<?xml version="1.0" encoding="UTF-8"?>
<oval_definitions xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-definitions-5 oval-definitions-schema.xsd http://oval.mitre.org/XMLSchema/oval-definitions-5#aix aix-definitions-schema.xsd http://oval.mitre.org/XMLSchema/oval-common-5 oval-common-schema.xsd" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:oval="http://oval.mitre.org/XMLSchema/oval-common-5" xmlns:oval-def="http://oval.mitre.org/XMLSchema/oval-definitions-5">
  <generator>
    <oval:product_name>The OVAL Repository</oval:product_name>
    <oval:schema_version>5.6</oval:schema_version>
    <oval:timestamp>2009-11-20T04:32:00.184-05:00</oval:timestamp>
  </generator>
  <definitions>
    <definition id="oval:org.mitre.oval:def:5796" version="1" class="vulnerability">
      <metadata>
        <title>IBM AIX 'piox25.c/piox25remote.sh' Local Buffer Overflow Vulnerability</title>
        <affected family="unix">
          <platform>IBM AIX 4.3</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-0509" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-0509"/>
        <description>Multiple buffer overflows in IBM AIX 4.3 allow remote attackers to cause a denial of service (crash) or possibly gain privileges via a long argument to (1) piox25, related to piox25.c; or (2) piox25remote, related to piox25remote.sh.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-08-11T15:10:44.000-05:00">
              <contributor organization="Hewlett-Packard">Yuzheng Zhou</contributor>
            </submitted>
            <status_change date="2008-08-14T15:02:55.131-04:00">DRAFT</status_change>
            <status_change date="2008-09-01T04:01:08.700-04:00">INTERIM</status_change>
            <status_change date="2008-09-22T04:00:31.939-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <extend_definition comment="IBM AIX 4.3 is installed" definition_ref="oval:org.mitre.oval:def:4980"/>
        <criterion negate="true" comment="All filesets for APAR IZ13739 are installed" test_ref="oval:org.mitre.oval:tst:8896"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:4980" version="1" class="inventory">
      <metadata>
        <title>IBM AIX 4.3 is installed</title>
        <affected family="unix">
          <platform>IBM AIX 4.3</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/o:ibm:aix:4.3"/>
        <description>The operating system installed on the system is IBM AIX 4.3.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-08-11T12:00:00.000-04:00">
              <contributor organization="Hewlett-Packard">Yuzheng Zhou</contributor>
            </submitted>
            <status_change date="2008-08-14T15:02:54.651-04:00">DRAFT</status_change>
            <status_change date="2008-09-01T04:00:50.865-04:00">INTERIM</status_change>
            <status_change date="2008-09-22T04:00:15.272-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="IBM AIX version is greater than or equal 4.3.0.0" test_ref="oval:org.mitre.oval:tst:8932"/>
        <criterion comment="IBM AIX version is less than 5.0.0.0" test_ref="oval:org.mitre.oval:tst:8777"/>
      </criteria>
    </definition>
  </definitions>
  <tests>
    <oslevel_test id="oval:org.mitre.oval:tst:8932" version="1" comment="IBM AIX version is greater than or equal 4.3.0.0" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#aix">
      <object object_ref="oval:org.mitre.oval:obj:6309"/>
      <state state_ref="oval:org.mitre.oval:ste:4181"/>
    </oslevel_test>
    <oslevel_test id="oval:org.mitre.oval:tst:8777" version="1" comment="IBM AIX version is less than 5.0.0.0" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#aix">
      <object object_ref="oval:org.mitre.oval:obj:6309"/>
      <state state_ref="oval:org.mitre.oval:ste:4275"/>
    </oslevel_test>
    <fix_test id="oval:org.mitre.oval:tst:8896" version="1" comment="All filesets for APAR IZ13739 are installed" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#aix">
      <object object_ref="oval:org.mitre.oval:obj:6457"/>
      <state state_ref="oval:org.mitre.oval:ste:4244"/>
    </fix_test>
  </tests>
  <objects>
    <oslevel_object id="oval:org.mitre.oval:obj:6309" version="1" comment="The single oslevel object." xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#aix"/>
    <fix_object id="oval:org.mitre.oval:obj:6457" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#aix">
      <apar_number>IZ13739</apar_number>
    </fix_object>
  </objects>
  <states>
    <oslevel_state id="oval:org.mitre.oval:ste:4181" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#aix">
      <maintenance_level operation="greater than or equal" datatype="version">4300-00</maintenance_level>
    </oslevel_state>
    <oslevel_state id="oval:org.mitre.oval:ste:4275" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#aix">
      <maintenance_level operation="less than" datatype="version">5000-00</maintenance_level>
    </oslevel_state>
    <fix_state id="oval:org.mitre.oval:ste:4244" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#aix">
      <installation_status>ALL_INSTALLED</installation_status>
    </fix_state>
  </states>
</oval_definitions>