">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2007-02-25T23:51:14.392-05:00">INTERIM</status_change>
            <status_change date="2007-03-21T16:17:18.694-04:00">ACCEPTED</status_change>
            <modified comment="modified patch test to only check for specific patch, checking for supersedence was incorrect and need a language change" date="2007-09-13T00:00:00.000-05:00">
              <contributor organization="Opsware, Inc.">Todd Dolinsky</contributor>
            </modified>
            <status_change date="2007-09-13T14:05:30.328-04:00">INTERIM</status_change>
            <status_change date="2007-10-02T08:08:12.214-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.04" negate="false">
          <criteria operator="AND" comment="700 Series OS Release 11.04" negate="false">
            <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:3443"/>
            <criterion comment="HP Release B.11.04" negate="false" test_ref="oval:org.mitre.oval:tst:3294"/>
          </criteria>
          <criteria operator="AND" comment="800 Series OS Release 11.04" negate="false">
            <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:4124"/>
            <criterion comment="HP Release B.11.04" negate="false" test_ref="oval:org.mitre.oval:tst:3294"/>
          </criteria>
        </criteria>
        <criterion comment="InternetSrvcs.INETSVCS-RUN for B.11.04 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3519"/>
        <criterion comment="Patch PHNE_34077 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:3609"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:405" version="3" class="vulnerability">
      <metadata>
        <title>HP-UX 11.23 Path MTU Discovery Attack Vulnerability</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
          <product>Operating System</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-1060" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1060"/>
        <description>Multiple TCP/IP and ICMP implementations, when using Path MTU (PMTU) discovery (PMTUD), allow remote attackers to cause a denial of service (network throughput reduction for TCP connections) via forged ICMP ("Fragmentation Needed and Don't Fragment was Set") packets with a low next-hop MTU value, aka the "Path MTU discovery attack."  NOTE: CVE-2004-0790, CVE-2004-0791, and CVE-2004-1060 have been SPLIT based on different attacks; CVE-2005-0065, CVE-2005-0066, CVE-2005-0067, and CVE-2005-0068 are related identifiers that are SPLIT based on the underlying vulnerability.  While CVE normally SPLITs based on vulnerability, the attack-based identifiers exist due to the variety and number of affected implementations and solutions that address the attacks instead of the underlying vulnerabilities.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-09-22T05:48:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-09-22T20:15:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-07T09:15:46.701-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:15:54.231-04:00">ACCEPTED</status_change>
            <modified comment="Added title." date="2007-02-22T17:44:00.552-05:00">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2007-02-22T17:44:54.576-05:00">INTERIM</status_change>
            <status_change date="2007-03-21T16:17:18.520-04:00">ACCEPTED</status_change>
            <modified comment="modified patch test to only check for specific patch, checking for supersedence was incorrect and need a language change" date="2007-09-13T00:00:00.000-05:00">
              <contributor organization="Opsware, Inc.">Todd Dolinsky</contributor>
            </modified>
            <status_change date="2007-09-13T14:05:30.190-04:00">INTERIM</status_change>
            <status_change date="2007-10-02T08:08:12.105-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.23" negate="false">
          <criteria operator="AND" comment="700 Series OS Release 11.23" negate="false">
            <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:3443"/>
            <criterion comment="HP Release B.11.23" negate="false" test_ref="oval:org.mitre.oval:tst:3901"/>
          </criteria>
          <criteria operator="AND" comment="800 Series OS Release 11.23" negate="false">
            <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:4124"/>
            <criterion comment="HP Release B.11.23" negate="false" test_ref="oval:org.mitre.oval:tst:3901"/>
          </criteria>
        </criteria>
        <criterion comment="Patch PHNE_32606 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:3439"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:354" version="3" class="vulnerability">
      <metadata>
        <title>HP-UX AutoRAID Critical Functionality Issue</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
          <product>AutoRAID Manager</product>
        </affected>
        <reference source="MISC" ref_id="http://www.itrc.hp.com/service/cki/patchDocDisplay.do?patchId=PHCO_23262"/>
        <description>Possible unknown vulnerability or vulnerabilities in HP DiskArray Utilities with AutoRAID Manager.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-09-22T05:48:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-09-22T20:15:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-07T09:15:45.771-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:15:53.395-04:00">ACCEPTED</status_change>
            <modified comment="Added title and reference, updated description and product." date="2007-02-26T00:44:00.241-05:00">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2007-02-26T00:44:58.261-05:00">INTERIM</status_change>
            <status_change date="2007-03-21T16:17:17.278-04:00">ACCEPTED</status_change>
            <modified comment="modified patch test to only check for specific patch, checking for supersedence was incorrect and need a language change" date="2007-09-13T00:00:00.000-05:00">
              <contributor organization="Opsware, Inc.">Todd Dolinsky</contributor>
            </modified>
            <status_change date="2007-09-13T14:05:30.092-04:00">INTERIM</status_change>
            <status_change date="2007-10-02T08:08:11.980-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.00 or 11.10" negate="false">
          <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.00" negate="false">
            <criteria operator="AND" comment="700 Series OS Release 11.00" negate="false">
              <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:3443"/>
              <criterion comment="HP Release B.11.00" negate="false" test_ref="oval:org.mitre.oval:tst:3571"/>
            </criteria>
            <criteria operator="AND" comment="800 Series OS Release 11.00" negate="false">
              <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:4124"/>
              <criterion comment="HP Release B.11.00" negate="false" test_ref="oval:org.mitre.oval:tst:3571"/>
            </criteria>
          </criteria>
          <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.10" negate="false">
            <criteria operator="AND" comment="700 Series OS Release 11.10" negate="false">
              <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:3443"/>
              <criterion comment="HP Release B.11.10" negate="false" test_ref="oval:org.mitre.oval:tst:3540"/>
            </criteria>
            <criteria operator="AND" comment="800 Series OS Release 11.10" negate="false">
              <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:4124"/>
              <criterion comment="HP Release B.11.10" negate="false" test_ref="oval:org.mitre.oval:tst:3540"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="OR" comment="OS-Core.ARRAY-MGMT or OS-Core.ADMN-ENG-A-MAN (11.00/11.10)" negate="false">
          <criterion comment="OS-Core.ARRAY-MGMT (B.11.00) is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3969"/>
          <criterion comment="OS-Core.ADMN-ENG-A-MAN (B.11.00) is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3707"/>
          <criterion comment="OS-Core.ARRAY-MGMT (B.11.10) is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3449"/>
          <criterion comment="OS-Core.ADMN-ENG-A-MAN (B.11.10) is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3377"/>
        </criteria>
        <criterion comment="Patch PHCO_23262 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:3536"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:312" version="3" class="vulnerability">
      <metadata>
        <title>HP-UX 11.04 swagentd Denial of Service</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
          <product>swagentd</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-1389" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1389"/>
        <description>Unspecified vulnerability in swagentd in HP-UX B.11.00, B.11.04, and B.11.11 allows remote attackers to cause a denial of service (application crash) via unspecified vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-09-22T05:48:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-09-22T20:15:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-07T09:15:45.485-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:15:53.044-04:00">ACCEPTED</status_change>
            <modified comment="Added title and CVE reference." date="2007-02-23T16:06:00.246-05:00">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2007-02-23T16:07:13.268-05:00">INTERIM</status_change>
            <status_change date="2007-03-21T16:17:16.049-04:00">ACCEPTED</status_change>
            <modified comment="modified patch test to only check for specific patch, checking for supersedence was incorrect and need a language change" date="2007-09-13T00:00:00.000-05:00">
              <contributor organization="Opsware, Inc.">Todd Dolinsky</contributor>
            </modified>
            <status_change date="2007-09-13T14:05:29.989-04:00">INTERIM</status_change>
            <status_change date="2007-10-02T08:08:11.870-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.04" negate="false">
          <criteria operator="AND" comment="700 Series OS Release 11.04" negate="false">
            <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:3443"/>
            <criterion comment="HP Release B.11.04" negate="false" test_ref="oval:org.mitre.oval:tst:3294"/>
          </criteria>
          <criteria operator="AND" comment="800 Series OS Release 11.04" negate="false">
            <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:4124"/>
            <criterion comment="HP Release B.11.04" negate="false" test_ref="oval:org.mitre.oval:tst:3294"/>
          </criteria>
        </criteria>
        <criteria operator="OR" comment="Installed B.11.04 software has not been patched for c00622788" negate="false">
          <criteria operator="AND" comment="DCE-Core.DCE-CORE-SHLIB is installed without PHSS_30302 or subsequent" negate="false">
            <criterion comment="DCE-Core.DCE-CORE-SHLIB is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3858"/>
            <criterion comment="Patch PHSS_30302 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:3559"/>
          </criteria>
          <criteria operator="AND" comment="SW-DIST.SD-AGENT is installed without PHCO_30006 or subsequent" negate="false">
            <criterion comment="SW-DIST.SD-AGENT is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3857"/>
            <criterion comment="Patch PHCO_30006 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:3243"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:211" version="3" class="vulnerability">
      <metadata>
        <title>HP-UX 11.23 Blind Connection Reset Attack Vulnerability</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
          <product>Operating System</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0790" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0790"/>
        <description>Multiple TCP/IP and ICMP implementations allow remote attackers to cause a denial of service (reset TCP connections) via spoofed ICMP error messages, aka the "blind connection-reset attack."  NOTE: CVE-2004-0790, CVE-2004-0791, and CVE-2004-1060 have been SPLIT based on different attacks; CVE-2005-0065, CVE-2005-0066, CVE-2005-0067, and CVE-2005-0068 are related identifiers that are SPLIT based on the underlying vulnerability.  While CVE normally SPLITs based on vulnerability, the attack-based identifiers exist due to the variety and number of affected implementations and solutions that address the attacks instead of the underlying vulnerabilities.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-09-22T05:48:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-09-22T20:15:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-07T09:15:44.322-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:15:51.097-04:00">ACCEPTED</status_change>
            <modified comment="Added title." date="2007-02-26T01:00:00.930-05:00">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2007-02-26T00:59:48.970-05:00">INTERIM</status_change>
            <status_change date="2007-03-21T16:17:11.753-04:00">ACCEPTED</status_change>
            <modified comment="modified patch test to only check for specific patch, checking for supersedence was incorrect and need a language change" date="2007-09-13T00:00:00.000-05:00">
              <contributor organization="Opsware, Inc.">Todd Dolinsky</contributor>
            </modified>
            <status_change date="2007-09-13T14:05:29.901-04:00">INTERIM</status_change>
            <status_change date="2007-10-02T08:08:11.686-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.23" negate="false">
          <criteria operator="AND" comment="700 Series OS Release 11.23" negate="false">
            <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:3443"/>
            <criterion comment="HP Release B.11.23" negate="false" test_ref="oval:org.mitre.oval:tst:3901"/>
          </criteria>
          <criteria operator="AND" comment="800 Series OS Release 11.23" negate="false">
            <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:4124"/>
            <criterion comment="HP Release B.11.23" negate="false" test_ref="oval:org.mitre.oval:tst:3901"/>
          </criteria>
        </criteria>
        <criterion comment="Patch PHNE_32606 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:3439"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:196" version="3" class="vulnerability">
      <metadata>
        <title>HP-UX 11.11 Path MTU Discovery Attack Vulnerability</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
          <product>Operating System</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-1060" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1060"/>
        <description>Multiple TCP/IP and ICMP implementations, when using Path MTU (PMTU) discovery (PMTUD), allow remote attackers to cause a denial of service (network throughput reduction for TCP connections) via forged ICMP ("Fragmentation Needed and Don't Fragment was Set") packets with a low next-hop MTU value, aka the "Path MTU discovery attack."  NOTE: CVE-2004-0790, CVE-2004-0791, and CVE-2004-1060 have been SPLIT based on different attacks; CVE-2005-0065, CVE-2005-0066, CVE-2005-0067, and CVE-2005-0068 are related identifiers that are SPLIT based on the underlying vulnerability.  While CVE normally SPLITs based on vulnerability, the attack-based identifiers exist due to the variety and number of affected implementations and solutions that address the attacks instead of the underlying vulnerabilities.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-09-22T05:48:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-09-22T20:15:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-07T09:15:40.215-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:15:43.584-04:00">ACCEPTED</status_change>
            <modified comment="Added title." date="2007-02-22T17:44:00.683-05:00">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2007-02-22T17:44:35.704-05:00">INTERIM</status_change>
            <status_change date="2007-03-21T16:17:09.637-04:00">ACCEPTED</status_change>
            <modified comment="modified patch test to only check for specific patch, checking for supersedence was incorrect and need a language change" date="2007-09-13T00:00:00.000-05:00">
              <contributor organization="Opsware, Inc.">Todd Dolinsky</contributor>
            </modified>
            <status_change date="2007-09-13T14:05:29.816-04:00">INTERIM</status_change>
            <status_change date="2007-10-02T08:08:11.581-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.11" negate="false">
          <criteria operator="AND" comment="700 Series OS Release 11.11" negate="false">
            <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:3443"/>
            <criterion comment="HP Release B.11.11" negate="false" test_ref="oval:org.mitre.oval:tst:3704"/>
          </criteria>
          <criteria operator="AND" comment="800 Series OS Release 11.11" negate="false">
            <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:4124"/>
            <criterion comment="HP Release B.11.11" negate="false" test_ref="oval:org.mitre.oval:tst:3704"/>
          </criteria>
        </criteria>
        <criterion comment="Patch PHNE_33159 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:3779"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:184" version="3" class="vulnerability">
      <metadata>
        <title>HP-UX 11.11 ICMP Source Quench Attack Vulnerability</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
          <product>Operating System</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0791" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0791"/>
        <description>Multiple TCP/IP and ICMP implementations allow remote attackers to cause a denial of service (network throughput reduction for TCP connections) via a blind throughput-reduction attack using spoofed Source Quench packets, aka the "ICMP Source Quench attack."  NOTE: CVE-2004-0790, CVE-2004-0791, and CVE-2004-1060 have been SPLIT based on different attacks; CVE-2005-0065, CVE-2005-0066, CVE-2005-0067, and CVE-2005-0068 are related identifiers that are SPLIT based on the underlying vulnerability.  While CVE normally SPLITs based on vulnerability, the attack-based identifiers exist due to the variety and number of affected implementations and solutions that address the attacks instead of the underlying vulnerabilities.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-09-22T05:48:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-09-22T20:15:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-07T09:15:34.000-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:15:32.152-04:00">ACCEPTED</status_change>
            <modified comment="Added title." date="2007-02-23T12:54:00.475-05:00">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2007-02-23T12:54:31.499-05:00">INTERIM</status_change>
            <status_change date="2007-03-21T16:17:05.483-04:00">ACCEPTED</status_change>
            <modified comment="modified patch test to only check for specific patch, checking for supersedence was incorrect and need a language change" date="2007-09-13T00:00:00.000-05:00">
              <contributor organization="Opsware, Inc.">Todd Dolinsky</contributor>
            </modified>
            <status_change date="2007-09-13T14:05:29.731-04:00">INTERIM</status_change>
            <status_change date="2007-10-02T08:08:11.315-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.11" negate="false">
          <criteria operator="AND" comment="700 Series OS Release 11.11" negate="false">
            <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:3443"/>
            <criterion comment="HP Release B.11.11" negate="false" test_ref="oval:org.mitre.oval:tst:3704"/>
          </criteria>
          <criteria operator="AND" comment="800 Series OS Release 11.11" negate="false">
            <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:4124"/>
            <criterion comment="HP Release B.11.11" negate="false" test_ref="oval:org.mitre.oval:tst:3704"/>
          </criteria>
        </criteria>
        <criterion comment="Patch PHNE_33159 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:3779"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:181" version="3" class="vulnerability">
      <metadata>
        <title>HP-UX 11.00 Path MTU Discovery Attack Vulnerability</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
          <product>Operating System</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-1060" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1060"/>
        <description>Multiple TCP/IP and ICMP implementations, when using Path MTU (PMTU) discovery (PMTUD), allow remote attackers to cause a denial of service (network throughput reduction for TCP connections) via forged ICMP ("Fragmentation Needed and Don't Fragment was Set") packets with a low next-hop MTU value, aka the "Path MTU discovery attack."  NOTE: CVE-2004-0790, CVE-2004-0791, and CVE-2004-1060 have been SPLIT based on different attacks; CVE-2005-0065, CVE-2005-0066, CVE-2005-0067, and CVE-2005-0068 are related identifiers that are SPLIT based on the underlying vulnerability.  While CVE normally SPLITs based on vulnerability, the attack-based identifiers exist due to the variety and number of affected implementations and solutions that address the attacks instead of the underlying vulnerabilities.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-09-22T05:48:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-09-22T20:15:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-07T09:15:32.283-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:15:28.466-04:00">ACCEPTED</status_change>
            <modified comment="Added title." date="2007-02-22T17:25:00.740-05:00">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2007-02-22T17:28:59.770-05:00">INTERIM</status_change>
            <status_change date="2007-03-21T16:17:04.459-04:00">ACCEPTED</status_change>
            <modified comment="modified patch test to only check for specific patch, checking for supersedence was incorrect and need a language change" date="2007-09-13T00:00:00.000-05:00">
              <contributor organization="Opsware, Inc.">Todd Dolinsky</contributor>
            </modified>
            <status_change date="2007-09-13T14:05:29.645-04:00">INTERIM</status_change>
            <status_change date="2007-10-02T08:08:11.204-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.00" negate="false">
          <criteria operator="AND" comment="700 Series OS Release 11.00" negate="false">
            <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:3443"/>
            <criterion comment="HP Release B.11.00" negate="false" test_ref="oval:org.mitre.oval:tst:3571"/>
          </criteria>
          <criteria operator="AND" comment="800 Series OS Release 11.00" negate="false">
            <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:4124"/>
            <criterion comment="HP Release B.11.00" negate="false" test_ref="oval:org.mitre.oval:tst:3571"/>
          </criteria>
        </criteria>
        <criterion comment="Patch PHNE_33395 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:3393"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1762" version="2" class="vulnerability">
      <metadata>
        <title>WU-FTPD "glob-*" Remote DoS Vulnerability (B.11.11)</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
          <product>ftpd</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0256" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0256"/>
        <description>The wu_fnmatch function in wu_fnmatch.c in wu-ftpd 2.6.1 and 2.6.2 allows remote attackers to cause a denial of service (CPU exhaustion by recursion) via a glob pattern with a large number of * (wildcard) characters, as demonstrated using the dir command.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-04-06T06:39:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-04-12T05:16:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-05-03T10:06:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-05-31T09:45:00.000-04:00">ACCEPTED</status_change>
            <modified comment="modified patch test to only check for specific patch, checking for supersedence was incorrect and need a language change" date="2007-09-13T00:00:00.000-05:00">
              <contributor organization="Opsware, Inc.">Todd Dolinsky</contributor>
            </modified>
            <status_change date="2007-09-13T14:05:29.565-04:00">INTERIM</status_change>
            <status_change date="2007-10-02T08:08:11.109-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.11">
          <criteria operator="AND" comment="700 Series OS Release 11.11">
            <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2515"/>
            <criterion comment="HP Release B.11.11" negate="false" test_ref="oval:org.mitre.oval:tst:2514"/>
          </criteria>
          <criteria operator="AND" comment="800 Series OS Release 11.11">
            <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2513"/>
            <criterion comment="HP Release B.11.11" negate="false" test_ref="oval:org.mitre.oval:tst:2514"/>
          </criteria>
        </criteria>
        <criteria operator="OR" comment="INETSVCS-RUN without patch PHNE_34544 or later, OR WUFTP-26.INETSVCS-FTP with version less than B.11.11.01.008 is installed">
          <criteria operator="AND" comment="INETSVCS-RUN without patch PHNE_34544 or later">
            <criterion comment="InternetSrvcs.INETSVCS-RUN is installed" negate="false" test_ref="oval:org.mitre.oval:tst:981"/>
            <criterion comment="Patch PHNE_34544 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:736"/>
          </criteria>
          <criterion comment="WUFTP-26.INETSVCS-FTP with version less than B.11.11.01.008 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:735"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:176" version="3" class="vulnerability">
      <metadata>
        <title>HP-UX 11.00 Blind Connection Reset Attack Vulnerability</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
          <product>Operating System</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0790" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0790"/>
        <description>Multiple TCP/IP and ICMP implementations allow remote attackers to cause a denial of service (reset TCP connections) via spoofed ICMP error messages, aka the "blind connection-reset attack."  NOTE: CVE-2004-0790, CVE-2004-0791, and CVE-2004-1060 have been SPLIT based on different attacks; CVE-2005-0065, CVE-2005-0066, CVE-2005-0067, and CVE-2005-0068 are related identifiers that are SPLIT based on the underlying vulnerability.  While CVE normally SPLITs based on vulnerability, the attack-based identifiers exist due to the variety and number of affected implementations and solutions that address the attacks instead of the underlying vulnerabilities.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-09-22T05:48:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-09-22T20:15:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-07T09:15:29.514-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:15:21.329-04:00">ACCEPTED</status_change>
            <modified comment="Added title." date="2007-02-26T01:00:00.112-05:00">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2007-02-26T01:00:37.137-05:00">INTERIM</status_change>
            <status_change date="2007-03-21T16:17:02.256-04:00">ACCEPTED</status_change>
            <modified comment="modified patch test to only check for specific patch, checking for supersedence was incorrect and need a language change" date="2007-09-13T00:00:00.000-05:00">
              <contributor organization="Opsware, Inc.">Todd Dolinsky</contributor>
            </modified>
            <status_change date="2007-09-13T14:05:29.478-04:00">INTERIM</status_change>
            <status_change date="2007-10-02T08:08:11.001-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.00" negate="false">
          <criteria operator="AND" comment="700 Series OS Release 11.00" negate="false">
            <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:3443"/>
            <criterion comment="HP Release B.11.00" negate="false" test_ref="oval:org.mitre.oval:tst:3571"/>
          </criteria>
          <criteria operator="AND" comment="800 Series OS Release 11.00" negate="false">
            <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:4124"/>
            <criterion comment="HP Release B.11.00" negate="false" test_ref="oval:org.mitre.oval:tst:3571"/>
          </criteria>
        </criteria>
        <criterion comment="Patch PHNE_33395 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:3393"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1747" version="2" class="vulnerability">
      <metadata>
        <title>Webproxy Off-by-One Error in mod_ssl CRL</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
          <product>Apache</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1268" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1268"/>
        <description>Off-by-one error in the mod_ssl Certificate Revocation List (CRL) verification callback in Apache, when configured to use a CRL, allows remote attackers to cause a denial of service (child process crash) via a CRL that causes a buffer overflow of one null byte.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-03-18T07:24:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-03-22T11:10:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-04-06T06:31:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-05-03T10:06:00.000-04:00">ACCEPTED</status_change>
            <modified comment="modified patch test to only check for specific patch, checking for supersedence was incorrect and need a language change" date="2007-09-13T00:00:00.000-05:00">
              <contributor organization="Opsware, Inc.">Todd Dolinsky</contributor>
            </modified>
            <status_change date="2007-09-13T14:05:29.310-04:00">INTERIM</status_change>
            <status_change date="2007-10-02T08:08:10.805-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="AND" comment="700 Series OS Release 11.04">
          <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2515"/>
          <criterion comment="HP Release B.11.04" negate="false" test_ref="oval:org.mitre.oval:tst:1276"/>
        </criteria>
        <criterion comment="Webproxy is installed" negate="false" test_ref="oval:org.mitre.oval:tst:890"/>
        <criterion comment="Patch PHSS_34163 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:889"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:174" version="3" class="vulnerability">
      <metadata>
        <title>HP-UX AutoRAID Critical Functionality Issue</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
          <product>AutoRAID Manager</product>
        </affected>
        <reference source="MISC" ref_id="http://www.itrc.hp.com/service/cki/patchDocDisplay.do?patchId=PHCO_23263"/>
        <description>Possible unknown vulnerability or vulnerabilities in HP DiskArray Utilities with AutoRAID Manager.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-09-22T05:48:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-09-22T20:15:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-07T09:15:28.688-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:15:19.562-04:00">ACCEPTED</status_change>
            <modified comment="Added title and reference, updated description and product." date="2007-02-26T00:42:00.583-05:00">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2007-02-26T00:44:35.610-05:00">INTERIM</status_change>
            <status_change date="2007-03-21T16:17:01.270-04:00">ACCEPTED</status_change>
            <modified comment="modified patch test to only check for specific patch, checking for supersedence was incorrect and need a language change" date="2007-09-13T00:00:00.000-05:00">
              <contributor organization="Opsware, Inc.">Todd Dolinsky</contributor>
            </modified>
            <status_change date="2007-09-13T14:05:29.169-04:00">INTERIM</status_change>
            <status_change date="2007-10-02T08:08:10.697-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.11" negate="false">
          <criteria operator="AND" comment="700 Series OS Release 11.11" negate="false">
            <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:3443"/>
            <criterion comment="HP Release B.11.11" negate="false" test_ref="oval:org.mitre.oval:tst:3704"/>
          </criteria>
          <criteria operator="AND" comment="800 Series OS Release 11.11" negate="false">
            <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:4124"/>
            <criterion comment="HP Release B.11.11" negate="false" test_ref="oval:org.mitre.oval:tst:3704"/>
          </criteria>
        </criteria>
        <criteria operator="OR" comment="OS-Core.ARRAY-MGMT or OS-Core.ADMN-ENG-A-MAN (11.11)" negate="false">
          <criterion comment="OS-Core.ARRAY-MGMT (B.11.11) is installed" negate="false" test_ref="oval:org.mitre.oval:tst:4152"/>
          <criterion comment="OS-Core.ADMN-ENG-A-MAN (B.11.11) is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3830"/>
        </criteria>
        <criterion comment="Patch PHCO_23263 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:3210"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1727" version="2" class="vulnerability">
      <metadata>
        <title>Webproxy CGI Byterange Request DoS</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
          <product>Apache</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2728" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2728"/>
        <description>The byte-range filter in Apache 2.0 before 2.0.54 allows remote attackers to cause a denial of service (memory consumption) via an HTTP header with a large Range field.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-03-18T07:24:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-03-22T11:10:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-04-06T06:31:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-05-03T10:06:00.000-04:00">ACCEPTED</status_change>
            <modified comment="modified patch test to only check for specific patch, checking for supersedence was incorrect and need a language change" date="2007-09-13T00:00:00.000-05:00">
              <contributor organization="Opsware, Inc.">Todd Dolinsky</contributor>
            </modified>
            <status_change date="2007-09-13T14:05:29.095-04:00">INTERIM</status_change>
            <status_change date="2007-10-02T08:08:10.608-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="AND" comment="700 Series OS Release 11.04">
          <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2515"/>
          <criterion comment="HP Release B.11.04" negate="false" test_ref="oval:org.mitre.oval:tst:1276"/>
        </criteria>
        <criterion comment="Webproxy is installed" negate="false" test_ref="oval:org.mitre.oval:tst:890"/>
        <criterion comment="Patch PHSS_34163 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:889"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1714" version="2" class="vulnerability">
      <metadata>
        <title>VirusVault Off-by-One Error in mod_ssl CRL</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
          <product>Apache</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1268" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1268"/>
        <description>Off-by-one error in the mod_ssl Certificate Revocation List (CRL) verification callback in Apache, when configured to use a CRL, allows remote attackers to cause a denial of service (child process crash) via a CRL that causes a buffer overflow of one null byte.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-03-18T07:24:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-03-22T11:10:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-04-06T06:31:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-05-03T10:06:00.000-04:00">ACCEPTED</status_change>
            <modified comment="modified patch test to only check for specific patch, checking for supersedence was incorrect and need a language change" date="2007-09-13T00:00:00.000-05:00">
              <contributor organization="Opsware, Inc.">Todd Dolinsky</contributor>
            </modified>
            <status_change date="2007-09-13T14:05:29.024-04:00">INTERIM</status_change>
            <status_change date="2007-10-02T08:08:10.523-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="AND" comment="700 Series OS Release 11.04">
          <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2515"/>
          <criterion comment="HP Release B.11.04" negate="false" test_ref="oval:org.mitre.oval:tst:1276"/>
        </criteria>
        <criterion comment="VirusVault is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1040"/>
        <criterion comment="Patch PHSS_34123 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:1039"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1690" version="3" class="vulnerability">
      <metadata>
        <title>passwd Local DoS Vulnerability (B.11.23)</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
          <product>Operating System</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-1509" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1509"/>
        <description>/sbin/passwd in HP-UX B.11.00, B.11.11, and B.11.23 before 20060326 "does not recover gracefully from some error conditions," which allows local users to cause a denial of service.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-03-29T06:11:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-04-06T06:30:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-05-03T10:06:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-05-31T09:45:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Added CVE reference. Implemented by Jon Baker of The MITRE Corporation." date="2007-03-19T20:27:00.585-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2007-03-19T20:28:59.623-04:00">INTERIM</status_change>
            <status_change date="2007-04-10T13:44:22.486-04:00">ACCEPTED</status_change>
            <modified comment="modified patch test to only check for specific patch, checking for supersedence was incorrect and need a language change" date="2007-09-13T00:00:00.000-05:00">
              <contributor organization="Opsware, Inc.">Todd Dolinsky</contributor>
            </modified>
            <status_change date="2007-09-13T14:05:28.928-04:00">INTERIM</status_change>
            <status_change date="2007-10-02T08:08:10.417-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.23">
          <criteria operator="AND" comment="700 Series OS Release 11.23">
            <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2515"/>
            <criterion comment="HP Release B.11.23" negate="false" test_ref="oval:org.mitre.oval:tst:2511"/>
          </criteria>
          <criteria operator="AND" comment="800 Series OS Release 11.23">
            <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2513"/>
            <criterion comment="HP Release B.11.23" negate="false" test_ref="oval:org.mitre.oval:tst:2511"/>
          </criteria>
        </criteria>
        <criterion comment="OS-Core.UX2-CORE is installed" negate="false" test_ref="oval:org.mitre.oval:tst:771"/>
        <criterion comment="Patch PHCO_32149 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:770"/>
        <criterion comment="Patch PHCO_32926 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:769"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1660" version="3" class="vulnerability">
      <metadata>
        <title>passwd Local DoS Vulnerability (B.11.11)</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
          <product>Operating System</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-1509" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1509"/>
        <description>/sbin/passwd in HP-UX B.11.00, B.11.11, and B.11.23 before 20060326 "does not recover gracefully from some error conditions," which allows local users to cause a denial of service.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-03-29T06:11:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-04-06T06:30:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-05-03T10:06:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-05-31T09:45:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Added CVE reference. Implemented by Jon Baker of The MITRE Corporation." date="2007-03-19T20:27:00.577-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2007-03-19T20:27:53.606-04:00">INTERIM</status_change>
            <status_change date="2007-04-10T13:44:21.599-04:00">ACCEPTED</status_change>
            <modified comment="modified patch test to only check for specific patch, checking for supersedence was incorrect and need a language change" date="2007-09-13T00:00:00.000-05:00">
              <contributor organization="Opsware, Inc.">Todd Dolinsky</contributor>
            </modified>
            <status_change date="2007-09-13T14:05:28.835-04:00">INTERIM</status_change>
            <status_change date="2007-10-02T08:08:10.304-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.11">
          <criteria operator="AND" comment="700 Series OS Release 11.11">
            <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2515"/>
            <criterion comment="HP Release B.11.11" negate="false" test_ref="oval:org.mitre.oval:tst:2514"/>
          </criteria>
          <criteria operator="AND" comment="800 Series OS Release 11.11">
            <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2513"/>
            <criterion comment="HP Release B.11.11" negate="false" test_ref="oval:org.mitre.oval:tst:2514"/>
          </criteria>
        </criteria>
        <criterion comment="OS-Core.UX-CORE is installed" negate="false" test_ref="oval:org.mitre.oval:tst:961"/>
        <criterion comment="Patch PHCO_33214 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:788"/>
        <criterion comment="Patch PHCO_33215 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:787"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1659" version="2" class="vulnerability">
      <metadata>
        <title>VirusVault Integer Overflow in pcre_compile</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
          <product>Apache</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2491" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2491"/>
        <description>Integer overflow in pcre_compile.c in Perl Compatible Regular Expressions (PCRE) before 6.2, as used in multiple products such as Python, Ethereal, and PHP, allows attackers to execute arbitrary code via quantifier values in regular expressions, which leads to a heap-based buffer overflow.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-03-18T07:24:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-03-22T11:10:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-04-06T06:31:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-05-03T10:06:00.000-04:00">ACCEPTED</status_change>
            <modified comment="modified patch test to only check for specific patch, checking for supersedence was incorrect and need a language change" date="2007-09-13T00:00:00.000-05:00">
              <contributor organization="Opsware, Inc.">Todd Dolinsky</contributor>
            </modified>
            <status_change date="2007-09-13T14:05:28.763-04:00">INTERIM</status_change>
            <status_change date="2007-10-02T08:08:10.207-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="AND" comment="700 Series OS Release 11.04">
          <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2515"/>
          <criterion comment="HP Release B.11.04" negate="false" test_ref="oval:org.mitre.oval:tst:1276"/>
        </criteria>
        <criterion comment="VirusVault is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1040"/>
        <criterion comment="Patch PHSS_34123 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:1039"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1636" version="2" class="vulnerability">
      <metadata>
        <title>HP-UX wuftpd Privilege Escalation Vulnerability (B.11.22)</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
          <product>ftpd</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0148" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0148"/>
        <description>wu-ftpd 2.6.2 and earlier, with the restricted-gid option enabled, allows local users to bypass access restrictions by changing the permissions to prevent access to their home directory, which causes wu-ftpd to use the root directory instead.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-01-30T07:20:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-02-01T09:08:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-02-22T08:27:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-03-09T12:19:00.000-04:00">ACCEPTED</status_change>
            <modified comment="modified patch test to only check for specific patch, checking for supersedence was incorrect and need a language change" date="2007-09-13T00:00:00.000-05:00">
              <contributor organization="Opsware, Inc.">Todd Dolinsky</contributor>
            </modified>
            <status_change date="2007-09-13T14:05:28.693-04:00">INTERIM</status_change>
            <status_change date="2007-10-02T08:08:10.118-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="AND" comment="700 Series OS Release 11.22">
          <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2515"/>
          <criterion comment="HP Release B.11.22" negate="false" test_ref="oval:org.mitre.oval:tst:1015"/>
        </criteria>
        <criterion comment="InternetSrvcs.INETSVCS2-RUN (B.11.22) is installed" negate="false" test_ref="oval:org.mitre.oval:tst:795"/>
        <criterion comment="Patch PHNE_29462 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:794"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1629" version="2" class="vulnerability">
      <metadata>
        <title>Webproxy HTTP Request Smuggling</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
          <product>Apache</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2088" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2088"/>
        <description>The Apache HTTP server before 1.3.34, and 2.0.x before 2.0.55, when acting as an HTTP proxy, allows remote attackers to poison the web cache, bypass web application firewall protection, and conduct XSS attacks via an HTTP request with both a "Transfer-Encoding: chunked" header and a Content-Length header, which causes Apache to incorrectly handle and forward the body of the request in a way that causes the receiving server to process it as a separate HTTP request, aka "HTTP Request Smuggling."</description>
        <oval_repository>
          <dates>
            <submitted date="2006-03-18T07:24:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-03-22T11:10:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-04-06T06:31:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-05-03T10:06:00.000-04:00">ACCEPTED</status_change>
            <modified comment="modified patch test to only check for specific patch, checking for supersedence was incorrect and need a language change" date="2007-09-13T00:00:00.000-05:00">
              <contributor organization="Opsware, Inc.">Todd Dolinsky</contributor>
            </modified>
            <status_change date="2007-09-13T14:05:28.568-04:00">INTERIM</status_change>
            <status_change date="2007-10-02T08:08:10.027-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="AND" comment="700 Series OS Release 11.04">
          <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2515"/>
          <criterion comment="HP Release B.11.04" negate="false" test_ref="oval:org.mitre.oval:tst:1276"/>
        </criteria>
        <criterion comment="Webproxy is installed" negate="false" test_ref="oval:org.mitre.oval:tst:890"/>
        <criterion comment="Patch PHSS_34163 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:889"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1607" version="2" class="vulnerability">
      <metadata>
        <title>HP-UX PMTUD Remote DoS (B.11.11)</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
          <product>Operating System</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1192" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1192"/>
        <description>Unknown vulnerability in HP-UX B.11.00, B.11.04, B.11.11, B.11.22, and B.11.23, when running TCP/IP on IPv4, allows remote attackers to cause a denial of service via certain packets, related to the PMTU, a different vulnerability than CVE-2004-1060.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-02-01T11:45:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-03-09T12:19:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-04-06T06:30:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-05-03T10:06:00.000-04:00">ACCEPTED</status_change>
            <modified comment="modified patch test to only check for specific patch, checking for supersedence was incorrect and need a language change" date="2007-09-13T00:00:00.000-05:00">
              <contributor organization="Opsware, Inc.">Todd Dolinsky</contributor>
            </modified>
            <status_change date="2007-09-13T14:05:28.493-04:00">INTERIM</status_change>
            <status_change date="2007-10-02T08:08:09.927-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.11">
          <criteria operator="AND" comment="700 Series OS Release 11.11">
            <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2515"/>
            <criterion comment="HP Release B.11.11" negate="false" test_ref="oval:org.mitre.oval:tst:2514"/>
          </criteria>
          <criteria operator="AND" comment="800 Series OS Release 11.11">
            <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2513"/>
            <criterion comment="HP Release B.11.11" negate="false" test_ref="oval:org.mitre.oval:tst:2514"/>
          </criteria>
        </criteria>
        <criterion comment="Networking.NET2-KRN is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1442"/>
        <criterion comment="Patch PHNE_33159 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:823"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1577" version="2" class="vulnerability">
      <metadata>
        <title>HP-UX Shared Library Privilege Escalation Vulnerability (B.11.00)</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
          <product>Operating System</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-0436" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0436"/>
        <description>Unspecified vulnerability in HP HP-UX B.11.00, B.11.04, and B.11.11 allows local users to gain privileges via unknown attack vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-01-30T07:20:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-02-01T09:08:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-02-22T08:27:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-03-09T12:19:00.000-04:00">ACCEPTED</status_change>
            <modified comment="modified patch test to only check for specific patch, checking for supersedence was incorrect and need a language change" date="2007-09-13T00:00:00.000-05:00">
              <contributor organization="Opsware, Inc.">Todd Dolinsky</contributor>
            </modified>
            <status_change date="2007-09-13T14:05:28.348-04:00">INTERIM</status_change>
            <status_change date="2007-10-02T08:08:09.738-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.00">
          <criteria operator="AND" comment="700 Series OS Release 11.00">
            <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2515"/>
            <criterion comment="HP Release B.11.00" negate="false" test_ref="oval:org.mitre.oval:tst:2512"/>
          </criteria>
          <criteria operator="AND" comment="800 Series OS Release 11.00">
            <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2513"/>
            <criterion comment="HP Release B.11.00" negate="false" test_ref="oval:org.mitre.oval:tst:2512"/>
          </criteria>
        </criteria>
        <criterion comment="Patch PHCO_29249 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:847"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1576" version="2" class="vulnerability">
      <metadata>
        <title>HP-UX Trusted Mode remshd Remote Unauthorized Access (B.11.23)</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
          <product>remshd</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-3565" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-3565"/>
        <description>Unknown vulnerability in remshd daemon in HP-UX B.11.00, B.11.11, and B.11.23 while running in "Trusted Mode" allows remote attackers to gain unauthorized system access via unknown attack vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-11-30T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-12-20T11:03:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-01-04T08:04:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-01-25T07:30:00.000-04:00">ACCEPTED</status_change>
            <modified comment="modified patch test to only check for specific patch, checking for supersedence was incorrect and need a language change" date="2007-09-13T00:00:00.000-05:00">
              <contributor organization="Opsware, Inc.">Todd Dolinsky</contributor>
            </modified>
            <status_change date="2007-09-13T14:05:28.271-04:00">INTERIM</status_change>
            <status_change date="2007-10-02T08:08:09.641-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.23">
          <criteria operator="AND" comment="700 Series OS Release 11.23">
            <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2515"/>
            <criterion comment="HP Release B.11.23" negate="false" test_ref="oval:org.mitre.oval:tst:2511"/>
          </criteria>
          <criteria operator="AND" comment="800 Series OS Release 11.23">
            <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2513"/>
            <criterion comment="HP Release B.11.23" negate="false" test_ref="oval:org.mitre.oval:tst:2511"/>
          </criteria>
        </criteria>
        <criteria operator="OR" comment="InternetSrvcs.INETSVCS2-RUN or InternetSrvcs.INET-ENG-A-MAN (B.11.23) is installed">
          <criterion comment="InternetSrvcs.INETSVCS2-RUN is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2472"/>
          <criterion comment="InternetSrvcs.INET-ENG-A-MAN is installed" negate="false" test_ref="oval:org.mitre.oval:tst:849"/>
        </criteria>
        <criterion comment="Patch PHNE_33792 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:848"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1526" version="2" class="vulnerability">
      <metadata>
        <title>VirusVault HTTP Request Smuggling</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
          <product>Apache</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2088" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2088"/>
        <description>The Apache HTTP server before 1.3.34, and 2.0.x before 2.0.55, when acting as an HTTP proxy, allows remote attackers to poison the web cache, bypass web application firewall protection, and conduct XSS attacks via an HTTP request with both a "Transfer-Encoding: chunked" header and a Content-Length header, which causes Apache to incorrectly handle and forward the body of the request in a way that causes the receiving server to process it as a separate HTTP request, aka "HTTP Request Smuggling."</description>
        <oval_repository>
          <dates>
            <submitted date="2006-03-18T07:24:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-03-22T11:10:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-04-06T06:31:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-05-03T10:06:00.000-04:00">ACCEPTED</status_change>
            <modified comment="modified patch test to only check for specific patch, checking for supersedence was incorrect and need a language change" date="2007-09-13T00:00:00.000-05:00">
              <contributor organization="Opsware, Inc.">Todd Dolinsky</contributor>
            </modified>
            <status_change date="2007-09-13T14:05:28.125-04:00">INTERIM</status_change>
            <status_change date="2007-10-02T08:08:09.431-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="AND" comment="700 Series OS Release 11.04">
          <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2515"/>
          <criterion comment="HP Release B.11.04" negate="false" test_ref="oval:org.mitre.oval:tst:1276"/>
        </criteria>
        <criterion comment="VirusVault is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1040"/>
        <criterion comment="Patch PHSS_34123 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:1039"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1496" version="2" class="vulnerability">
      <metadata>
        <title>Webproxy Integer Overflow in pcre_compile</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
          <product>Apache</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2491" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2491"/>
        <description>Integer overflow in pcre_compile.c in Perl Compatible Regular Expressions (PCRE) before 6.2, as used in multiple products such as Python, Ethereal, and PHP, allows attackers to execute arbitrary code via quantifier values in regular expressions, which leads to a heap-based buffer overflow.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-03-18T07:24:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-03-22T11:10:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-04-06T06:31:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-05-03T10:06:00.000-04:00">ACCEPTED</status_change>
            <modified comment="modified patch test to only check for specific patch, checking for supersedence was incorrect and need a language change" date="2007-09-13T00:00:00.000-05:00">
              <contributor organization="Opsware, Inc.">Todd Dolinsky</contributor>
            </modified>
            <status_change date="2007-09-13T14:05:28.056-04:00">INTERIM</status_change>
            <status_change date="2007-10-02T08:08:09.337-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="AND" comment="700 Series OS Release 11.04">
          <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2515"/>
          <criterion comment="HP Release B.11.04" negate="false" test_ref="oval:org.mitre.oval:tst:1276"/>
        </criteria>
        <criterion comment="Webproxy is installed" negate="false" test_ref="oval:org.mitre.oval:tst:890"/>
        <criterion comment="Patch PHSS_34163 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:889"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1461" version="2" class="vulnerability">
      <metadata>
        <title>HP-UX xterm Privilege Escalation Vulnerability (B.11.11)</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
          <product>Operating System</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-3779" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-3779"/>
        <description>Unspecified vulnerability in xterm for HP-UX 11.00, 11.11, and 11.23 allows local users to gain privileges via unknown vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-01-11T12:55:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-01-12T09:18:00.000-04:00">DRAFT</status_change>
            <modified date="2006-01-26T01:55:00.000-04:00" comment="Updated to CVE-2005-3779.  HP is so vague that it's not completely certain.">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2006-02-22T08:27:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-03-09T12:19:00.000-04:00">ACCEPTED</status_change>
            <modified comment="modified patch test to only check for specific patch, checking for supersedence was incorrect and need a language change" date="2007-09-13T00:00:00.000-05:00">
              <contributor organization="Opsware, Inc.">Todd Dolinsky</contributor>
            </modified>
            <status_change date="2007-09-13T14:05:27.897-04:00">INTERIM</status_change>
            <status_change date="2007-10-02T08:08:09.141-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.11">
          <criteria operator="AND" comment="700 Series OS Release 11.11">
            <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2515"/>
            <criterion comment="HP Release B.11.11" negate="false" test_ref="oval:org.mitre.oval:tst:2514"/>
          </criteria>
          <criteria operator="AND" comment="800 Series OS Release 11.11">
            <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2513"/>
            <criterion comment="HP Release B.11.11" negate="false" test_ref="oval:org.mitre.oval:tst:2514"/>
          </criteria>
        </criteria>
        <criterion comment="Patch PHSS_34102 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:915"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1453" version="2" class="vulnerability">
      <metadata>
        <title>HP-UX Shared Library Privilege Escalation Vulnerability (B.11.11)</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
          <product>Operating System</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-0436" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0436"/>
        <description>Unspecified vulnerability in HP HP-UX B.11.00, B.11.04, and B.11.11 allows local users to gain privileges via unknown attack vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-01-30T07:20:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-02-01T09:08:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-02-22T08:27:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-03-09T12:19:00.000-04:00">ACCEPTED</status_change>
            <modified comment="modified patch test to only check for specific patch, checking for supersedence was incorrect and need a language change" date="2007-09-13T00:00:00.000-05:00">
              <contributor organization="Opsware, Inc.">Todd Dolinsky</contributor>
            </modified>
            <status_change date="2007-09-13T14:05:27.825-04:00">INTERIM</status_change>
            <status_change date="2007-10-02T08:08:09.049-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.11">
          <criteria operator="AND" comment="700 Series OS Release 11.11">
            <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2515"/>
            <criterion comment="HP Release B.11.11" negate="false" test_ref="oval:org.mitre.oval:tst:2514"/>
          </criteria>
          <criteria operator="AND" comment="800 Series OS Release 11.11">
            <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2513"/>
            <criterion comment="HP Release B.11.11" negate="false" test_ref="oval:org.mitre.oval:tst:2514"/>
          </criteria>
        </criteria>
        <criterion comment="Patch PHCO_30402 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:924"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1439" version="2" class="vulnerability">
      <metadata>
        <title>HP-UX ftpd Remote Unauthorized Data Access (B.11.11)</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
          <product>ftpd</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-3296" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-3296"/>
        <description>The FTP server in HP-UX 10.20, B.11.00, and B.11.11, allows remote attackers to list arbitrary directories as root by running the LIST command before logging in.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-11-30T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-12-20T11:03:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-01-04T08:04:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-01-25T07:30:00.000-04:00">ACCEPTED</status_change>
            <modified comment="modified patch test to only check for specific patch, checking for supersedence was incorrect and need a language change" date="2007-09-13T00:00:00.000-05:00">
              <contributor organization="Opsware, Inc.">Todd Dolinsky</contributor>
            </modified>
            <status_change date="2007-09-13T14:05:27.700-04:00">INTERIM</status_change>
            <status_change date="2007-10-02T08:08:08.941-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.11">
          <criteria operator="AND" comment="700 Series OS Release 11.11">
            <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2515"/>
            <criterion comment="HP Release B.11.11" negate="false" test_ref="oval:org.mitre.oval:tst:2514"/>
          </criteria>
          <criteria operator="AND" comment="800 Series OS Release 11.11">
            <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2513"/>
            <criterion comment="HP Release B.11.11" negate="false" test_ref="oval:org.mitre.oval:tst:2514"/>
          </criteria>
        </criteria>
        <criteria operator="OR" comment="InternetSrvcs.INETSVCS-RUN or InternetSrvcs.INET-ENG-A-MAN (B.11.11) is installed">
          <criterion comment="InternetSrvcs.INETSVCS-RUN is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1119"/>
          <criterion comment="InternetSrvcs.INET-ENG-A-MAN is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1118"/>
        </criteria>
        <criterion comment="Patch PHNE_23950 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:934"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1429" version="2" class="vulnerability">
      <metadata>
        <title>HP-UX envd Local Execution of Privileged Code (B.11.00)</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
          <product>envd</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-3564" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-3564"/>
        <description>envd daemon in HP-UX B.11.00 through B.11.11 allows local users to obtain privileges via unknown attack vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-11-30T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-12-20T11:03:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-01-04T08:04:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-01-25T07:30:00.000-04:00">ACCEPTED</status_change>
            <modified comment="modified patch test to only check for specific patch, checking for supersedence was incorrect and need a language change" date="2007-09-13T00:00:00.000-05:00">
              <contributor organization="Opsware, Inc.">Todd Dolinsky</contributor>
            </modified>
            <status_change date="2007-09-13T14:05:27.611-04:00">INTERIM</status_change>
            <status_change date="2007-10-02T08:08:08.833-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.00">
          <criteria operator="AND" comment="700 Series OS Release 11.00">
            <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2515"/>
            <criterion comment="HP Release B.11.00" negate="false" test_ref="oval:org.mitre.oval:tst:2512"/>
          </criteria>
          <criteria operator="AND" comment="800 Series OS Release 11.00">
            <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2513"/>
            <criterion comment="HP Release B.11.00" negate="false" test_ref="oval:org.mitre.oval:tst:2512"/>
          </criteria>
        </criteria>
        <criteria operator="OR" comment="OS-Core.CORE-ENG-A-MAN or OS-Core.UX-CORE (B.11.00) is installed">
          <criterion comment="OS-Core.CORE-ENG-A-MAN is installed" negate="false" test_ref="oval:org.mitre.oval:tst:946"/>
          <criterion comment="OS-Core.UX-CORE is installed" negate="false" test_ref="oval:org.mitre.oval:tst:945"/>
        </criteria>
        <criterion comment="Patch PHCO_33989 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:944"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1407" version="2" class="vulnerability">
      <metadata>
        <title>HP-UX PMTUD Remote DoS (B.11.23-IPSEC)</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
          <product>Operating System</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1192" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1192"/>
        <description>Unknown vulnerability in HP-UX B.11.00, B.11.04, B.11.11, B.11.22, and B.11.23, when running TCP/IP on IPv4, allows remote attackers to cause a denial of service via certain packets, related to the PMTU, a different vulnerability than CVE-2004-1060.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-02-01T11:45:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-03-09T12:19:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-04-06T06:30:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-05-03T10:06:00.000-04:00">ACCEPTED</status_change>
            <modified comment="modified patch test to only check for specific patch, checking for supersedence was incorrect and need a language change" date="2007-09-13T00:00:00.000-05:00">
              <contributor organization="Opsware, Inc.">Todd Dolinsky</contributor>
            </modified>
            <status_change date="2007-09-13T14:05:27.446-04:00">INTERIM</status_change>
            <status_change date="2007-10-02T08:08:08.618-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="AND" comment="700 Series OS Release 11.22">
          <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2515"/>
          <criterion comment="HP Release B.11.22" negate="false" test_ref="oval:org.mitre.oval:tst:1015"/>
        </criteria>
        <criterion comment="IPSec.IPSEC2-KRN is installed" negate="false" test_ref="oval:org.mitre.oval:tst:966"/>
        <criteria operator="OR" comment="IPSec.IPSEC2-KRN version is under A.2.00.01 or TOUR version is under 3.0 or patch PHNE_32606 is not installed">
          <criterion comment="IPSec.IPSEC2-KRN with version less than A.2.00.01 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:965"/>
          <criterion comment="TOUR_PRODUCT.T-NET2-KRN with version less than A.03.00 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:964"/>
          <criterion comment="Patch PHNE_32606 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:1441"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1333" version="2" class="vulnerability">
      <metadata>
        <title>WU-FTPD "glob-*" Remote DoS Vulnerability (B.11.00)</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
          <product>ftpd</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0256" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0256"/>
        <description>The wu_fnmatch function in wu_fnmatch.c in wu-ftpd 2.6.1 and 2.6.2 allows remote attackers to cause a denial of service (CPU exhaustion by recursion) via a glob pattern with a large number of * (wildcard) characters, as demonstrated using the dir command.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-04-06T06:39:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-04-12T05:16:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-05-03T10:06:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-05-31T09:45:00.000-04:00">ACCEPTED</status_change>
            <modified comment="modified patch test to only check for specific patch, checking for supersedence was incorrect and need a language change" date="2007-09-13T00:00:00.000-05:00">
              <contributor organization="Opsware, Inc.">Todd Dolinsky</contributor>
            </modified>
            <status_change date="2007-09-13T14:05:27.368-04:00">INTERIM</status_change>
            <status_change date="2007-10-02T08:08:08.517-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.00">
          <criteria operator="AND" comment="700 Series OS Release 11.00">
            <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2515"/>
            <criterion comment="HP Release B.11.00" negate="false" test_ref="oval:org.mitre.oval:tst:2512"/>
          </criteria>
          <criteria operator="AND" comment="800 Series OS Release 11.00">
            <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2513"/>
            <criterion comment="HP Release B.11.00" negate="false" test_ref="oval:org.mitre.oval:tst:2512"/>
          </criteria>
        </criteria>
        <criteria operator="OR" comment="INETSVCS-RUN without patch PHNE_34543 or later, OR WUFTP-26.INETSVCS-FTP with version less than B.11.11.01.006 is installed">
          <criteria operator="AND" comment="INETSVCS-RUN without patch PHNE_34543 or later">
            <criterion comment="InternetSrvcs.INETSVCS-RUN is installed" negate="false" test_ref="oval:org.mitre.oval:tst:981"/>
            <criterion comment="Patch PHNE_34543 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:980"/>
          </criteria>
          <criterion comment="WUFTP-26.INETSVCS-FTP with version less than B.11.11.01.006 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:979"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1265" version="2" class="vulnerability">
      <metadata>
        <title>WU-FTPD "glob-*" Remote DoS Vulnerability (B.11.23)</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
          <product>ftpd</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0256" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0256"/>
        <description>The wu_fnmatch function in wu_fnmatch.c in wu-ftpd 2.6.1 and 2.6.2 allows remote attackers to cause a denial of service (CPU exhaustion by recursion) via a glob pattern with a large number of * (wildcard) characters, as demonstrated using the dir command.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-04-06T06:39:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-04-12T05:16:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-05-03T10:06:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-05-31T09:45:00.000-04:00">ACCEPTED</status_change>
            <modified comment="modified patch test to only check for specific patch, checking for supersedence was incorrect and need a language change" date="2007-09-13T00:00:00.000-05:00">
              <contributor organization="Opsware, Inc.">Todd Dolinsky</contributor>
            </modified>
            <status_change date="2007-09-13T14:05:27.213-04:00">INTERIM</status_change>
            <status_change date="2007-10-02T08:08:08.109-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.23">
          <criteria operator="AND" comment="700 Series OS Release 11.23">
            <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2515"/>
            <criterion comment="HP Release B.11.23" negate="false" test_ref="oval:org.mitre.oval:tst:2511"/>
          </criteria>
          <criteria operator="AND" comment="800 Series OS Release 11.23">
            <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2513"/>
            <criterion comment="HP Release B.11.23" negate="false" test_ref="oval:org.mitre.oval:tst:2511"/>
          </criteria>
        </criteria>
        <criterion comment="Patch PHNE_34306 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:1030"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1246" version="2" class="vulnerability">
      <metadata>
        <title>VirusVault CGI Byterange Request DoS</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
          <product>Apache</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2728" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2728"/>
        <description>The byte-range filter in Apache 2.0 before 2.0.54 allows remote attackers to cause a denial of service (memory consumption) via an HTTP header with a large Range field.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-03-18T07:24:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-03-22T11:10:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-04-06T06:31:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-05-03T10:06:00.000-04:00">ACCEPTED</status_change>
            <modified comment="modified patch test to only check for specific patch, checking for supersedence was incorrect and need a language change" date="2007-09-13T00:00:00.000-05:00">
              <contributor organization="Opsware, Inc.">Todd Dolinsky</contributor>
            </modified>
            <status_change date="2007-09-13T14:05:27.140-04:00">INTERIM</status_change>
            <status_change date="2007-10-02T08:08:08.010-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="AND" comment="700 Series OS Release 11.04">
          <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2515"/>
          <criterion comment="HP Release B.11.04" negate="false" test_ref="oval:org.mitre.oval:tst:1276"/>
        </criteria>
        <criterion comment="VirusVault is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1040"/>
        <criterion comment="Patch PHSS_34123 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:1039"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1237" version="3" class="vulnerability">
      <metadata>
        <title>Webproxy HTTP Request Smuggling (B.11.04)</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
          <product>Apache</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2088" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2088"/>
        <description>The Apache HTTP server before 1.3.34, and 2.0.x before 2.0.55, when acting as an HTTP proxy, allows remote attackers to poison the web cache, bypass web application firewall protection, and conduct XSS attacks via an HTTP request with both a "Transfer-Encoding: chunked" header and a Content-Length header, which causes Apache to incorrectly handle and forward the body of the request in a way that causes the receiving server to process it as a separate HTTP request, aka "HTTP Request Smuggling."</description>
        <oval_repository>
          <dates>
            <submitted date="2006-03-18T07:24:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-03-22T11:10:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-04-06T06:31:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-05-03T10:06:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Added CVE reference. Implemented by Jon Baker of The MITRE Corporation." date="2007-03-19T21:23:00.442-04:00">
              <contributor organization="Opsware, Inc.">Todd Dolinsky</contributor>
            </modified>
            <status_change date="2007-03-19T21:30:48.475-04:00">INTERIM</status_change>
            <status_change date="2007-04-10T13:44:19.545-04:00">ACCEPTED</status_change>
            <modified comment="modified patch test to only check for specific patch, checking for supersedence was incorrect and need a language change" date="2007-09-13T00:00:00.000-05:00">
              <contributor organization="Opsware, Inc.">Todd Dolinsky</contributor>
            </modified>
            <status_change date="2007-09-13T14:05:26.988-04:00">INTERIM</status_change>
            <status_change date="2007-10-02T08:08:07.831-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="OR">
        <criteria operator="AND" comment="VirtualvaultTS A.04.70 is installed without patch PHSS_34169 or later">
          <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.04">
            <criteria operator="AND" comment="700 Series OS Release 11.04">
              <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2515"/>
              <criterion comment="HP Release B.11.04" negate="false" test_ref="oval:org.mitre.oval:tst:1276"/>
            </criteria>
            <criteria operator="AND" comment="800 Series OS Release 11.04">
              <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2513"/>
              <criterion comment="HP Release B.11.04" negate="false" test_ref="oval:org.mitre.oval:tst:1276"/>
            </criteria>
          </criteria>
          <criterion comment="VirtualvaultTS A.04.70 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1062"/>
          <criterion comment="Patch PHSS_34169 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2341"/>
        </criteria>
        <criteria operator="AND" comment="VirtualvaultWS A.04.70 is installed without patch PHSS_34121 or later">
          <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.04">
            <criteria operator="AND" comment="700 Series OS Release 11.04">
              <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2515"/>
              <criterion comment="HP Release B.11.04" negate="false" test_ref="oval:org.mitre.oval:tst:1276"/>
            </criteria>
            <criteria operator="AND" comment="800 Series OS Release 11.04">
              <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2513"/>
              <criterion comment="HP Release B.11.04" negate="false" test_ref="oval:org.mitre.oval:tst:1276"/>
            </criteria>
          </criteria>
          <criterion comment="VirtualvaultWS A.04.70 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1061"/>
          <criterion comment="Patch PHSS_34121 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:1060"/>
        </criteria>
        <criteria operator="AND" comment="VirtualvaultTS A.04.60 is installed without patch PHSS_34170 or later">
          <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.04">
            <criteria operator="AND" comment="700 Series OS Release 11.04">
              <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2515"/>
              <criterion comment="HP Release B.11.04" negate="false" test_ref="oval:org.mitre.oval:tst:1276"/>
            </criteria>
            <criteria operator="AND" comment="800 Series OS Release 11.04">
              <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2513"/>
              <criterion comment="HP Release B.11.04" negate="false" test_ref="oval:org.mitre.oval:tst:1276"/>
            </criteria>
          </criteria>
          <criterion comment="VirtualvaultTS A.04.60 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1059"/>
          <criterion comment="Patch PHSS_34170 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:1058"/>
        </criteria>
        <criteria operator="AND" comment="VirtualvaultWS A.04.60 is installed without patch PHSS_34120 or later">
          <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.04">
            <criteria operator="AND" comment="700 Series OS Release 11.04">
              <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2515"/>
              <criterion comment="HP Release B.11.04" negate="false" test_ref="oval:org.mitre.oval:tst:1276"/>
            </criteria>
            <criteria operator="AND" comment="800 Series OS Release 11.04">
              <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2513"/>
              <criterion comment="HP Release B.11.04" negate="false" test_ref="oval:org.mitre.oval:tst:1276"/>
            </criteria>
          </criteria>
          <criterion comment="VirtualvaultWS A.04.60 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1057"/>
          <criterion comment="Patch PHSS_34120 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:1056"/>
        </criteria>
        <criteria operator="AND" comment="VirtualvaultTS A.04.50 is installed without patch PHSS_34171 or later">
          <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.04">
            <criteria operator="AND" comment="700 Series OS Release 11.04">
              <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2515"/>
              <criterion comment="HP Release B.11.04" negate="false" test_ref="oval:org.mitre.oval:tst:1276"/>
            </criteria>
            <criteria operator="AND" comment="800 Series OS Release 11.04">
              <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2513"/>
              <criterion comment="HP Release B.11.04" negate="false" test_ref="oval:org.mitre.oval:tst:1276"/>
            </criteria>
          </criteria>
          <criterion comment="VirtualvaultTS A.04.50 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1055"/>
          <criterion comment="Patch PHSS_34171 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:1054"/>
        </criteria>
        <criteria operator="AND" comment="VirtualvaultWS A.04.50 is installed without patch PHSS_34119 or later">
          <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.04">
            <criteria operator="AND" comment="700 Series OS Release 11.04">
              <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2515"/>
              <criterion comment="HP Release B.11.04" negate="false" test_ref="oval:org.mitre.oval:tst:1276"/>
            </criteria>
            <criteria operator="AND" comment="800 Series OS Release 11.04">
              <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2513"/>
              <criterion comment="HP Release B.11.04" negate="false" test_ref="oval:org.mitre.oval:tst:1276"/>
            </criteria>
          </criteria>
          <criterion comment="VirtualvaultWS A.04.50 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1053"/>
          <criterion comment="Patch PHSS_34119 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:1052"/>
        </criteria>
        <criteria operator="AND" comment="HP_Webproxy.HPWEB-PX-CORE A.02.10 is installed without patch PHSS_34203 or later">
          <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.04">
            <criteria operator="AND" comment="700 Series OS Release 11.04">
              <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2515"/>
              <criterion comment="HP Release B.11.04" negate="false" test_ref="oval:org.mitre.oval:tst:1276"/>
            </criteria>
            <criteria operator="AND" comment="800 Series OS Release 11.04">
              <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2513"/>
              <criterion comment="HP Release B.11.04" negate="false" test_ref="oval:org.mitre.oval:tst:1276"/>
            </criteria>
          </criteria>
          <criterion comment="HP_Webproxy.HPWEB-PX-CORE A.02.10 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1051"/>
          <criterion comment="Patch PHSS_34203 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:1050"/>
        </criteria>
        <criteria operator="AND" comment="HP_Webproxy.HPWEB-PX-CORE A.02.00 is installed without patch PHSS_34204 or later">
          <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.04">
            <criteria operator="AND" comment="700 Series OS Release 11.04">
              <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2515"/>
              <criterion comment="HP Release B.11.04" negate="false" test_ref="oval:org.mitre.oval:tst:1276"/>
            </criteria>
            <criteria operator="AND" comment="800 Series OS Release 11.04">
              <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2513"/>
              <criterion comment="HP Release B.11.04" negate="false" test_ref="oval:org.mitre.oval:tst:1276"/>
            </criteria>
          </criteria>
          <criterion comment="HP_Webproxy.HPWEB-PX-CORE A.02.00 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1049"/>
          <criterion comment="Patch PHSS_34204 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:1048"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1212" version="2" class="vulnerability">
      <metadata>
        <title>HP-UX ftpd Remote Unauthorized Data Access (B.10.24)</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
          <product>ftpd</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-3296" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-3296"/>
        <description>The FTP server in HP-UX 10.20, B.11.00, and B.11.11, allows remote attackers to list arbitrary directories as root by running the LIST command before logging in.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-11-30T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-12-20T11:03:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-01-04T08:04:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-01-25T07:30:00.000-04:00">ACCEPTED</status_change>
            <modified comment="modified patch test to only check for specific patch, checking for supersedence was incorrect and need a language change" date="2007-09-13T00:00:00.000-05:00">
              <contributor organization="Opsware, Inc.">Todd Dolinsky</contributor>
            </modified>
            <status_change date="2007-09-13T14:05:26.911-04:00">INTERIM</status_change>
            <status_change date="2007-10-02T08:08:07.720-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="700 Series or 800 Series OS Release 10.24">
          <criteria operator="AND" comment="700 Series OS Release 10.24">
            <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2515"/>
            <criterion comment="HP Release B.10.24" negate="false" test_ref="oval:org.mitre.oval:tst:1077"/>
          </criteria>
          <criteria operator="AND" comment="800 Series OS Release 10.24">
            <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2513"/>
            <criterion comment="HP Release B.10.24" negate="false" test_ref="oval:org.mitre.oval:tst:1077"/>
          </criteria>
        </criteria>
        <criterion comment="Patch PHNE_24394 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:1076"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1177" version="3" class="vulnerability">
      <metadata>
        <title>HP-UX 11.11 Blind Connection Reset Attack Vulnerability</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
          <product>Operating System</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0790" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0790"/>
        <description>Multiple TCP/IP and ICMP implementations allow remote attackers to cause a denial of service (reset TCP connections) via spoofed ICMP error messages, aka the "blind connection-reset attack."  NOTE: CVE-2004-0790, CVE-2004-0791, and CVE-2004-1060 have been SPLIT based on different attacks; CVE-2005-0065, CVE-2005-0066, CVE-2005-0067, and CVE-2005-0068 are related identifiers that are SPLIT based on the underlying vulnerability.  While CVE normally SPLITs based on vulnerability, the attack-based identifiers exist due to the variety and number of affected implementations and solutions that address the attacks instead of the underlying vulnerabilities.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-09-22T05:48:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-09-22T20:15:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-07T09:15:14.323-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:15:04.370-04:00">ACCEPTED</status_change>
            <modified comment="Added title. Implemented by Jon Baker of The MITRE Corporation." date="2007-02-13T14:07:00.724-05:00">
              <contributor organization="Security-Database">Nabil Ouchn</contributor>
            </modified>
            <status_change date="2007-02-13T14:09:38.747-05:00">INTERIM</status_change>
            <modified comment="Standardized title." date="2007-02-26T00:59:00.698-05:00">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2007-03-21T16:16:43.707-04:00">ACCEPTED</status_change>
            <modified comment="modified patch test to only check for specific patch, checking for supersedence was incorrect and need a language change" date="2007-09-13T00:00:00.000-05:00">
              <contributor organization="Opsware, Inc.">Todd Dolinsky</contributor>
            </modified>
            <status_change date="2007-09-13T14:05:26.785-04:00">INTERIM</status_change>
            <status_change date="2007-10-02T08:08:07.606-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.11" negate="false">
          <criteria operator="AND" comment="700 Series OS Release 11.11" negate="false">
            <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:3443"/>
            <criterion comment="HP Release B.11.11" negate="false" test_ref="oval:org.mitre.oval:tst:3704"/>
          </criteria>
          <criteria operator="AND" comment="800 Series OS Release 11.11" negate="false">
            <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:4124"/>
            <criterion comment="HP Release B.11.11" negate="false" test_ref="oval:org.mitre.oval:tst:3704"/>
          </criteria>
        </criteria>
        <criterion comment="Patch PHNE_33159 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:3779"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1151" version="2" class="vulnerability">
      <metadata>
        <title>HP-UX Trusted Mode remshd Remote Unauthorized Access (B.11.11)</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
          <product>remshd</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-3565" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-3565"/>
        <description>Unknown vulnerability in remshd daemon in HP-UX B.11.00, B.11.11, and B.11.23 while running in "Trusted Mode" allows remote attackers to gain unauthorized system access via unknown attack vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-11-30T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-12-20T11:03:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-01-04T08:04:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-01-25T07:30:00.000-04:00">ACCEPTED</status_change>
            <modified comment="modified patch test to only check for specific patch, checking for supersedence was incorrect and need a language change" date="2007-09-13T00:00:00.000-05:00">
              <contributor organization="Opsware, Inc.">Todd Dolinsky</contributor>
            </modified>
            <status_change date="2007-09-13T14:05:26.704-04:00">INTERIM</status_change>
            <status_change date="2007-10-02T08:08:07.497-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.11">
          <criteria operator="AND" comment="700 Series OS Release 11.11">
            <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2515"/>
            <criterion comment="HP Release B.11.11" negate="false" test_ref="oval:org.mitre.oval:tst:2514"/>
          </criteria>
          <criteria operator="AND" comment="800 Series OS Release 11.11">
            <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2513"/>
            <criterion comment="HP Release B.11.11" negate="false" test_ref="oval:org.mitre.oval:tst:2514"/>
          </criteria>
        </criteria>
        <criteria operator="OR" comment="InternetSrvcs.INETSVCS-RUN or InternetSrvcs.INET-ENG-A-MAN (B.11.11) is installed">
          <criterion comment="InternetSrvcs.INETSVCS-RUN is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1119"/>
          <criterion comment="InternetSrvcs.INET-ENG-A-MAN is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1118"/>
        </criteria>
        <criterion comment="Patch PHNE_33791 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:1117"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1112" version="3" class="vulnerability">
      <metadata>
        <title>HP-UX 11.04 ICMP Source Quench Attack Vulnerability</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
          <product>Operating System</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0791" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0791"/>
        <description>Multiple TCP/IP and ICMP implementations allow remote attackers to cause a denial of service (network throughput reduction for TCP connections) via a blind throughput-reduction attack using spoofed Source Quench packets, aka the "ICMP Source Quench attack."  NOTE: CVE-2004-0790, CVE-2004-0791, and CVE-2004-1060 have been SPLIT based on different attacks; CVE-2005-0065, CVE-2005-0066, CVE-2005-0067, and CVE-2005-0068 are related identifiers that are SPLIT based on the underlying vulnerability.  While CVE normally SPLITs based on vulnerability, the attack-based identifiers exist due to the variety and number of affected implementations and solutions that address the attacks instead of the underlying vulnerabilities.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-09-22T05:48:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-09-22T20:15:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-07T09:15:12.194-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:15:00.625-04:00">ACCEPTED</status_change>
            <modified comment="Added title. Implemented by Jon Baker of The MITRE Corporation." date="2007-02-13T14:09:00.867-05:00">
              <contributor organization="Security-Database">Nabil Ouchn</contributor>
            </modified>
            <status_change date="2007-02-13T14:10:38.893-05:00">INTERIM</status_change>
            <modified comment="Standardized title." date="2007-02-23T13:00:00.713-05:00">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2007-03-21T16:16:41.884-04:00">ACCEPTED</status_change>
            <modified comment="modified patch test to only check for specific patch, checking for supersedence was incorrect and need a language change" date="2007-09-13T00:00:00.000-05:00">
              <contributor organization="Opsware, Inc.">Todd Dolinsky</contributor>
            </modified>
            <status_change date="2007-09-13T14:05:26.604-04:00">INTERIM</status_change>
            <status_change date="2007-10-02T08:08:07.376-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.04" negate="false">
          <criteria operator="AND" comment="700 Series OS Release 11.04" negate="false">
            <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:3443"/>
            <criterion comment="HP Release B.11.04" negate="false" test_ref="oval:org.mitre.oval:tst:3294"/>
          </criteria>
          <criteria operator="AND" comment="800 Series OS Release 11.04" negate="false">
            <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:4124"/>
            <criterion comment="HP Release B.11.04" negate="false" test_ref="oval:org.mitre.oval:tst:3294"/>
          </criteria>
        </criteria>
        <criterion comment="Patch PHNE_33427 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:3468"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1029" version="2" class="vulnerability">
      <metadata>
        <title>HP-UX ftpd Remote Unauthorized Data Access (B.11.04)</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
          <product>ftpd</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-3296" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-3296"/>
        <description>The FTP server in HP-UX 10.20, B.11.00, and B.11.11, allows remote attackers to list arbitrary directories as root by running the LIST command before logging in.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-11-30T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-12-20T11:03:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-01-04T08:04:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-01-25T07:30:00.000-04:00">ACCEPTED</status_change>
            <modified comment="modified patch test to only check for specific patch, checking for supersedence was incorrect and need a language change" date="2007-09-13T00:00:00.000-05:00">
              <contributor organization="Opsware, Inc.">Todd Dolinsky</contributor>
            </modified>
            <status_change date="2007-09-13T14:05:26.418-04:00">INTERIM</status_change>
            <status_change date="2007-10-02T08:08:06.860-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="InternetSrvcs.INETSVCS-RUN, InternetSrvcs.INET-ENG-A-MAN, or VirtualVaultOS.VVOS-AUX-IA (B.11.04) is installed">
          <criterion comment="InternetSrvcs.INETSVCS-RUN is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1279"/>
          <criterion comment="InternetSrvcs.INET-ENG-A-MAN is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1278"/>
          <criterion comment="VirtualVaultOS.VVOS-AUX-IA is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1277"/>
        </criteria>
        <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.04">
          <criteria operator="AND" comment="700 Series OS Release 11.04">
            <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2515"/>
            <criterion comment="HP Release B.11.04" negate="false" test_ref="oval:org.mitre.oval:tst:1276"/>
          </criteria>
          <criteria operator="AND" comment="800 Series OS Release 11.04">
            <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2513"/>
            <criterion comment="HP Release B.11.04" negate="false" test_ref="oval:org.mitre.oval:tst:1276"/>
          </criteria>
        </criteria>
        <criterion comment="Patch PHNE_24395 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:1275"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1276" version="3" class="vulnerability">
      <metadata>
        <title>HP-UX ftpd Remote Unauthorized Data Access</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-3296" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-3296"/>
        <description>The FTP server in HP-UX 10.20, B.11.00, and B.11.11, allows remote attackers to list arbitrary directories as root by running the LIST command before logging in.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-11-30T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-12-20T11:03:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-01-04T08:04:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-01-25T07:30:00.000-04:00">ACCEPTED</status_change>
            <modified comment="modified patch test to only check for specific patch, checking for supersedence was incorrect and need a language change" date="2007-09-13T00:00:00.000-05:00">
              <contributor organization="Opsware, Inc.">Todd Dolinsky</contributor>
            </modified>
            <status_change date="2007-09-13T14:05:27.290-04:00">INTERIM</status_change>
            <status_change date="2007-10-02T08:08:08.412-04:00">ACCEPTED</status_change>
            <modified comment="Criteria meets HP Security Bulletin HPSBUX02071" date="2008-07-14T10:21:00.633-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </modified>
            <status_change date="2008-07-14T10:25:01.649-04:00">INTERIM</status_change>
            <status_change date="2008-08-04T04:00:07.820-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02071">
          <criterion comment="HP Release B.11.04" test_ref="oval:org.mitre.oval:tst:3294"/>
          <criterion comment="InternetSrvcs.INETSVCS-RUN is installed" test_ref="oval:org.mitre.oval:tst:8168"/>
          <criterion negate="true" comment="Patch PHNE_24395 is installed" test_ref="oval:org.mitre.oval:tst:7709"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02071">
          <criterion comment="HP Release B.11.00" test_ref="oval:org.mitre.oval:tst:3571"/>
          <criterion comment="InternetSrvcs.INETSVCS-RUN is installed" test_ref="oval:org.mitre.oval:tst:8168"/>
          <criterion negate="true" comment="Patch PHNE_23949 is installed" test_ref="oval:org.mitre.oval:tst:8198"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1572" version="3" class="vulnerability">
      <metadata>
        <title>HP-UX envd, Local Execution of Privileged Code</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-3564" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-3564"/>
        <description>envd daemon in HP-UX B.11.00 through B.11.11 allows local users to obtain privileges via unknown attack vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-11-30T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-12-20T11:03:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-01-04T08:04:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-01-25T07:30:00.000-04:00">ACCEPTED</status_change>
            <modified comment="modified patch test to only check for specific patch, checking for supersedence was incorrect and need a language change" date="2007-09-13T00:00:00.000-05:00">
              <contributor organization="Opsware, Inc.">Todd Dolinsky</contributor>
            </modified>
            <status_change date="2007-09-13T14:05:28.194-04:00">INTERIM</status_change>
            <status_change date="2007-10-02T08:08:09.535-04:00">ACCEPTED</status_change>
            <modified comment="Criteria meets HP Security Bulletin HPSBUX02073" date="2008-07-14T10:21:00.241-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </modified>
            <status_change date="2008-07-14T10:24:39.257-04:00">INTERIM</status_change>
            <status_change date="2008-08-04T04:00:09.047-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02073">
          <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
          <criterion comment="OS-Core.UX-CORE is installed" test_ref="oval:org.mitre.oval:tst:8404"/>
          <criterion negate="true" comment="Patch PHCO_33967 is installed" test_ref="oval:org.mitre.oval:tst:8188"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02073">
          <criterion comment="HP Release B.11.00" test_ref="oval:org.mitre.oval:tst:3571"/>
          <criterion comment="OS-Core.UX-CORE is installed" test_ref="oval:org.mitre.oval:tst:8404"/>
          <criterion negate="true" comment="Patch PHCO_33989 is installed" test_ref="oval:org.mitre.oval:tst:8401"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1586" version="3" class="vulnerability">
      <metadata>
        <title>HP-UX Local Increased Privilege</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-0436" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0436"/>
        <description>Unspecified vulnerability in HP HP-UX B.11.00, B.11.04, and B.11.11 allows local users to gain privileges via unknown attack vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-01-30T07:20:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-02-01T09:08:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-02-22T08:27:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-03-09T12:19:00.000-04:00">ACCEPTED</status_change>
            <modified comment="modified patch test to only check for specific patch, checking for supersedence was incorrect and need a language change" date="2007-09-13T00:00:00.000-05:00">
              <contributor organization="Opsware, Inc.">Todd Dolinsky</contributor>
            </modified>
            <status_change date="2007-09-13T14:05:28.420-04:00">INTERIM</status_change>
            <status_change date="2007-10-02T08:08:09.830-04:00">ACCEPTED</status_change>
            <modified comment="Criteria meets HP Security Bulletin HPSBUX02091" date="2008-07-14T10:21:00.589-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </modified>
            <status_change date="2008-07-14T10:23:36.603-04:00">INTERIM</status_change>
            <status_change date="2008-08-04T04:00:09.456-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02091">
          <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
          <criterion comment="OS-Core.CORE-SHLIBS is installed" test_ref="oval:org.mitre.oval:tst:8229"/>
          <criterion negate="true" comment="Patch PHCO_30402 is installed" test_ref="oval:org.mitre.oval:tst:8002"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02091">
          <criterion comment="HP Release B.11.04" test_ref="oval:org.mitre.oval:tst:3294"/>
          <criterion comment="OS-Core.CORE-SHLIBS is installed" test_ref="oval:org.mitre.oval:tst:8229"/>
          <criterion negate="true" comment="Patch PHCO_32280 is installed" test_ref="oval:org.mitre.oval:tst:8427"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02091">
          <criterion comment="HP Release B.11.00" test_ref="oval:org.mitre.oval:tst:3571"/>
          <criterion comment="OS-Core.CORE-SHLIBS is installed" test_ref="oval:org.mitre.oval:tst:8229"/>
          <criterion negate="true" comment="Patch PHCO_29249 is installed" test_ref="oval:org.mitre.oval:tst:8107"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1754" version="4" class="vulnerability">
      <metadata>
        <title>HP-UX su(1) Local Unauthorized Access</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-1689" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1689"/>
        <description>Unspecified vulnerability in su in HP HP-UX B.11.11, when using the LDAP netgroup feature, allows local users to gain unspecified access.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-04-06T06:39:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-04-12T05:16:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-05-03T10:06:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-05-31T09:45:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Added CVE reference. Implemented by Jon Baker of The MITRE Corporation." date="2007-03-19T21:15:00.392-04:00">
              <contributor organization="Opsware, Inc.">Todd Dolinsky</contributor>
            </modified>
            <status_change date="2007-03-19T21:23:35.434-04:00">INTERIM</status_change>
            <status_change date="2007-04-10T13:44:22.733-04:00">ACCEPTED</status_change>
            <modified comment="modified patch test to only check for specific patch, checking for supersedence was incorrect and need a language change" date="2007-09-13T00:00:00.000-05:00">
              <contributor organization="Opsware, Inc.">Todd Dolinsky</contributor>
            </modified>
            <status_change date="2007-09-13T14:05:29.390-04:00">INTERIM</status_change>
            <status_change date="2007-10-02T08:08:10.899-04:00">ACCEPTED</status_change>
            <modified comment="Criteria meets Security Bulletin HPSBUX02111" date="2008-07-14T10:21:00.768-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </modified>
            <status_change date="2008-07-14T10:23:14.802-04:00">INTERIM</status_change>
            <status_change date="2008-08-04T04:00:09.946-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND" comment="Criteria meets Security Bulletin HPSBUX02111">
        <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
        <criterion comment="OS-Core.UX-CORE is installed" test_ref="oval:org.mitre.oval:tst:8404"/>
        <criterion negate="true" comment="Patch PHCO_34545 is installed" test_ref="oval:org.mitre.oval:tst:8166"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:598" version="3" class="vulnerability">
      <metadata>
        <title>HP-UX Running xterm Local Unauthorized Access</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-3779" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-3779"/>
        <description>Unspecified vulnerability in xterm for HP-UX 11.00, 11.11, and 11.23 allows local users to gain privileges via unknown vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-11-30T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-12-20T11:03:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-01-04T08:04:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-01-25T07:30:00.000-04:00">ACCEPTED</status_change>
            <modified comment="modified patch test to only check for specific patch, checking for supersedence was incorrect and need a language change" date="2007-09-13T00:00:00.000-05:00">
              <contributor organization="Opsware, Inc.">Todd Dolinsky</contributor>
            </modified>
            <status_change date="2007-09-13T14:05:30.676-04:00">INTERIM</status_change>
            <status_change date="2007-10-02T08:08:12.645-04:00">ACCEPTED</status_change>
            <modified comment="Criteria meets HP Security Bulletin HPSBUX02075" date="2008-07-14T10:21:00.902-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </modified>
            <status_change date="2008-07-14T10:23:55.918-04:00">INTERIM</status_change>
            <status_change date="2008-08-04T04:00:42.071-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02075">
          <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
          <criterion comment="X11.X11-RUN-CL is installed" test_ref="oval:org.mitre.oval:tst:8371"/>
          <criterion negate="true" comment="Patch PHSS_34102 is installed" test_ref="oval:org.mitre.oval:tst:8317"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02075">
          <criterion comment="HP Release B.11.00" test_ref="oval:org.mitre.oval:tst:3571"/>
          <criterion comment="X11.X11-RUN-CL is installed" test_ref="oval:org.mitre.oval:tst:8371"/>
          <criterion negate="true" comment="Patch PHSS_34160 is installed" test_ref="oval:org.mitre.oval:tst:8362"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02075">
          <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
          <criterion comment="X11.X11-RUN-CL is installed" test_ref="oval:org.mitre.oval:tst:8371"/>
          <criterion negate="true" comment="Patch PHSS_34159 is installed" test_ref="oval:org.mitre.oval:tst:8389"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:766" version="3" class="vulnerability">
      <metadata>
        <title>HP-UX Trusted Mode remshd, Remote Unauthorized Access</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-3565" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-3565"/>
        <description>Unknown vulnerability in remshd daemon in HP-UX B.11.00, B.11.11, and B.11.23 while running in "Trusted Mode" allows remote attackers to gain unauthorized system access via unknown attack vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-11-30T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-12-20T11:03:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-01-04T08:04:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-01-25T07:30:00.000-04:00">ACCEPTED</status_change>
            <modified comment="modified patch test to only check for specific patch, checking for supersedence was incorrect and need a language change" date="2007-09-13T00:00:00.000-05:00">
              <contributor organization="Opsware, Inc.">Todd Dolinsky</contributor>
            </modified>
            <status_change date="2007-09-13T14:05:31.246-04:00">INTERIM</status_change>
            <status_change date="2007-10-02T08:08:13.446-04:00">ACCEPTED</status_change>
            <modified comment="Criteria meets HP Security Bulletin HPSBUX02072" date="2008-07-14T10:21:00.631-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </modified>
            <status_change date="2008-07-14T10:24:15.648-04:00">INTERIM</status_change>
            <status_change date="2008-08-04T04:00:42.468-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02072">
          <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
          <criterion comment="InternetSrvcs.INETSVCS-RUN is installed" test_ref="oval:org.mitre.oval:tst:8168"/>
          <criterion negate="true" comment="Patch PHNE_33791 is installed" test_ref="oval:org.mitre.oval:tst:8349"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02072">
          <criterion comment="HP Release B.11.00" test_ref="oval:org.mitre.oval:tst:3571"/>
          <criterion comment="InternetSrvcs.INETSVCS-RUN is installed" test_ref="oval:org.mitre.oval:tst:8168"/>
          <criterion negate="true" comment="Patch PHNE_33790 is installed" test_ref="oval:org.mitre.oval:tst:8118"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02072">
          <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
          <criterion comment="InternetSrvcs.INETSVCS2-RUN is installed" test_ref="oval:org.mitre.oval:tst:8005"/>
          <criterion negate="true" comment="Patch PHNE_33792 is installed" test_ref="oval:org.mitre.oval:tst:8139"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:785" version="4" class="vulnerability">
      <metadata>
        <title>HP-UX usermod(1M) Local Unauthorized Access.</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-1248" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1248"/>
        <description>Unspecified vulnerability in usermod in HP-UX B.11.00, B.11.11, and B.11.23, when run with certain options that involve a new home directory, might cause usermod to change the ownership of all directories and files under the new directory, which might result in less secure permissions than intended.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-03-18T07:24:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-03-22T11:10:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-04-06T06:31:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-05-03T10:06:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Added CVE reference. Implemented by Jon Baker of The MITRE Corporation." date="2007-05-07T12:00:00.048-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2007-05-07T12:01:40.074-04:00">INTERIM</status_change>
            <status_change date="2007-05-23T15:05:52.817-04:00">ACCEPTED</status_change>
            <modified comment="modified patch test to only check for specific patch, checking for supersedence was incorrect and need a language change" date="2007-09-13T00:00:00.000-05:00">
              <contributor organization="Opsware, Inc.">Todd Dolinsky</contributor>
            </modified>
            <status_change date="2007-09-13T14:05:31.466-04:00">INTERIM</status_change>
            <status_change date="2007-10-02T08:08:13.680-04:00">ACCEPTED</status_change>
            <modified comment="Criteria meets HP Security Bulletin HPSBUX02102" date="2008-07-14T10:21:00.322-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </modified>
            <status_change date="2008-07-14T10:22:19.346-04:00">INTERIM</status_change>
            <status_change date="2008-08-04T04:00:42.912-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02102">
          <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="OS-Core.SYS-ADMIN is installed" test_ref="oval:org.mitre.oval:tst:8212"/>
            <criterion comment="OS-Core.SYS2-ADMIN is installed" test_ref="oval:org.mitre.oval:tst:7877"/>
          </criteria>
          <criterion negate="true" comment="Patch PHCO_34764 is installed" test_ref="oval:org.mitre.oval:tst:8277"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02102">
          <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
          <criterion comment="OS-Core.SYS-ADMIN is installed" test_ref="oval:org.mitre.oval:tst:8212"/>
          <criterion negate="true" comment="Patch PHCO_33142 is installed" test_ref="oval:org.mitre.oval:tst:8598"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02102">
          <criterion comment="HP Release B.11.00" test_ref="oval:org.mitre.oval:tst:3571"/>
          <criterion comment="OS-Core.SYS-ADMIN is installed" test_ref="oval:org.mitre.oval:tst:8212"/>
          <criterion negate="true" comment="Patch PHCO_34763 is installed" test_ref="oval:org.mitre.oval:tst:8081"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5510" version="1" class="vulnerability">
      <metadata>
        <title>HP-UX Running Apache with PHP, Remote Execution of Arbitrary Code</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-0599" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-0599"/>
        <description>The init_request_info function in sapi/cgi/cgi_main.c in PHP before 5.2.6 does not properly consider operator precedence when calculating the length of PATH_TRANSLATED, which might allow remote attackers to execute arbitrary code via a crafted URI.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-06-30T13:13:25.000-04:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2008-07-02T17:04:32.160-04:00">DRAFT</status_change>
            <status_change date="2008-07-21T04:00:15.507-04:00">INTERIM</status_change>
            <status_change date="2008-08-11T04:00:30.486-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02342">
          <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="hpuxwsAPACHE.PHP version is less than B.2.0.59.04.2" test_ref="oval:org.mitre.oval:tst:8181"/>
            <criterion comment="hpuxwsAPACHE.PHP2 version is less than B.2.0.59.04.2" test_ref="oval:org.mitre.oval:tst:7550"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02342">
          <criteria operator="OR" comment="platforms">
            <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
            <criterion comment="HP-UX B.11.31" test_ref="oval:org.mitre.oval:tst:8260"/>
          </criteria>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="hpuxwsAPCH32.PHP version is less than B.2.0.59.04.2" test_ref="oval:org.mitre.oval:tst:7962"/>
            <criterion comment="hpuxwsAPCH32.PHP2 version is less than B.2.0.59.04.2" test_ref="oval:org.mitre.oval:tst:7265"/>
            <criterion comment="hpuxwsAPACHE.PHP version is less than B.2.0.59.04.2" test_ref="oval:org.mitre.oval:tst:8181"/>
            <criterion comment="hpuxwsAPACHE.PHP2 version is less than B.2.0.59.04.2" test_ref="oval:org.mitre.oval:tst:7550"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5605" version="1" class="vulnerability">
      <metadata>
        <title>HP-UX running HP CIFS Server (Samba), Remote Execution of Arbitrary Code</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-6015" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6015"/>
        <description>Stack-based buffer overflow in the send_mailslot function in nmbd in Samba 3.0.0 through 3.0.27a, when the "domain logons" option is enabled, allows remote attackers to execute arbitrary code via a GETDC mailslot request composed of a long GETDC string following an offset username in a SAMLOGON logon request.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-06-30T13:13:25.000-04:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2008-07-02T17:04:31.492-04:00">DRAFT</status_change>
            <status_change date="2008-07-21T04:00:18.303-04:00">INTERIM</status_change>
            <status_change date="2008-08-11T04:00:40.161-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND" comment="Criteria meets Security Bulletin HPSBUX02341">
        <criteria operator="OR" comment="platforms">
          <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
          <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
          <criterion comment="HP-UX B.11.31" test_ref="oval:org.mitre.oval:tst:8260"/>
        </criteria>
        <criteria operator="OR" comment="filesets tests">
          <criterion comment="CIFS-Server.CIFS-ADMIN version is less than A.02.03.04" test_ref="oval:org.mitre.oval:tst:8191"/>
          <criterion comment="CIFS-Server.CIFS-DOC version is less than A.02.03.04" test_ref="oval:org.mitre.oval:tst:8249"/>
          <criterion comment="CIFS-Server.CIFS-LIB version is less than A.02.03.04" test_ref="oval:org.mitre.oval:tst:7825"/>
          <criterion comment="CIFS-Server.CIFS-MAN version is less than A.02.03.04" test_ref="oval:org.mitre.oval:tst:7691"/>
          <criterion comment="CIFS-Server.CIFS-RUN version is less than A.02.03.04" test_ref="oval:org.mitre.oval:tst:7982"/>
          <criterion comment="CIFS-Server.CIFS-UTIL version is less than A.02.03.04" test_ref="oval:org.mitre.oval:tst:8125"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5643" version="1" class="vulnerability">
      <metadata>
        <title>HP-UX running HP CIFS Server (Samba), Remote Execution of Arbitrary Code</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-4572" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4572"/>
        <description>Stack-based buffer overflow in nmbd in Samba 3.0.0 through 3.0.26a, when configured as a Primary or Backup Domain controller, allows remote attackers to have an unknown impact via crafted GETDC mailslot requests, related to handling of GETDC logon server requests.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-06-30T13:13:25.000-04:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2008-07-02T17:04:31.239-04:00">DRAFT</status_change>
            <status_change date="2008-07-21T04:00:19.177-04:00">INTERIM</status_change>
            <status_change date="2008-08-11T04:00:41.242-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND" comment="Criteria meets Security Bulletin HPSBUX02341">
        <criteria operator="OR" comment="platforms">
          <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
          <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
          <criterion comment="HP-UX B.11.31" test_ref="oval:org.mitre.oval:tst:8260"/>
        </criteria>
        <criteria operator="OR" comment="filesets tests">
          <criterion comment="CIFS-Server.CIFS-ADMIN version is less than A.02.03.04" test_ref="oval:org.mitre.oval:tst:8191"/>
          <criterion comment="CIFS-Server.CIFS-DOC version is less than A.02.03.04" test_ref="oval:org.mitre.oval:tst:8249"/>
          <criterion comment="CIFS-Server.CIFS-LIB version is less than A.02.03.04" test_ref="oval:org.mitre.oval:tst:7825"/>
          <criterion comment="CIFS-Server.CIFS-MAN version is less than A.02.03.04" test_ref="oval:org.mitre.oval:tst:7691"/>
          <criterion comment="CIFS-Server.CIFS-RUN version is less than A.02.03.04" test_ref="oval:org.mitre.oval:tst:7982"/>
          <criterion comment="CIFS-Server.CIFS-UTIL version is less than A.02.03.04" test_ref="oval:org.mitre.oval:tst:8125"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5733" version="1" class="vulnerability">
      <metadata>
        <title>HP-UX running HP CIFS Server (Samba), Remote Execution of Arbitrary Code</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-1105" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1105"/>
        <description>Heap-based buffer overflow in the receive_smb_raw function in util/sock.c in Samba 3.0.0 through 3.0.29 allows remote attackers to execute arbitrary code via a crafted SMB response.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-06-30T13:13:25.000-04:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2008-07-02T17:04:30.957-04:00">DRAFT</status_change>
            <status_change date="2008-07-21T04:00:20.151-04:00">INTERIM</status_change>
            <status_change date="2008-08-11T04:00:42.899-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND" comment="Criteria meets Security Bulletin HPSBUX02341">
        <criteria operator="OR" comment="platforms">
          <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
          <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
          <criterion comment="HP-UX B.11.31" test_ref="oval:org.mitre.oval:tst:8260"/>
        </criteria>
        <criteria operator="OR" comment="filesets tests">
          <criterion comment="CIFS-Server.CIFS-ADMIN version is less than A.02.03.04" test_ref="oval:org.mitre.oval:tst:8191"/>
          <criterion comment="CIFS-Server.CIFS-DOC version is less than A.02.03.04" test_ref="oval:org.mitre.oval:tst:8249"/>
          <criterion comment="CIFS-Server.CIFS-LIB version is less than A.02.03.04" test_ref="oval:org.mitre.oval:tst:7825"/>
          <criterion comment="CIFS-Server.CIFS-MAN version is less than A.02.03.04" test_ref="oval:org.mitre.oval:tst:7691"/>
          <criterion comment="CIFS-Server.CIFS-RUN version is less than A.02.03.04" test_ref="oval:org.mitre.oval:tst:7982"/>
          <criterion comment="CIFS-Server.CIFS-UTIL version is less than A.02.03.04" test_ref="oval:org.mitre.oval:tst:8125"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5811" version="1" class="vulnerability">
      <metadata>
        <title>HP-UX running HP CIFS Server (Samba), Remote Execution of Arbitrary Code</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-5398" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5398"/>
        <description>Stack-based buffer overflow in the reply_netbios_packet function in nmbd/nmbd_packets.c in nmbd in Samba 3.0.0 through 3.0.26a, when operating as a WINS server, allows remote attackers to execute arbitrary code via crafted WINS Name Registration requests followed by a WINS Name Query request.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-06-30T13:13:25.000-04:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2008-07-02T17:04:30.472-04:00">DRAFT</status_change>
            <status_change date="2008-07-21T04:00:20.447-04:00">INTERIM</status_change>
            <status_change date="2008-08-11T04:00:44.118-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND" comment="Criteria meets Security Bulletin HPSBUX02341">
        <criteria operator="OR" comment="platforms">
          <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
          <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
          <criterion comment="HP-UX B.11.31" test_ref="oval:org.mitre.oval:tst:8260"/>
        </criteria>
        <criteria operator="OR" comment="filesets tests">
          <criterion comment="CIFS-Server.CIFS-ADMIN version is less than A.02.03.04" test_ref="oval:org.mitre.oval:tst:8191"/>
          <criterion comment="CIFS-Server.CIFS-DOC version is less than A.02.03.04" test_ref="oval:org.mitre.oval:tst:8249"/>
          <criterion comment="CIFS-Server.CIFS-LIB version is less than A.02.03.04" test_ref="oval:org.mitre.oval:tst:7825"/>
          <criterion comment="CIFS-Server.CIFS-MAN version is less than A.02.03.04" test_ref="oval:org.mitre.oval:tst:7691"/>
          <criterion comment="CIFS-Server.CIFS-RUN version is less than A.02.03.04" test_ref="oval:org.mitre.oval:tst:7982"/>
          <criterion comment="CIFS-Server.CIFS-UTIL version is less than A.02.03.04" test_ref="oval:org.mitre.oval:tst:8125"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5175" version="1" class="vulnerability">
      <metadata>
        <title>HP-UX Running dtmail, Local Execution of Arbitrary Code</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-5452" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-5452"/>
        <description>Buffer overflow in dtmail on HP Tru64 UNIX 4.0F through 5.1B and HP-UX B.11.00 through B.11.23 allows local users to execute arbitrary code via a long -a (aka attachment) argument.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-07-03T16:09:05.000-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2008-07-07T14:19:42.662-04:00">DRAFT</status_change>
            <status_change date="2008-07-28T04:00:08.637-04:00">INTERIM</status_change>
            <status_change date="2008-08-18T04:00:19.601-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02162">
          <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
          <criterion comment="CDE.CDE-RUN is installed" test_ref="oval:org.mitre.oval:tst:8213"/>
          <criterion negate="true" comment="Patch PHSS_35434 is installed" test_ref="oval:org.mitre.oval:tst:8238"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02162">
          <criterion comment="HP Release B.11.00" test_ref="oval:org.mitre.oval:tst:3571"/>
          <criterion comment="CDE.CDE-RUN is installed" test_ref="oval:org.mitre.oval:tst:8213"/>
          <criterion negate="true" comment="Patch PHSS_35433 is installed" test_ref="oval:org.mitre.oval:tst:8083"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02162">
          <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
          <criterion comment="CDE.CDE-RUN is installed" test_ref="oval:org.mitre.oval:tst:8213"/>
          <criterion negate="true" comment="Patch PHSS_35435 is installed" test_ref="oval:org.mitre.oval:tst:8202"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5239" version="1" class="vulnerability">
      <metadata>
        <title>HP-UX Running ARPA Transport, Local Denial of Service (DoS)</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-0916" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0916"/>
        <description>Unspecified vulnerability in the Address and Routing Parameter Area (ARPA) transport functionality in HP-UX B.11.11 and B.11.23 allows local users to cause an unspecified denial of service via unknown vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-07-03T16:09:05.000-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2008-07-07T14:19:42.125-04:00">DRAFT</status_change>
            <status_change date="2008-07-28T04:00:09.705-04:00">INTERIM</status_change>
            <status_change date="2008-08-18T04:00:22.137-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02192">
          <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="Networking.NET-KRN is installed" test_ref="oval:org.mitre.oval:tst:8321"/>
            <criterion comment="Networking.NET-RUN is installed" test_ref="oval:org.mitre.oval:tst:8305"/>
            <criterion comment="Networking.NET2-KRN is installed" test_ref="oval:org.mitre.oval:tst:7924"/>
            <criterion comment="Networking.NMS2-KRN is installed" test_ref="oval:org.mitre.oval:tst:7807"/>
            <criterion comment="OS-Core.CORE2-KRN is installed" test_ref="oval:org.mitre.oval:tst:8276"/>
          </criteria>
          <criterion negate="true" comment="Patch PHNE_35183 is installed" test_ref="oval:org.mitre.oval:tst:8051"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02192">
          <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="Networking.NET-KRN is installed" test_ref="oval:org.mitre.oval:tst:8321"/>
            <criterion comment="Networking.NET-RUN is installed" test_ref="oval:org.mitre.oval:tst:8305"/>
            <criterion comment="Networking.NET2-KRN is installed" test_ref="oval:org.mitre.oval:tst:7924"/>
            <criterion comment="Networking.NMS2-KRN is installed" test_ref="oval:org.mitre.oval:tst:7807"/>
            <criterion comment="OS-Core.CORE2-KRN is installed" test_ref="oval:org.mitre.oval:tst:8276"/>
          </criteria>
          <criterion negate="true" comment="Patch PHNE_35182 is installed" test_ref="oval:org.mitre.oval:tst:7701"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5289" version="1" class="vulnerability">
      <metadata>
        <title>HP-UX Running ftp, Remote Denial of Service (DoS)</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-0713" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-0713"/>
        <description>Unspecified vulnerability in the FTP server for HP-UX B.11.11, B.11.23, and B.11.31 allows remote authenticated users to cause a denial of service (FTP server outage) via unknown attack vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-07-03T16:09:03.000-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2008-07-07T14:19:35.490-04:00">DRAFT</status_change>
            <status_change date="2008-07-28T04:00:10.461-04:00">INTERIM</status_change>
            <status_change date="2008-08-18T04:00:23.987-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02334">
          <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
          <criterion comment="InternetSrvcs.INETSVCS-RUN is installed" test_ref="oval:org.mitre.oval:tst:8266"/>
          <criterion negate="true" comment="Patch PHNE_36192 is installed" test_ref="oval:org.mitre.oval:tst:8114"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02334">
          <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
          <criterion comment="WUFTP-26.INETSVCS-FTP version is less than B.11.11.01.011" test_ref="oval:org.mitre.oval:tst:8075"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02334">
          <criterion comment="HP-UX B.11.31" test_ref="oval:org.mitre.oval:tst:8138"/>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="FTP.FTP-AUX version is less than C.2.6.1.3.0" test_ref="oval:org.mitre.oval:tst:7536"/>
            <criterion comment="FTP.FTP-RUN version is less than C.2.6.1.3.0" test_ref="oval:org.mitre.oval:tst:7995"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02334">
          <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
          <criterion comment="InternetSrvcs.INETSVCS2-RUN is installed" test_ref="oval:org.mitre.oval:tst:7851"/>
          <criterion negate="true" comment="Patch PHNE_36193 is installed" test_ref="oval:org.mitre.oval:tst:8265"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5427" version="1" class="vulnerability">
      <metadata>
        <title>HP-UX Running ARPA Transport Software, Local Denial of Service (DoS)</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-4795" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-4795"/>
        <description>Unspecified vulnerability in the Address and Routing Parameter Area (ARPA) transport software in HP-UX B.11.11 and B.11.23 before 20060912 allows local users to cause a denial of service via unspecified vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-07-03T16:09:06.000-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2008-07-07T14:19:45.868-04:00">DRAFT</status_change>
            <status_change date="2008-07-28T04:00:13.163-04:00">INTERIM</status_change>
            <status_change date="2008-08-18T04:00:28.257-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02151">
          <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
          <criterion comment="OS-Core.CORE2-KRN is installed" test_ref="oval:org.mitre.oval:tst:8276"/>
          <criterion negate="true" comment="Patch PHNE_34672 is installed" test_ref="oval:org.mitre.oval:tst:8073"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02151">
          <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
          <criterion comment="OS-Core.CORE2-KRN is installed" test_ref="oval:org.mitre.oval:tst:8276"/>
          <criterion negate="true" comment="Patch PHNE_34671 is installed" test_ref="oval:org.mitre.oval:tst:7849"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5500" version="1" class="vulnerability">
      <metadata>
        <title>HP-UX Running the LP Subsystem, remote Denial of Service (DoS)</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-4188" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-4188"/>
        <description>Unspecified vulnerability in the LP subsystem in HP-UX B.11.00, B.11.04, B.11.11, and B.11.23 allows remote attackers to cause a denial of service via unknown vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-07-03T16:09:06.000-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2008-07-07T14:19:46.422-04:00">DRAFT</status_change>
            <status_change date="2008-07-28T04:00:13.456-04:00">INTERIM</status_change>
            <status_change date="2008-08-18T04:00:35.268-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02139">
          <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
          <criterion comment="InternetSrvcs.INETSVCS-RUN is installed" test_ref="oval:org.mitre.oval:tst:8266"/>
          <criterion negate="true" comment="Patch PHNE_33791 is installed" test_ref="oval:org.mitre.oval:tst:8244"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02139">
          <criterion comment="HP Release B.11.04" test_ref="oval:org.mitre.oval:tst:3294"/>
          <criterion comment="InternetSrvcs.INETSVCS-RUN is installed" test_ref="oval:org.mitre.oval:tst:8266"/>
          <criterion negate="true" comment="Patch PHNE_35146 is installed" test_ref="oval:org.mitre.oval:tst:7737"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02139">
          <criterion comment="HP Release B.11.00" test_ref="oval:org.mitre.oval:tst:3571"/>
          <criterion comment="InternetSrvcs.INETSVCS-RUN is installed" test_ref="oval:org.mitre.oval:tst:8266"/>
          <criterion negate="true" comment="Patch PHNE_33790 is installed" test_ref="oval:org.mitre.oval:tst:8241"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02139">
          <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
          <criterion comment="InternetSrvcs.INETSVCS2-RUN is installed" test_ref="oval:org.mitre.oval:tst:7851"/>
          <criterion negate="true" comment="Patch PHNE_33792 is installed" test_ref="oval:org.mitre.oval:tst:8182"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5548" version="1" class="vulnerability">
      <metadata>
        <title>HP-UX Running Aries PA Emulator, Local Unauthorized Access</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-5946" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5946"/>
        <description>Unspecified vulnerability in the Aries PA-RISC emulator on HP-UX B.11.23 and B.11.31 on the IA-64 platform allows local users to obtain unspecified access.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-07-03T16:09:04.000-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2008-07-07T14:19:39.256-04:00">DRAFT</status_change>
            <status_change date="2008-07-28T04:00:14.102-04:00">INTERIM</status_change>
            <status_change date="2008-08-18T04:00:37.988-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02285">
          <criterion comment="HP-UX B.11.31" test_ref="oval:org.mitre.oval:tst:8138"/>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="OS-Core.CORE2-64SLIB is installed" test_ref="oval:org.mitre.oval:tst:8272"/>
            <criterion comment="OS-Core.CORE2-SHLIBS is installed" test_ref="oval:org.mitre.oval:tst:8319"/>
          </criteria>
          <criterion negate="true" comment="Patch PHSS_36311 is installed" test_ref="oval:org.mitre.oval:tst:8246"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02285">
          <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="OS-Core.CORE2-64SLIB is installed" test_ref="oval:org.mitre.oval:tst:8272"/>
            <criterion comment="OS-Core.CORE2-SHLIBS is installed" test_ref="oval:org.mitre.oval:tst:8319"/>
          </criteria>
          <criterion negate="true" comment="Patch PHSS_35528 is installed" test_ref="oval:org.mitre.oval:tst:7931"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5553" version="1" class="vulnerability">
      <metadata>
        <title>HP-UX in Trusted mode, Local Denial of Service (DoS)</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-4187" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-4187"/>
        <description>Unspecified vulnerability in HP-UX B.11.00, B.11.11 and B.11.23, when running in trusted mode, allows local users to cause a denial of service via unspecified vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-07-03T16:09:06.000-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2008-07-07T14:19:46.897-04:00">DRAFT</status_change>
            <status_change date="2008-07-28T04:00:14.404-04:00">INTERIM</status_change>
            <status_change date="2008-08-18T04:00:38.471-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02141">
          <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
          <criterion comment="OS-Core.CORE-SHLIBS is installed" test_ref="oval:org.mitre.oval:tst:8402"/>
          <criterion negate="true" comment="Patch PHCO_34214 is installed" test_ref="oval:org.mitre.oval:tst:8176"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02141">
          <criterion comment="HP Release B.11.00" test_ref="oval:org.mitre.oval:tst:3571"/>
          <criterion comment="OS-Core.CORE-SHLIBS is installed" test_ref="oval:org.mitre.oval:tst:8402"/>
          <criterion negate="true" comment="Patch PHCO_34806 is installed" test_ref="oval:org.mitre.oval:tst:8283"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02141">
          <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="OS-Core.CORE2-64SLIB is installed" test_ref="oval:org.mitre.oval:tst:8272"/>
            <criterion comment="OS-Core.CORE2-SHLIBS is installed" test_ref="oval:org.mitre.oval:tst:8319"/>
          </criteria>
          <criterion negate="true" comment="Patch PHCO_34215 is installed" test_ref="oval:org.mitre.oval:tst:8140"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5558" version="1" class="vulnerability">
      <metadata>
        <title>HP-UX Running useradd(1M), Local Unauthorized Access</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-1660" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1660"/>
        <description>Unspecified vulnerability in useradd on HP-UX B.11.11, B.11.23, and B.11.31 allows local users to access arbitrary files and directories via unspecified vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-07-03T16:09:03.000-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2008-07-07T14:19:33.870-04:00">DRAFT</status_change>
            <status_change date="2008-07-28T04:00:14.735-04:00">INTERIM</status_change>
            <status_change date="2008-08-18T04:00:38.872-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02335">
          <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="OS-Core.ADMN-ENG-A-MAN is installed" test_ref="oval:org.mitre.oval:tst:8060"/>
            <criterion comment="OS-Core.SYS-ADMIN is installed" test_ref="oval:org.mitre.oval:tst:7631"/>
          </criteria>
          <criterion negate="true" comment="Patch PHCO_37290 is installed" test_ref="oval:org.mitre.oval:tst:8219"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02335">
          <criterion comment="HP-UX B.11.31" test_ref="oval:org.mitre.oval:tst:8138"/>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="OS-Core.ADMN-ENG-A-MAN is installed" test_ref="oval:org.mitre.oval:tst:8060"/>
            <criterion comment="OS-Core.SYS2-ADMIN is installed" test_ref="oval:org.mitre.oval:tst:7285"/>
          </criteria>
          <criterion negate="true" comment="Patch PHCO_36953 is installed" test_ref="oval:org.mitre.oval:tst:8247"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02335">
          <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="OS-Core.ADMN-ENG-A-MAN is installed" test_ref="oval:org.mitre.oval:tst:8060"/>
            <criterion comment="OS-Core.SYS-ADMIN is installed" test_ref="oval:org.mitre.oval:tst:7631"/>
            <criterion comment="OS-Core.SYS2-ADMIN is installed" test_ref="oval:org.mitre.oval:tst:7285"/>
          </criteria>
          <criterion negate="true" comment="Patch PHCO_37291 is installed" test_ref="oval:org.mitre.oval:tst:7999"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5624" version="1" class="vulnerability">
      <metadata>
        <title>HP-UX Running ARPA Transport, Local Denial of Service (DoS)</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-1994" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1994"/>
        <description>Unspecified vulnerability in the Address and Routing Parameter Area (ARPA) transport functionality in HP-UX B.11.00 allows local users to cause a denial of service via unknown vectors.  NOTE: due to lack of vendor details, it is not clear whether this is the same as CVE-2007-0916.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-07-03T16:09:04.000-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2008-07-07T14:19:41.758-04:00">DRAFT</status_change>
            <status_change date="2008-07-28T04:00:17.924-04:00">INTERIM</status_change>
            <status_change date="2008-08-18T04:00:44.049-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND" comment="Criteria meets Security Bulletin HPSBUX02205">
        <criterion comment="HP Release B.11.00" test_ref="oval:org.mitre.oval:tst:3571"/>
        <criteria operator="OR" comment="filesets tests">
          <criterion comment="OS-Core.CORE2-KRN is installed" test_ref="oval:org.mitre.oval:tst:8276"/>
          <criterion comment="Networking.NET-KRN is installed" test_ref="oval:org.mitre.oval:tst:8321"/>
          <criterion comment="Networking.NET-PRG is installed" test_ref="oval:org.mitre.oval:tst:7546"/>
          <criterion comment="Networking.NET-RUN is installed" test_ref="oval:org.mitre.oval:tst:8305"/>
          <criterion comment="Networking.NET2-KRN is installed" test_ref="oval:org.mitre.oval:tst:7924"/>
          <criterion comment="Networking.NMS2-KRN is installed" test_ref="oval:org.mitre.oval:tst:7807"/>
        </criteria>
        <criterion negate="true" comment="Patch PHNE_35729 is installed" test_ref="oval:org.mitre.oval:tst:7730"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5634" version="1" class="vulnerability">
      <metadata>
        <title>HP-UX CIFS Server (Samba) Local Unauthorized Access, Elevated Privileges</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-5091" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-5091"/>
        <description>Unspecified vulnerability in HP-UX B.11.11 and B.11.23 CIFS Server (Samba) allows local users to gain privileges or obtain "unauthorized access" via unspecified vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-07-03T16:09:05.000-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2008-07-07T14:19:43.569-04:00">DRAFT</status_change>
            <status_change date="2008-07-28T04:00:18.821-04:00">INTERIM</status_change>
            <status_change date="2008-08-18T04:00:44.611-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND" comment="Criteria meets Security Bulletin HPSBUX02155">
        <criteria operator="OR" comment="platforms">
          <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
          <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
        </criteria>
        <criteria operator="OR" comment="filesets tests">
          <criterion comment="CIFS-Server.CIFS-RUN version is less than A.02.03" test_ref="oval:org.mitre.oval:tst:8127"/>
          <criterion comment="CIFS-Server.CIFS-UTIL version is less than A.02.03" test_ref="oval:org.mitre.oval:tst:8339"/>
          <criterion comment="CIFS-Server.CIFS-ADMIN version is less than A.02.03" test_ref="oval:org.mitre.oval:tst:8281"/>
          <criterion comment="CIFS-Server.CIFS-LIB version is less than A.02.03" test_ref="oval:org.mitre.oval:tst:8331"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5658" version="1" class="vulnerability">
      <metadata>
        <title>HP-UX Running Ignite-UX Server, Remote Unauthorized Access and Privilege Elevation</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-5151" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-5151"/>
        <description>Unspecified vulnerability in HP Ignite-UX server before C.6.9.150 for HP-UX B.11.00, B.11.11, and B.11.23 allows remote attackers to "gain root access" via unspecified vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-07-03T16:09:05.000-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2008-07-07T14:19:43.014-04:00">DRAFT</status_change>
            <status_change date="2008-07-28T04:00:20.512-04:00">INTERIM</status_change>
            <status_change date="2008-08-18T04:00:45.901-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND" comment="Criteria meets Security Bulletin HPSBUX02157">
        <criteria operator="OR" comment="platforms">
          <criterion comment="HP Release B.11.00" test_ref="oval:org.mitre.oval:tst:3571"/>
          <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
          <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
        </criteria>
        <criterion comment="Ignite-UX.BOOT-SERVICES version is less than C.6.9.150" test_ref="oval:org.mitre.oval:tst:8370"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5676" version="1" class="vulnerability">
      <metadata>
        <title>HP-UX mkdir(1) Local Unauthorized Access</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-3335" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-3335"/>
        <description>Unspecified vulnerability in mkdir in HP-UX B.11.00, B.11.04, B.11.11, and B.11.23 allows local users to gain privileges via unknown attack vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-07-03T16:09:06.000-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2008-07-07T14:19:47.456-04:00">DRAFT</status_change>
            <status_change date="2008-07-28T04:00:21.089-04:00">INTERIM</status_change>
            <status_change date="2008-08-18T04:00:48.034-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02128">
          <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
          <criterion comment="OS-Core.UX-CORE is installed" test_ref="oval:org.mitre.oval:tst:8352"/>
          <criterion negate="true" comment="Patch PHCO_32036 is installed" test_ref="oval:org.mitre.oval:tst:8390"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02128">
          <criterion comment="HP Release B.11.04" test_ref="oval:org.mitre.oval:tst:3294"/>
          <criterion comment="OS-Core.UX-CORE is installed" test_ref="oval:org.mitre.oval:tst:8352"/>
          <criterion negate="true" comment="Patch PHCO_35040 is installed" test_ref="oval:org.mitre.oval:tst:8159"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02128">
          <criterion comment="HP Release B.11.00" test_ref="oval:org.mitre.oval:tst:3571"/>
          <criterion comment="OS-Core.UX-CORE is installed" test_ref="oval:org.mitre.oval:tst:8352"/>
          <criterion negate="true" comment="Patch PHCO_34533 is installed" test_ref="oval:org.mitre.oval:tst:8042"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02128">
          <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
          <criterion comment="OS-Core.UX2-CORE is installed" test_ref="oval:org.mitre.oval:tst:8363"/>
          <criterion negate="true" comment="Patch PHCO_34151 is installed" test_ref="oval:org.mitre.oval:tst:8387"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5710" version="1" class="vulnerability">
      <metadata>
        <title>HP-UX Running DCE, Remote Denial of Service (DoS)</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-6195" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6195"/>
        <description>Buffer overflow in the sw_rpc_agent_init function in swagentd in Software Distributor (SD), and possibly other DCE applications, in HP HP-UX B.11.11 and B.11.23 allows remote attackers to execute arbitrary code or cause a denial of service via malformed arguments in an opcode 0x04 DCE RPC request.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-07-03T16:09:04.000-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2008-07-07T14:19:38.573-04:00">DRAFT</status_change>
            <status_change date="2008-07-28T04:00:23.352-04:00">INTERIM</status_change>
            <status_change date="2008-08-18T04:00:51.007-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02294">
          <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="DCE-Core.DCEC-ENG-A-MAN is installed" test_ref="oval:org.mitre.oval:tst:7422"/>
            <criterion comment="DCE-Core.DCE-CORE-DTS is installed" test_ref="oval:org.mitre.oval:tst:7983"/>
            <criterion comment="DCE-Core.DCE-CORE-RUN is installed" test_ref="oval:org.mitre.oval:tst:8210"/>
            <criterion comment="DCE-Core.DCE-CORE-SHLIB is installed" test_ref="oval:org.mitre.oval:tst:7341"/>
            <criterion comment="DCE-Core.DCE-COR-64SLIB is installed" test_ref="oval:org.mitre.oval:tst:8194"/>
          </criteria>
          <criterion negate="true" comment="Patch PHSS_36004 is installed" test_ref="oval:org.mitre.oval:tst:8328"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02294">
          <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="DCE-CoreTools.DCE-BPRG is installed" test_ref="oval:org.mitre.oval:tst:8087"/>
            <criterion comment="DCE-Core.DCE-CORE-DTS is installed" test_ref="oval:org.mitre.oval:tst:7983"/>
            <criterion comment="DCE-Core.DCE-CORE-RUN is installed" test_ref="oval:org.mitre.oval:tst:8210"/>
            <criterion comment="DCE-Core.DCE-COR-PA-RUN is installed" test_ref="oval:org.mitre.oval:tst:8214"/>
            <criterion comment="DCE-Core.DCE-COR-IA-RUN is installed" test_ref="oval:org.mitre.oval:tst:8223"/>
            <criterion comment="DCE-Core.DCE-COR-64SLIB is installed" test_ref="oval:org.mitre.oval:tst:8194"/>
            <criterion comment="DCE-Core.DCE-CORE-SHLIB is installed" test_ref="oval:org.mitre.oval:tst:7341"/>
            <criterion comment="DCE-Core.DCE-IA64-SHLIB is installed" test_ref="oval:org.mitre.oval:tst:8286"/>
            <criterion comment="DCE-Core.DCEC-ENG-A-MAN is installed" test_ref="oval:org.mitre.oval:tst:7422"/>
          </criteria>
          <criterion negate="true" comment="Patch PHSS_36005 is installed" test_ref="oval:org.mitre.oval:tst:8134"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5734" version="1" class="vulnerability">
      <metadata>
        <title>HP-UX Running rpc.yppasswdd, Remote Denial of Service (DoS)</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-6419" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6419"/>
        <description>Unspecified vulnerability in rpc.yppasswdd in HP HP-UX B.11.11, B.11.23, and B.11.31 allows remote attackers to cause a denial of service (daemon crash) via unspecified vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-07-03T16:09:04.000-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2008-07-07T14:19:37.367-04:00">DRAFT</status_change>
            <status_change date="2008-07-28T04:00:24.521-04:00">INTERIM</status_change>
            <status_change date="2008-08-18T04:00:53.468-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02295">
          <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="NFS.NISPLUS-CORE is installed" test_ref="oval:org.mitre.oval:tst:7923"/>
            <criterion comment="NFS.NFS-SHLIBS is installed" test_ref="oval:org.mitre.oval:tst:8171"/>
            <criterion comment="NFS.NIS-CLIENT is installed" test_ref="oval:org.mitre.oval:tst:8102"/>
            <criterion comment="OS-Core.CORE-ENG-A-MAN is installed" test_ref="oval:org.mitre.oval:tst:7936"/>
            <criterion comment="NFS.NFS-KRN is installed" test_ref="oval:org.mitre.oval:tst:8257"/>
            <criterion comment="NFS.KEY-CORE is installed" test_ref="oval:org.mitre.oval:tst:7850"/>
            <criterion comment="NFS.NFS-64ALIB is installed" test_ref="oval:org.mitre.oval:tst:8231"/>
            <criterion comment="NFS.NFS-64SLIB is installed" test_ref="oval:org.mitre.oval:tst:8172"/>
            <criterion comment="NFS.NFS-CLIENT is installed" test_ref="oval:org.mitre.oval:tst:7618"/>
            <criterion comment="NFS.NFS-CORE is installed" test_ref="oval:org.mitre.oval:tst:8269"/>
            <criterion comment="NFS.NFS-ENG-A-MAN is installed" test_ref="oval:org.mitre.oval:tst:8228"/>
            <criterion comment="NFS.NIS-CORE is installed" test_ref="oval:org.mitre.oval:tst:8263"/>
            <criterion comment="NFS.NFS-PRG is installed" test_ref="oval:org.mitre.oval:tst:8026"/>
            <criterion comment="NFS.NFS-SERVER is installed" test_ref="oval:org.mitre.oval:tst:8240"/>
            <criterion comment="NFS.NIS-SERVER is installed" test_ref="oval:org.mitre.oval:tst:8130"/>
          </criteria>
          <criterion negate="true" comment="Patch PHNE_36168 is installed" test_ref="oval:org.mitre.oval:tst:7312"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02295">
          <criterion comment="HP-UX B.11.31" test_ref="oval:org.mitre.oval:tst:8138"/>
          <criterion comment="NFS.NIS2-SERVER is installed" test_ref="oval:org.mitre.oval:tst:8304"/>
          <criterion negate="true" comment="Patch PHNE_36449 is installed" test_ref="oval:org.mitre.oval:tst:8160"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02295">
          <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="NFS.NFS-64SLIB is installed" test_ref="oval:org.mitre.oval:tst:8172"/>
            <criterion comment="NFS.NIS2-CLIENT is installed" test_ref="oval:org.mitre.oval:tst:7323"/>
            <criterion comment="NFS.NFS-ENG-A-MAN is installed" test_ref="oval:org.mitre.oval:tst:8228"/>
            <criterion comment="NFS.NISPLUS-CORE is installed" test_ref="oval:org.mitre.oval:tst:7923"/>
            <criterion comment="NFS.KEY-CORE is installed" test_ref="oval:org.mitre.oval:tst:7850"/>
            <criterion comment="NFS.NFS-64SLIB is installed" test_ref="oval:org.mitre.oval:tst:8172"/>
            <criterion comment="NFS.NIS2-CLIENT is installed" test_ref="oval:org.mitre.oval:tst:7323"/>
            <criterion comment="NFS.NIS2-CORE is installed" test_ref="oval:org.mitre.oval:tst:8316"/>
            <criterion comment="NFS.NIS2-SERVER is installed" test_ref="oval:org.mitre.oval:tst:8304"/>
            <criterion comment="NFS.NIS2-CORE is installed" test_ref="oval:org.mitre.oval:tst:8316"/>
            <criterion comment="NFS.KEY-CORE is installed" test_ref="oval:org.mitre.oval:tst:7850"/>
            <criterion comment="NFS.NIS2-SERVER is installed" test_ref="oval:org.mitre.oval:tst:8304"/>
          </criteria>
          <criterion negate="true" comment="Patch PHNE_36260 is installed" test_ref="oval:org.mitre.oval:tst:7570"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5773" version="1" class="vulnerability">
      <metadata>
        <title>HP System Management Homepage (SMH) for HP-UX, Remote Cross Site Scripting (XSS)</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-5302" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5302"/>
        <description>Multiple cross-site scripting (XSS) vulnerabilities in HP System Management Homepage (SMH) in HP-UX B.11.11, B.11.23, and B.11.31, and SMH before 2.1.10 for Linux and Windows, allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-07-03T16:09:04.000-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2008-07-07T14:19:39.840-04:00">DRAFT</status_change>
            <status_change date="2008-07-28T04:00:26.590-04:00">INTERIM</status_change>
            <status_change date="2008-08-18T04:00:56.797-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBMA02274">
          <criteria operator="OR" comment="platforms">
            <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
            <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
            <criterion comment="HP-UX B.11.31" test_ref="oval:org.mitre.oval:tst:8138"/>
          </criteria>
          <criterion comment="SysMgmtHomepage.SMH-RUN version is less than A.2.2.6.2" test_ref="oval:org.mitre.oval:tst:8169"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBMA02274">
          <criterion comment="HP-UX B.11.31" test_ref="oval:org.mitre.oval:tst:8138"/>
          <criterion comment="SysMgmtHomepage.SMH-RUN is installed" test_ref="oval:org.mitre.oval:tst:7642"/>
          <criterion negate="true" comment="Patch PHSS_36871 is installed" test_ref="oval:org.mitre.oval:tst:8335"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBMA02274">
          <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
          <criterion comment="SysMgmtHomepage.SMH-RUN is installed" test_ref="oval:org.mitre.oval:tst:7642"/>
          <criterion negate="true" comment="Patch PHSS_36869 is installed" test_ref="oval:org.mitre.oval:tst:8094"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBMA02274">
          <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
          <criterion comment="SysMgmtHomepage.SMH-RUN is installed" test_ref="oval:org.mitre.oval:tst:7642"/>
          <criterion negate="true" comment="Patch PHSS_36870 is installed" test_ref="oval:org.mitre.oval:tst:8208"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5779" version="1" class="vulnerability">
      <metadata>
        <title>HP-UX Running logins(1M), Remote Unauthorized Access</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-5008" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5008"/>
        <description>The logins command in HP-UX B.11.31, B.11.23, and B.11.11 does not correctly report password status, which allows remote attackers to obtain privileges when certain "password issues" are not detected.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-07-03T16:09:04.000-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2008-07-07T14:19:40.397-04:00">DRAFT</status_change>
            <status_change date="2008-07-28T04:00:27.092-04:00">INTERIM</status_change>
            <status_change date="2008-08-18T04:00:57.487-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02259">
          <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
          <criterion comment="SOE.SOE is installed" test_ref="oval:org.mitre.oval:tst:7374"/>
          <criterion negate="true" comment="Patch PHCO_36809 is installed" test_ref="oval:org.mitre.oval:tst:8204"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02259">
          <criterion comment="HP-UX B.11.31" test_ref="oval:org.mitre.oval:tst:8138"/>
          <criterion comment="SOE.SOE is installed" test_ref="oval:org.mitre.oval:tst:7374"/>
          <criterion negate="true" comment="Patch PHCO_36003 is installed" test_ref="oval:org.mitre.oval:tst:8254"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02259">
          <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
          <criterion comment="SOE.SOE is installed" test_ref="oval:org.mitre.oval:tst:7374"/>
          <criterion negate="true" comment="Patch PHCO_36808 is installed" test_ref="oval:org.mitre.oval:tst:8264"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:4897" version="1" class="vulnerability">
      <metadata>
        <title>HP-UX LP subsystem, Local Denial of Service (DoS)</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-1461" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-1461"/>
        <description>Buffer overflow in rwrite for HP-UX 11.0 could allow local users to execute arbitrary code via a long argument.  NOTE: the vendor was unable to reproduce the problem on a system that had been patched for an lp vulnerability (CVE-2002-1473).</description>
        <oval_repository>
          <dates>
            <submitted date="2008-07-08T17:01:37.000-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2008-07-14T10:52:30.293-04:00">DRAFT</status_change>
            <status_change date="2008-08-04T04:00:11.587-04:00">INTERIM</status_change>
            <status_change date="2008-08-25T04:00:05.975-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX00213">
          <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
          <criterion comment="PrinterMgmt.LP-SPOOL is installed" test_ref="oval:org.mitre.oval:tst:8549"/>
          <criterion negate="true" comment="Patch PHCO_27020 is installed" test_ref="oval:org.mitre.oval:tst:8217"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX00213">
          <criterion comment="HP Release B.11.00" test_ref="oval:org.mitre.oval:tst:3571"/>
          <criterion comment="PrinterMgmt.LP-SPOOL is installed" test_ref="oval:org.mitre.oval:tst:8549"/>
          <criterion negate="true" comment="Patch PHCO_27132 is installed" test_ref="oval:org.mitre.oval:tst:8439"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:4959" version="1" class="vulnerability">
      <metadata>
        <title>HP-UX running xntpd, Remote Denial of Service (DoS)</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-2262" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-2262"/>
        <description>Unspecified vulnerability in xntpd of HP-UX 10.20 through 11.11 allows remote attackers to cause a denial of service (hang) via unknown attack vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-07-09T16:48:33.000-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2008-07-14T10:52:29.634-04:00">DRAFT</status_change>
            <status_change date="2008-08-04T04:00:11.831-04:00">INTERIM</status_change>
            <status_change date="2008-08-25T04:00:06.836-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX00232">
          <criterion comment="HP Release B.11.04" test_ref="oval:org.mitre.oval:tst:3294"/>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="InternetSrvcs.INETSVCS-BOOT is installed" test_ref="oval:org.mitre.oval:tst:7640"/>
            <criterion comment="InternetSrvcs.INET-ENG-A-MAN is installed" test_ref="oval:org.mitre.oval:tst:8303"/>
          </criteria>
          <criterion negate="true" comment="Patch PHNE_27442 is installed" test_ref="oval:org.mitre.oval:tst:8525"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX00232">
          <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
          <criterion comment="InternetSrvcs.INETSVCS-BOOT is installed" test_ref="oval:org.mitre.oval:tst:7640"/>
          <criterion negate="true" comment="Patch PHNE_24512 is installed" test_ref="oval:org.mitre.oval:tst:8466"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX00232">
          <criterion comment="HP Release B.11.00" test_ref="oval:org.mitre.oval:tst:3571"/>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="InternetSrvcs.INETSVCS-BOOT is installed" test_ref="oval:org.mitre.oval:tst:7640"/>
            <criterion comment="InternetSrvcs.INET-ENG-A-MAN is installed" test_ref="oval:org.mitre.oval:tst:8303"/>
          </criteria>
          <criterion negate="true" comment="Patch PHNE_27223 is installed" test_ref="oval:org.mitre.oval:tst:8615"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5035" version="1" class="vulnerability">
      <metadata>
        <title>HP-UX Running Software Distributor Local Elevation of Privilege</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-5557" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-5557"/>
        <description>Stack-based buffer overflow in the (1) swpackage and (2) swmodify commands in HP-UX B.11.11 and possibly other versions allows local users to execute arbitrary code via a long -S argument.  NOTE: this might be a duplicate of CVE-2006-2574, but the details relating to CVE-2006-2574 are too vague to be certain.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-07-08T17:01:37.000-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2008-07-14T10:52:29.048-04:00">DRAFT</status_change>
            <status_change date="2008-08-04T04:00:12.110-04:00">INTERIM</status_change>
            <status_change date="2008-08-25T04:00:07.252-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02114">
          <criterion comment="HP Release B.11.04" test_ref="oval:org.mitre.oval:tst:3294"/>
          <criterion comment="SW-DIST.SD-CMDS is installed" test_ref="oval:org.mitre.oval:tst:8300"/>
          <criterion negate="true" comment="Patch PHCO_34814 is installed" test_ref="oval:org.mitre.oval:tst:8280"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02114">
          <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
          <criterion comment="SW-DIST.SD-CMDS version is less than B.11.23.0606.045" test_ref="oval:org.mitre.oval:tst:8496"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02114">
          <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
          <criterion comment="SW-DIST.SD-CMDS is installed" test_ref="oval:org.mitre.oval:tst:8300"/>
          <criterion negate="true" comment="Patch PHCO_34539 is installed" test_ref="oval:org.mitre.oval:tst:8186"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02114">
          <criterion comment="HP Release B.11.00" test_ref="oval:org.mitre.oval:tst:3571"/>
          <criterion comment="SW-DIST.SD-CMDS is installed" test_ref="oval:org.mitre.oval:tst:8300"/>
          <criterion negate="true" comment="Patch PHCO_34568 is installed" test_ref="oval:org.mitre.oval:tst:7611"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5052" version="1" class="vulnerability">
      <metadata>
        <title>The Audio Security File is world writable.</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2000-0083" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2000-0083"/>
        <description>HP asecure creates the Audio Security File audio.sec with insecure permissions, which allows local users to cause a denial of service or gain additional privileges.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-07-11T14:41:52.000-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2008-07-15T15:26:16.488-04:00">DRAFT</status_change>
            <status_change date="2008-08-04T04:00:12.342-04:00">INTERIM</status_change>
            <status_change date="2008-08-25T04:00:07.692-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND" comment="Criteria meets Security Bulletin HPSBUX0001-109">
        <criterion comment="HP Release B.11.00" test_ref="oval:org.mitre.oval:tst:3571"/>
        <criterion negate="true" comment="Patch PHSS_24608 is installed" test_ref="oval:org.mitre.oval:tst:7774"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5146" version="1" class="vulnerability">
      <metadata>
        <title>HP-UX Running Partition Manager parmgr (1M), Remote Unauthorized Access</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0951" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0951"/>
        <description>Partition Manager (parmgr) in HP-UX B.11.23 does not properly validate certificates that are provided by the cimserver, which allows attackers to obtain sensitive data or gain privileges.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-07-09T16:48:33.000-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2008-07-14T10:52:28.878-04:00">DRAFT</status_change>
            <status_change date="2008-08-04T04:00:12.522-04:00">INTERIM</status_change>
            <status_change date="2008-08-25T04:00:07.968-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND" comment="Criteria meets Security Bulletin HPSBUX0029">
        <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
        <criteria operator="OR" comment="filesets tests">
          <criterion comment="PartitionManager.PARMGR-RUN version is less than B.11.23.02.00" test_ref="oval:org.mitre.oval:tst:8572"/>
          <criterion comment="PartitionManager.PARMGR-HELP version is less than B.11.23.02.00" test_ref="oval:org.mitre.oval:tst:8595"/>
          <criterion comment="PartitionManager.PARMGR-MAN version is less than B.11.23.02.00" test_ref="oval:org.mitre.oval:tst:8477"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5194" version="1" class="vulnerability">
      <metadata>
        <title>the top(1) command has a security defect.</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2001-0105" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-0105"/>
        <description>Vulnerability in top in HP-UX 11.04 and earlier allows local users to overwrite files owned by the "sys" group.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-07-11T14:41:52.000-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2008-07-15T15:26:13.533-04:00">DRAFT</status_change>
            <status_change date="2008-08-04T04:00:12.952-04:00">INTERIM</status_change>
            <status_change date="2008-08-25T04:00:08.255-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin  HPSBUX0012-134">
          <criterion comment="HP Release B.11.04" test_ref="oval:org.mitre.oval:tst:3294"/>
          <criterion negate="true" comment="Patch PHCO_22921 is installed" test_ref="oval:org.mitre.oval:tst:8679"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin  HPSBUX0012-134">
          <criterion comment="HP Release B.11.00" test_ref="oval:org.mitre.oval:tst:3571"/>
          <criterion negate="true" comment="Patch PHCO_22686 is installed" test_ref="oval:org.mitre.oval:tst:8640"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5243" version="1" class="vulnerability">
      <metadata>
        <title>HP-UX Running ARPA Transport, Remote Denial of Service (DoS)</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-4125" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4125"/>
        <description>Unspecified vulnerability in the Address and Routing Parameter Area (ARPA) transport functionality in HP-UX B.11.11, B.11.23, and B.11.31 allows remote attackers to cause an unspecified denial of service via unknown vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-07-08T17:01:37.000-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2008-07-14T10:52:27.892-04:00">DRAFT</status_change>
            <status_change date="2008-08-04T04:00:14.216-04:00">INTERIM</status_change>
            <status_change date="2008-08-25T04:00:08.580-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02248">
          <criterion comment="HP-UX B.11.31" test_ref="oval:org.mitre.oval:tst:8260"/>
          <criterion comment="Networking.NET2-KRN is installed" test_ref="oval:org.mitre.oval:tst:8232"/>
          <criterion negate="true" comment="Patch PHNE_35352 is installed" test_ref="oval:org.mitre.oval:tst:8455"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02248">
          <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
          <criterion comment="Networking.NET2-KRN is installed" test_ref="oval:org.mitre.oval:tst:8232"/>
          <criterion negate="true" comment="Patch PHNE_35351 is installed" test_ref="oval:org.mitre.oval:tst:8399"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02248">
          <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
          <criterion comment="Networking.NET2-KRN is installed" test_ref="oval:org.mitre.oval:tst:8232"/>
          <criterion negate="true" comment="Patch PHNE_35766 is installed" test_ref="oval:org.mitre.oval:tst:8064"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5294" version="1" class="vulnerability">
      <metadata>
        <title>rpc.pcnfsd has an error in its use of the spool directory</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-1999-0353" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-0353"/>
        <description>rpc.pcnfsd in HP gives remote root access by changing the permissions on the main printer spool directory.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-07-11T14:41:52.000-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2008-07-15T15:26:18.225-04:00">DRAFT</status_change>
            <status_change date="2008-08-04T04:00:14.448-04:00">INTERIM</status_change>
            <status_change date="2008-08-25T04:00:08.939-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND" comment="Criteria meets Security Bulletin HPSBUX9902-091">
        <criterion comment="HP Release B.11.00" test_ref="oval:org.mitre.oval:tst:3571"/>
        <criterion negate="true" comment="Patch PHNE_16470 is installed" test_ref="oval:org.mitre.oval:tst:8597"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5311" version="1" class="vulnerability">
      <metadata>
        <title>the ied(1) command reveals data improperly.</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-2270" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-2270"/>
        <description>Unspecified vulnerability in the ied command in HP-UX 10.10, 10.20, and 11.0 allows local users to view "normally invisible data" via unknown attack vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-07-10T16:22:36.000-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2008-07-14T10:52:27.539-04:00">DRAFT</status_change>
            <status_change date="2008-08-04T04:00:14.648-04:00">INTERIM</status_change>
            <status_change date="2008-08-25T04:00:09.201-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND" comment="Criteria meets Security Bulletin HPSBUX0212-227">
        <criterion comment="HP Release B.11.00" test_ref="oval:org.mitre.oval:tst:3571"/>
        <criterion negate="true" comment="Patch PHCO_24446 is installed" test_ref="oval:org.mitre.oval:tst:8650"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5328" version="1" class="vulnerability">
      <metadata>
        <title>Fixes a problem with the e-mail or modem traffic to and from on-site customer machines and Response Center Predictive machines.</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-1999-1136" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-1136"/>
        <description>Vulnerability in Predictive on HP-UX 11.0 and earlier, and MPE/iX 5.5 and earlier, allows attackers to compromise data transfer for Predictive messages (using e-mail or modem) between customer and Response Center Predictive systems.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-07-11T14:41:52.000-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2008-07-15T15:26:18.830-04:00">DRAFT</status_change>
            <status_change date="2008-08-04T04:00:14.802-04:00">INTERIM</status_change>
            <status_change date="2008-08-25T04:00:09.468-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND" comment="Criteria meets Security Bulletin HPSBUX9807-081">
        <criterion comment="HP Release B.11.00" test_ref="oval:org.mitre.oval:tst:3571"/>
        <criterion negate="true" comment="Patch PHSS_14592 is installed" test_ref="oval:org.mitre.oval:tst:8627"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5364" version="1" class="vulnerability">
      <metadata>
        <title>Security restrictions are not consistently enforced when starting applications under HP-UX 11.20.</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2001-1509" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-1509"/>
        <description>geteuid in Itanium Architecture (IA) running on HP-UX 11.20 does not properly identify a user's effective user id, which could allow local users to gain privileges.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-07-10T16:22:36.000-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2008-07-14T10:52:26.442-04:00">DRAFT</status_change>
            <status_change date="2008-08-04T04:00:15.168-04:00">INTERIM</status_change>
            <status_change date="2008-08-25T04:00:09.754-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND" comment="Criteria meets Security Bulletin HPSBUX0110-171">
        <criterion comment="HP-UX B.11.20" test_ref="oval:org.mitre.oval:tst:8457"/>
        <criterion negate="true" comment="Patch PHSS_25454 is installed" test_ref="oval:org.mitre.oval:tst:8581"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5435" version="1" class="vulnerability">
      <metadata>
        <title>HP-UX Running System Administration Manager (SAM), Local Elevation of Privilege</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-1375" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1375"/>
        <description>Unknown vulnerability in System Administration Manager (SAM) in HP-UX B.11.00, B.11.11, B.11.22, and B.11.23 allows local users to gain privileges.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-07-07T16:38:38.000-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2008-07-14T10:52:24.539-04:00">DRAFT</status_change>
            <status_change date="2008-08-04T04:00:15.713-04:00">INTERIM</status_change>
            <status_change date="2008-08-25T04:00:10.040-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX01104">
          <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
          <criterion comment="SystemAdmin.OBAM-RUN is installed" test_ref="oval:org.mitre.oval:tst:7960"/>
          <criterion negate="true" comment="Patch PHSS_31240 is installed" test_ref="oval:org.mitre.oval:tst:8242"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX01104">
          <criterion comment="HP Release B.11.04" test_ref="oval:org.mitre.oval:tst:3294"/>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="InternetSrvcs.INETSVCS-BOOT is installed" test_ref="oval:org.mitre.oval:tst:7514"/>
            <criterion comment="OS-Core.UX-CORE is installed" test_ref="oval:org.mitre.oval:tst:8404"/>
            <criterion comment="SystemAdmin.OBAM-RUN is installed" test_ref="oval:org.mitre.oval:tst:7960"/>
            <criterion comment="SystemAdmin.SAM is installed" test_ref="oval:org.mitre.oval:tst:8338"/>
          </criteria>
          <criterion negate="true" comment="Patch PHCO_32549 is installed" test_ref="oval:org.mitre.oval:tst:8161"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX01104">
          <criterion comment="HP Release B.11.22" test_ref="oval:org.mitre.oval:tst:1015"/>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="SystemAdmin.OBAM-RUN is installed" test_ref="oval:org.mitre.oval:tst:7960"/>
            <criterion comment="SystemAdmin.OBAM-RUN-IA is installed" test_ref="oval:org.mitre.oval:tst:8480"/>
          </criteria>
          <criterion negate="true" comment="Patch PHSS_31243 is installed" test_ref="oval:org.mitre.oval:tst:8259"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX01104">
          <criterion comment="HP Release B.11.00" test_ref="oval:org.mitre.oval:tst:3571"/>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="InternetSrvcs.INETSVCS-BOOT is installed" test_ref="oval:org.mitre.oval:tst:7514"/>
            <criterion comment="OS-Core.UX-CORE is installed" test_ref="oval:org.mitre.oval:tst:8404"/>
            <criterion comment="SystemAdmin.OBAM-RUN is installed" test_ref="oval:org.mitre.oval:tst:7960"/>
            <criterion comment="SystemAdmin.SAM is installed" test_ref="oval:org.mitre.oval:tst:8338"/>
          </criteria>
          <criterion negate="true" comment="Patch PHCO_28125 is installed" test_ref="oval:org.mitre.oval:tst:8471"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX01104">
          <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="SystemAdmin.OBAM-RUN is installed" test_ref="oval:org.mitre.oval:tst:7960"/>
            <criterion comment="SystemAdmin.OBAM-RUN-IA is installed" test_ref="oval:org.mitre.oval:tst:8480"/>
          </criteria>
          <criterion negate="true" comment="Patch PHSS_31817 is installed" test_ref="oval:org.mitre.oval:tst:8056"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5436" version="1" class="vulnerability">
      <metadata>
        <title>HP-UX Running ARPA Transport, Remote Denial of Service (DoS)</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-6425" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6425"/>
        <description>Unspecified vulnerability in HP-UX B.11.31, when running ARPA Transport, allows remote attackers to cause a denial of service via unknown vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-07-08T17:01:37.000-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2008-07-14T10:52:23.714-04:00">DRAFT</status_change>
            <status_change date="2008-08-04T04:00:16.581-04:00">INTERIM</status_change>
            <status_change date="2008-08-25T04:00:10.513-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND" comment="Criteria meets Security Bulletin HPSBUX02306">
        <criterion comment="HP-UX B.11.31" test_ref="oval:org.mitre.oval:tst:8260"/>
        <criteria operator="OR" comment="filesets tests">
          <criterion comment="Networking.NET2-KRN is installed" test_ref="oval:org.mitre.oval:tst:8232"/>
          <criterion comment="OS-Core.CORE2-KRN is installed" test_ref="oval:org.mitre.oval:tst:8297"/>
        </criteria>
        <criterion negate="true" comment="Patch PHNE_36281 is installed" test_ref="oval:org.mitre.oval:tst:8243"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5439" version="1" class="vulnerability">
      <metadata>
        <title>HP-UX Running wall(1), Local Privilege Increase, Denial of Service (DoS)</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-1375" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-1375"/>
        <description>Buffer overflow in wall for HP-UX 10.20 through 11.11 may allow local users to execute arbitrary code by calling wall with a large file as an argument.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-07-08T17:01:38.000-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2008-07-14T10:52:23.320-04:00">DRAFT</status_change>
            <status_change date="2008-08-04T04:00:16.844-04:00">INTERIM</status_change>
            <status_change date="2008-08-25T04:00:10.831-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX00258">
          <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
          <criterion comment="OS-Core.UX-CORE is installed" test_ref="oval:org.mitre.oval:tst:8271"/>
          <criterion negate="true" comment="Patch PHCO_28719 is installed" test_ref="oval:org.mitre.oval:tst:8590"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX00258">
          <criterion comment="HP Release B.11.04" test_ref="oval:org.mitre.oval:tst:3294"/>
          <criterion comment="OS-Core.UX-CORE is installed" test_ref="oval:org.mitre.oval:tst:8271"/>
          <criterion negate="true" comment="Patch PHCO_29085 is installed" test_ref="oval:org.mitre.oval:tst:8511"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX00258">
          <criterion comment="HP Release B.11.00" test_ref="oval:org.mitre.oval:tst:3571"/>
          <criterion comment="OS-Core.UX-CORE is installed" test_ref="oval:org.mitre.oval:tst:8271"/>
          <criterion negate="true" comment="Patch PHCO_28718 is installed" test_ref="oval:org.mitre.oval:tst:8586"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5464" version="1" class="vulnerability">
      <metadata>
        <title>HP-UX ftpd, Remote Unauthorized Access</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0547" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0547"/>
        <description>Unknown vulnerability in ftpd on HP-UX B.11.00, B.11.04, B.11.11, B.11.22, and B.11.23 allows remote authenticated users to gain "unauthorized access to files."</description>
        <oval_repository>
          <dates>
            <submitted date="2008-07-08T17:01:37.000-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2008-07-14T10:52:22.828-04:00">DRAFT</status_change>
            <status_change date="2008-08-04T04:00:17.478-04:00">INTERIM</status_change>
            <status_change date="2008-08-25T04:00:11.178-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX01119">
          <criterion comment="HP Release B.11.00" test_ref="oval:org.mitre.oval:tst:3571"/>
          <criterion comment="InternetSrvcs.INETSVCS-RUN is installed" test_ref="oval:org.mitre.oval:tst:8437"/>
          <criterion negate="true" comment="Patch PHNE_30989 is installed" test_ref="oval:org.mitre.oval:tst:8605"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX01119">
          <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
          <criterion comment="InternetSrvcs.INETSVCS-RUN is installed" test_ref="oval:org.mitre.oval:tst:8437"/>
          <criterion negate="true" comment="Patch PHNE_30990 is installed" test_ref="oval:org.mitre.oval:tst:8456"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX01119">
          <criterion comment="HP Release B.11.04" test_ref="oval:org.mitre.oval:tst:3294"/>
          <criterion comment="InternetSrvcs.INETSVCS-RUN is installed" test_ref="oval:org.mitre.oval:tst:8437"/>
          <criterion negate="true" comment="Patch PHNE_32813 is installed" test_ref="oval:org.mitre.oval:tst:8609"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX01119">
          <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
          <criterion comment="WUFTP-26.INETSVCS-FTP version is less than B.11.11.01.004" test_ref="oval:org.mitre.oval:tst:8534"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX01119">
          <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
          <criterion comment="InternetSrvcs.INETSVCS2-RUN is installed" test_ref="oval:org.mitre.oval:tst:8367"/>
          <criterion negate="true" comment="Patch PHNE_30983 is installed" test_ref="oval:org.mitre.oval:tst:8584"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX01119">
          <criterion comment="HP Release B.11.22" test_ref="oval:org.mitre.oval:tst:1015"/>
          <criterion comment="InternetSrvcs.INETSVCS-RUN is installed" test_ref="oval:org.mitre.oval:tst:8437"/>
          <criterion negate="true" comment="Patch PHNE_29462 is installed" test_ref="oval:org.mitre.oval:tst:8342"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX01119">
          <criterion comment="HP Release B.11.00" test_ref="oval:org.mitre.oval:tst:3571"/>
          <criterion comment="WUFTP-26.INETSVCS-FTP version is less than B.11.00.01.004" test_ref="oval:org.mitre.oval:tst:8568"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5466" version="1" class="vulnerability">
      <metadata>
        <title>HP-UX Running Software Distributor (SD), Local Increased Privileges.</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0089" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0089"/>
        <description>Buffer overflow in the Software Distributor utilities for HP-UX B.11.00 and B.11.11 allows local users to execute arbitrary code via a long LANG environment variable to setuid programs such as (1) swinstall and (2) swmodify.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-07-09T16:48:33.000-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2008-07-14T10:52:22.194-04:00">DRAFT</status_change>
            <status_change date="2008-08-04T04:00:17.742-04:00">INTERIM</status_change>
            <status_change date="2008-08-25T04:00:11.609-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX00293">
          <criterion comment="HP Release B.11.04" test_ref="oval:org.mitre.oval:tst:3294"/>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="SW-DIST.SD-CMDS is installed" test_ref="oval:org.mitre.oval:tst:8299"/>
            <criterion comment="SW-DIST.SD-AGENT is installed" test_ref="oval:org.mitre.oval:tst:8604"/>
          </criteria>
          <criterion negate="true" comment="Patch PHCO_30006 is installed" test_ref="oval:org.mitre.oval:tst:7928"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX00293">
          <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="SW-DIST.SD-CMDS is installed" test_ref="oval:org.mitre.oval:tst:8299"/>
            <criterion comment="SW-DIST.SD-AGENT is installed" test_ref="oval:org.mitre.oval:tst:8604"/>
          </criteria>
          <criterion negate="true" comment="Patch PHCO_28848 is installed" test_ref="oval:org.mitre.oval:tst:8344"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX00293">
          <criterion comment="HP Release B.11.00" test_ref="oval:org.mitre.oval:tst:3571"/>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="SW-DIST.SD-CMDS is installed" test_ref="oval:org.mitre.oval:tst:8299"/>
            <criterion comment="SW-DIST.SD-AGENT is installed" test_ref="oval:org.mitre.oval:tst:8604"/>
          </criteria>
          <criterion negate="true" comment="Patch PHCO_28847 is installed" test_ref="oval:org.mitre.oval:tst:8201"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5469" version="1" class="vulnerability">
      <metadata>
        <title>HP-UX, Local Denial of Service (DoS)</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-0279" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0279"/>
        <description>The kernel in HP-UX 11.11 does not properly provide arguments for setrlimit, which could allow local attackers to cause a denial of service (kernel panic) and possibly gain privileges.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-07-09T16:48:34.000-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2008-07-14T10:52:21.842-04:00">DRAFT</status_change>
            <status_change date="2008-08-04T04:00:18.658-04:00">INTERIM</status_change>
            <status_change date="2008-08-25T04:00:11.926-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND" comment="Criteria meets Security Bulletin HPSBUX00183">
        <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
        <criterion comment="OS-Core.CORE2-KRN is installed" test_ref="oval:org.mitre.oval:tst:8517"/>
        <criterion negate="true" comment="Patch PHKL_26233 is installed" test_ref="oval:org.mitre.oval:tst:8101"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5479" version="1" class="vulnerability">
      <metadata>
        <title>HP-UX running dlkm, Local Unauthorized Increase in Privilege</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2001-1181" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-1181"/>
        <description>Dynamically Loadable Kernel Module (dlkm) static kernel symbol table in HP-UX 11.11 is not properly configured, which allows local users to gain privileges.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-07-10T16:22:35.000-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2008-07-14T10:52:21.615-04:00">DRAFT</status_change>
            <status_change date="2008-08-04T04:00:18.848-04:00">INTERIM</status_change>
            <status_change date="2008-08-25T04:00:12.300-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND" comment="Criteria meets Security Bulletin HPSBUX00159">
        <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
        <criterion comment="OS-Core.CORE-KRN is installed" test_ref="oval:org.mitre.oval:tst:8687"/>
        <criterion negate="true" comment="Patch PHCO_23492 is installed" test_ref="oval:org.mitre.oval:tst:8520"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5482" version="1" class="vulnerability">
      <metadata>
        <title>Buffer overflow vulnerability in the CDE Calendar Manager Service Daemon, rpc.cmsd.</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-1999-0696" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-0696"/>
        <description>Buffer overflow in CDE Calendar Manager Service Daemon (rpc.cmsd).</description>
        <oval_repository>
          <dates>
            <submitted date="2008-07-11T14:41:52.000-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2008-07-15T15:26:17.481-04:00">DRAFT</status_change>
            <status_change date="2008-08-04T04:00:19.314-04:00">INTERIM</status_change>
            <status_change date="2008-08-25T04:00:12.669-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND" comment="Criteria meets Security Bulletin HPSBUX9908-102">
        <criterion comment="HP Release B.11.00" test_ref="oval:org.mitre.oval:tst:3571"/>
        <criterion negate="true" comment="Patch PHSS_19483 is installed" test_ref="oval:org.mitre.oval:tst:8494"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5490" version="1" class="vulnerability">
      <metadata>
        <title>HP-UX running ndd(1M), Local Denial of Service (DoS)</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-0585" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0585"/>
        <description>Unknown vulnerability in ndd for HP-UX 11.11 with certain TRANSPORT patches allows attackers to cause a denial of service.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-07-09T16:48:34.000-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2008-07-14T10:52:21.178-04:00">DRAFT</status_change>
            <status_change date="2008-08-04T04:00:19.571-04:00">INTERIM</status_change>
            <status_change date="2008-08-25T04:00:13.409-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND" comment="Criteria meets Security Bulletin HPSBUX00192">
        <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
        <criteria operator="OR" comment="filesets tests">
          <criterion comment="Networking.NMS2-KRN is installed" test_ref="oval:org.mitre.oval:tst:8099"/>
          <criterion comment="Networking.NMS2-KRN is installed" test_ref="oval:org.mitre.oval:tst:8099"/>
          <criterion comment="OS-Core.CORE2-KRN is installed" test_ref="oval:org.mitre.oval:tst:8517"/>
          <criterion comment="OS-Core.CORE2-KRN is installed" test_ref="oval:org.mitre.oval:tst:8517"/>
          <criterion comment="OS-Core.SYS-ADMIN is installed" test_ref="oval:org.mitre.oval:tst:8592"/>
          <criterion comment="Networking.NET-KRN is installed" test_ref="oval:org.mitre.oval:tst:8147"/>
          <criterion comment="Networking.NET-PRG is installed" test_ref="oval:org.mitre.oval:tst:8562"/>
          <criterion comment="Networking.NET-RUN is installed" test_ref="oval:org.mitre.oval:tst:8236"/>
          <criterion comment="Networking.NET-RUN-64 is installed" test_ref="oval:org.mitre.oval:tst:8447"/>
          <criterion comment="Networking.NW-ENG-A-MAN is installed" test_ref="oval:org.mitre.oval:tst:7663"/>
          <criterion comment="OS-Core.CORE-KRN is installed" test_ref="oval:org.mitre.oval:tst:7985"/>
          <criterion comment="OS-Core.SYS-ADMIN is installed" test_ref="oval:org.mitre.oval:tst:8592"/>
          <criterion comment="ProgSupport.C-INC is installed" test_ref="oval:org.mitre.oval:tst:8355"/>
          <criterion comment="Networking.NET2-KRN is installed" test_ref="oval:org.mitre.oval:tst:8578"/>
          <criterion comment="Networking.NET2-KRN is installed" test_ref="oval:org.mitre.oval:tst:8578"/>
        </criteria>
        <criterion negate="true" comment="Patch PHNE_25644 is installed" test_ref="oval:org.mitre.oval:tst:8561"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5502" version="1" class="vulnerability">
      <metadata>
        <title>The inet server (inetd) on HP-UX can be hung by malicious users.</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2001-0106" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-0106"/>
        <description>Vulnerability in inetd server in HP-UX 11.04 and earlier allows attackers to cause a denial of service when the "swait" state is used by a server.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-07-10T16:22:36.000-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2008-07-14T10:52:20.259-04:00">DRAFT</status_change>
            <status_change date="2008-08-04T04:00:19.888-04:00">INTERIM</status_change>
            <status_change date="2008-08-25T04:00:14.222-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND" comment="Criteria meets Security Bulletin HPSBUX0101-136">
        <criterion comment="HP Release B.11.00" test_ref="oval:org.mitre.oval:tst:3571"/>
        <criterion negate="true" comment="Patch PHNE_21835 is installed" test_ref="oval:org.mitre.oval:tst:8516"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5515" version="1" class="vulnerability">
      <metadata>
        <title>HP-UX Running the Ignite-UX or the DynRootDisk (DRD) get_system_info Command, Local Unqualified Configuration Change</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-4590" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4590"/>
        <description>The get_system_info command in Ignite-UX C.7.0 through C.7.3, and DynRootDisk (DRD) A.1.0.16.417 through A.2.0.0.592, on HP-UX B.11.11, B.11.23, and B.11.31 does not inform local users of networking changes made by the command, which has unknown impact and attack vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-07-03T16:09:04.000-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2008-07-07T14:19:41.038-04:00">DRAFT</status_change>
            <modified comment="Criteria meets HP Security Bulletin HPSBUX02249" date="2008-07-14T10:21:00.168-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </modified>
            <status_change date="2008-08-04T04:00:20.086-04:00">INTERIM</status_change>
            <status_change date="2008-08-25T04:00:14.670-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02249">
          <criteria operator="OR" comment="platforms">
            <criterion comment="HP-UX B.11.31" test_ref="oval:org.mitre.oval:tst:8260"/>
            <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
          </criteria>
          <criterion comment="DRD.DRD-RUN version is less than A.3.0.0" test_ref="oval:org.mitre.oval:tst:8445"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02249">
          <criteria operator="OR" comment="platforms">
            <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
            <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
            <criterion comment="HP-UX B.11.31" test_ref="oval:org.mitre.oval:tst:8260"/>
          </criteria>
          <criterion comment="Ignite-UX.MGMT-TOOLS version is less than C.7.3.148" test_ref="oval:org.mitre.oval:tst:8468"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5518" version="1" class="vulnerability">
      <metadata>
        <title>HP-UX passwd(1), Local Denial of Service (DoS)</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-0577" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0577"/>
        <description>Vulnerability in passwd for HP-UX 11.00 and 11.11 allows local users to corrupt the password file and cause a denial of service.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-07-09T16:48:34.000-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2008-07-14T10:52:19.400-04:00">DRAFT</status_change>
            <status_change date="2008-08-04T04:00:20.449-04:00">INTERIM</status_change>
            <status_change date="2008-08-25T04:00:15.030-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX00191">
          <criterion comment="HP Release B.11.04" test_ref="oval:org.mitre.oval:tst:3294"/>
          <criterion comment="OS-Core.CORE-SHLIBS is installed" test_ref="oval:org.mitre.oval:tst:7643"/>
          <criterion negate="true" comment="Patch PHCO_26904 is installed" test_ref="oval:org.mitre.oval:tst:7698"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX00191">
          <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
          <criterion comment="OS-Core.CORE-SHLIBS is installed" test_ref="oval:org.mitre.oval:tst:7643"/>
          <criterion negate="true" comment="Patch PHCO_24839 is installed" test_ref="oval:org.mitre.oval:tst:8667"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX00191">
          <criterion comment="HP Release B.11.00" test_ref="oval:org.mitre.oval:tst:3571"/>
          <criterion comment="OS-Core.CORE-SHLIBS is installed" test_ref="oval:org.mitre.oval:tst:7643"/>
          <criterion negate="true" comment="Patch PHCO_25527 is installed" test_ref="oval:org.mitre.oval:tst:8673"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5533" version="1" class="vulnerability">
      <metadata>
        <title>HP-UX running rlpdaemon, Remote Unauthorized Access, Increased Privilege</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2001-0668" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-0668"/>
        <description>Buffer overflow in line printer daemon (rlpdaemon) in HP-UX 10.01 through 11.11 allows remote attackers to execute arbitrary commands.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-07-09T16:48:34.000-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2008-07-14T10:52:18.890-04:00">DRAFT</status_change>
            <status_change date="2008-08-04T04:00:20.919-04:00">INTERIM</status_change>
            <status_change date="2008-08-25T04:00:15.397-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX00163">
          <criterion comment="HP-UX B.11.20" test_ref="oval:org.mitre.oval:tst:8336"/>
          <criterion comment="PrinterMgmt.LP-SPOOL is installed" test_ref="oval:org.mitre.oval:tst:8082"/>
          <criterion negate="true" comment="Patch PHCO_24868 is installed" test_ref="oval:org.mitre.oval:tst:8310"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX00163">
          <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
          <criterion comment="PrinterMgmt.LP-SPOOL is installed" test_ref="oval:org.mitre.oval:tst:8082"/>
          <criterion negate="true" comment="Patch PHCO_24701 is installed" test_ref="oval:org.mitre.oval:tst:8537"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX00163">
          <criterion comment="HP Release B.11.00" test_ref="oval:org.mitre.oval:tst:3571"/>
          <criterion comment="PrinterMgmt.LP-SPOOL is installed" test_ref="oval:org.mitre.oval:tst:8082"/>
          <criterion negate="true" comment="Patch PHCO_24700 is installed" test_ref="oval:org.mitre.oval:tst:8649"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5538" version="1" class="vulnerability">
      <metadata>
        <title>HP-UX stmkfont Local Unauthorized Privileged Access</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0965" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0965"/>
        <description>stmkfont in HP-UX B.11.00 through B.11.23 relies on the user-specified PATH when executing certain commands, which allows local users to execute arbitrary code by modifying the PATH environment variable to point to malicious programs.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-07-07T16:38:36.000-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2008-07-14T10:52:18.235-04:00">DRAFT</status_change>
            <status_change date="2008-08-04T04:00:21.645-04:00">INTERIM</status_change>
            <status_change date="2008-08-25T04:00:15.957-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX01088">
          <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
          <criterion comment="X11.X11-FONTSRV is installed" test_ref="oval:org.mitre.oval:tst:7653"/>
          <criterion negate="true" comment="Patch PHSS_31988 is installed" test_ref="oval:org.mitre.oval:tst:8221"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX01088">
          <criterion comment="HP Release B.11.04" test_ref="oval:org.mitre.oval:tst:3294"/>
          <criterion comment="X11.X11-FONTSRV is installed" test_ref="oval:org.mitre.oval:tst:7653"/>
          <criterion negate="true" comment="Patch PHSS_32196 is installed" test_ref="oval:org.mitre.oval:tst:8251"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX01088">
          <criterion comment="HP Release B.11.00" test_ref="oval:org.mitre.oval:tst:3571"/>
          <criterion comment="X11.X11-FONTSRV is installed" test_ref="oval:org.mitre.oval:tst:7653"/>
          <criterion negate="true" comment="Patch PHSS_31987 is installed" test_ref="oval:org.mitre.oval:tst:8375"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX01088">
          <criterion comment="HP Release B.11.22" test_ref="oval:org.mitre.oval:tst:1015"/>
          <criterion comment="X11.X11-FONTSRV is installed" test_ref="oval:org.mitre.oval:tst:7653"/>
          <criterion negate="true" comment="Patch PHSS_31989 is installed" test_ref="oval:org.mitre.oval:tst:8314"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX01088">
          <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
          <criterion comment="X11.X11-FONTSRV is installed" test_ref="oval:org.mitre.oval:tst:7653"/>
          <criterion negate="true" comment="Patch PHSS_31990 is installed" test_ref="oval:org.mitre.oval:tst:7713"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5547" version="1" class="vulnerability">
      <metadata>
        <title>Security Vulnerability during ftp operations.</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-1999-0432" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-0432"/>
        <description>ftp on HP-UX 11.00 allows local users to gain privileges.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-07-11T14:41:52.000-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2008-07-15T15:26:17.990-04:00">DRAFT</status_change>
            <status_change date="2008-08-04T04:00:22.021-04:00">INTERIM</status_change>
            <status_change date="2008-08-25T04:00:16.377-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND" comment="Criteria meets Security Bulletin HPSBUX9903-094">
        <criterion comment="HP Release B.11.00" test_ref="oval:org.mitre.oval:tst:3571"/>
        <criterion negate="true" comment="Patch PHCO_17601 is installed" test_ref="oval:org.mitre.oval:tst:8636"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5549" version="1" class="vulnerability">
      <metadata>
        <title>/opt/audio/bin/Aserver can be used to gain root access.</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2000-0077" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2000-0077"/>
        <description>The October 1998 version of the HP-UX aserver program allows local users to gain privileges by specifying an alternate PATH which aserver uses to find the ps and grep commands.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-07-11T14:41:52.000-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2008-07-15T15:26:16.904-04:00">DRAFT</status_change>
            <status_change date="2008-08-04T04:00:22.396-04:00">INTERIM</status_change>
            <status_change date="2008-08-25T04:00:16.902-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND" comment="Criteria meets Security Bulletin HPSBUX0001-108">
        <criterion comment="HP Release B.11.00" test_ref="oval:org.mitre.oval:tst:3571"/>
        <criterion negate="true" comment="Patch PHSS_21663 is installed" test_ref="oval:org.mitre.oval:tst:8307"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5550" version="1" class="vulnerability">
      <metadata>
        <title>Various remote network commands have security defects.</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-1999-1573" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-1573"/>
        <description>Multiple unknown vulnerabilities in the "r-cmnds" (1) remshd, (2) rexecd, (3) rlogind, (4) rlogin, (5) remsh, (6) rcp, (7) rexec, and (8) rdist for HP-UX 10.00 through 11.00 allow attackers to gain privileges or access files.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-07-11T14:41:52.000-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2008-07-15T15:26:17.159-04:00">DRAFT</status_change>
            <status_change date="2008-08-04T04:00:22.656-04:00">INTERIM</status_change>
            <status_change date="2008-08-25T04:00:17.173-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND" comment="Criteria meets Security Bulletin HPSBUX9812-090">
        <criterion comment="HP Release B.11.00" test_ref="oval:org.mitre.oval:tst:3571"/>
        <criterion negate="true" comment="Patch PHNE_16091 is installed" test_ref="oval:org.mitre.oval:tst:7808"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5568" version="1" class="vulnerability">
      <metadata>
        <title>HP-UX Running Software Distributor Local Elevation of Privilege</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-2574" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-2574"/>
        <description>Multiple unspecified vulnerabilities in Software Distributor in HP-UX B.11.00, B.11.04, B.11.11, and B.11.23 allow local users to gain privileges via unspecified attack vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-07-07T16:38:36.000-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2008-07-14T10:52:17.388-04:00">DRAFT</status_change>
            <status_change date="2008-08-04T04:00:23.193-04:00">INTERIM</status_change>
            <status_change date="2008-08-25T04:00:17.485-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02114">
          <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
          <criterion comment="SW-DIST.SD-CMDS is installed" test_ref="oval:org.mitre.oval:tst:8222"/>
          <criterion negate="true" comment="Patch PHCO_34539 is installed" test_ref="oval:org.mitre.oval:tst:8373"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02114">
          <criterion comment="HP Release B.11.04" test_ref="oval:org.mitre.oval:tst:3294"/>
          <criterion comment="SW-DIST.SD-CMDS is installed" test_ref="oval:org.mitre.oval:tst:8222"/>
          <criterion negate="true" comment="Patch PHCO_34814 is installed" test_ref="oval:org.mitre.oval:tst:8379"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02114">
          <criterion comment="HP Release B.11.00" test_ref="oval:org.mitre.oval:tst:3571"/>
          <criterion comment="SW-DIST.SD-CMDS is installed" test_ref="oval:org.mitre.oval:tst:8222"/>
          <criterion negate="true" comment="Patch PHCO_34568 is installed" test_ref="oval:org.mitre.oval:tst:8148"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02114">
          <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
          <criterion comment="SW-DIST.SD-CMDS version is less than B.11.23.0606.045" test_ref="oval:org.mitre.oval:tst:8385"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5576" version="1" class="vulnerability">
      <metadata>
        <title>shutdown(1M) improperly handles input variables.</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2000-0414" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2000-0414"/>
        <description>Vulnerability in shutdown command for HP-UX 11.X and 10.X allows allows local users to gain privileges via malformed input variables.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-07-11T14:41:52.000-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2008-07-15T15:26:16.202-04:00">DRAFT</status_change>
            <status_change date="2008-08-04T04:00:23.526-04:00">INTERIM</status_change>
            <status_change date="2008-08-25T04:00:17.929-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin  HPSBUX0005-113">
          <criterion comment="HP Release B.11.04" test_ref="oval:org.mitre.oval:tst:3294"/>
          <criterion negate="true" comment="Patch PHCO_21567 is installed" test_ref="oval:org.mitre.oval:tst:8542"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin  HPSBUX0005-113">
          <criterion comment="HP Release B.11.00" test_ref="oval:org.mitre.oval:tst:3571"/>
          <criterion negate="true" comment="Patch PHCO_21534 is installed" test_ref="oval:org.mitre.oval:tst:8187"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5579" version="1" class="vulnerability">
      <metadata>
        <title>A TCP SYN packet with target host's address as both source and destination can cause system hangs.</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-1999-0015" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-0015"/>
        <description>Teardrop IP denial of service.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-07-11T14:41:52.000-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2008-07-15T15:26:19.201-04:00">DRAFT</status_change>
            <status_change date="2008-08-04T04:00:23.791-04:00">INTERIM</status_change>
            <status_change date="2008-08-25T04:00:18.670-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND" comment="Criteria meets Security Bulletin HPSBUX9801-076">
        <criterion comment="HP Release B.11.00" test_ref="oval:org.mitre.oval:tst:3571"/>
        <criterion negate="true" comment="Patch PHNE_14017 is installed" test_ref="oval:org.mitre.oval:tst:8302"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5584" version="1" class="vulnerability">
      <metadata>
        <title>HP-UX running ptrace(2), Local Denial of Service (DoS)</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-1409" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-1409"/>
        <description>ptrace on HP-UX 11.00 through 11.11 allows local users to cause a denial of service (data page fault panic) via "an incorrect reference to thread register state."</description>
        <oval_repository>
          <dates>
            <submitted date="2008-07-09T16:48:33.000-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2008-07-14T10:52:16.636-04:00">DRAFT</status_change>
            <status_change date="2008-08-04T04:00:24.012-04:00">INTERIM</status_change>
            <status_change date="2008-08-25T04:00:18.924-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX00206">
          <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
          <criterion comment="OS-Core.CORE2-KRN is installed" test_ref="oval:org.mitre.oval:tst:8517"/>
          <criterion negate="true" comment="Patch PHKL_27179 is installed" test_ref="oval:org.mitre.oval:tst:8388"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX00206">
          <criterion comment="HP Release B.11.04" test_ref="oval:org.mitre.oval:tst:3294"/>
          <criterion comment="OS-Core.CORE2-KRN is installed" test_ref="oval:org.mitre.oval:tst:8517"/>
          <criterion negate="true" comment="Patch PHKL_27536 is installed" test_ref="oval:org.mitre.oval:tst:8230"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX00206">
          <criterion comment="HP Release B.11.00" test_ref="oval:org.mitre.oval:tst:3571"/>
          <criterion comment="OS-Core.CORE2-KRN is installed" test_ref="oval:org.mitre.oval:tst:8517"/>
          <criterion negate="true" comment="Patch PHKL_27180 is installed" test_ref="oval:org.mitre.oval:tst:8539"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5587" version="1" class="vulnerability">
      <metadata>
        <title>There is a potential buffer overflow in /usr/bin/stmkfont.</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-1359" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-1359"/>
        <description>Buffer overflow in stmkfont utility of HP-UX 10.0 through 11.22 allows local users to gain privileges via a long command line argument.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-07-10T16:22:36.000-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2008-07-14T10:52:15.936-04:00">DRAFT</status_change>
            <status_change date="2008-08-04T04:00:24.448-04:00">INTERIM</status_change>
            <status_change date="2008-08-25T04:00:19.348-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX0302-241">
          <criterion comment="HP Release B.11.04" test_ref="oval:org.mitre.oval:tst:3294"/>
          <criterion negate="true" comment="Patch PHSS_31104 is installed" test_ref="oval:org.mitre.oval:tst:8508"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX0302-241">
          <criterion comment="HP Release B.11.00" test_ref="oval:org.mitre.oval:tst:3571"/>
          <criterion negate="true" comment="Patch PHSS_29744 is installed" test_ref="oval:org.mitre.oval:tst:8489"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5593" version="1" class="vulnerability">
      <metadata>
        <title>HP-UX running LDAP-UX Integration, Remote Increased Privilege</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-1794" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-1794"/>
        <description>Unknown vulnerability in pam_authz in the LDAP-UX Integration product on HP-UX 11.00 and 11.11 allows remote attackers to execute r-commands with privileges of other users.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-07-09T16:48:33.000-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2008-07-14T10:52:14.706-04:00">DRAFT</status_change>
            <status_change date="2008-08-04T04:00:24.634-04:00">INTERIM</status_change>
            <status_change date="2008-08-25T04:00:20.166-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND" comment="Criteria meets Security Bulletin HPSBUX00221">
        <criteria operator="OR" comment="platforms">
          <criterion comment="HP Release B.11.00" test_ref="oval:org.mitre.oval:tst:3571"/>
          <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
        </criteria>
        <criteria operator="OR" comment="filesets tests">
          <criterion comment="LdapUxClient.ADMIN-RUN version is less than B.03.01" test_ref="oval:org.mitre.oval:tst:8452"/>
          <criterion comment="LdapUxClient.CORE-RUN version is less than B.03.01" test_ref="oval:org.mitre.oval:tst:8225"/>
          <criterion comment="LdapUxClient.LDAP-C-SDK version is less than B.03.01" test_ref="oval:org.mitre.oval:tst:7918"/>
          <criterion comment="LdapUxClient.LDUX-ENG-A-MAN version is less than B.03.01" test_ref="oval:org.mitre.oval:tst:8559"/>
          <criterion comment="LdapUxClient.NATIVELDAP-RUN version is less than B.03.01" test_ref="oval:org.mitre.oval:tst:8523"/>
          <criterion comment="LdapUxClient.PAM-AUTHZ-RUN version is less than B.03.01" test_ref="oval:org.mitre.oval:tst:8544"/>
          <criterion comment="NisLdapServer.YPLDAP-SERVER version is less than B.03.01" test_ref="oval:org.mitre.oval:tst:8332"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5611" version="1" class="vulnerability">
      <metadata>
        <title>Potential buffer overflow in rexec(1)</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-1097" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-1097"/>
        <description>Buffer overflow in rexec on HP-UX B.10.20, B.11.00, and B.11.04, when setuid root, may allow local users to gain privileges via a long -l option.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-07-10T16:22:36.000-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2008-07-14T10:52:09.833-04:00">DRAFT</status_change>
            <status_change date="2008-08-04T04:00:24.913-04:00">INTERIM</status_change>
            <status_change date="2008-08-25T04:00:20.623-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX0304-257">
          <criterion comment="HP Release B.11.04" test_ref="oval:org.mitre.oval:tst:3294"/>
          <criterion negate="true" comment="Patch PHCO_2919 is installed" test_ref="oval:org.mitre.oval:tst:8267"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX0304-257">
          <criterion comment="HP Release B.11.00" test_ref="oval:org.mitre.oval:tst:3571"/>
          <criterion negate="true" comment="Patch PHCO_24723 is installed" test_ref="oval:org.mitre.oval:tst:8655"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5617" version="1" class="vulnerability">
      <metadata>
        <title>HP-UX Running IPSec, Remote Unauthorized Access</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-4090" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-4090"/>
        <description>Unspecified vulnerability in HP-UX B.11.00 to B.11.23, when IPSEC is running, allows remote attackers to have unknown impact.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-07-07T16:38:36.000-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2008-07-14T10:52:09.476-04:00">DRAFT</status_change>
            <status_change date="2008-08-04T04:00:25.092-04:00">INTERIM</status_change>
            <status_change date="2008-08-25T04:00:21.107-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02082">
          <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
          <criterion comment="IPSec.IPSEC2-KRN version is less than A.01.07.02" test_ref="oval:org.mitre.oval:tst:8149"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02082">
          <criterion comment="HP Release B.11.00" test_ref="oval:org.mitre.oval:tst:3571"/>
          <criterion comment="IPSec.IPSEC2-KRN version is less than A.01.05.01" test_ref="oval:org.mitre.oval:tst:8397"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02082">
          <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
          <criterion comment="IPSec.IPSEC2-KRN version is less than A.02.01" test_ref="oval:org.mitre.oval:tst:8416"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5621" version="1" class="vulnerability">
      <metadata>
        <title>Certain files used by the asecure program have unsafe permissions.</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2001-0607" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-0607"/>
        <description>asecure as included with HP-UX 10.01 through 11.00 can allow a local attacker to create a denial of service and gain additional privileges via unsafe permissions on the asecure program, a different vulnerability than CVE-2000-0083.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-07-10T16:22:36.000-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2008-07-14T10:52:09.232-04:00">DRAFT</status_change>
            <status_change date="2008-08-04T04:00:25.265-04:00">INTERIM</status_change>
            <status_change date="2008-08-25T04:00:21.529-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND" comment="Criteria meets Security Bulletin HPSBUX0103-145">
        <criterion comment="HP Release B.11.00" test_ref="oval:org.mitre.oval:tst:3571"/>
        <criterion negate="true" comment="Patch PHSS_24608 is installed" test_ref="oval:org.mitre.oval:tst:8630"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5622" version="1" class="vulnerability">
      <metadata>
        <title>HP-UX Running newgrp(1), Local Privilege Elevation</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-1328" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1328"/>
        <description>Unknown vulnerability in newgrp in HP-UX B.11.00, B.11.04, and B.11.11 allows local users to gain elevated privileges.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-07-07T16:38:37.000-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2008-07-14T10:52:08.938-04:00">DRAFT</status_change>
            <status_change date="2008-08-04T04:00:25.537-04:00">INTERIM</status_change>
            <status_change date="2008-08-25T04:00:21.817-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX01102">
          <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
          <criterion comment="OS-Core.CMDS-AUX is installed" test_ref="oval:org.mitre.oval:tst:8112"/>
          <criterion negate="true" comment="Patch PHCO_26385 is installed" test_ref="oval:org.mitre.oval:tst:8428"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX01102">
          <criterion comment="HP Release B.11.04" test_ref="oval:org.mitre.oval:tst:3294"/>
          <criterion comment="OS-Core.CORE-SHLIBS is installed" test_ref="oval:org.mitre.oval:tst:8229"/>
          <criterion negate="true" comment="Patch PHCO_32280 is installed" test_ref="oval:org.mitre.oval:tst:8427"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX01102">
          <criterion comment="HP Release B.11.00" test_ref="oval:org.mitre.oval:tst:3571"/>
          <criterion comment="OS-Core.CMDS-AUX is installed" test_ref="oval:org.mitre.oval:tst:8112"/>
          <criterion negate="true" comment="Patch PHCO_29682 is installed" test_ref="oval:org.mitre.oval:tst:8273"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5623" version="1" class="vulnerability">
      <metadata>
        <title>HP-UX running SD, Local Unauthorized Access, Denial of Service (DoS)</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-0798" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0798"/>
        <description>Vulnerability in swinstall for HP-UX 11.00 and 11.11 allows local users to view obtain data views for files that cannot be directly read by the user, which reportedly can be used to cause a denial of service.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-07-09T16:48:33.000-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2008-07-14T10:52:08.207-04:00">DRAFT</status_change>
            <status_change date="2008-08-04T04:00:25.868-04:00">INTERIM</status_change>
            <status_change date="2008-08-25T04:00:22.201-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX00194">
          <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="SW-DIST.SD-AGENT is installed" test_ref="oval:org.mitre.oval:tst:8604"/>
            <criterion comment="SW-DIST.SD-CMDS is installed" test_ref="oval:org.mitre.oval:tst:8299"/>
            <criterion comment="SW-DIST.SD-HELP is installed" test_ref="oval:org.mitre.oval:tst:8417"/>
            <criterion comment="SW-DIST.SD-JPN-E-HELP is installed" test_ref="oval:org.mitre.oval:tst:8614"/>
            <criterion comment="SW-DIST.SD-JPN-S-HELP is installed" test_ref="oval:org.mitre.oval:tst:8203"/>
          </criteria>
          <criterion negate="true" comment="Patch PHCO_25887 is installed" test_ref="oval:org.mitre.oval:tst:8253"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX00194">
          <criterion comment="HP Release B.11.00" test_ref="oval:org.mitre.oval:tst:3571"/>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="SW-DIST.SD-JPN-E-MAN is installed" test_ref="oval:org.mitre.oval:tst:8470"/>
            <criterion comment="SW-DIST.SD-JPN-S-HELP is installed" test_ref="oval:org.mitre.oval:tst:8203"/>
            <criterion comment="SW-DIST.SD-AGENT is installed" test_ref="oval:org.mitre.oval:tst:8604"/>
            <criterion comment="SW-DIST.SD-CMDS is installed" test_ref="oval:org.mitre.oval:tst:8299"/>
            <criterion comment="SW-DIST.SD-JPN-E-MSG is installed" test_ref="oval:org.mitre.oval:tst:8311"/>
            <criterion comment="SW-DIST.SD-JPN-S-MSG is installed" test_ref="oval:org.mitre.oval:tst:8617"/>
            <criterion comment="SW-DIST.SD-ENG-A-MAN is installed" test_ref="oval:org.mitre.oval:tst:8566"/>
            <criterion comment="SW-DIST.SD-FAL is installed" test_ref="oval:org.mitre.oval:tst:8478"/>
            <criterion comment="SW-DIST.SD-JPN-S-MAN is installed" test_ref="oval:org.mitre.oval:tst:8622"/>
            <criterion comment="SW-DIST.SD-HELP is installed" test_ref="oval:org.mitre.oval:tst:8417"/>
            <criterion comment="SW-DIST.SD-JPN-E-HELP is installed" test_ref="oval:org.mitre.oval:tst:8614"/>
          </criteria>
          <criterion negate="true" comment="Patch PHCO_25875 is installed" test_ref="oval:org.mitre.oval:tst:8189"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5627" version="1" class="vulnerability">
      <metadata>
        <title>HP-UX running Support Tools Manager (xstm, cstm, stm) Local Denial of Service (DoS)</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-3097" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-3097"/>
        <description>Unspecified vulnerability in Support Tools Manager (xstm, cstm, and stm) on HP-UX B.11.11 and B.11.23 allows local users to cause an unspecified denial of service via unknown vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-07-08T17:01:37.000-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2008-07-14T10:52:07.018-04:00">DRAFT</status_change>
            <status_change date="2008-08-04T04:00:26.325-04:00">INTERIM</status_change>
            <status_change date="2008-08-25T04:00:22.772-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02115">
          <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
          <criterion comment="Sup-Tool-Mgr.STM-SHLIBS version is less than B.11.11.17.02" test_ref="oval:org.mitre.oval:tst:8510"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02115">
          <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
          <criterion comment="Sup-Tool-Mgr.STM-SHLIBS version is less than B.11.23.07.04" test_ref="oval:org.mitre.oval:tst:8560"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02115">
          <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
          <criterion comment="Sup-Tool-Mgr.STM-SHLIBS is installed" test_ref="oval:org.mitre.oval:tst:8322"/>
          <criterion negate="true" comment="Patch PHSS_34288 is installed" test_ref="oval:org.mitre.oval:tst:8440"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5628" version="1" class="vulnerability">
      <metadata>
        <title>HP-UX kmmodreg (1M), Local Denial of Service (DoS), Increased Privilege</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2001-1256" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-1256"/>
        <description>kmmodreg in HP-UX 11.11, 11.04 and 11.00 allows local users to create arbitrary world-writeable files via a symlink attack on the (1) /tmp/.kmmodreg_lock and (2) /tmp/kmpath.tmp temporary files.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-07-10T16:22:36.000-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2008-07-14T10:52:06.437-04:00">DRAFT</status_change>
            <status_change date="2008-08-04T04:00:26.753-04:00">INTERIM</status_change>
            <status_change date="2008-08-25T04:00:23.116-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX00153">
          <criterion comment="HP Release B.11.04" test_ref="oval:org.mitre.oval:tst:3294"/>
          <criterion comment="OS-Core.CORE-KRN is installed" test_ref="oval:org.mitre.oval:tst:8687"/>
          <criterion negate="true" comment="Patch PHCO_24197 is installed" test_ref="oval:org.mitre.oval:tst:8360"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX00153">
          <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
          <criterion comment="OS-Core.CORE-KRN is installed" test_ref="oval:org.mitre.oval:tst:8687"/>
          <criterion negate="true" comment="Patch PHCO_24147 is installed" test_ref="oval:org.mitre.oval:tst:8657"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX00153">
          <criterion comment="HP Release B.11.00" test_ref="oval:org.mitre.oval:tst:3571"/>
          <criterion comment="OS-Core.CORE-KRN is installed" test_ref="oval:org.mitre.oval:tst:8687"/>
          <criterion negate="true" comment="Patch PHCO_24112 is installed" test_ref="oval:org.mitre.oval:tst:8557"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5635" version="1" class="vulnerability">
      <metadata>
        <title>/opt/audio/bin/Aserver can be used to gain root access.</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2000-0005" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2000-0005"/>
        <description>HP-UX aserver program allows local users to gain privileges via a symlink attack.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-07-11T14:41:52.000-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2008-07-15T15:26:18.385-04:00">DRAFT</status_change>
            <status_change date="2008-08-04T04:00:27.153-04:00">INTERIM</status_change>
            <status_change date="2008-08-25T04:00:23.491-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND" comment="Criteria meets Security Bulletin HPSBUX0001-108">
        <criterion comment="HP Release B.11.00" test_ref="oval:org.mitre.oval:tst:3571"/>
        <criterion negate="true" comment="Patch PHSS_21663 is installed" test_ref="oval:org.mitre.oval:tst:8307"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5637" version="1" class="vulnerability">
      <metadata>
        <title>Kermit communications software contains a buffer overflow.</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2001-0085" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-0085"/>
        <description>Buffer overflow in Kermit communications software in HP-UX 11.0 and earlier allows local users to cause a denial of service and possibly execute arbitrary commands.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-07-11T14:41:52.000-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2008-07-15T15:26:14.600-04:00">DRAFT</status_change>
            <status_change date="2008-08-04T04:00:27.853-04:00">INTERIM</status_change>
            <status_change date="2008-08-25T04:00:23.814-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND" comment="Criteria meets Security Bulletin HPSBUX0012-135">
        <criterion comment="HP Release B.11.00" test_ref="oval:org.mitre.oval:tst:3571"/>
        <criterion negate="true" comment="Patch PHCO_22665 is installed" test_ref="oval:org.mitre.oval:tst:8497"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5638" version="1" class="vulnerability">
      <metadata>
        <title>HP-UX Running Software Distributor (SD) Remote Unauthorized Access</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-4451" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-4451"/>
        <description>Unspecified vulnerability in Software Distributor in HP-UX B.11.11 allows remote attackers to gain access via unspecified attack vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-07-07T16:38:36.000-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2008-07-14T10:52:05.929-04:00">DRAFT</status_change>
            <status_change date="2008-08-04T04:00:28.073-04:00">INTERIM</status_change>
            <status_change date="2008-08-25T04:00:24.107-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND" comment="Criteria meets Security Bulletin HPSBUX02089">
        <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
        <criteria operator="OR" comment="filesets tests">
          <criterion comment="SW-DIST.SD-AGENT is installed" test_ref="oval:org.mitre.oval:tst:8398"/>
          <criterion comment="SW-DIST.SD-CMDS is installed" test_ref="oval:org.mitre.oval:tst:8222"/>
        </criteria>
        <criterion negate="true" comment="Patch PHCO_33822 is installed" test_ref="oval:org.mitre.oval:tst:8226"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5642" version="1" class="vulnerability">
      <metadata>
        <title>HP-UX Running IPSec, Remote Denial of Service (DoS)</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-3670" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-3670"/>
        <description>Multiple unspecified vulnerabilities in the Internet Key Exchange version 1 (IKEv1) implementation in HP HP-UX B.11.00, B.11.11, and B.11.23 running IPSec, HP Jetdirect 635n IPv6/IPsec Print Server, and HP Tru64 UNIX 5.1B-3 and 5.1B-2/PK4, allow remote attackers to cause a denial of service via certain IKE packets, as demonstrated by the PROTOS ISAKMP Test Suite for IKEv1.  NOTE: due to the lack of details in the HP advisory, it is unclear which of CVE-2005-3666, CVE-2005-3667, and/or CVE-2005-3668 this issue applies to.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-07-07T16:38:36.000-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2008-07-14T10:52:05.517-04:00">DRAFT</status_change>
            <status_change date="2008-08-04T04:00:28.655-04:00">INTERIM</status_change>
            <status_change date="2008-08-25T04:00:24.856-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02076">
          <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
          <criterion comment="IPSec.IPSEC2-KRN version is less than A.02.01" test_ref="oval:org.mitre.oval:tst:8416"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02076">
          <criterion comment="HP Release B.11.00" test_ref="oval:org.mitre.oval:tst:3571"/>
          <criterion comment="IPSec.IPSEC2-KRN version is less than A.01.05.01" test_ref="oval:org.mitre.oval:tst:8397"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02076">
          <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
          <criterion comment="IPSec.IPSEC2-KRN version is less than A.02.01" test_ref="oval:org.mitre.oval:tst:8416"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5654" version="1" class="vulnerability">
      <metadata>
        <title>HP-UX Running Advanced Server/9000 for HP-UX (AS/U) RFC-Netbios, Remote Denial of Service (DoS)</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-2138" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-2138"/>
        <description>RFC-NETBIOS in HP Advanced Server/9000 B.04.05 through B.04.09, when running HP-UX 11.00 or 11.11, allows remote attackers to cause a denial of sevrice (panic) via a malformed UDP packet on port 139.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-07-09T16:48:33.000-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2008-07-14T10:52:05.143-04:00">DRAFT</status_change>
            <status_change date="2008-08-04T04:00:29.048-04:00">INTERIM</status_change>
            <status_change date="2008-08-25T04:00:25.212-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND" comment="Criteria meets Security Bulletin HPSBUX00198">
        <criteria operator="OR" comment="platforms">
          <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
          <criterion comment="HP Release B.11.00" test_ref="oval:org.mitre.oval:tst:3571"/>
        </criteria>
        <criterion comment="RFC-NETBIOS.RFC-NETBIOS is installed" test_ref="oval:org.mitre.oval:tst:8108"/>
        <criterion negate="true" comment="Patch PHNE_26988 is installed" test_ref="oval:org.mitre.oval:tst:8589"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5655" version="1" class="vulnerability">
      <metadata>
        <title>Security vulnerability in auto_parms and set_parms</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2000-1126" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2000-1126"/>
        <description>Vulnerability in auto_parms and set_parms in HP-UX 11.00 and earlier allows remote attackers to execute arbitrary commands or cause a denial of service.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-07-11T14:41:52.000-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2008-07-15T15:26:14.914-04:00">DRAFT</status_change>
            <status_change date="2008-08-04T04:00:29.580-04:00">INTERIM</status_change>
            <status_change date="2008-08-25T04:00:25.680-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX0011-130">
          <criterion comment="HP Release B.11.04" test_ref="oval:org.mitre.oval:tst:3294"/>
          <criterion negate="true" comment="Patch PHCO_22186 is installed" test_ref="oval:org.mitre.oval:tst:8505"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX0011-130">
          <criterion comment="HP Release B.11.00" test_ref="oval:org.mitre.oval:tst:3571"/>
          <criterion negate="true" comment="Patch PHCO_21993 is installed" test_ref="oval:org.mitre.oval:tst:8664"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5656" version="1" class="vulnerability">
      <metadata>
        <title>dtterm has misuse potential.</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2000-0730" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2000-0730"/>
        <description>Vulnerability in newgrp command in HP-UX 11.0 allows local users to gain privileges.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-07-11T14:41:52.000-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2008-07-15T15:26:15.821-04:00">DRAFT</status_change>
            <status_change date="2008-08-04T04:00:29.836-04:00">INTERIM</status_change>
            <status_change date="2008-08-25T04:00:26.057-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin  HPSBUX0011-128">
          <criterion comment="HP Release B.11.04" test_ref="oval:org.mitre.oval:tst:3294"/>
          <criterion negate="true" comment="Patch PHSS_22548 is installed" test_ref="oval:org.mitre.oval:tst:8491"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin  HPSBUX0011-128">
          <criterion comment="HP Release B.11.00" test_ref="oval:org.mitre.oval:tst:3571"/>
          <criterion negate="true" comment="Patch PHSS_22320 is installed" test_ref="oval:org.mitre.oval:tst:7766"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5657" version="1" class="vulnerability">
      <metadata>
        <title>HP-UX running login(1), Local Increased Privilege</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2001-1182" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-1182"/>
        <description>Vulnerability in login in HP-UX 11.00, 11.11, and 10.20 allows restricted shell users to bypass certain security checks and gain privileges.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-07-10T16:22:35.000-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2008-07-14T10:52:04.779-04:00">DRAFT</status_change>
            <status_change date="2008-08-04T04:00:30.330-04:00">INTERIM</status_change>
            <status_change date="2008-08-25T04:00:26.394-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX00160">
          <criterion comment="HP Release B.11.04" test_ref="oval:org.mitre.oval:tst:3294"/>
          <criterion comment="OS-Core.UX-CORE is installed" test_ref="oval:org.mitre.oval:tst:8585"/>
          <criterion negate="true" comment="Patch PHCO_24418 is installed" test_ref="oval:org.mitre.oval:tst:8312"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX00160">
          <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
          <criterion comment="OS-Core.UX-CORE is installed" test_ref="oval:org.mitre.oval:tst:8585"/>
          <criterion negate="true" comment="Patch PHCO_23900 is installed" test_ref="oval:org.mitre.oval:tst:8426"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX00160">
          <criterion comment="HP Release B.11.00" test_ref="oval:org.mitre.oval:tst:3571"/>
          <criterion comment="OS-Core.UX-CORE is installed" test_ref="oval:org.mitre.oval:tst:8585"/>
          <criterion negate="true" comment="Patch PHCO_24083 is installed" test_ref="oval:org.mitre.oval:tst:8681"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5673" version="1" class="vulnerability">
      <metadata>
        <title>HP-UX CIFS Server (Samba) Local Unauthorized Access, Elevated Privileges</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2001-0809" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-0809"/>
        <description>Vulnerability in CIFS/9000 Server (SAMBA) A.01.06 and earlier in HP-UX 11.0 and 11.11, when configured as a print server, allows local users to overwrite arbitrary files by modifying certain resources.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-07-09T16:48:34.000-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2008-07-14T10:52:04.173-04:00">DRAFT</status_change>
            <status_change date="2008-08-04T04:00:30.644-04:00">INTERIM</status_change>
            <status_change date="2008-08-25T04:00:26.934-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND" comment="Criteria meets Security Bulletin HPSBUX02155">
        <criteria operator="OR" comment="platforms">
          <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
          <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
        </criteria>
        <criteria operator="OR" comment="filesets tests">
          <criterion comment="CIFS-Server.CIFS-RUN version is less than A.02.03" test_ref="oval:org.mitre.oval:tst:8672"/>
          <criterion comment="CIFS-Server.CIFS-UTIL version is less than A.02.03" test_ref="oval:org.mitre.oval:tst:8606"/>
          <criterion comment="CIFS-Server.CIFS-ADMIN version is less than A.02.03" test_ref="oval:org.mitre.oval:tst:8651"/>
          <criterion comment="CIFS-Server.CIFS-LIB version is less than A.02.03" test_ref="oval:org.mitre.oval:tst:8686"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5674" version="1" class="vulnerability">
      <metadata>
        <title>HP-UX Java Web Start, Remote Unauthorized Privileged Access</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-1029" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1029"/>
        <description>The Sun Java Plugin capability in Java 2 Runtime Environment (JRE) 1.4.2_01, 1.4.2_04, and possibly earlier versions, does not properly restrict access between Javascript and Java applets during data transfer, which allows remote attackers to load unsafe classes and execute arbitrary code by using the reflection API to access private Java packages.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-07-07T16:38:37.000-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2008-07-14T10:52:03.213-04:00">DRAFT</status_change>
            <status_change date="2008-08-04T04:00:30.972-04:00">INTERIM</status_change>
            <status_change date="2008-08-25T04:00:27.301-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND" comment="Criteria meets Security Bulletin HPSBUX01214">
        <criteria operator="OR" comment="platforms">
          <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
          <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
        </criteria>
        <criteria operator="OR" comment="filesets tests">
          <criterion comment="Jre15.JRE15-IPF64 version is less than 1.5.0.01.00" test_ref="oval:org.mitre.oval:tst:8293"/>
          <criterion comment="Jre15.JRE15-COM version is less than 1.5.0.01.00" test_ref="oval:org.mitre.oval:tst:8145"/>
          <criterion comment="Jre15.JRE15-COM-DOC version is less than 1.5.0.01.00" test_ref="oval:org.mitre.oval:tst:7447"/>
          <criterion comment="Jre15.JRE15-IPF64-HS version is less than 1.5.0.01.00" test_ref="oval:org.mitre.oval:tst:8365"/>
          <criterion comment="Jre15.JRE15-PA20 version is less than 1.5.0.01.00" test_ref="oval:org.mitre.oval:tst:8128"/>
          <criterion comment="Jdk15.JDK15-COM version is less than 1.5.0.01.00" test_ref="oval:org.mitre.oval:tst:8381"/>
          <criterion comment="Jre15.JRE15-PA20-HS version is less than 1.5.0.01.00" test_ref="oval:org.mitre.oval:tst:8421"/>
          <criterion comment="Jdk15.JDK15-DEMO version is less than 1.5.0.01.00" test_ref="oval:org.mitre.oval:tst:8434"/>
          <criterion comment="Jre15.JRE15-PA20W version is less than 1.5.0.01.00" test_ref="oval:org.mitre.oval:tst:8291"/>
          <criterion comment="Jre15.JRE15-PA20W-HS version is less than 1.5.0.01.00" test_ref="oval:org.mitre.oval:tst:8237"/>
          <criterion comment="Jdk15.JDK15-IPF32 version is less than 1.5.0.01.00" test_ref="oval:org.mitre.oval:tst:8098"/>
          <criterion comment="Jdk15.JDK15-IPF64 version is less than 1.5.0.01.00" test_ref="oval:org.mitre.oval:tst:8315"/>
          <criterion comment="Jre15.JRE15-PNV2 version is less than 1.5.0.01.00" test_ref="oval:org.mitre.oval:tst:8343"/>
          <criterion comment="Jre15.JRE15-PNV2-H version is less than 1.5.0.01.00" test_ref="oval:org.mitre.oval:tst:8393"/>
          <criterion comment="Jdk15.JDK15-PA20 version is less than 1.5.0.01.00" test_ref="oval:org.mitre.oval:tst:7969"/>
          <criterion comment="Jre15.JRE15-PWV2 version is less than 1.5.0.01.00" test_ref="oval:org.mitre.oval:tst:8320"/>
          <criterion comment="Jdk15.JDK15-PA20W version is less than 1.5.0.01.00" test_ref="oval:org.mitre.oval:tst:8074"/>
          <criterion comment="Jre15.JRE15-IPF32 version is less than 1.5.0.01.00" test_ref="oval:org.mitre.oval:tst:8270"/>
          <criterion comment="Jre15.JRE15-PWV2-H version is less than 1.5.0.01.00" test_ref="oval:org.mitre.oval:tst:8403"/>
          <criterion comment="Jdk15.JDK15-PNV2 version is less than 1.5.0.01.00" test_ref="oval:org.mitre.oval:tst:8443"/>
          <criterion comment="Jdk15.JDK15-PWV2 version is less than 1.5.0.01.00" test_ref="oval:org.mitre.oval:tst:8215"/>
          <criterion comment="Jre15.JRE15-IPF32-HS version is less than 1.5.0.01.00" test_ref="oval:org.mitre.oval:tst:8250"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5683" version="1" class="vulnerability">
      <metadata>
        <title>HP-UX Running rpcbind Software, Denial of Service (DoS)</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2001-1124" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-1124"/>
        <description>rpcbind in HP-UX 11.00, 11.04 and 11.11 allows remote attackers to cause a denial of service (core dump) via a malformed RPC portmap requests, possibly related to a buffer overflow.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-07-09T16:48:34.000-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2008-07-14T10:51:58.934-04:00">DRAFT</status_change>
            <status_change date="2008-08-04T04:00:31.853-04:00">INTERIM</status_change>
            <status_change date="2008-08-25T04:00:27.882-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX00169">
          <criterion comment="HP Release B.11.04" test_ref="oval:org.mitre.oval:tst:3294"/>
          <criterion comment="rpcbind is installed" test_ref="oval:org.mitre.oval:tst:8376"/>
          <criterion negate="true" comment="Patch PHNE_25077 is installed" test_ref="oval:org.mitre.oval:tst:8583"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX00169">
          <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
          <criterion comment="rpcbind is installed" test_ref="oval:org.mitre.oval:tst:8376"/>
          <criterion negate="true" comment="Patch PHNE_24035 is installed" test_ref="oval:org.mitre.oval:tst:8547"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX00169">
          <criterion comment="HP Release B.11.00" test_ref="oval:org.mitre.oval:tst:3571"/>
          <criterion comment="rpcbind is installed" test_ref="oval:org.mitre.oval:tst:8376"/>
          <criterion negate="true" comment="Patch PHNE_24034 is installed" test_ref="oval:org.mitre.oval:tst:8301"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5690" version="1" class="vulnerability">
      <metadata>
        <title>HP-UX Running BIND v9.2.0, Remote Denial of Service (DoS)</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0364" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0364"/>
        <description>Unknown vulnerability in BIND 9.2.0 in HP-UX B.11.00, B.11.11, and B.11.23 allows remote attackers to cause a denial of service.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-07-07T16:38:36.000-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2008-07-14T10:51:58.162-04:00">DRAFT</status_change>
            <status_change date="2008-08-04T04:00:32.403-04:00">INTERIM</status_change>
            <status_change date="2008-08-25T04:00:28.211-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX01117">
          <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
          <criterion comment="BINDv920.INETSVCS-BIND version is less than B.11.11.01.006" test_ref="oval:org.mitre.oval:tst:8068"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX01117">
          <criterion comment="HP Release B.11.22" test_ref="oval:org.mitre.oval:tst:1015"/>
          <criterion comment="InternetSrvcs.INETSVCS2-RUN is installed" test_ref="oval:org.mitre.oval:tst:8005"/>
          <criterion negate="true" comment="Patch PHNE_32783 is installed" test_ref="oval:org.mitre.oval:tst:8354"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX01117">
          <criterion comment="HP Release B.11.00" test_ref="oval:org.mitre.oval:tst:3571"/>
          <criterion comment="BINDv920.INETSVCS-BIND version is less than B.11.00.01.004" test_ref="oval:org.mitre.oval:tst:8409"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX01117">
          <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
          <criterion comment="InternetSrvcs.INETSVCS2-RUN is installed" test_ref="oval:org.mitre.oval:tst:8005"/>
          <criterion negate="true" comment="Patch PHNE_32443 is installed" test_ref="oval:org.mitre.oval:tst:7978"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5694" version="1" class="vulnerability">
      <metadata>
        <title>HP-UX Running ARPA Transport, Local Denial of Service (DoS)</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-2665" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-2665"/>
        <description>Unspecified vulnerability in the Address and Routing Parameter Area (ARPA) transport software in HP-UX B.11.00, B.11.04, and B.11.11 before 20040628 allows local users to cause a denial of service via unspecified vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-07-07T16:38:37.000-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2008-07-14T10:51:57.129-04:00">DRAFT</status_change>
            <status_change date="2008-08-04T04:00:32.725-04:00">INTERIM</status_change>
            <status_change date="2008-08-25T04:00:28.595-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX01054">
          <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="Networking.NET-KRN is installed" test_ref="oval:org.mitre.oval:tst:8422"/>
            <criterion comment="Networking.NET-RUN is installed" test_ref="oval:org.mitre.oval:tst:8288"/>
            <criterion comment="Networking.NET2-KRN is installed" test_ref="oval:org.mitre.oval:tst:8224"/>
            <criterion comment="Networking.NMS2-KRN is installed" test_ref="oval:org.mitre.oval:tst:8289"/>
            <criterion comment="OS-Core.CORE2-KRN is installed" test_ref="oval:org.mitre.oval:tst:7902"/>
          </criteria>
          <criterion negate="true" comment="Patch PHNE_29887 is installed" test_ref="oval:org.mitre.oval:tst:7915"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX01054">
          <criterion comment="HP Release B.11.04" test_ref="oval:org.mitre.oval:tst:3294"/>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="Networking.NET-KRN is installed" test_ref="oval:org.mitre.oval:tst:8422"/>
            <criterion comment="Networking.NET-RUN is installed" test_ref="oval:org.mitre.oval:tst:8288"/>
            <criterion comment="Networking.NET2-KRN is installed" test_ref="oval:org.mitre.oval:tst:8224"/>
            <criterion comment="Networking.NMS2-KRN is installed" test_ref="oval:org.mitre.oval:tst:8289"/>
            <criterion comment="OS-Core.CORE2-KRN is installed" test_ref="oval:org.mitre.oval:tst:7902"/>
          </criteria>
          <criterion negate="true" comment="Patch PHNE_30905 is installed" test_ref="oval:org.mitre.oval:tst:8438"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX01054">
          <criterion comment="HP Release B.11.00" test_ref="oval:org.mitre.oval:tst:3571"/>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="Networking.NET-KRN is installed" test_ref="oval:org.mitre.oval:tst:8422"/>
            <criterion comment="Networking.NET-RUN is installed" test_ref="oval:org.mitre.oval:tst:8288"/>
            <criterion comment="Networking.NET2-KRN is installed" test_ref="oval:org.mitre.oval:tst:8224"/>
            <criterion comment="Networking.NMS2-KRN is installed" test_ref="oval:org.mitre.oval:tst:8289"/>
            <criterion comment="OS-Core.CORE2-KRN is installed" test_ref="oval:org.mitre.oval:tst:7902"/>
          </criteria>
          <criterion negate="true" comment="Patch PHNE_29473 is installed" test_ref="oval:org.mitre.oval:tst:7722"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5700" version="1" class="vulnerability">
      <metadata>
        <title>OnLineJFS sticky bit does not function properly.</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-1618" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-1618"/>
        <description>JFS (JFS3.1 and OnlineJFS) in HP-UX 10.20, 11.00, and 11.04 does not properly implement the sticky bit functionality, which could allow attackers to bypass intended restrictions on filesystems.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-07-10T16:22:36.000-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2008-07-14T10:51:52.820-04:00">DRAFT</status_change>
            <status_change date="2008-08-04T04:00:33.081-04:00">INTERIM</status_change>
            <status_change date="2008-08-25T04:00:28.948-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND" comment="Criteria meets Security Bulletin HPSBUX0210-223">
        <criterion comment="HP Release B.11.00" test_ref="oval:org.mitre.oval:tst:3571"/>
        <criterion negate="true" comment="Patch PHKL_24201 is installed" test_ref="oval:org.mitre.oval:tst:7939"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5701" version="1" class="vulnerability">
      <metadata>
        <title>HP-UX ftpd, Remote Privileged Access</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-1332" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1332"/>
        <description>Stack-based buffer overflow in the FTP daemon in HP-UX 11.11i, with the -v (debug) option enabled, allows remote attackers to execute arbitrary code via a long command request.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-07-08T17:01:37.000-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2008-07-14T10:51:52.234-04:00">DRAFT</status_change>
            <status_change date="2008-08-04T04:00:33.540-04:00">INTERIM</status_change>
            <status_change date="2008-08-25T04:00:29.191-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX01118">
          <criterion comment="HP Release B.11.00" test_ref="oval:org.mitre.oval:tst:3571"/>
          <criterion comment="WUFTP-26.INETSVCS-FTP version is less than B.11.00.01.003" test_ref="oval:org.mitre.oval:tst:8499"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX01118">
          <criterion comment="HP Release B.11.04" test_ref="oval:org.mitre.oval:tst:3294"/>
          <criterion comment="InternetSrvcs.INETSVCS-RUN is installed" test_ref="oval:org.mitre.oval:tst:8437"/>
          <criterion negate="true" comment="Patch PHNE_31034 is installed" test_ref="oval:org.mitre.oval:tst:8485"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX01118">
          <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
          <criterion comment="WUFTP-26.INETSVCS-FTP version is less than B.11.11.01.003" test_ref="oval:org.mitre.oval:tst:8411"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX01118">
          <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
          <criterion comment="InternetSrvcs.INETSVCS-RUN is installed" test_ref="oval:org.mitre.oval:tst:8437"/>
          <criterion negate="true" comment="Patch PHNE_29461 is installed" test_ref="oval:org.mitre.oval:tst:8461"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX01118">
          <criterion comment="HP Release B.11.22" test_ref="oval:org.mitre.oval:tst:1015"/>
          <criterion comment="InternetSrvcs.INETSVCS2-RUN is installed" test_ref="oval:org.mitre.oval:tst:8367"/>
          <criterion negate="true" comment="Patch PHNE_29462 is installed" test_ref="oval:org.mitre.oval:tst:8342"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX01118">
          <criterion comment="HP Release B.11.00" test_ref="oval:org.mitre.oval:tst:3571"/>
          <criterion comment="InternetSrvcs.INETSVCS-RUN is installed" test_ref="oval:org.mitre.oval:tst:8437"/>
          <criterion negate="true" comment="Patch PHNE_29460 is installed" test_ref="oval:org.mitre.oval:tst:8395"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5702" version="1" class="vulnerability">
      <metadata>
        <title>HP-UX Local Denial of Service (DoS)</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-2551" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-2551"/>
        <description>Unspecified vulnerability in the kernel in HP-UX B.11.00 allows local users to cause an unspecified denial of service via unknown vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-07-07T16:38:36.000-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2008-07-14T10:51:51.534-04:00">DRAFT</status_change>
            <status_change date="2008-08-04T04:00:33.911-04:00">INTERIM</status_change>
            <status_change date="2008-08-25T04:00:29.589-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02120">
          <criterion comment="HP Release B.11.04" test_ref="oval:org.mitre.oval:tst:3294"/>
          <criterion comment="OS-Core.CORE2-KRN is installed" test_ref="oval:org.mitre.oval:tst:7902"/>
          <criterion negate="true" comment="Patch PHKL_34940 is installed" test_ref="oval:org.mitre.oval:tst:8324"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02120">
          <criterion comment="HP Release B.11.00" test_ref="oval:org.mitre.oval:tst:3571"/>
          <criterion comment="OS-Core.CORE2-KRN is installed" test_ref="oval:org.mitre.oval:tst:7902"/>
          <criterion negate="true" comment="Patch PHKL_34406 is installed" test_ref="oval:org.mitre.oval:tst:8359"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5709" version="1" class="vulnerability">
      <metadata>
        <title>HP-UX Running ftpd Remote Denial of Service (DoS)</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2993" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2993"/>
        <description>Unspecified vulnerability in the FTP Daemon (ftpd) for HP Tru64 UNIX 4.0F PK8 and other versions up to HP Tru64 UNIX 5.1B-3, and HP-UX B.11.00, B.11.04, B.11.11, and B.11.23, allows remote authenticated users to cause a denial of service (hang).</description>
        <oval_repository>
          <dates>
            <submitted date="2008-07-08T17:01:37.000-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2008-07-14T10:51:51.032-04:00">DRAFT</status_change>
            <status_change date="2008-08-04T04:00:34.272-04:00">INTERIM</status_change>
            <status_change date="2008-08-25T04:00:29.875-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02092">
          <criterion comment="HP Release B.11.00" test_ref="oval:org.mitre.oval:tst:3571"/>
          <criterion comment="WUFTP-26.INETSVCS-FTP version is less than B.11.00.01.005" test_ref="oval:org.mitre.oval:tst:7619"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02092">
          <criterion comment="HP Release B.11.04" test_ref="oval:org.mitre.oval:tst:3294"/>
          <criterion comment="InternetSrvcs.INETSVCS-RUN is installed" test_ref="oval:org.mitre.oval:tst:8437"/>
          <criterion negate="true" comment="Patch PHNE_34077 is installed" test_ref="oval:org.mitre.oval:tst:7658"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02092">
          <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
          <criterion comment="WUFTP-26.INETSVCS-FTP version is less than B.11.11.01.006" test_ref="oval:org.mitre.oval:tst:8501"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02092">
          <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
          <criterion comment="InternetSrvcs.INETSVCS2-RUN is installed" test_ref="oval:org.mitre.oval:tst:8367"/>
          <criterion negate="true" comment="Patch PHNE_33414 is installed" test_ref="oval:org.mitre.oval:tst:8565"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02092">
          <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
          <criterion comment="InternetSrvcs.INETSVCS-RUN is installed" test_ref="oval:org.mitre.oval:tst:8437"/>
          <criterion negate="true" comment="Patch PHNE_33412 is installed" test_ref="oval:org.mitre.oval:tst:8556"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02092">
          <criterion comment="HP Release B.11.00" test_ref="oval:org.mitre.oval:tst:3571"/>
          <criterion comment="InternetSrvcs.INETSVCS-RUN is installed" test_ref="oval:org.mitre.oval:tst:8437"/>
          <criterion negate="true" comment="Patch PHNE_33406 is installed" test_ref="oval:org.mitre.oval:tst:8502"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5727" version="1" class="vulnerability">
      <metadata>
        <title>A TCP SYN packet with target host's address as both source and destination can cause system hangs.</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-1999-0016" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-0016"/>
        <description>Land IP denial of service.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-07-11T14:41:52.000-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2008-07-15T15:26:19.348-04:00">DRAFT</status_change>
            <status_change date="2008-08-04T04:00:34.904-04:00">INTERIM</status_change>
            <status_change date="2008-08-25T04:00:30.261-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND" comment="Criteria meets Security Bulletin HPSBUX9801-076">
        <criterion comment="HP Release B.11.00" test_ref="oval:org.mitre.oval:tst:3571"/>
        <criterion negate="true" comment="Patch PHNE_14017 is installed" test_ref="oval:org.mitre.oval:tst:8302"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5728" version="1" class="vulnerability">
      <metadata>
        <title>/opt/audio/bin/Aserver can be used to gain root access.</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2000-0078" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2000-0078"/>
        <description>The June 1999 version of the HP-UX aserver program allows local users to gain privileges by specifying an alternate PATH which aserver uses to find the awk command.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-07-11T14:41:52.000-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2008-07-15T15:26:16.740-04:00">DRAFT</status_change>
            <status_change date="2008-08-04T04:00:35.146-04:00">INTERIM</status_change>
            <status_change date="2008-08-25T04:00:30.491-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND" comment="Criteria meets Security Bulletin HPSBUX0001-108">
        <criterion comment="HP Release B.11.00" test_ref="oval:org.mitre.oval:tst:3571"/>
        <criterion negate="true" comment="Patch PHSS_21663 is installed" test_ref="oval:org.mitre.oval:tst:8307"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5730" version="1" class="vulnerability">
      <metadata>
        <title>The lpspool subsystem has various security oriented defects.</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2000-0966" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2000-0966"/>
        <description>Buffer overflows in lpspooler in the fileset PrinterMgmt.LP-SPOOL of HP-UX 11.0 and earlier allows local users to gain privileges.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-07-11T14:41:52.000-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2008-07-15T15:26:15.206-04:00">DRAFT</status_change>
            <status_change date="2008-08-04T04:00:35.403-04:00">INTERIM</status_change>
            <status_change date="2008-08-25T04:00:30.720-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND" comment="Criteria meets Security Bulletin HPSBUX0010-125">
        <criterion comment="HP Release B.11.00" test_ref="oval:org.mitre.oval:tst:3571"/>
        <criterion negate="true" comment="Patch PHCO_22365 is installed" test_ref="oval:org.mitre.oval:tst:8486"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5735" version="1" class="vulnerability">
      <metadata>
        <title>The NSAPI plugin versions of the TGA and the Java Servlet proxy demonstrate high CPU utilization under certain conditions.</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2000-0965" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2000-0965"/>
        <description>The NSAPI plugins for TGA and the Java Servlet proxy in HP-UX VVOS 10.24 and 11.04 allows an attacker to cause a denial of service (high CPU utilization).</description>
        <oval_repository>
          <dates>
            <submitted date="2008-07-11T14:41:52.000-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2008-07-15T15:26:15.467-04:00">DRAFT</status_change>
            <status_change date="2008-08-04T04:00:35.742-04:00">INTERIM</status_change>
            <status_change date="2008-08-25T04:00:30.960-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND" comment="Criteria meets Security Bulletin HPSBUX0010-124">
        <criterion comment="HP Release B.11.04" test_ref="oval:org.mitre.oval:tst:3294"/>
        <criterion negate="true" comment="Patch PHSS_22296 is installed" test_ref="oval:org.mitre.oval:tst:8633"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5743" version="1" class="vulnerability">
      <metadata>
        <title>A TCP SYN packet with target host's address as both source and destination can cause system hangs.</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-1999-0104" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-0104"/>
        <description>A later variation on the Teardrop IP denial of service attack, a.k.a. Teardrop-2.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-07-11T14:41:52.000-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2008-07-15T15:26:19.052-04:00">DRAFT</status_change>
            <status_change date="2008-08-04T04:00:36.058-04:00">INTERIM</status_change>
            <status_change date="2008-08-25T04:00:31.216-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND" comment="Criteria meets Security Bulletin HPSBUX9801-076">
        <criterion comment="HP Release B.11.00" test_ref="oval:org.mitre.oval:tst:3571"/>
        <criterion negate="true" comment="Patch PHNE_14017 is installed" test_ref="oval:org.mitre.oval:tst:8302"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5746" version="1" class="vulnerability">
      <metadata>
        <title>HP-UX Kernel Local Denial of Service (DoS)</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-3201" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-3201"/>
        <description>Unspecified vulnerability in the kernel in HP-UX B.11.00, B.11.11, and B.11.23 allows local users to cause an unspecified denial of service via unknown vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-07-07T16:38:36.000-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2008-07-14T10:51:43.427-04:00">DRAFT</status_change>
            <status_change date="2008-08-04T04:00:36.260-04:00">INTERIM</status_change>
            <status_change date="2008-08-25T04:00:31.485-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02127">
          <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
          <criterion comment="OS-Core.CORE2-KRN is installed" test_ref="oval:org.mitre.oval:tst:7902"/>
          <criterion negate="true" comment="Patch PHKL_34193 is installed" test_ref="oval:org.mitre.oval:tst:8306"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02127">
          <criterion comment="HP Release B.11.00" test_ref="oval:org.mitre.oval:tst:3571"/>
          <criterion comment="OS-Core.CORE2-KRN is installed" test_ref="oval:org.mitre.oval:tst:7902"/>
          <criterion negate="true" comment="Patch PHKL_34192 is installed" test_ref="oval:org.mitre.oval:tst:8418"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02127">
          <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
          <criterion comment="OS-Core.CORE2-KRN is installed" test_ref="oval:org.mitre.oval:tst:7902"/>
          <criterion negate="true" comment="Patch PHKL_34194 is installed" test_ref="oval:org.mitre.oval:tst:8384"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5747" version="1" class="vulnerability">
      <metadata>
        <title>HP-UX running X.25 Local Denial of Service (Dos)</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-4820" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-4820"/>
        <description>Unspecified vulnerability in X.25 on HP-UX B.11.00, B.11.11, and B.11.23 allows local users to cause an unspecified denial of service via unknown vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-07-10T16:22:35.000-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <modified comment="Criteria meets HP Security Bulletin HPSBUX02126" date="2008-07-14T10:21:00.896-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </modified>
            <status_change date="2008-08-04T04:00:36.637-04:00">INTERIM</status_change>
            <status_change date="2008-08-25T04:00:31.779-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02126">
          <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="SX25-HPerf.SX25-HPERF-COM is installed" test_ref="oval:org.mitre.oval:tst:8693"/>
            <criterion comment="SX25-HPerf.COM-ALIB is installed" test_ref="oval:org.mitre.oval:tst:8654"/>
            <criterion comment="SX25-HPerf.IP-ALIB is installed" test_ref="oval:org.mitre.oval:tst:8350"/>
            <criterion comment="SX25-HPerf.SX25-HPERF-PAD is installed" test_ref="oval:org.mitre.oval:tst:7703"/>
            <criterion comment="SYNC-WAN.SYNC-ALIB is installed" test_ref="oval:org.mitre.oval:tst:7910"/>
          </criteria>
          <criterion negate="true" comment="Patch PHNE_34999 is installed" test_ref="oval:org.mitre.oval:tst:8700"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02126">
          <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="SX25-HPerf.SX25-HPERF-IP is installed" test_ref="oval:org.mitre.oval:tst:8433"/>
            <criterion comment="SX25-HPerf.SX25-HPERF-PA is installed" test_ref="oval:org.mitre.oval:tst:8126"/>
            <criterion comment="SX25-HPerf.COM-64SLIB is installed" test_ref="oval:org.mitre.oval:tst:8235"/>
            <criterion comment="SX25-HPerf.SX25-HPERF-SAM is installed" test_ref="oval:org.mitre.oval:tst:8648"/>
            <criterion comment="SYNC-WAN.SYNC-ALIB is installed" test_ref="oval:org.mitre.oval:tst:7910"/>
            <criterion comment="SX25-HPerf.SX25-HPERF-PAD is installed" test_ref="oval:org.mitre.oval:tst:7703"/>
            <criterion comment="SX25-HPerf.SX25-HPERF-COM is installed" test_ref="oval:org.mitre.oval:tst:8693"/>
            <criterion comment="SX25-HPerf.PA-ALIB is installed" test_ref="oval:org.mitre.oval:tst:8683"/>
            <criterion comment="SX25-HPerf.COM-ALIB is installed" test_ref="oval:org.mitre.oval:tst:8654"/>
            <criterion comment="SYNC-WAN.SYNC-COM is installed" test_ref="oval:org.mitre.oval:tst:8190"/>
            <criterion comment="SX25-HPerf.SX25-SNMP is installed" test_ref="oval:org.mitre.oval:tst:8689"/>
            <criterion comment="SX25-HPerf.SX25-HPERF-MAN is installed" test_ref="oval:org.mitre.oval:tst:7710"/>
            <criterion comment="SX25-HPerf.IP-ALIB is installed" test_ref="oval:org.mitre.oval:tst:8350"/>
          </criteria>
          <criterion negate="true" comment="Patch PHNE_34988 is installed" test_ref="oval:org.mitre.oval:tst:8448"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02126">
          <criterion comment="HP Release B.11.00" test_ref="oval:org.mitre.oval:tst:3571"/>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="SX25-HPerf.SX25-SNMP is installed" test_ref="oval:org.mitre.oval:tst:8689"/>
            <criterion comment="SX25-HPerf.SX25-HPERF-MAN is installed" test_ref="oval:org.mitre.oval:tst:7710"/>
            <criterion comment="SX25-HPerf.SX25-HPERF-PA is installed" test_ref="oval:org.mitre.oval:tst:8126"/>
            <criterion comment="SYNC-WAN.SYNC-32ALIB is installed" test_ref="oval:org.mitre.oval:tst:8483"/>
            <criterion comment="SYNC-WAN.SYNC-64ALIB is installed" test_ref="oval:org.mitre.oval:tst:8146"/>
            <criterion comment="SX25-HPerf.COM-32ALIB is installed" test_ref="oval:org.mitre.oval:tst:8645"/>
            <criterion comment="SYNC-WAN.SYNC-COM is installed" test_ref="oval:org.mitre.oval:tst:8190"/>
            <criterion comment="SX25-HPerf.COM-64ALIB is installed" test_ref="oval:org.mitre.oval:tst:8678"/>
            <criterion comment="SX25-HPerf.IP-32ALIB is installed" test_ref="oval:org.mitre.oval:tst:8619"/>
            <criterion comment="SX25-HPerf.IP-64ALIB is installed" test_ref="oval:org.mitre.oval:tst:8669"/>
            <criterion comment="SX25-HPerf.PA-32ALIB is installed" test_ref="oval:org.mitre.oval:tst:8522"/>
            <criterion comment="SX25-HPerf.PA-64ALIB is installed" test_ref="oval:org.mitre.oval:tst:8192"/>
            <criterion comment="SX25-HPerf.SX25-HPERF-PAD is installed" test_ref="oval:org.mitre.oval:tst:7703"/>
            <criterion comment="SX25-HPerf.SX25-HPERF-COM is installed" test_ref="oval:org.mitre.oval:tst:8693"/>
            <criterion comment="SX25-HPerf.SX25-HPERF-IP is installed" test_ref="oval:org.mitre.oval:tst:8433"/>
            <criterion comment="SX25-HPerf.SX25-HPERF-SAM is installed" test_ref="oval:org.mitre.oval:tst:8648"/>
          </criteria>
          <criterion negate="true" comment="Patch PHNE_34009 is installed" test_ref="oval:org.mitre.oval:tst:8621"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5752" version="1" class="vulnerability">
      <metadata>
        <title>The SharedX program recserv is vulnerable to a denial of service attack.</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-1999-0779" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-0779"/>
        <description>Denial of service in HP-UX SharedX recserv program.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-07-11T14:41:52.000-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2008-07-15T15:26:18.615-04:00">DRAFT</status_change>
            <status_change date="2008-08-04T04:00:37.217-04:00">INTERIM</status_change>
            <status_change date="2008-08-25T04:00:32.398-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND" comment="Criteria meets Security Bulletin HPSBUX9810-086">
        <criterion comment="HP Release B.11.00" test_ref="oval:org.mitre.oval:tst:3571"/>
        <criterion negate="true" comment="Patch PHSS_16649 is installed" test_ref="oval:org.mitre.oval:tst:8765"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5758" version="1" class="vulnerability">
      <metadata>
        <title>HP-UX Running sort, Remote Unauthorized Access, Denial of Service (DoS)</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-1356" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-1356"/>
        <description>The "file handling" in sort in HP-UX 10.01 through 10.20, and 11.00 through 11.11 is "incorrect," which allows attackers to gain access or cause a denial of service via unknown vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-07-08T17:01:38.000-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2008-07-14T10:51:40.640-04:00">DRAFT</status_change>
            <status_change date="2008-08-04T04:00:37.429-04:00">INTERIM</status_change>
            <status_change date="2008-08-25T04:00:32.634-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX00237">
          <criterion comment="HP Release B.11.04" test_ref="oval:org.mitre.oval:tst:3294"/>
          <criterion comment="OS-Core.UX-CORE is installed" test_ref="oval:org.mitre.oval:tst:8271"/>
          <criterion negate="true" comment="Patch PHCO_28467 is installed" test_ref="oval:org.mitre.oval:tst:8407"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX00237">
          <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
          <criterion comment="OS-Core.UX-CORE is installed" test_ref="oval:org.mitre.oval:tst:8271"/>
          <criterion negate="true" comment="Patch PHCO_25918 is installed" test_ref="oval:org.mitre.oval:tst:7899"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX00237">
          <criterion comment="HP Release B.11.00" test_ref="oval:org.mitre.oval:tst:3571"/>
          <criterion comment="OS-Core.UX-CORE is installed" test_ref="oval:org.mitre.oval:tst:8271"/>
          <criterion negate="true" comment="Patch PHCO_27565 is installed" test_ref="oval:org.mitre.oval:tst:8209"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5760" version="1" class="vulnerability">
      <metadata>
        <title>HP-UX running TCP/IP Remote Denial of Service (DoS)</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-4316" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-4316"/>
        <description>HP-UX B.11.00, B.11.04, B.11.11, and B.11.23 allows remote attackers to cause a denial of service via a "Rose Attack" that involves sending a subset of small IP fragments that do not form a complete, larger packet.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-07-07T16:38:36.000-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2008-07-14T10:51:39.974-04:00">DRAFT</status_change>
            <status_change date="2008-08-04T04:00:37.771-04:00">INTERIM</status_change>
            <status_change date="2008-08-25T04:00:33.024-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02087">
          <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
          <criterion comment="Streams.STREAMS-KRN is installed" test_ref="oval:org.mitre.oval:tst:8347"/>
          <criterion negate="true" comment="Patch PHNE_34131 is installed" test_ref="oval:org.mitre.oval:tst:8382"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02087">
          <criterion comment="HP Release B.11.04" test_ref="oval:org.mitre.oval:tst:3294"/>
          <criterion comment="Networking.NET-KRN is installed" test_ref="oval:org.mitre.oval:tst:8422"/>
          <criterion negate="true" comment="Patch PHNE_33427 is installed" test_ref="oval:org.mitre.oval:tst:8100"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02087">
          <criterion comment="HP Release B.11.00" test_ref="oval:org.mitre.oval:tst:3571"/>
          <criterion comment="Streams.STREAMS-KRN is installed" test_ref="oval:org.mitre.oval:tst:8347"/>
          <criterion negate="true" comment="Patch PHNE_30161 is installed" test_ref="oval:org.mitre.oval:tst:8396"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02087">
          <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
          <criterion comment="Streams.STREAMS2-KRN is installed" test_ref="oval:org.mitre.oval:tst:8262"/>
          <criterion negate="true" comment="Patch PHKL_31500 is installed" test_ref="oval:org.mitre.oval:tst:8386"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5763" version="1" class="vulnerability">
      <metadata>
        <title>An rlpdaemon logic flaw vulnerability has been reported to us that may allow a remote or local attacker to execute arbitrary code with superuser privilege.</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2001-1198" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-1198"/>
        <description>RLPDaemon in HP-UX 10.20 and 11.0 allows local users to overwrite arbitrary files and gain privileges by specifying the target file in the -L option.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-07-10T16:22:36.000-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2008-07-14T10:51:39.112-04:00">DRAFT</status_change>
            <status_change date="2008-08-04T04:00:39.285-04:00">INTERIM</status_change>
            <status_change date="2008-08-25T04:00:33.762-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX0111-176">
          <criterion comment="HP Release B.11.00" test_ref="oval:org.mitre.oval:tst:3571"/>
          <criterion negate="true" comment="Patch PHCO_25110 is installed" test_ref="oval:org.mitre.oval:tst:8611"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX0111-176">
          <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
          <criterion negate="true" comment="Patch PHCO_25111 is installed" test_ref="oval:org.mitre.oval:tst:8629"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5765" version="1" class="vulnerability">
      <metadata>
        <title>The Xserver was built incorrectly for HP-UX 11.22.</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-1098" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-1098"/>
        <description>The Xserver for HP-UX 11.22 was not properly built, which introduced a vulnerability that allows local users to gain privileges.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-07-10T16:22:36.000-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2008-07-14T10:51:38.764-04:00">DRAFT</status_change>
            <status_change date="2008-08-04T04:00:39.717-04:00">INTERIM</status_change>
            <status_change date="2008-08-25T04:00:34.065-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND" comment="Criteria meets Security Bulletin HPSBUX0301-238">
        <criterion comment="HP Release B.11.22" test_ref="oval:org.mitre.oval:tst:1015"/>
        <criterion negate="true" comment="Patch PHSS_25291 is installed" test_ref="oval:org.mitre.oval:tst:8261"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5775" version="1" class="vulnerability">
      <metadata>
        <title>HP-UX Ignite-UX, Remote Unauthorized Access</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0952" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0952"/>
        <description>HP-UX B.11.00 through B.11.23, when running Ignite-UX and using the add_new_client command, causes the TFTP server to set world-writable permissions on part of the directory tree, which allows remote attackers to modify data or cause disk consumption.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-07-07T16:38:38.000-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2008-07-14T10:51:38.058-04:00">DRAFT</status_change>
            <status_change date="2008-08-04T04:00:39.985-04:00">INTERIM</status_change>
            <status_change date="2008-08-25T04:00:34.341-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX01219">
          <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="Ignite-UX.BOOT-KRN-11-11 version is less than C.6.2.241" test_ref="oval:org.mitre.oval:tst:8234"/>
            <criterion comment="Ignite-UX.BOOT-SERVICES version is less than C.6.2.241" test_ref="oval:org.mitre.oval:tst:8284"/>
            <criterion comment="Ignite-UX.FILE-SRV-11-11 version is less than C.6.2.241" test_ref="oval:org.mitre.oval:tst:8218"/>
            <criterion comment="Ignite-UX.MGMT-TOOLS version is less than C.6.2.241" test_ref="oval:org.mitre.oval:tst:8436"/>
            <criterion comment="Ignite-UX.IGNITE version is less than C.6.2.241" test_ref="oval:org.mitre.oval:tst:7501"/>
            <criterion comment="Ignite-UX.OBAM-RUN version is less than C.6.2.241" test_ref="oval:org.mitre.oval:tst:8109"/>
            <criterion comment="Ignite-UX.RECOVERY version is less than C.6.2.241" test_ref="oval:org.mitre.oval:tst:8500"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX01219">
          <criterion comment="HP Release B.11.00" test_ref="oval:org.mitre.oval:tst:3571"/>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="Ignite-UX.BOOT-KRN-11-00 version is less than C.6.2.241" test_ref="oval:org.mitre.oval:tst:8444"/>
            <criterion comment="Ignite-UX.BOOT-SERVICES version is less than C.6.2.241" test_ref="oval:org.mitre.oval:tst:8284"/>
            <criterion comment="Ignite-UX.FILE-SRV-11-00 version is less than C.6.2.241" test_ref="oval:org.mitre.oval:tst:8296"/>
            <criterion comment="Ignite-UX.MGMT-TOOLS version is less than C.6.2.241" test_ref="oval:org.mitre.oval:tst:8436"/>
            <criterion comment="Ignite-UX.IGNITE version is less than C.6.2.241" test_ref="oval:org.mitre.oval:tst:7501"/>
            <criterion comment="Ignite-UX.OBAM-RUN version is less than C.6.2.241" test_ref="oval:org.mitre.oval:tst:8109"/>
            <criterion comment="Ignite-UX.RECOVERY version is less than C.6.2.241" test_ref="oval:org.mitre.oval:tst:8500"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX01219">
          <criterion comment="HP Release B.11.22" test_ref="oval:org.mitre.oval:tst:1015"/>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="Ignite-UX.BOOT-COMMON-IA version is less than C.6.2.241" test_ref="oval:org.mitre.oval:tst:8400"/>
            <criterion comment="Ignite-UX.BOOT-KRN-11-22 version is less than C.6.2.241" test_ref="oval:org.mitre.oval:tst:8463"/>
            <criterion comment="Ignite-UX.BOOT-SERVICES version is less than C.6.2.241" test_ref="oval:org.mitre.oval:tst:8284"/>
            <criterion comment="Ignite-UX.FILESRV-1122IA version is less than C.6.2.241" test_ref="oval:org.mitre.oval:tst:8487"/>
            <criterion comment="Ignite-UX.CFG-FILE-11-22 version is less than C.6.2.241" test_ref="oval:org.mitre.oval:tst:7502"/>
            <criterion comment="Ignite-UX.MGMT-TOOLS version is less than C.6.2.241" test_ref="oval:org.mitre.oval:tst:8436"/>
            <criterion comment="Ignite-UX.IGNITE version is less than C.6.2.241" test_ref="oval:org.mitre.oval:tst:7501"/>
            <criterion comment="Ignite-UX.OBAM-RUN version is less than C.6.2.241" test_ref="oval:org.mitre.oval:tst:8109"/>
            <criterion comment="Ignite-UX.RECOVERY version is less than C.6.2.241" test_ref="oval:org.mitre.oval:tst:8500"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX01219">
          <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="Ignite-UX.BOOT-COMMON-IA version is less than C.6.2.241" test_ref="oval:org.mitre.oval:tst:8400"/>
            <criterion comment="Ignite-UX.BOOT-KRN-11-23 version is less than C.6.2.241" test_ref="oval:org.mitre.oval:tst:8239"/>
            <criterion comment="Ignite-UX.BOOT-SERVICES version is less than C.6.2.241" test_ref="oval:org.mitre.oval:tst:8284"/>
            <criterion comment="Ignite-UX.MGMT-TOOLS version is less than C.6.2.241" test_ref="oval:org.mitre.oval:tst:8436"/>
            <criterion comment="Ignite-UX.IGNITE version is less than C.6.2.241" test_ref="oval:org.mitre.oval:tst:7501"/>
            <criterion comment="Ignite-UX.OBAM-RUN version is less than C.6.2.241" test_ref="oval:org.mitre.oval:tst:8109"/>
            <criterion comment="Ignite-UX.RECOVERY version is less than C.6.2.241" test_ref="oval:org.mitre.oval:tst:8500"/>
            <criterion comment="Ignite-UX.FILE-SRV-11-23 version is less than C.6.2.241" test_ref="oval:org.mitre.oval:tst:8327"/>
            <criterion comment="Ignite-UX.BOOT-COMMON-PA version is less than C.6.2.241" test_ref="oval:org.mitre.oval:tst:7883"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5783" version="1" class="vulnerability">
      <metadata>
        <title>Buffer overflows in Software Distributor (SD) commands.</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-1999-0688" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-0688"/>
        <description>Buffer overflows in HP Software Distributor (SD) for HPUX 10.x and 11.x.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-07-11T14:41:52.000-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2008-07-15T15:26:17.742-04:00">DRAFT</status_change>
            <status_change date="2008-08-04T04:00:40.631-04:00">INTERIM</status_change>
            <status_change date="2008-08-25T04:00:34.885-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND" comment="Criteria meets Security Bulletin HPSBUX9907-101">
        <criterion comment="HP Release B.11.00" test_ref="oval:org.mitre.oval:tst:3571"/>
        <criterion negate="true" comment="Patch PHCO_18183 is installed" test_ref="oval:org.mitre.o