<?xml version="1.0" encoding="UTF-8"?>
<oval_definitions xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-definitions-5 oval-definitions-schema.xsd http://oval.mitre.org/XMLSchema/oval-definitions-5#linux linux-definitions-schema.xsd http://oval.mitre.org/XMLSchema/oval-common-5 oval-common-schema.xsd http://oval.mitre.org/XMLSchema/oval-definitions-5#unix unix-definitions-schema.xsd" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:oval="http://oval.mitre.org/XMLSchema/oval-common-5" xmlns:oval-def="http://oval.mitre.org/XMLSchema/oval-definitions-5">
  <generator>
    <oval:product_name>The OVAL Repository</oval:product_name>
    <oval:schema_version>5.9</oval:schema_version>
    <oval:timestamp>2012-01-27T05:10:56.711-05:00</oval:timestamp>
  </generator>
  <definitions>
    <definition id="oval:org.mitre.oval:def:9999" version="3" class="vulnerability">
      <metadata>
        <title>Race condition in backend/ctrl.c in KDM in KDE Software Compilation (SC) 2.2.0 through 4.4.2 allows local users to change the permissions of arbitrary files, and consequently gain privileges, by blocking the removal of a certain directory that contains a control socket, related to improper interaction with ksm.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0436" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0436"/>
        <description>Race condition in backend/ctrl.c in KDM in KDE Software Compilation (SC) 2.2.0 through 4.4.2 allows local users to change the permissions of arbitrary files, and consequently gain privileges, by blocking the removal of a certain directory that contains a control socket, related to improper interaction with ksm.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:22:35.831-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:15:27.675-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:16:36.709-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <criteria operator="OR">
            <criterion comment="kdebase is earlier than 6:3.3.1-13.el4_8.1" test_ref="oval:org.mitre.oval:tst:39507"/>
            <criterion comment="kdebase-devel is earlier than 6:3.3.1-13.el4_8.1" test_ref="oval:org.mitre.oval:tst:40464"/>
          </criteria>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criteria operator="OR">
            <criterion comment="kdebase is earlier than 6:3.5.4-21.el5_5.1" test_ref="oval:org.mitre.oval:tst:40335"/>
            <criterion comment="kdebase-devel is earlier than 6:3.5.4-21.el5_5.1" test_ref="oval:org.mitre.oval:tst:40374"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9998" version="3" class="vulnerability">
      <metadata>
        <title>Heap-based buffer overflow in RealNetworks RealPlayer 10, RealPlayer 10.5 6.0.12.1040 through 6.0.12.1741, RealPlayer 11 11.0.0 through 11.0.4, RealPlayer Enterprise, Mac RealPlayer 10 and 10.1, Linux RealPlayer 10, and Helix Player 10.x allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a compressed GIF file, related to gifcodec.cpp and gifimage.cpp.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-4245" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4245"/>
        <description>Heap-based buffer overflow in RealNetworks RealPlayer 10, RealPlayer 10.5 6.0.12.1040 through 6.0.12.1741, RealPlayer 11 11.0.0 through 11.0.4, RealPlayer Enterprise, Mac RealPlayer 10 and 10.1, Linux RealPlayer 10, and Helix Player 10.x allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a compressed GIF file, related to gifcodec.cpp and gifimage.cpp.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:24:38.878-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:15:27.493-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:16:36.516-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
        <criterion comment="HelixPlayer is earlier than 1:1.0.6-1.el4_8.1" test_ref="oval:org.mitre.oval:tst:39912"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9996" version="3" class="vulnerability">
      <metadata>
        <title>Stack-based buffer overflow in the rename_principal_2_svc function in kadmind for MIT Kerberos 1.5.3, 1.6.1, and other versions allows remote authenticated users to execute arbitrary code via a crafted request to rename a principal.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-2798" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2798"/>
        <description>Stack-based buffer overflow in the rename_principal_2_svc function in kadmind for MIT Kerberos 1.5.3, 1.6.1, and other versions allows remote authenticated users to execute arbitrary code via a crafted request to rename a principal.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:19:10.334-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:15:26.770-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:16:35.766-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
          <criteria operator="OR">
            <criterion comment="krb5-workstation is earlier than 0:1.2.7-66" test_ref="oval:org.mitre.oval:tst:33627"/>
            <criterion comment="krb5 is earlier than 0:1.2.7-66" test_ref="oval:org.mitre.oval:tst:34238"/>
            <criterion comment="krb5-libs is earlier than 0:1.2.7-66" test_ref="oval:org.mitre.oval:tst:34171"/>
            <criterion comment="krb5-server is earlier than 0:1.2.7-66" test_ref="oval:org.mitre.oval:tst:33767"/>
            <criterion comment="krb5-devel is earlier than 0:1.2.7-66" test_ref="oval:org.mitre.oval:tst:34147"/>
          </criteria>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <criteria operator="OR">
            <criterion comment="krb5-workstation is earlier than 0:1.3.4-49" test_ref="oval:org.mitre.oval:tst:34640"/>
            <criterion comment="krb5 is earlier than 0:1.3.4-49" test_ref="oval:org.mitre.oval:tst:34202"/>
            <criterion comment="krb5-libs is earlier than 0:1.3.4-49" test_ref="oval:org.mitre.oval:tst:34749"/>
            <criterion comment="krb5-server is earlier than 0:1.3.4-49" test_ref="oval:org.mitre.oval:tst:34767"/>
            <criterion comment="krb5-devel is earlier than 0:1.3.4-49" test_ref="oval:org.mitre.oval:tst:34660"/>
          </criteria>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criteria operator="OR">
            <criterion comment="krb5-workstation is earlier than 0:1.5-26" test_ref="oval:org.mitre.oval:tst:34728"/>
            <criterion comment="krb5 is earlier than 0:1.5-26" test_ref="oval:org.mitre.oval:tst:34350"/>
            <criterion comment="krb5-libs is earlier than 0:1.5-26" test_ref="oval:org.mitre.oval:tst:34575"/>
            <criterion comment="krb5-server is earlier than 0:1.5-26" test_ref="oval:org.mitre.oval:tst:34729"/>
            <criterion comment="krb5-devel is earlier than 0:1.5-26" test_ref="oval:org.mitre.oval:tst:34195"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9995" version="3" class="vulnerability">
      <metadata>
        <title>The Linux kernel before 2.6.16.9 and the FreeBSD kernel, when running on AMD64 and other 7th and 8th generation AuthenticAMD processors, only save/restore the FOP, FIP, and FDP x87 registers in FXSAVE/FXRSTOR when an exception is pending, which allows one process to determine portions of the state of floating point instructions of other processes, which can be leveraged to obtain sensitive information such as cryptographic keys.  NOTE: this is the documented behavior of AMD64 processors, but it is inconsistent with Intel processers in a security-relevant fashion that was not addressed by the kernels.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-1056" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1056"/>
        <description>The Linux kernel before 2.6.16.9 and the FreeBSD kernel, when running on AMD64 and other 7th and 8th generation AuthenticAMD processors, only save/restore the FOP, FIP, and FDP x87 registers in FXSAVE/FXRSTOR when an exception is pending, which allows one process to determine portions of the state of floating point instructions of other processes, which can be leveraged to obtain sensitive information such as cryptographic keys.  NOTE: this is the documented behavior of AMD64 processors, but it is inconsistent with Intel processers in a security-relevant fashion that was not addressed by the kernels.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:25:05.980-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:15:26.348-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:16:35.189-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
          <criteria operator="OR">
            <criterion comment="kernel-BOOT is earlier than 0:2.4.21-47.EL" test_ref="oval:org.mitre.oval:tst:32158"/>
            <criterion comment="kernel-unsupported is earlier than 0:2.4.21-47.EL" test_ref="oval:org.mitre.oval:tst:32589"/>
            <criterion comment="kernel-smp-unsupported is earlier than 0:2.4.21-47.EL" test_ref="oval:org.mitre.oval:tst:32704"/>
            <criterion comment="kernel-hugemem-unsupported is earlier than 0:2.4.21-47.EL" test_ref="oval:org.mitre.oval:tst:32562"/>
            <criterion comment="kernel-hugemem is earlier than 0:2.4.21-47.EL" test_ref="oval:org.mitre.oval:tst:32078"/>
            <criterion comment="kernel is earlier than 0:2.4.21-47.EL" test_ref="oval:org.mitre.oval:tst:32513"/>
            <criterion comment="kernel-source is earlier than 0:2.4.21-47.EL" test_ref="oval:org.mitre.oval:tst:32231"/>
            <criterion comment="kernel-doc is earlier than 0:2.4.21-47.EL" test_ref="oval:org.mitre.oval:tst:32097"/>
            <criterion comment="kernel-smp is earlier than 0:2.4.21-47.EL" test_ref="oval:org.mitre.oval:tst:32708"/>
          </criteria>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <criteria operator="OR">
            <criterion comment="kernel-hugemem is earlier than 0:2.6.9-42.EL" test_ref="oval:org.mitre.oval:tst:32335"/>
            <criterion comment="kernel-hugemem-devel is earlier than 0:2.6.9-42.EL" test_ref="oval:org.mitre.oval:tst:32833"/>
            <criterion comment="kernel-smp-devel is earlier than 0:2.6.9-42.EL" test_ref="oval:org.mitre.oval:tst:32825"/>
            <criterion comment="kernel-largesmp-devel is earlier than 0:2.6.9-42.EL" test_ref="oval:org.mitre.oval:tst:32836"/>
            <criterion comment="kernel is earlier than 0:2.6.9-42.EL" test_ref="oval:org.mitre.oval:tst:32736"/>
            <criterion comment="kernel-devel is earlier than 0:2.6.9-42.EL" test_ref="oval:org.mitre.oval:tst:31931"/>
            <criterion comment="kernel-doc is earlier than 0:2.6.9-42.EL" test_ref="oval:org.mitre.oval:tst:32361"/>
            <criterion comment="kernel-largesmp is earlier than 0:2.6.9-42.EL" test_ref="oval:org.mitre.oval:tst:32793"/>
            <criterion comment="kernel-smp is earlier than 0:2.6.9-42.EL" test_ref="oval:org.mitre.oval:tst:32795"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9994" version="3" class="vulnerability">
      <metadata>
        <title>Mozilla Thunderbird before 2.0.0.22 and SeaMonkey before 1.1.17 allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a multipart/alternative e-mail message containing a text/enhanced part that triggers access to an incorrect object type.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-2210" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2210"/>
        <description>Mozilla Thunderbird before 2.0.0.22 and SeaMonkey before 1.1.17 allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a multipart/alternative e-mail message containing a text/enhanced part that triggers access to an incorrect object type.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:20:16.910-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:15:25.828-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:16:34.694-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
          <criteria operator="OR">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.9-0.39.el3" test_ref="oval:org.mitre.oval:tst:38621"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-0.39.el3" test_ref="oval:org.mitre.oval:tst:38710"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.9-0.39.el3" test_ref="oval:org.mitre.oval:tst:38897"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-0.39.el3" test_ref="oval:org.mitre.oval:tst:38330"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.9-0.39.el3" test_ref="oval:org.mitre.oval:tst:38382"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-0.39.el3" test_ref="oval:org.mitre.oval:tst:38913"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-0.39.el3" test_ref="oval:org.mitre.oval:tst:38781"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-0.39.el3" test_ref="oval:org.mitre.oval:tst:38614"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-0.39.el3" test_ref="oval:org.mitre.oval:tst:38727"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.9-0.39.el3" test_ref="oval:org.mitre.oval:tst:38447"/>
          </criteria>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <criteria operator="OR">
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-44.el4_8" test_ref="oval:org.mitre.oval:tst:38465"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-44.el4_8" test_ref="oval:org.mitre.oval:tst:38839"/>
            <criterion comment="thunderbird is earlier than 0:1.5.0.12-23.el4" test_ref="oval:org.mitre.oval:tst:38562"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-44.el4_8" test_ref="oval:org.mitre.oval:tst:38248"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-44.el4_8" test_ref="oval:org.mitre.oval:tst:38879"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-44.el4_8" test_ref="oval:org.mitre.oval:tst:38157"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-44.el4_8" test_ref="oval:org.mitre.oval:tst:38757"/>
          </criteria>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criterion comment="thunderbird is earlier than 0:2.0.0.22-2.el5_3" test_ref="oval:org.mitre.oval:tst:38801"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9993" version="3" class="vulnerability">
      <metadata>
        <title>pwmconfig in LM_sensors before 2.9.1 creates temporary files insecurely, which allows local users to overwrite arbitrary files via a symlink attack on the fancontrol temporary file.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2672" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2672"/>
        <description>pwmconfig in LM_sensors before 2.9.1 creates temporary files insecurely, which allows local users to overwrite arbitrary files via a symlink attack on the fancontrol temporary file.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:23:27.771-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:15:25.632-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:16:34.487-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
        <criteria operator="OR">
          <criterion comment="lm_sensors-devel is earlier than 0:2.8.7-2.40.3" test_ref="oval:org.mitre.oval:tst:31850"/>
          <criterion comment="lm_sensors is earlier than 0:2.8.7-2.40.3" test_ref="oval:org.mitre.oval:tst:32360"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9992" version="3" class="vulnerability">
      <metadata>
        <title>Xpdf, as used in products such as gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others, allows attackers to cause a denial of service (crash) via a crafted FlateDecode stream that triggers a null dereference.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-3626" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-3626"/>
        <description>Xpdf, as used in products such as gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others, allows attackers to cause a denial of service (crash) via a crafted FlateDecode stream that triggers a null dereference.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:19:48.624-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:15:25.147-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:16:33.964-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
          <criteria operator="OR">
            <criterion comment="tetex-latex is earlier than 0:1.0.7-67.9" test_ref="oval:org.mitre.oval:tst:32436"/>
            <criterion comment="tetex-dvips is earlier than 0:1.0.7-67.9" test_ref="oval:org.mitre.oval:tst:32311"/>
            <criterion comment="tetex-fonts is earlier than 0:1.0.7-67.9" test_ref="oval:org.mitre.oval:tst:32279"/>
            <criterion comment="cups-libs is earlier than 1:1.1.17-13.3.36" test_ref="oval:org.mitre.oval:tst:32437"/>
            <criterion comment="tetex is earlier than 0:1.0.7-67.9" test_ref="oval:org.mitre.oval:tst:32507"/>
            <criterion comment="cups-devel is earlier than 1:1.1.17-13.3.36" test_ref="oval:org.mitre.oval:tst:32206"/>
            <criterion comment="tetex-afm is earlier than 0:1.0.7-67.9" test_ref="oval:org.mitre.oval:tst:32377"/>
            <criterion comment="xpdf is earlier than 1:2.02-9.8" test_ref="oval:org.mitre.oval:tst:31474"/>
            <criterion comment="tetex-xdvi is earlier than 0:1.0.7-67.9" test_ref="oval:org.mitre.oval:tst:31613"/>
            <criterion comment="cups is earlier than 1:1.1.17-13.3.36" test_ref="oval:org.mitre.oval:tst:31553"/>
          </criteria>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <criteria operator="OR">
            <criterion comment="tetex-latex is earlier than 0:2.0.2-22.EL4.7" test_ref="oval:org.mitre.oval:tst:32260"/>
            <criterion comment="kdegraphics-devel is earlier than 7:3.3.1-3.6" test_ref="oval:org.mitre.oval:tst:32395"/>
            <criterion comment="tetex-dvips is earlier than 0:2.0.2-22.EL4.7" test_ref="oval:org.mitre.oval:tst:32095"/>
            <criterion comment="kdegraphics is earlier than 7:3.3.1-3.6" test_ref="oval:org.mitre.oval:tst:31805"/>
            <criterion comment="tetex-fonts is earlier than 0:2.0.2-22.EL4.7" test_ref="oval:org.mitre.oval:tst:32489"/>
            <criterion comment="cups-libs is earlier than 1:1.1.22-0.rc1.9.10" test_ref="oval:org.mitre.oval:tst:32284"/>
            <criterion comment="tetex is earlier than 0:2.0.2-22.EL4.7" test_ref="oval:org.mitre.oval:tst:32199"/>
            <criterion comment="gpdf is earlier than 0:2.8.2-7.4" test_ref="oval:org.mitre.oval:tst:32545"/>
            <criterion comment="cups-devel is earlier than 1:1.1.22-0.rc1.9.10" test_ref="oval:org.mitre.oval:tst:32254"/>
            <criterion comment="tetex-afm is earlier than 0:2.0.2-22.EL4.7" test_ref="oval:org.mitre.oval:tst:32308"/>
            <criterion comment="xpdf is earlier than 1:3.00-11.10" test_ref="oval:org.mitre.oval:tst:32152"/>
            <criterion comment="tetex-xdvi is earlier than 0:2.0.2-22.EL4.7" test_ref="oval:org.mitre.oval:tst:32333"/>
            <criterion comment="tetex-doc is earlier than 0:2.0.2-22.EL4.7" test_ref="oval:org.mitre.oval:tst:32317"/>
            <criterion comment="cups is earlier than 1:1.1.22-0.rc1.9.10" test_ref="oval:org.mitre.oval:tst:32499"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9991" version="3" class="vulnerability">
      <metadata>
        <title>Integer overflow in the ProcDbeGetVisualInfo function in the DBE extension for X.Org 6.8.2, 6.9.0, 7.0, and 7.1, and XFree86 X server, allows local users to execute arbitrary code via a crafted X protocol request that triggers memory corruption during processing of unspecified data structures.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-6102" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-6102"/>
        <description>Integer overflow in the ProcDbeGetVisualInfo function in the DBE extension for X.Org 6.8.2, 6.9.0, 7.0, and 7.1, and XFree86 X server, allows local users to execute arbitrary code via a crafted X protocol request that triggers memory corruption during processing of unspecified data structures.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:17:44.536-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:15:24.308-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:16:33.178-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
          <criteria operator="OR">
            <criterion comment="XFree86-cyrillic-fonts is earlier than 0:4.3.0-115.EL" test_ref="oval:org.mitre.oval:tst:33279"/>
            <criterion comment="XFree86-Xvfb is earlier than 0:4.3.0-115.EL" test_ref="oval:org.mitre.oval:tst:33033"/>
            <criterion comment="XFree86-ISO8859-14-100dpi-fonts is earlier than 0:4.3.0-115.EL" test_ref="oval:org.mitre.oval:tst:33135"/>
            <criterion comment="XFree86-libs is earlier than 0:4.3.0-115.EL" test_ref="oval:org.mitre.oval:tst:32975"/>
            <criterion comment="XFree86-75dpi-fonts is earlier than 0:4.3.0-115.EL" test_ref="oval:org.mitre.oval:tst:33134"/>
            <criterion comment="XFree86-truetype-fonts is earlier than 0:4.3.0-115.EL" test_ref="oval:org.mitre.oval:tst:32756"/>
            <criterion comment="XFree86-twm is earlier than 0:4.3.0-115.EL" test_ref="oval:org.mitre.oval:tst:33026"/>
            <criterion comment="XFree86-ISO8859-9-75dpi-fonts is earlier than 0:4.3.0-115.EL" test_ref="oval:org.mitre.oval:tst:33238"/>
            <criterion comment="XFree86-libs-data is earlier than 0:4.3.0-115.EL" test_ref="oval:org.mitre.oval:tst:33343"/>
            <criterion comment="XFree86-doc is earlier than 0:4.3.0-115.EL" test_ref="oval:org.mitre.oval:tst:32868"/>
            <criterion comment="XFree86-ISO8859-15-100dpi-fonts is earlier than 0:4.3.0-115.EL" test_ref="oval:org.mitre.oval:tst:32574"/>
            <criterion comment="XFree86-base-fonts is earlier than 0:4.3.0-115.EL" test_ref="oval:org.mitre.oval:tst:33217"/>
            <criterion comment="XFree86-100dpi-fonts is earlier than 0:4.3.0-115.EL" test_ref="oval:org.mitre.oval:tst:33260"/>
            <criterion comment="XFree86-ISO8859-15-75dpi-fonts is earlier than 0:4.3.0-115.EL" test_ref="oval:org.mitre.oval:tst:33106"/>
            <criterion comment="XFree86-ISO8859-2-75dpi-fonts is earlier than 0:4.3.0-115.EL" test_ref="oval:org.mitre.oval:tst:33262"/>
            <criterion comment="XFree86-font-utils is earlier than 0:4.3.0-115.EL" test_ref="oval:org.mitre.oval:tst:33329"/>
            <criterion comment="XFree86-Mesa-libGL is earlier than 0:4.3.0-115.EL" test_ref="oval:org.mitre.oval:tst:32993"/>
            <criterion comment="XFree86-ISO8859-2-100dpi-fonts is earlier than 0:4.3.0-115.EL" test_ref="oval:org.mitre.oval:tst:33159"/>
            <criterion comment="XFree86-xdm is earlier than 0:4.3.0-115.EL" test_ref="oval:org.mitre.oval:tst:33053"/>
            <criterion comment="XFree86-sdk is earlier than 0:4.3.0-115.EL" test_ref="oval:org.mitre.oval:tst:33163"/>
            <criterion comment="XFree86 is earlier than 0:4.3.0-115.EL" test_ref="oval:org.mitre.oval:tst:33308"/>
            <criterion comment="XFree86-ISO8859-9-100dpi-fonts is earlier than 0:4.3.0-115.EL" test_ref="oval:org.mitre.oval:tst:32484"/>
            <criterion comment="XFree86-Xnest is earlier than 0:4.3.0-115.EL" test_ref="oval:org.mitre.oval:tst:33294"/>
            <criterion comment="XFree86-xfs is earlier than 0:4.3.0-115.EL" test_ref="oval:org.mitre.oval:tst:33176"/>
            <criterion comment="XFree86-tools is earlier than 0:4.3.0-115.EL" test_ref="oval:org.mitre.oval:tst:32802"/>
            <criterion comment="XFree86-syriac-fonts is earlier than 0:4.3.0-115.EL" test_ref="oval:org.mitre.oval:tst:32909"/>
            <criterion comment="XFree86-ISO8859-14-75dpi-fonts is earlier than 0:4.3.0-115.EL" test_ref="oval:org.mitre.oval:tst:33270"/>
            <criterion comment="XFree86-xauth is earlier than 0:4.3.0-115.EL" test_ref="oval:org.mitre.oval:tst:33234"/>
            <criterion comment="XFree86-Mesa-libGLU is earlier than 0:4.3.0-115.EL" test_ref="oval:org.mitre.oval:tst:33180"/>
            <criterion comment="XFree86-devel is earlier than 0:4.3.0-115.EL" test_ref="oval:org.mitre.oval:tst:32796"/>
          </criteria>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <criteria operator="OR">
            <criterion comment="xorg-x11-doc is earlier than 0:6.8.2-1.EL.13.37.5" test_ref="oval:org.mitre.oval:tst:33158"/>
            <criterion comment="xorg-x11-libs is earlier than 0:6.8.2-1.EL.13.37.5" test_ref="oval:org.mitre.oval:tst:33322"/>
            <criterion comment="xorg-x11-xauth is earlier than 0:6.8.2-1.EL.13.37.5" test_ref="oval:org.mitre.oval:tst:33297"/>
            <criterion comment="xorg-x11-Mesa-libGLU is earlier than 0:6.8.2-1.EL.13.37.5" test_ref="oval:org.mitre.oval:tst:33211"/>
            <criterion comment="xorg-x11-twm is earlier than 0:6.8.2-1.EL.13.37.5" test_ref="oval:org.mitre.oval:tst:33206"/>
            <criterion comment="xorg-x11-Mesa-libGL is earlier than 0:6.8.2-1.EL.13.37.5" test_ref="oval:org.mitre.oval:tst:33346"/>
            <criterion comment="xorg-x11-Xdmx is earlier than 0:6.8.2-1.EL.13.37.5" test_ref="oval:org.mitre.oval:tst:33222"/>
            <criterion comment="xorg-x11-xfs is earlier than 0:6.8.2-1.EL.13.37.5" test_ref="oval:org.mitre.oval:tst:33340"/>
            <criterion comment="xorg-x11-deprecated-libs-devel is earlier than 0:6.8.2-1.EL.13.37.5" test_ref="oval:org.mitre.oval:tst:33228"/>
            <criterion comment="xorg-x11-devel is earlier than 0:6.8.2-1.EL.13.37.5" test_ref="oval:org.mitre.oval:tst:33187"/>
            <criterion comment="xorg-x11-Xvfb is earlier than 0:6.8.2-1.EL.13.37.5" test_ref="oval:org.mitre.oval:tst:33289"/>
            <criterion comment="xorg-x11-deprecated-libs is earlier than 0:6.8.2-1.EL.13.37.5" test_ref="oval:org.mitre.oval:tst:33242"/>
            <criterion comment="xorg-x11-sdk is earlier than 0:6.8.2-1.EL.13.37.5" test_ref="oval:org.mitre.oval:tst:33068"/>
            <criterion comment="xorg-x11-xdm is earlier than 0:6.8.2-1.EL.13.37.5" test_ref="oval:org.mitre.oval:tst:33283"/>
            <criterion comment="xorg-x11-Xnest is earlier than 0:6.8.2-1.EL.13.37.5" test_ref="oval:org.mitre.oval:tst:33337"/>
            <criterion comment="xorg-x11 is earlier than 0:6.8.2-1.EL.13.37.5" test_ref="oval:org.mitre.oval:tst:32984"/>
            <criterion comment="xorg-x11-font-utils is earlier than 0:6.8.2-1.EL.13.37.5" test_ref="oval:org.mitre.oval:tst:33352"/>
            <criterion comment="xorg-x11-tools is earlier than 0:6.8.2-1.EL.13.37.5" test_ref="oval:org.mitre.oval:tst:33122"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9990" version="3" class="vulnerability">
      <metadata>
        <title>The nfs_permission function in fs/nfs/dir.c in the NFS client implementation in the Linux kernel 2.6.29.3 and earlier, when atomic_open is available, does not check execute (aka EXEC or MAY_EXEC) permission bits, which allows local users to bypass permissions and execute files, as demonstrated by files on an NFSv4 fileserver.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-1630" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1630"/>
        <description>The nfs_permission function in fs/nfs/dir.c in the NFS client implementation in the Linux kernel 2.6.29.3 and earlier, when atomic_open is available, does not check execute (aka EXEC or MAY_EXEC) permission bits, which allows local users to bypass permissions and execute files, as demonstrated by files on an NFSv4 fileserver.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:17:18.827-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:15:23.779-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:16:32.649-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <criteria operator="OR">
            <criterion comment="kernel-xenU is earlier than 0:2.6.9-89.0.3.EL" test_ref="oval:org.mitre.oval:tst:38892"/>
            <criterion comment="kernel-hugemem is earlier than 0:2.6.9-89.0.3.EL" test_ref="oval:org.mitre.oval:tst:38222"/>
            <criterion comment="kernel-hugemem-devel is earlier than 0:2.6.9-89.0.3.EL" test_ref="oval:org.mitre.oval:tst:37924"/>
            <criterion comment="kernel-xenU-devel is earlier than 0:2.6.9-89.0.3.EL" test_ref="oval:org.mitre.oval:tst:38847"/>
            <criterion comment="kernel-smp-devel is earlier than 0:2.6.9-89.0.3.EL" test_ref="oval:org.mitre.oval:tst:38834"/>
            <criterion comment="kernel-largesmp-devel is earlier than 0:2.6.9-89.0.3.EL" test_ref="oval:org.mitre.oval:tst:38158"/>
            <criterion comment="kernel is earlier than 0:2.6.9-89.0.3.EL" test_ref="oval:org.mitre.oval:tst:38513"/>
            <criterion comment="kernel-devel is earlier than 0:2.6.9-89.0.3.EL" test_ref="oval:org.mitre.oval:tst:38317"/>
            <criterion comment="kernel-doc is earlier than 0:2.6.9-89.0.3.EL" test_ref="oval:org.mitre.oval:tst:38277"/>
            <criterion comment="kernel-largesmp is earlier than 0:2.6.9-89.0.3.EL" test_ref="oval:org.mitre.oval:tst:38667"/>
            <criterion comment="kernel-smp is earlier than 0:2.6.9-89.0.3.EL" test_ref="oval:org.mitre.oval:tst:38814"/>
          </criteria>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criteria operator="OR">
            <criterion comment="kernel-kdump is earlier than 0:2.6.18-128.1.14.el5" test_ref="oval:org.mitre.oval:tst:37971"/>
            <criterion comment="kernel-debug is earlier than 0:2.6.18-128.1.14.el5" test_ref="oval:org.mitre.oval:tst:38820"/>
            <criterion comment="kernel-xen is earlier than 0:2.6.18-128.1.14.el5" test_ref="oval:org.mitre.oval:tst:38641"/>
            <criterion comment="kernel-headers is earlier than 0:2.6.18-128.1.14.el5" test_ref="oval:org.mitre.oval:tst:38838"/>
            <criterion comment="kernel-kdump-devel is earlier than 0:2.6.18-128.1.14.el5" test_ref="oval:org.mitre.oval:tst:38699"/>
            <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-128.1.14.el5" test_ref="oval:org.mitre.oval:tst:38813"/>
            <criterion comment="kernel is earlier than 0:2.6.18-128.1.14.el5" test_ref="oval:org.mitre.oval:tst:38840"/>
            <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-128.1.14.el5" test_ref="oval:org.mitre.oval:tst:38890"/>
            <criterion comment="kernel-devel is earlier than 0:2.6.18-128.1.14.el5" test_ref="oval:org.mitre.oval:tst:38529"/>
            <criterion comment="kernel-PAE is earlier than 0:2.6.18-128.1.14.el5" test_ref="oval:org.mitre.oval:tst:38350"/>
            <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-128.1.14.el5" test_ref="oval:org.mitre.oval:tst:38066"/>
            <criterion comment="kernel-doc is earlier than 0:2.6.18-128.1.14.el5" test_ref="oval:org.mitre.oval:tst:38388"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9988" version="3" class="vulnerability">
      <metadata>
        <title>Multiple cross-site scripting (XSS) vulnerabilities in SquirrelMail 1.4.0 through 1.4.9 allow remote attackers to inject arbitrary web script or HTML via the (1) mailto parameter in (a) webmail.php, the (2) session and (3) delete_draft parameters in (b) compose.php, and (4) unspecified vectors involving "a shortcoming in the magicHTML filter."</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-6142" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-6142"/>
        <description>Multiple cross-site scripting (XSS) vulnerabilities in SquirrelMail 1.4.0 through 1.4.9 allow remote attackers to inject arbitrary web script or HTML via the (1) mailto parameter in (a) webmail.php, the (2) session and (3) delete_draft parameters in (b) compose.php, and (4) unspecified vectors involving "a shortcoming in the magicHTML filter."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:21:40.683-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:15:23.364-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:16:32.209-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
          <criterion comment="squirrelmail is earlier than 0:1.4.8-4.el3" test_ref="oval:org.mitre.oval:tst:32449"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <criterion comment="squirrelmail is earlier than 0:1.4.8-4.el4" test_ref="oval:org.mitre.oval:tst:33384"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9986" version="3" class="vulnerability">
      <metadata>
        <title>Net-SNMP 5.0.x before 5.0.10.2, 5.2.x before 5.2.1.2, and 5.1.3, when net-snmp is using stream sockets such as TCP, allows remote attackers to cause a denial of service (daemon hang and CPU consumption) via a TCP packet of length 1, which triggers an infinite loop.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2177" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2177"/>
        <description>Net-SNMP 5.0.x before 5.0.10.2, 5.2.x before 5.2.1.2, and 5.1.3, when net-snmp is using stream sockets such as TCP, allows remote attackers to cause a denial of service (daemon hang and CPU consumption) via a TCP packet of length 1, which triggers an infinite loop.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:17:35.807-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:15:22.617-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:16:31.507-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
          <criteria operator="OR">
            <criterion comment="net-snmp-utils is earlier than 0:5.0.9-2.30E.19" test_ref="oval:org.mitre.oval:tst:31395"/>
            <criterion comment="net-snmp is earlier than 0:5.0.9-2.30E.19" test_ref="oval:org.mitre.oval:tst:30763"/>
            <criterion comment="net-snmp-libs is earlier than 0:5.0.9-2.30E.19" test_ref="oval:org.mitre.oval:tst:31684"/>
            <criterion comment="net-snmp-perl is earlier than 0:5.0.9-2.30E.19" test_ref="oval:org.mitre.oval:tst:31547"/>
            <criterion comment="net-snmp-devel is earlier than 0:5.0.9-2.30E.19" test_ref="oval:org.mitre.oval:tst:31390"/>
          </criteria>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <criteria operator="OR">
            <criterion comment="net-snmp-utils is earlier than 0:5.1.2-11.EL4.6" test_ref="oval:org.mitre.oval:tst:31408"/>
            <criterion comment="net-snmp is earlier than 0:5.1.2-11.EL4.6" test_ref="oval:org.mitre.oval:tst:30993"/>
            <criterion comment="net-snmp-libs is earlier than 0:5.1.2-11.EL4.6" test_ref="oval:org.mitre.oval:tst:31414"/>
            <criterion comment="net-snmp-perl is earlier than 0:5.1.2-11.EL4.6" test_ref="oval:org.mitre.oval:tst:31691"/>
            <criterion comment="net-snmp-devel is earlier than 0:5.1.2-11.EL4.6" test_ref="oval:org.mitre.oval:tst:31766"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9985" version="3" class="vulnerability">
      <metadata>
        <title>RIPd in Quagga 0.98 and 0.99 before 20060503 does not properly implement configurations that (1) disable RIPv1 or (2) require plaintext or MD5 authentication, which allows remote attackers to obtain sensitive information (routing state) via REQUEST packets such as SEND UPDATE.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-2223" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-2223"/>
        <description>RIPd in Quagga 0.98 and 0.99 before 20060503 does not properly implement configurations that (1) disable RIPv1 or (2) require plaintext or MD5 authentication, which allows remote attackers to obtain sensitive information (routing state) via REQUEST packets such as SEND UPDATE.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:19:42.350-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:15:22.376-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:16:31.248-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
          <criterion comment="quagga is earlier than 0:0.96.2-11.3E" test_ref="oval:org.mitre.oval:tst:32541"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <criteria operator="OR">
            <criterion comment="quagga-devel is earlier than 0:0.98.3-2.4E" test_ref="oval:org.mitre.oval:tst:32744"/>
            <criterion comment="quagga is earlier than 0:0.98.3-2.4E" test_ref="oval:org.mitre.oval:tst:32471"/>
            <criterion comment="quagga-contrib is earlier than 0:0.98.3-2.4E" test_ref="oval:org.mitre.oval:tst:32544"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9984" version="3" class="vulnerability">
      <metadata>
        <title>The BN_from_montgomery function in crypto/bn/bn_mont.c in OpenSSL 0.9.8e and earlier does not properly perform Montgomery multiplication, which might allow local users to conduct a side-channel attack and retrieve RSA private keys.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-3108" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3108"/>
        <description>The BN_from_montgomery function in crypto/bn/bn_mont.c in OpenSSL 0.9.8e and earlier does not properly perform Montgomery multiplication, which might allow local users to conduct a side-channel attack and retrieve RSA private keys.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:21:59.428-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:15:21.994-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:16:30.859-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
          <criteria operator="OR">
            <criterion comment="openssl-perl is earlier than 0:0.9.7a-33.24" test_ref="oval:org.mitre.oval:tst:35001"/>
            <criterion comment="openssl-devel is earlier than 0:0.9.7a-33.24" test_ref="oval:org.mitre.oval:tst:34962"/>
            <criterion comment="openssl is earlier than 0:0.9.7a-33.24" test_ref="oval:org.mitre.oval:tst:34324"/>
          </criteria>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <criteria operator="OR">
            <criterion comment="openssl-perl is earlier than 0:0.9.7a-43.17.el4_6.1" test_ref="oval:org.mitre.oval:tst:35545"/>
            <criterion comment="openssl-devel is earlier than 0:0.9.7a-43.17.el4_6.1" test_ref="oval:org.mitre.oval:tst:35457"/>
            <criterion comment="openssl is earlier than 0:0.9.7a-43.17.el4_6.1" test_ref="oval:org.mitre.oval:tst:35580"/>
          </criteria>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criteria operator="OR">
            <criterion comment="openssl-perl is earlier than 0:0.9.8b-8.3.el5_0.2" test_ref="oval:org.mitre.oval:tst:35181"/>
            <criterion comment="openssl-devel is earlier than 0:0.9.8b-8.3.el5_0.2" test_ref="oval:org.mitre.oval:tst:35460"/>
            <criterion comment="openssl is earlier than 0:0.9.8b-8.3.el5_0.2" test_ref="oval:org.mitre.oval:tst:35053"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9983" version="3" class="vulnerability">
      <metadata>
        <title>Multiple unspecified vulnerabilities in Ruby before 1.8.5 allow remote attackers to bypass "safe level" checks via unspecified vectors involving (1) the alias function and (2) "directory operations".</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-3694" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-3694"/>
        <description>Multiple unspecified vulnerabilities in Ruby before 1.8.5 allow remote attackers to bypass "safe level" checks via unspecified vectors involving (1) the alias function and (2) "directory operations".</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:20:34.640-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:15:21.628-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:16:30.476-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
          <criteria operator="OR">
            <criterion comment="ruby-mode is earlier than 0:1.6.8-9.EL3.6" test_ref="oval:org.mitre.oval:tst:32443"/>
            <criterion comment="ruby-docs is earlier than 0:1.6.8-9.EL3.6" test_ref="oval:org.mitre.oval:tst:32730"/>
            <criterion comment="ruby-devel is earlier than 0:1.6.8-9.EL3.6" test_ref="oval:org.mitre.oval:tst:32800"/>
            <criterion comment="ruby-tcltk is earlier than 0:1.6.8-9.EL3.6" test_ref="oval:org.mitre.oval:tst:32566"/>
            <criterion comment="ruby is earlier than 0:1.6.8-9.EL3.6" test_ref="oval:org.mitre.oval:tst:32264"/>
            <criterion comment="irb is earlier than 0:1.6.8-9.EL3.6" test_ref="oval:org.mitre.oval:tst:32482"/>
            <criterion comment="ruby-libs is earlier than 0:1.6.8-9.EL3.6" test_ref="oval:org.mitre.oval:tst:32617"/>
          </criteria>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <criteria operator="OR">
            <criterion comment="ruby-mode is earlier than 0:1.8.1-7.EL4.6" test_ref="oval:org.mitre.oval:tst:32600"/>
            <criterion comment="ruby-docs is earlier than 0:1.8.1-7.EL4.6" test_ref="oval:org.mitre.oval:tst:32723"/>
            <criterion comment="ruby-devel is earlier than 0:1.8.1-7.EL4.6" test_ref="oval:org.mitre.oval:tst:32881"/>
            <criterion comment="ruby-tcltk is earlier than 0:1.8.1-7.EL4.6" test_ref="oval:org.mitre.oval:tst:32751"/>
            <criterion comment="ruby is earlier than 0:1.8.1-7.EL4.6" test_ref="oval:org.mitre.oval:tst:32913"/>
            <criterion comment="irb is earlier than 0:1.8.1-7.EL4.6" test_ref="oval:org.mitre.oval:tst:32117"/>
            <criterion comment="ruby-libs is earlier than 0:1.8.1-7.EL4.6" test_ref="oval:org.mitre.oval:tst:32804"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9982" version="3" class="vulnerability">
      <metadata>
        <title>Unspecified vulnerability in PHP before 5.2.11, and 5.3.x before 5.3.1, has unknown impact and attack vectors related to "missing sanity checks around exif processing."</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-3292" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3292"/>
        <description>Unspecified vulnerability in PHP before 5.2.11, and 5.3.x before 5.3.1, has unknown impact and attack vectors related to "missing sanity checks around exif processing."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:18:28.890-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:15:20.856-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:16:29.709-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
          <criteria operator="OR">
            <criterion comment="php is earlier than 0:4.3.2-54.ent" test_ref="oval:org.mitre.oval:tst:39717"/>
            <criterion comment="php-pgsql is earlier than 0:4.3.2-54.ent" test_ref="oval:org.mitre.oval:tst:39629"/>
            <criterion comment="php-mysql is earlier than 0:4.3.2-54.ent" test_ref="oval:org.mitre.oval:tst:39915"/>
            <criterion comment="php-ldap is earlier than 0:4.3.2-54.ent" test_ref="oval:org.mitre.oval:tst:39741"/>
            <criterion comment="php-imap is earlier than 0:4.3.2-54.ent" test_ref="oval:org.mitre.oval:tst:40003"/>
            <criterion comment="php-odbc is earlier than 0:4.3.2-54.ent" test_ref="oval:org.mitre.oval:tst:39901"/>
            <criterion comment="php-devel is earlier than 0:4.3.2-54.ent" test_ref="oval:org.mitre.oval:tst:39326"/>
          </criteria>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <criteria operator="OR">
            <criterion comment="php-xmlrpc is earlier than 0:4.3.9-3.29" test_ref="oval:org.mitre.oval:tst:39580"/>
            <criterion comment="php-snmp is earlier than 0:4.3.9-3.29" test_ref="oval:org.mitre.oval:tst:40010"/>
            <criterion comment="php-domxml is earlier than 0:4.3.9-3.29" test_ref="oval:org.mitre.oval:tst:39927"/>
            <criterion comment="php-mysql is earlier than 0:4.3.9-3.29" test_ref="oval:org.mitre.oval:tst:39619"/>
            <criterion comment="php-imap is earlier than 0:4.3.9-3.29" test_ref="oval:org.mitre.oval:tst:39111"/>
            <criterion comment="php-gd is earlier than 0:4.3.9-3.29" test_ref="oval:org.mitre.oval:tst:39417"/>
            <criterion comment="php is earlier than 0:4.3.9-3.29" test_ref="oval:org.mitre.oval:tst:39899"/>
            <criterion comment="php-mbstring is earlier than 0:4.3.9-3.29" test_ref="oval:org.mitre.oval:tst:39642"/>
            <criterion comment="php-pgsql is earlier than 0:4.3.9-3.29" test_ref="oval:org.mitre.oval:tst:39821"/>
            <criterion comment="php-pear is earlier than 0:4.3.9-3.29" test_ref="oval:org.mitre.oval:tst:39461"/>
            <criterion comment="php-ldap is earlier than 0:4.3.9-3.29" test_ref="oval:org.mitre.oval:tst:39627"/>
            <criterion comment="php-odbc is earlier than 0:4.3.9-3.29" test_ref="oval:org.mitre.oval:tst:39886"/>
            <criterion comment="php-ncurses is earlier than 0:4.3.9-3.29" test_ref="oval:org.mitre.oval:tst:39848"/>
            <criterion comment="php-devel is earlier than 0:4.3.9-3.29" test_ref="oval:org.mitre.oval:tst:39908"/>
          </criteria>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criteria operator="OR">
            <criterion comment="php-bcmath is earlier than 0:5.1.6-24.el5_4.5" test_ref="oval:org.mitre.oval:tst:39883"/>
            <criterion comment="php-soap is earlier than 0:5.1.6-24.el5_4.5" test_ref="oval:org.mitre.oval:tst:39544"/>
            <criterion comment="php-common is earlier than 0:5.1.6-24.el5_4.5" test_ref="oval:org.mitre.oval:tst:39804"/>
            <criterion comment="php-mysql is earlier than 0:5.1.6-24.el5_4.5" test_ref="oval:org.mitre.oval:tst:39875"/>
            <criterion comment="php-imap is earlier than 0:5.1.6-24.el5_4.5" test_ref="oval:org.mitre.oval:tst:39748"/>
            <criterion comment="php-gd is earlier than 0:5.1.6-24.el5_4.5" test_ref="oval:org.mitre.oval:tst:39802"/>
            <criterion comment="php is earlier than 0:5.1.6-24.el5_4.5" test_ref="oval:org.mitre.oval:tst:39053"/>
            <criterion comment="php-mbstring is earlier than 0:5.1.6-24.el5_4.5" test_ref="oval:org.mitre.oval:tst:39854"/>
            <criterion comment="php-pgsql is earlier than 0:5.1.6-24.el5_4.5" test_ref="oval:org.mitre.oval:tst:39980"/>
            <criterion comment="php-xml is earlier than 0:5.1.6-24.el5_4.5" test_ref="oval:org.mitre.oval:tst:39581"/>
            <criterion comment="php-ldap is earlier than 0:5.1.6-24.el5_4.5" test_ref="oval:org.mitre.oval:tst:39954"/>
            <criterion comment="php-odbc is earlier than 0:5.1.6-24.el5_4.5" test_ref="oval:org.mitre.oval:tst:39018"/>
            <criterion comment="php-ncurses is earlier than 0:5.1.6-24.el5_4.5" test_ref="oval:org.mitre.oval:tst:39463"/>
            <criterion comment="php-devel is earlier than 0:5.1.6-24.el5_4.5" test_ref="oval:org.mitre.oval:tst:39634"/>
            <criterion comment="php-xmlrpc is earlier than 0:5.1.6-24.el5_4.5" test_ref="oval:org.mitre.oval:tst:39436"/>
            <criterion comment="php-snmp is earlier than 0:5.1.6-24.el5_4.5" test_ref="oval:org.mitre.oval:tst:39969"/>
            <criterion comment="php-pdo is earlier than 0:5.1.6-24.el5_4.5" test_ref="oval:org.mitre.oval:tst:39664"/>
            <criterion comment="php-dba is earlier than 0:5.1.6-24.el5_4.5" test_ref="oval:org.mitre.oval:tst:39913"/>
            <criterion comment="php-cli is earlier than 0:5.1.6-24.el5_4.5" test_ref="oval:org.mitre.oval:tst:39765"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9979" version="3" class="vulnerability">
      <metadata>
        <title>Array index error in the DCTStream::readProgressiveDataUnit method in xpdf/Stream.cc in Xpdf 3.02pl1, as used in poppler, teTeX, KDE, KOffice, CUPS, and other products, allows remote attackers to trigger memory corruption and execute arbitrary code via a crafted PDF file.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-4352" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4352"/>
        <description>Array index error in the DCTStream::readProgressiveDataUnit method in xpdf/Stream.cc in Xpdf 3.02pl1, as used in poppler, teTeX, KDE, KOffice, CUPS, and other products, allows remote attackers to trigger memory corruption and execute arbitrary code via a crafted PDF file.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:18:15.192-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:15:19.616-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:16:28.532-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
          <criterion comment="xpdf is earlier than 0:2.02-11.el3" test_ref="oval:org.mitre.oval:tst:35634"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <criteria operator="OR">
            <criterion comment="tetex-latex is earlier than 0:2.0.2-22.0.1.EL4.10" test_ref="oval:org.mitre.oval:tst:34998"/>
            <criterion comment="kdegraphics-devel is earlier than 7:3.3.1-6.el4_5" test_ref="oval:org.mitre.oval:tst:35446"/>
            <criterion comment="tetex-dvips is earlier than 0:2.0.2-22.0.1.EL4.10" test_ref="oval:org.mitre.oval:tst:35156"/>
            <criterion comment="kdegraphics is earlier than 7:3.3.1-6.el4_5" test_ref="oval:org.mitre.oval:tst:35404"/>
            <criterion comment="tetex-fonts is earlier than 0:2.0.2-22.0.1.EL4.10" test_ref="oval:org.mitre.oval:tst:35455"/>
            <criterion comment="cups-libs is earlier than 0:1.1.22-0.rc1.9.20.2.el4_5.2" test_ref="oval:org.mitre.oval:tst:35415"/>
            <criterion comment="tetex is earlier than 0:2.0.2-22.0.1.EL4.10" test_ref="oval:org.mitre.oval:tst:35178"/>
            <criterion comment="gpdf is earlier than 0:2.8.2-7.7.1" test_ref="oval:org.mitre.oval:tst:35574"/>
            <criterion comment="cups-devel is earlier than 0:1.1.22-0.rc1.9.20.2.el4_5.2" test_ref="oval:org.mitre.oval:tst:34735"/>
            <criterion comment="tetex-afm is earlier than 0:2.0.2-22.0.1.EL4.10" test_ref="oval:org.mitre.oval:tst:35585"/>
            <criterion comment="xpdf is earlier than 1:3.00-14.el4" test_ref="oval:org.mitre.oval:tst:35315"/>
            <criterion comment="tetex-xdvi is earlier than 0:2.0.2-22.0.1.EL4.10" test_ref="oval:org.mitre.oval:tst:35591"/>
            <criterion comment="tetex-doc is earlier than 0:2.0.2-22.0.1.EL4.10" test_ref="oval:org.mitre.oval:tst:35283"/>
            <criterion comment="cups is earlier than 0:1.1.22-0.rc1.9.20.2.el4_5.2" test_ref="oval:org.mitre.oval:tst:35537"/>
          </criteria>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criteria operator="OR">
            <criterion comment="tetex-latex is earlier than 0:3.0-33.2.el5_1.2" test_ref="oval:org.mitre.oval:tst:35498"/>
            <criterion comment="cups-lpd is earlier than 0:1.2.4-11.14.el5_1.3" test_ref="oval:org.mitre.oval:tst:35274"/>
            <criterion comment="tetex-dvips is earlier than 0:3.0-33.2.el5_1.2" test_ref="oval:org.mitre.oval:tst:35509"/>
            <criterion comment="poppler-utils is earlier than 0:0.5.4-4.3.el5_1" test_ref="oval:org.mitre.oval:tst:35147"/>
            <criterion comment="poppler is earlier than 0:0.5.4-4.3.el5_1" test_ref="oval:org.mitre.oval:tst:35549"/>
            <criterion comment="tetex-fonts is earlier than 0:3.0-33.2.el5_1.2" test_ref="oval:org.mitre.oval:tst:35527"/>
            <criterion comment="cups-libs is earlier than 0:1.2.4-11.14.el5_1.3" test_ref="oval:org.mitre.oval:tst:35427"/>
            <criterion comment="tetex is earlier than 0:3.0-33.2.el5_1.2" test_ref="oval:org.mitre.oval:tst:35459"/>
            <criterion comment="cups-devel is earlier than 0:1.2.4-11.14.el5_1.3" test_ref="oval:org.mitre.oval:tst:35508"/>
            <criterion comment="tetex-afm is earlier than 0:3.0-33.2.el5_1.2" test_ref="oval:org.mitre.oval:tst:35407"/>
            <criterion comment="tetex-xdvi is earlier than 0:3.0-33.2.el5_1.2" test_ref="oval:org.mitre.oval:tst:34618"/>
            <criterion comment="tetex-doc is earlier than 0:3.0-33.2.el5_1.2" test_ref="oval:org.mitre.oval:tst:34727"/>
            <criterion comment="poppler-devel is earlier than 0:0.5.4-4.3.el5_1" test_ref="oval:org.mitre.oval:tst:35496"/>
            <criterion comment="cups is earlier than 0:1.2.4-11.14.el5_1.3" test_ref="oval:org.mitre.oval:tst:35530"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9978" version="3" class="vulnerability">
      <metadata>
        <title>Linux kernel 2.4.x and 2.6.x up to 2.6.16 allows local users to bypass IPC permissions and modify a readonly attachment of shared memory by using mprotect to give write permission to the attachment.  NOTE: some original raw sources combined this issue with CVE-2006-1524, but they are different bugs.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-2071" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-2071"/>
        <description>Linux kernel 2.4.x and 2.6.x up to 2.6.16 allows local users to bypass IPC permissions and modify a readonly attachment of shared memory by using mprotect to give write permission to the attachment.  NOTE: some original raw sources combined this issue with CVE-2006-1524, but they are different bugs.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:20:57.150-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:15:19.204-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:16:28.103-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
          <criteria operator="OR">
            <criterion comment="kernel-BOOT is earlier than 0:2.4.21-47.0.1.EL" test_ref="oval:org.mitre.oval:tst:33074"/>
            <criterion comment="kernel-unsupported is earlier than 0:2.4.21-47.0.1.EL" test_ref="oval:org.mitre.oval:tst:32633"/>
            <criterion comment="kernel-smp-unsupported is earlier than 0:2.4.21-47.0.1.EL" test_ref="oval:org.mitre.oval:tst:33103"/>
            <criterion comment="kernel-hugemem-unsupported is earlier than 0:2.4.21-47.0.1.EL" test_ref="oval:org.mitre.oval:tst:33001"/>
            <criterion comment="kernel-hugemem is earlier than 0:2.4.21-47.0.1.EL" test_ref="oval:org.mitre.oval:tst:32937"/>
            <criterion comment="kernel is earlier than 0:2.4.21-47.0.1.EL" test_ref="oval:org.mitre.oval:tst:32280"/>
            <criterion comment="kernel-source is earlier than 0:2.4.21-47.0.1.EL" test_ref="oval:org.mitre.oval:tst:33127"/>
            <criterion comment="kernel-doc is earlier than 0:2.4.21-47.0.1.EL" test_ref="oval:org.mitre.oval:tst:32855"/>
            <criterion comment="kernel-smp is earlier than 0:2.4.21-47.0.1.EL" test_ref="oval:org.mitre.oval:tst:33021"/>
          </criteria>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <criteria operator="OR">
            <criterion comment="kernel-hugemem is earlier than 0:2.6.9-42.0.3.EL" test_ref="oval:org.mitre.oval:tst:32678"/>
            <criterion comment="kernel-hugemem-devel is earlier than 0:2.6.9-42.0.3.EL" test_ref="oval:org.mitre.oval:tst:32900"/>
            <criterion comment="kernel-smp-devel is earlier than 0:2.6.9-42.0.3.EL" test_ref="oval:org.mitre.oval:tst:33014"/>
            <criterion comment="kernel-largesmp-devel is earlier than 0:2.6.9-42.0.3.EL" test_ref="oval:org.mitre.oval:tst:32947"/>
            <criterion comment="kernel is earlier than 0:2.6.9-42.0.3.EL" test_ref="oval:org.mitre.oval:tst:32944"/>
            <criterion comment="kernel-devel is earlier than 0:2.6.9-42.0.3.EL" test_ref="oval:org.mitre.oval:tst:32956"/>
            <criterion comment="kernel-doc is earlier than 0:2.6.9-42.0.3.EL" test_ref="oval:org.mitre.oval:tst:32602"/>
            <criterion comment="kernel-largesmp is earlier than 0:2.6.9-42.0.3.EL" test_ref="oval:org.mitre.oval:tst:33081"/>
            <criterion comment="kernel-smp is earlier than 0:2.6.9-42.0.3.EL" test_ref="oval:org.mitre.oval:tst:32892"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9976" version="3" class="vulnerability">
      <metadata>
        <title>Squid 2.5 STABLE9 and earlier, when the DNS client port is unfiltered and the environment does not prevent IP spoofing, allows remote attackers to spoof DNS lookups.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1519" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1519"/>
        <description>Squid 2.5 STABLE9 and earlier, when the DNS client port is unfiltered and the environment does not prevent IP spoofing, allows remote attackers to spoof DNS lookups.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:21:57.423-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:15:18.667-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:16:27.542-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
          <criterion comment="squid is earlier than 7:2.5.STABLE3-6.3E.13" test_ref="oval:org.mitre.oval:tst:31246"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <criterion comment="squid is earlier than 7:2.5.STABLE6-3.4E.9" test_ref="oval:org.mitre.oval:tst:31854"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9975" version="3" class="vulnerability">
      <metadata>
        <title>Race condition in Unzip 5.52 allows local users to modify permissions of arbitrary files via a hard link attack on a file while it is being decompressed, whose permissions are changed by Unzip after the decompression is complete.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2475" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2475"/>
        <description>Race condition in Unzip 5.52 allows local users to modify permissions of arbitrary files via a hard link attack on a file while it is being decompressed, whose permissions are changed by Unzip after the decompression is complete.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:19:39.402-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:15:18.451-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:16:27.314-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
          <criterion comment="unzip is earlier than 0:5.50-35.EL3" test_ref="oval:org.mitre.oval:tst:30464"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <criterion comment="unzip is earlier than 0:5.51-9.EL4.5" test_ref="oval:org.mitre.oval:tst:33619"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9973" version="3" class="vulnerability">
      <metadata>
        <title>src/sdp.c in bluez-libs 3.30 in BlueZ, and other bluez-libs before 3.34 and bluez-utils before 3.34 versions, does not validate string length fields in SDP packets, which allows remote SDP servers to cause a denial of service or possibly have unspecified other impact via a crafted length field that triggers excessive memory allocation or a buffer over-read.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-2374" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-2374"/>
        <description>src/sdp.c in bluez-libs 3.30 in BlueZ, and other bluez-libs before 3.34 and bluez-utils before 3.34 versions, does not validate string length fields in SDP packets, which allows remote SDP servers to cause a denial of service or possibly have unspecified other impact via a crafted length field that triggers excessive memory allocation or a buffer over-read.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:27:11.733-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:15:17.888-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:16:26.715-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <criteria operator="OR">
            <criterion comment="bluez-libs is earlier than 0:2.10-3" test_ref="oval:org.mitre.oval:tst:37371"/>
            <criterion comment="bluez-utils-cups is earlier than 0:2.10-2.4" test_ref="oval:org.mitre.oval:tst:37307"/>
            <criterion comment="bluez-utils is earlier than 0:2.10-2.4" test_ref="oval:org.mitre.oval:tst:36921"/>
            <criterion comment="bluez-libs-devel is earlier than 0:2.10-3" test_ref="oval:org.mitre.oval:tst:37129"/>
          </criteria>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criteria operator="OR">
            <criterion comment="bluez-libs is earlier than 0:3.7-1.1" test_ref="oval:org.mitre.oval:tst:37391"/>
            <criterion comment="bluez-utils-cups is earlier than 0:3.7-2.2" test_ref="oval:org.mitre.oval:tst:37349"/>
            <criterion comment="bluez-utils is earlier than 0:3.7-2.2" test_ref="oval:org.mitre.oval:tst:37379"/>
            <criterion comment="bluez-libs-devel is earlier than 0:3.7-1.1" test_ref="oval:org.mitre.oval:tst:36988"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9972" version="3" class="vulnerability">
      <metadata>
        <title>Mozilla Firefox before 2.0.0.12 and SeaMonkey before 1.1.8 allows user-assisted remote attackers to cause a denial of service via a plain .txt file with a "Content-Disposition: attachment" and an invalid "Content-Type: plain/text," which prevents Firefox from rendering future plain text files within the browser.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-0592" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-0592"/>
        <description>Mozilla Firefox before 2.0.0.12 and SeaMonkey before 1.1.8 allows user-assisted remote attackers to cause a denial of service via a plain .txt file with a "Content-Disposition: attachment" and an invalid "Content-Type: plain/text," which prevents Firefox from rendering future plain text files within the browser.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:24:01.426-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:15:17.359-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:16:26.170-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
          <criteria operator="OR">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.9-0.9.el3" test_ref="oval:org.mitre.oval:tst:36256"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-0.9.el3" test_ref="oval:org.mitre.oval:tst:36236"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.9-0.9.el3" test_ref="oval:org.mitre.oval:tst:35996"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-0.9.el3" test_ref="oval:org.mitre.oval:tst:36279"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.9-0.9.el3" test_ref="oval:org.mitre.oval:tst:36046"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-0.9.el3" test_ref="oval:org.mitre.oval:tst:36052"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-0.9.el3" test_ref="oval:org.mitre.oval:tst:36034"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-0.9.el3" test_ref="oval:org.mitre.oval:tst:36284"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-0.9.el3" test_ref="oval:org.mitre.oval:tst:35748"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.9-0.9.el3" test_ref="oval:org.mitre.oval:tst:35994"/>
          </criteria>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <criteria operator="OR">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.9-9.el4" test_ref="oval:org.mitre.oval:tst:36164"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-9.el4" test_ref="oval:org.mitre.oval:tst:36050"/>
            <criterion comment="thunderbird is earlier than 0:1.5.0.12-8.el4" test_ref="oval:org.mitre.oval:tst:36202"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.9-9.el4" test_ref="oval:org.mitre.oval:tst:36193"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-9.el4" test_ref="oval:org.mitre.oval:tst:36093"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.9-9.el4" test_ref="oval:org.mitre.oval:tst:36053"/>
            <criterion comment="firefox is earlier than 0:1.5.0.12-0.10.el4" test_ref="oval:org.mitre.oval:tst:35919"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-9.el4" test_ref="oval:org.mitre.oval:tst:35600"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-9.el4" test_ref="oval:org.mitre.oval:tst:36141"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.9-9.el4" test_ref="oval:org.mitre.oval:tst:35397"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-9.el4" test_ref="oval:org.mitre.oval:tst:35684"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-9.el4" test_ref="oval:org.mitre.oval:tst:36203"/>
          </criteria>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criteria operator="OR">
            <criterion comment="firefox-devel is earlier than 0:1.5.0.12-9.el5" test_ref="oval:org.mitre.oval:tst:36281"/>
            <criterion comment="firefox is earlier than 0:1.5.0.12-9.el5" test_ref="oval:org.mitre.oval:tst:35480"/>
            <criterion comment="thunderbird is earlier than 0:1.5.0.12-8.el5" test_ref="oval:org.mitre.oval:tst:35675"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9970" version="3" class="vulnerability">
      <metadata>
        <title>Multiple unknown dissectors in Ethereal before 0.10.11 allow remote attackers to cause a denial of service (assert error) via an invalid protocol tree item length.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1460" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1460"/>
        <description>Multiple unknown dissectors in Ethereal before 0.10.11 allow remote attackers to cause a denial of service (assert error) via an invalid protocol tree item length.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:18:29.604-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:15:16.878-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:16:25.648-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
          <criteria operator="OR">
            <criterion comment="ethereal-gnome is earlier than 0:0.10.11-1.EL3.1" test_ref="oval:org.mitre.oval:tst:31458"/>
            <criterion comment="ethereal is earlier than 0:0.10.11-1.EL3.1" test_ref="oval:org.mitre.oval:tst:31546"/>
          </criteria>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <criteria operator="OR">
            <criterion comment="ethereal-gnome is earlier than 0:0.10.11-1.EL4.1" test_ref="oval:org.mitre.oval:tst:31674"/>
            <criterion comment="ethereal is earlier than 0:0.10.11-1.EL4.1" test_ref="oval:org.mitre.oval:tst:31865"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9967" version="3" class="vulnerability">
      <metadata>
        <title>Integer overflow in the TIFF parser in OpenOffice.org (OOo) before 2.3; and Sun StarOffice 6, 7, and 8 Office Suite (StarSuite); allows remote attackers to execute arbitrary code via a TIFF file with crafted values of unspecified length fields, which triggers allocation of an incorrect amount of memory, resulting in a heap-based buffer overflow.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-2834" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2834"/>
        <description>Integer overflow in the TIFF parser in OpenOffice.org (OOo) before 2.3; and Sun StarOffice 6, 7, and 8 Office Suite (StarSuite); allows remote attackers to execute arbitrary code via a TIFF file with crafted values of unspecified length fields, which triggers allocation of an incorrect amount of memory, resulting in a heap-based buffer overflow.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:18:04.925-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:15:14.306-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:16:22.938-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
          <criteria operator="OR">
            <criterion comment="openoffice.org-libs is earlier than 0:1.1.2-40.2.0.EL3" test_ref="oval:org.mitre.oval:tst:34967"/>
            <criterion comment="openoffice.org is earlier than 0:1.1.2-40.2.0.EL3" test_ref="oval:org.mitre.oval:tst:34907"/>
            <criterion comment="openoffice.org-i18n is earlier than 0:1.1.2-40.2.0.EL3" test_ref="oval:org.mitre.oval:tst:34663"/>
          </criteria>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <criteria operator="OR">
            <criterion comment="openoffice.org2-langpack-lt_LT is earlier than 1:2.0.4-5.7.0.2.0" test_ref="oval:org.mitre.oval:tst:34624"/>
            <criterion comment="openoffice.org2-langpack-nn_NO is earlier than 1:2.0.4-5.7.0.2.0" test_ref="oval:org.mitre.oval:tst:34985"/>
            <criterion comment="openoffice.org2-langpack-ga_IE is earlier than 1:2.0.4-5.7.0.2.0" test_ref="oval:org.mitre.oval:tst:34600"/>
            <criterion comment="openoffice.org2-langpack-zh_CN is earlier than 1:2.0.4-5.7.0.2.0" test_ref="oval:org.mitre.oval:tst:35058"/>
            <criterion comment="openoffice.org2-javafilter is earlier than 1:2.0.4-5.7.0.2.0" test_ref="oval:org.mitre.oval:tst:34840"/>
            <criterion comment="openoffice.org2-langpack-he_IL is earlier than 1:2.0.4-5.7.0.2.0" test_ref="oval:org.mitre.oval:tst:34776"/>
            <criterion comment="openoffice.org2-draw is earlier than 1:2.0.4-5.7.0.2.0" test_ref="oval:org.mitre.oval:tst:34590"/>
            <criterion comment="openoffice.org2-langpack-ko_KR is earlier than 1:2.0.4-5.7.0.2.0" test_ref="oval:org.mitre.oval:tst:35090"/>
            <criterion comment="openoffice.org2-langpack-ca_ES is earlier than 1:2.0.4-5.7.0.2.0" test_ref="oval:org.mitre.oval:tst:35105"/>
            <criterion comment="openoffice.org2-base is earlier than 1:2.0.4-5.7.0.2.0" test_ref="oval:org.mitre.oval:tst:34685"/>
            <criterion comment="openoffice.org2-langpack-fr is earlier than 1:2.0.4-5.7.0.2.0" test_ref="oval:org.mitre.oval:tst:34233"/>
            <criterion comment="openoffice.org is earlier than 0:1.1.5-10.6.0.2.EL4" test_ref="oval:org.mitre.oval:tst:34999"/>
            <criterion comment="openoffice.org-libs is earlier than 0:1.1.5-10.6.0.2.EL4" test_ref="oval:org.mitre.oval:tst:34898"/>
            <criterion comment="openoffice.org2-langpack-pa_IN is earlier than 1:2.0.4-5.7.0.2.0" test_ref="oval:org.mitre.oval:tst:35138"/>
            <criterion comment="openoffice.org2-langpack-da_DK is earlier than 1:2.0.4-5.7.0.2.0" test_ref="oval:org.mitre.oval:tst:34744"/>
            <criterion comment="openoffice.org2-emailmerge is earlier than 1:2.0.4-5.7.0.2.0" test_ref="oval:org.mitre.oval:tst:34838"/>
            <criterion comment="openoffice.org2-langpack-pt_PT is earlier than 1:2.0.4-5.7.0.2.0" test_ref="oval:org.mitre.oval:tst:34903"/>
            <criterion comment="openoffice.org2-langpack-es is earlier than 1:2.0.4-5.7.0.2.0" test_ref="oval:org.mitre.oval:tst:34783"/>
            <criterion comment="openoffice.org2-langpack-sv is earlier than 1:2.0.4-5.7.0.2.0" test_ref="oval:org.mitre.oval:tst:35127"/>
            <criterion comment="openoffice.org2-langpack-ms_MY is earlier than 1:2.0.4-5.7.0.2.0" test_ref="oval:org.mitre.oval:tst:35036"/>
            <criterion comment="openoffice.org2-langpack-cs_CZ is earlier than 1:2.0.4-5.7.0.2.0" test_ref="oval:org.mitre.oval:tst:35135"/>
            <criterion comment="openoffice.org2-xsltfilter is earlier than 1:2.0.4-5.7.0.2.0" test_ref="oval:org.mitre.oval:tst:35130"/>
            <criterion comment="openoffice.org2-langpack-ja_JP is earlier than 1:2.0.4-5.7.0.2.0" test_ref="oval:org.mitre.oval:tst:34854"/>
            <criterion comment="openoffice.org2-langpack-hu_HU is earlier than 1:2.0.4-5.7.0.2.0" test_ref="oval:org.mitre.oval:tst:34867"/>
            <criterion comment="openoffice.org2-langpack-zh_TW is earlier than 1:2.0.4-5.7.0.2.0" test_ref="oval:org.mitre.oval:tst:35190"/>
            <criterion comment="openoffice.org2-langpack-sl_SI is earlier than 1:2.0.4-5.7.0.2.0" test_ref="oval:org.mitre.oval:tst:34239"/>
            <criterion comment="openoffice.org2-langpack-de is earlier than 1:2.0.4-5.7.0.2.0" test_ref="oval:org.mitre.oval:tst:34269"/>
            <criterion comment="openoffice.org2-pyuno is earlier than 1:2.0.4-5.7.0.2.0" test_ref="oval:org.mitre.oval:tst:35163"/>
            <criterion comment="openoffice.org2 is earlier than 1:2.0.4-5.7.0.2.0" test_ref="oval:org.mitre.oval:tst:34429"/>
            <criterion comment="openoffice.org2-langpack-tr_TR is earlier than 1:2.0.4-5.7.0.2.0" test_ref="oval:org.mitre.oval:tst:34318"/>
            <criterion comment="openoffice.org2-impress is earlier than 1:2.0.4-5.7.0.2.0" test_ref="oval:org.mitre.oval:tst:34522"/>
            <criterion comment="openoffice.org2-langpack-bn is earlier than 1:2.0.4-5.7.0.2.0" test_ref="oval:org.mitre.oval:tst:34715"/>
            <criterion comment="openoffice.org2-langpack-ar is earlier than 1:2.0.4-5.7.0.2.0" test_ref="oval:org.mitre.oval:tst:34987"/>
            <criterion comment="openoffice.org2-langpack-pt_BR is earlier than 1:2.0.4-5.7.0.2.0" test_ref="oval:org.mitre.oval:tst:35152"/>
            <criterion comment="openoffice.org2-langpack-af_ZA is earlier than 1:2.0.4-5.7.0.2.0" test_ref="oval:org.mitre.oval:tst:34733"/>
            <criterion comment="openoffice.org2-langpack-pl_PL is earlier than 1:2.0.4-5.7.0.2.0" test_ref="oval:org.mitre.oval:tst:34947"/>
            <criterion comment="openoffice.org2-calc is earlier than 1:2.0.4-5.7.0.2.0" test_ref="oval:org.mitre.oval:tst:34830"/>
            <criterion comment="openoffice.org2-langpack-zu_ZA is earlier than 1:2.0.4-5.7.0.2.0" test_ref="oval:org.mitre.oval:tst:35107"/>
            <criterion comment="openoffice.org2-langpack-fi_FI is earlier than 1:2.0.4-5.7.0.2.0" test_ref="oval:org.mitre.oval:tst:34895"/>
            <criterion comment="openoffice.org2-langpack-sk_SK is earlier than 1:2.0.4-5.7.0.2.0" test_ref="oval:org.mitre.oval:tst:34353"/>
            <criterion comment="openoffice.org2-langpack-hi_IN is earlier than 1:2.0.4-5.7.0.2.0" test_ref="oval:org.mitre.oval:tst:35096"/>
            <criterion comment="openoffice.org2-langpack-nb_NO is earlier than 1:2.0.4-5.7.0.2.0" test_ref="oval:org.mitre.oval:tst:34629"/>
            <criterion comment="openoffice.org2-langpack-th_TH is earlier than 1:2.0.4-5.7.0.2.0" test_ref="oval:org.mitre.oval:tst:35089"/>
            <criterion comment="openoffice.org2-langpack-et_EE is earlier than 1:2.0.4-5.7.0.2.0" test_ref="oval:org.mitre.oval:tst:34887"/>
            <criterion comment="openoffice.org2-langpack-gl_ES is earlier than 1:2.0.4-5.7.0.2.0" test_ref="oval:org.mitre.oval:tst:34939"/>
            <criterion comment="openoffice.org2-langpack-it is earlier than 1:2.0.4-5.7.0.2.0" test_ref="oval:org.mitre.oval:tst:34988"/>
            <criterion comment="openoffice.org2-langpack-hr_HR is earlier than 1:2.0.4-5.7.0.2.0" test_ref="oval:org.mitre.oval:tst:34591"/>
            <criterion comment="openoffice.org-i18n is earlier than 0:1.1.5-10.6.0.2.EL4" test_ref="oval:org.mitre.oval:tst:34737"/>
            <criterion comment="openoffice.org2-langpack-ta_IN is earlier than 1:2.0.4-5.7.0.2.0" test_ref="oval:org.mitre.oval:tst:34412"/>
            <criterion comment="openoffice.org2-langpack-gu_IN is earlier than 1:2.0.4-5.7.0.2.0" test_ref="oval:org.mitre.oval:tst:34871"/>
            <criterion comment="openoffice.org2-testtools is earlier than 1:2.0.4-5.7.0.2.0" test_ref="oval:org.mitre.oval:tst:34717"/>
            <criterion comment="openoffice.org-kde is earlier than 0:1.1.5-10.6.0.2.EL4" test_ref="oval:org.mitre.oval:tst:34942"/>
            <criterion comment="openoffice.org2-langpack-eu_ES is earlier than 1:2.0.4-5.7.0.2.0" test_ref="oval:org.mitre.oval:tst:35019"/>
            <criterion comment="openoffice.org2-langpack-el_GR is earlier than 1:2.0.4-5.7.0.2.0" test_ref="oval:org.mitre.oval:tst:34969"/>
            <criterion comment="openoffice.org2-core is earlier than 1:2.0.4-5.7.0.2.0" test_ref="oval:org.mitre.oval:tst:35129"/>
            <criterion comment="openoffice.org2-langpack-ru is earlier than 1:2.0.4-5.7.0.2.0" test_ref="oval:org.mitre.oval:tst:34980"/>
            <criterion comment="openoffice.org2-langpack-bg_BG is earlier than 1:2.0.4-5.7.0.2.0" test_ref="oval:org.mitre.oval:tst:34548"/>
            <criterion comment="openoffice.org2-langpack-nl is earlier than 1:2.0.4-5.7.0.2.0" test_ref="oval:org.mitre.oval:tst:35098"/>
            <criterion comment="openoffice.org2-langpack-sr_CS is earlier than 1:2.0.4-5.7.0.2.0" test_ref="oval:org.mitre.oval:tst:34983"/>
            <criterion comment="openoffice.org2-langpack-cy_GB is earlier than 1:2.0.4-5.7.0.2.0" test_ref="oval:org.mitre.oval:tst:34904"/>
            <criterion comment="openoffice.org2-math is earlier than 1:2.0.4-5.7.0.2.0" test_ref="oval:org.mitre.oval:tst:35206"/>
            <criterion comment="openoffice.org2-graphicfilter is earlier than 1:2.0.4-5.7.0.2.0" test_ref="oval:org.mitre.oval:tst:34571"/>
            <criterion comment="openoffice.org2-writer is earlier than 1:2.0.4-5.7.0.2.0" test_ref="oval:org.mitre.oval:tst:35205"/>
          </criteria>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criteria operator="OR">
            <criterion comment="openoffice.org-langpack-sk_SK is earlier than 1:2.0.4-5.4.17.3" test_ref="oval:org.mitre.oval:tst:35157"/>
            <criterion comment="openoffice.org-langpack-zu_ZA is earlier than 1:2.0.4-5.4.17.3" test_ref="oval:org.mitre.oval:tst:35006"/>
            <criterion comment="openoffice.org-langpack-pa_IN is earlier than 1:2.0.4-5.4.17.3" test_ref="oval:org.mitre.oval:tst:34919"/>
            <criterion comment="openoffice.org-langpack-hi_IN is earlier than 1:2.0.4-5.4.17.3" test_ref="oval:org.mitre.oval:tst:35196"/>
            <criterion comment="openoffice.org-langpack-et_EE is earlier than 1:2.0.4-5.4.17.3" test_ref="oval:org.mitre.oval:tst:35104"/>
            <criterion comment="openoffice.org-langpack-kn_IN is earlier than 1:2.0.4-5.4.17.3" test_ref="oval:org.mitre.oval:tst:34449"/>
            <criterion comment="openoffice.org is earlier than 1:2.0.4-5.4.17.3" test_ref="oval:org.mitre.oval:tst:34768"/>
            <criterion comment="openoffice.org-langpack-zh_TW is earlier than 1:2.0.4-5.4.17.3" test_ref="oval:org.mitre.oval:tst:35222"/>
            <criterion comment="openoffice.org-writer is earlier than 1:2.0.4-5.4.17.3" test_ref="oval:org.mitre.oval:tst:35111"/>
            <criterion comment="openoffice.org-langpack-ve_ZA is earlier than 1:2.0.4-5.4.17.3" test_ref="oval:org.mitre.oval:tst:35231"/>
            <criterion comment="openoffice.org-langpack-ga_IE is earlier than 1:2.0.4-5.4.17.3" test_ref="oval:org.mitre.oval:tst:35237"/>
            <criterion comment="openoffice.org-langpack-ta_IN is earlier than 1:2.0.4-5.4.17.3" test_ref="oval:org.mitre.oval:tst:34488"/>
            <criterion comment="openoffice.org-langpack-ko_KR is earlier than 1:2.0.4-5.4.17.3" test_ref="oval:org.mitre.oval:tst:34457"/>
            <criterion comment="openoffice.org-langpack-or_IN is earlier than 1:2.0.4-5.4.17.3" test_ref="oval:org.mitre.oval:tst:35232"/>
            <criterion comment="openoffice.org-langpack-da_DK is earlier than 1:2.0.4-5.4.17.3" test_ref="oval:org.mitre.oval:tst:35235"/>
            <criterion comment="openoffice.org-langpack-sr_CS is earlier than 1:2.0.4-5.4.17.3" test_ref="oval:org.mitre.oval:tst:35194"/>
            <criterion comment="openoffice.org-langpack-pl_PL is earlier than 1:2.0.4-5.4.17.3" test_ref="oval:org.mitre.oval:tst:34862"/>
            <criterion comment="openoffice.org-langpack-fr is earlier than 1:2.0.4-5.4.17.3" test_ref="oval:org.mitre.oval:tst:34938"/>
            <criterion comment="openoffice.org-langpack-ts_ZA is earlier than 1:2.0.4-5.4.17.3" test_ref="oval:org.mitre.oval:tst:34706"/>
            <criterion comment="openoffice.org-javafilter is earlier than 1:2.0.4-5.4.17.3" test_ref="oval:org.mitre.oval:tst:34766"/>
            <criterion comment="openoffice.org-langpack-as_IN is earlier than 1:2.0.4-5.4.17.3" test_ref="oval:org.mitre.oval:tst:35172"/>
            <criterion comment="openoffice.org-testtools is earlier than 1:2.0.4-5.4.17.3" test_ref="oval:org.mitre.oval:tst:34709"/>
            <criterion comment="openoffice.org-langpack-hr_HR is earlier than 1:2.0.4-5.4.17.3" test_ref="oval:org.mitre.oval:tst:35079"/>
            <criterion comment="openoffice.org-langpack-de is earlier than 1:2.0.4-5.4.17.3" test_ref="oval:org.mitre.oval:tst:35080"/>
            <criterion comment="openoffice.org-emailmerge is earlier than 1:2.0.4-5.4.17.3" test_ref="oval:org.mitre.oval:tst:34726"/>
            <criterion comment="openoffice.org-xsltfilter is earlier than 1:2.0.4-5.4.17.3" test_ref="oval:org.mitre.oval:tst:34972"/>
            <criterion comment="openoffice.org-langpack-tn_ZA is earlier than 1:2.0.4-5.4.17.3" test_ref="oval:org.mitre.oval:tst:35101"/>
            <criterion comment="openoffice.org-langpack-te_IN is earlier than 1:2.0.4-5.4.17.3" test_ref="oval:org.mitre.oval:tst:34674"/>
            <criterion comment="openoffice.org-langpack-sv is earlier than 1:2.0.4-5.4.17.3" test_ref="oval:org.mitre.oval:tst:35094"/>
            <criterion comment="openoffice.org-base is earlier than 1:2.0.4-5.4.17.3" test_ref="oval:org.mitre.oval:tst:35137"/>
            <criterion comment="openoffice.org-langpack-ca_ES is earlier than 1:2.0.4-5.4.17.3" test_ref="oval:org.mitre.oval:tst:34909"/>
            <criterion comment="openoffice.org-langpack-nr_ZA is earlier than 1:2.0.4-5.4.17.3" test_ref="oval:org.mitre.oval:tst:35201"/>
            <criterion comment="openoffice.org-core is earlier than 1:2.0.4-5.4.17.3" test_ref="oval:org.mitre.oval:tst:34989"/>
            <criterion comment="openoffice.org-langpack-nl is earlier than 1:2.0.4-5.4.17.3" test_ref="oval:org.mitre.oval:tst:35225"/>
            <criterion comment="openoffice.org-langpack-ur is earlier than 1:2.0.4-5.4.17.3" test_ref="oval:org.mitre.oval:tst:34978"/>
            <criterion comment="openoffice.org-langpack-nn_NO is earlier than 1:2.0.4-5.4.17.3" test_ref="oval:org.mitre.oval:tst:35038"/>
            <criterion comment="openoffice.org-langpack-ar is earlier than 1:2.0.4-5.4.17.3" test_ref="oval:org.mitre.oval:tst:35198"/>
            <criterion comment="openoffice.org-langpack-ja_JP is earlier than 1:2.0.4-5.4.17.3" test_ref="oval:org.mitre.oval:tst:34866"/>
            <criterion comment="openoffice.org-langpack-gu_IN is earlier than 1:2.0.4-5.4.17.3" test_ref="oval:org.mitre.oval:tst:34918"/>
            <criterion comment="openoffice.org-langpack-tr_TR is earlier than 1:2.0.4-5.4.17.3" test_ref="oval:org.mitre.oval:tst:34874"/>
            <criterion comment="openoffice.org-langpack-eu_ES is earlier than 1:2.0.4-5.4.17.3" test_ref="oval:org.mitre.oval:tst:35203"/>
            <criterion comment="openoffice.org-langpack-fi_FI is earlier than 1:2.0.4-5.4.17.3" test_ref="oval:org.mitre.oval:tst:35211"/>
            <criterion comment="openoffice.org-graphicfilter is earlier than 1:2.0.4-5.4.17.3" test_ref="oval:org.mitre.oval:tst:34963"/>
            <criterion comment="openoffice.org-pyuno is earlier than 1:2.0.4-5.4.17.3" test_ref="oval:org.mitre.oval:tst:34932"/>
            <criterion comment="openoffice.org-langpack-ml_IN is earlier than 1:2.0.4-5.4.17.3" test_ref="oval:org.mitre.oval:tst:35151"/>
            <criterion comment="openoffice.org-langpack-gl_ES is earlier than 1:2.0.4-5.4.17.3" test_ref="oval:org.mitre.oval:tst:34242"/>
            <criterion comment="openoffice.org-langpack-zh_CN is earlier than 1:2.0.4-5.4.17.3" test_ref="oval:org.mitre.oval:tst:35217"/>
            <criterion comment="openoffice.org-langpack-xh_ZA is earlier than 1:2.0.4-5.4.17.3" test_ref="oval:org.mitre.oval:tst:35027"/>
            <criterion comment="openoffice.org-langpack-it is earlier than 1:2.0.4-5.4.17.3" test_ref="oval:org.mitre.oval:tst:34687"/>
            <criterion comment="openoffice.org-langpack-es is earlier than 1:2.0.4-5.4.17.3" test_ref="oval:org.mitre.oval:tst:34666"/>
            <criterion comment="openoffice.org-langpack-nb_NO is earlier than 1:2.0.4-5.4.17.3" test_ref="oval:org.mitre.oval:tst:34639"/>
            <criterion comment="openoffice.org-langpack-sl_SI is earlier than 1:2.0.4-5.4.17.3" test_ref="oval:org.mitre.oval:tst:34834"/>
            <criterion comment="openoffice.org-draw is earlier than 1:2.0.4-5.4.17.3" test_ref="oval:org.mitre.oval:tst:35238"/>
            <criterion comment="openoffice.org-langpack-nso_ZA is earlier than 1:2.0.4-5.4.17.3" test_ref="oval:org.mitre.oval:tst:35072"/>
            <criterion comment="openoffice.org-langpack-ms_MY is earlier than 1:2.0.4-5.4.17.3" test_ref="oval:org.mitre.oval:tst:35082"/>
            <criterion comment="openoffice.org-langpack-el_GR is earlier than 1:2.0.4-5.4.17.3" test_ref="oval:org.mitre.oval:tst:34878"/>
            <criterion comment="openoffice.org-langpack-hu_HU is earlier than 1:2.0.4-5.4.17.3" test_ref="oval:org.mitre.oval:tst:34330"/>
            <criterion comment="openoffice.org-langpack-ss_ZA is earlier than 1:2.0.4-5.4.17.3" test_ref="oval:org.mitre.oval:tst:35063"/>
            <criterion comment="openoffice.org-langpack-bn is earlier than 1:2.0.4-5.4.17.3" test_ref="oval:org.mitre.oval:tst:34592"/>
            <criterion comment="openoffice.org-langpack-he_IL is earlier than 1:2.0.4-5.4.17.3" test_ref="oval:org.mitre.oval:tst:35109"/>
            <criterion comment="openoffice.org-langpack-pt_PT is earlier than 1:2.0.4-5.4.17.3" test_ref="oval:org.mitre.oval:tst:34705"/>
            <criterion comment="openoffice.org-langpack-lt_LT is earlier than 1:2.0.4-5.4.17.3" test_ref="oval:org.mitre.oval:tst:34515"/>
            <criterion comment="openoffice.org-langpack-af_ZA is earlier than 1:2.0.4-5.4.17.3" test_ref="oval:org.mitre.oval:tst:34792"/>
            <criterion comment="openoffice.org-langpack-bg_BG is earlier than 1:2.0.4-5.4.17.3" test_ref="oval:org.mitre.oval:tst:35068"/>
            <criterion comment="openoffice.org-calc is earlier than 1:2.0.4-5.4.17.3" test_ref="oval:org.mitre.oval:tst:35132"/>
            <criterion comment="openoffice.org-langpack-cs_CZ is earlier than 1:2.0.4-5.4.17.3" test_ref="oval:org.mitre.oval:tst:35188"/>
            <criterion comment="openoffice.org-langpack-cy_GB is earlier than 1:2.0.4-5.4.17.3" test_ref="oval:org.mitre.oval:tst:35128"/>
            <criterion comment="openoffice.org-langpack-mr_IN is earlier than 1:2.0.4-5.4.17.3" test_ref="oval:org.mitre.oval:tst:34875"/>
            <criterion comment="openoffice.org-langpack-th_TH is earlier than 1:2.0.4-5.4.17.3" test_ref="oval:org.mitre.oval:tst:34788"/>
            <criterion comment="openoffice.org-langpack-pt_BR is earlier than 1:2.0.4-5.4.17.3" test_ref="oval:org.mitre.oval:tst:35158"/>
            <criterion comment="openoffice.org-langpack-ru is earlier than 1:2.0.4-5.4.17.3" test_ref="oval:org.mitre.oval:tst:34970"/>
            <criterion comment="openoffice.org-math is earlier than 1:2.0.4-5.4.17.3" test_ref="oval:org.mitre.oval:tst:34996"/>
            <criterion comment="openoffice.org-impress is earlier than 1:2.0.4-5.4.17.3" test_ref="oval:org.mitre.oval:tst:34349"/>
            <criterion comment="openoffice.org-langpack-st_ZA is earlier than 1:2.0.4-5.4.17.3" test_ref="oval:org.mitre.oval:tst:35193"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9966" version="3" class="vulnerability">
      <metadata>
        <title>HTTP response smuggling vulnerability in Mozilla Firefox and Thunderbird before 1.5.0.4, when used with certain proxy servers, allows remote attackers to cause Firefox to interpret certain responses as if they were responses from two different sites via (1) invalid HTTP response headers with spaces between the header name and the colon, which might not be ignored in some cases, or (2) HTTP 1.1 headers through an HTTP 1.0 proxy, which are ignored by the proxy but processed by the client.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-2786" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-2786"/>
        <description>HTTP response smuggling vulnerability in Mozilla Firefox and Thunderbird before 1.5.0.4, when used with certain proxy servers, allows remote attackers to cause Firefox to interpret certain responses as if they were responses from two different sites via (1) invalid HTTP response headers with spaces between the header name and the colon, which might not be ignored in some cases, or (2) HTTP 1.1 headers through an HTTP 1.0 proxy, which are ignored by the proxy but processed by the client.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:20:22.234-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:15:13.731-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:16:22.390-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
          <criteria operator="OR">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.2-0.1.0.EL3" test_ref="oval:org.mitre.oval:tst:32575"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.2-0.1.0.EL3" test_ref="oval:org.mitre.oval:tst:32674"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.2-0.1.0.EL3" test_ref="oval:org.mitre.oval:tst:32918"/>
            <criterion comment="seamonkey is earlier than 0:1.0.2-0.1.0.EL3" test_ref="oval:org.mitre.oval:tst:32919"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.2-0.1.0.EL3" test_ref="oval:org.mitre.oval:tst:32864"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.2-0.1.0.EL3" test_ref="oval:org.mitre.oval:tst:32659"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.2-0.1.0.EL3" test_ref="oval:org.mitre.oval:tst:32859"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.2-0.1.0.EL3" test_ref="oval:org.mitre.oval:tst:32511"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.2-0.1.0.EL3" test_ref="oval:org.mitre.oval:tst:32902"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.2-0.1.0.EL3" test_ref="oval:org.mitre.oval:tst:32837"/>
          </criteria>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <criteria operator="OR">
            <criterion comment="devhelp-devel is earlier than 0:0.10-0.2.el4" test_ref="oval:org.mitre.oval:tst:32873"/>
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.3-0.el4.1" test_ref="oval:org.mitre.oval:tst:32693"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.3-0.el4.1" test_ref="oval:org.mitre.oval:tst:32886"/>
            <criterion comment="thunderbird is earlier than 0:1.5.0.5-0.el4.1" test_ref="oval:org.mitre.oval:tst:32810"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.3-0.el4.1" test_ref="oval:org.mitre.oval:tst:32418"/>
            <criterion comment="seamonkey is earlier than 0:1.0.3-0.el4.1" test_ref="oval:org.mitre.oval:tst:32496"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.3-0.el4.1" test_ref="oval:org.mitre.oval:tst:32929"/>
            <criterion comment="devhelp is earlier than 0:0.10-0.2.el4" test_ref="oval:org.mitre.oval:tst:32777"/>
            <criterion comment="firefox is earlier than 0:1.5.0.5-0.el4.1" test_ref="oval:org.mitre.oval:tst:32896"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.3-0.el4.1" test_ref="oval:org.mitre.oval:tst:32722"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.3-0.el4.1" test_ref="oval:org.mitre.oval:tst:32906"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.3-0.el4.1" test_ref="oval:org.mitre.oval:tst:32905"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.3-0.el4.1" test_ref="oval:org.mitre.oval:tst:32925"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.3-0.el4.1" test_ref="oval:org.mitre.oval:tst:32624"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9964" version="3" class="vulnerability">
      <metadata>
        <title>Wireshark before 0.99.6 allows remote attackers to cause a denial of service (crash) via a crafted chunked encoding in an HTTP response, possibly related to a zero-length payload.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-3389" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3389"/>
        <description>Wireshark before 0.99.6 allows remote attackers to cause a denial of service (crash) via a crafted chunked encoding in an HTTP response, possibly related to a zero-length payload.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:22:24.387-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:15:13.136-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:16:21.723-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
          <criteria operator="OR">
            <criterion comment="wireshark is earlier than 0:0.99.7-EL3.1" test_ref="oval:org.mitre.oval:tst:36111"/>
            <criterion comment="wireshark-gnome is earlier than 0:0.99.7-EL3.1" test_ref="oval:org.mitre.oval:tst:36043"/>
            <criterion comment="libsmi is earlier than 0:0.4.5-3.el3" test_ref="oval:org.mitre.oval:tst:35411"/>
            <criterion comment="libsmi-devel is earlier than 0:0.4.5-3.el3" test_ref="oval:org.mitre.oval:tst:36140"/>
          </criteria>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <criteria operator="OR">
            <criterion comment="wireshark is earlier than 0:0.99.6-EL4.1" test_ref="oval:org.mitre.oval:tst:34755"/>
            <criterion comment="wireshark-gnome is earlier than 0:0.99.6-EL4.1" test_ref="oval:org.mitre.oval:tst:34881"/>
          </criteria>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criteria operator="OR">
            <criterion comment="wireshark is earlier than 0:0.99.6-1.el5" test_ref="oval:org.mitre.oval:tst:34336"/>
            <criterion comment="wireshark-gnome is earlier than 0:0.99.6-1.el5" test_ref="oval:org.mitre.oval:tst:34784"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9963" version="3" class="vulnerability">
      <metadata>
        <title>Multiple integer overflows in ImageMagick before 6.3.5-9 allow context-dependent attackers to execute arbitrary code via a crafted (1) .dcm, (2) .dib, (3) .xbm, (4) .xcf, or (5) .xwd image file, which triggers a heap-based buffer overflow.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-4986" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4986"/>
        <description>Multiple integer overflows in ImageMagick before 6.3.5-9 allow context-dependent attackers to execute arbitrary code via a crafted (1) .dcm, (2) .dib, (3) .xbm, (4) .xcf, or (5) .xwd image file, which triggers a heap-based buffer overflow.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:21:14.834-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:15:12.686-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:16:21.299-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
          <criteria operator="OR">
            <criterion comment="ImageMagick-c++-devel is earlier than 0:5.5.6-28" test_ref="oval:org.mitre.oval:tst:36023"/>
            <criterion comment="ImageMagick is earlier than 0:5.5.6-28" test_ref="oval:org.mitre.oval:tst:36184"/>
            <criterion comment="ImageMagick-perl is earlier than 0:5.5.6-28" test_ref="oval:org.mitre.oval:tst:36260"/>
            <criterion comment="ImageMagick-devel is earlier than 0:5.5.6-28" test_ref="oval:org.mitre.oval:tst:36208"/>
            <criterion comment="ImageMagick-c++ is earlier than 0:5.5.6-28" test_ref="oval:org.mitre.oval:tst:36056"/>
          </criteria>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <criteria operator="OR">
            <criterion comment="ImageMagick-c++-devel is earlier than 0:6.0.7.1-17.el4_6.1" test_ref="oval:org.mitre.oval:tst:36311"/>
            <criterion comment="ImageMagick is earlier than 0:6.0.7.1-17.el4_6.1" test_ref="oval:org.mitre.oval:tst:36459"/>
            <criterion comment="ImageMagick-perl is earlier than 0:6.0.7.1-17.el4_6.1" test_ref="oval:org.mitre.oval:tst:36349"/>
            <criterion comment="ImageMagick-devel is earlier than 0:6.0.7.1-17.el4_6.1" test_ref="oval:org.mitre.oval:tst:35927"/>
            <criterion comment="ImageMagick-c++ is earlier than 0:6.0.7.1-17.el4_6.1" test_ref="oval:org.mitre.oval:tst:36106"/>
          </criteria>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criteria operator="OR">
            <criterion comment="ImageMagick-c++-devel is earlier than 0:6.2.8.0-4.el5_1.1" test_ref="oval:org.mitre.oval:tst:36419"/>
            <criterion comment="ImageMagick is earlier than 0:6.2.8.0-4.el5_1.1" test_ref="oval:org.mitre.oval:tst:36360"/>
            <criterion comment="ImageMagick-perl is earlier than 0:6.2.8.0-4.el5_1.1" test_ref="oval:org.mitre.oval:tst:36388"/>
            <criterion comment="ImageMagick-devel is earlier than 0:6.2.8.0-4.el5_1.1" test_ref="oval:org.mitre.oval:tst:35921"/>
            <criterion comment="ImageMagick-c++ is earlier than 0:6.2.8.0-4.el5_1.1" test_ref="oval:org.mitre.oval:tst:36133"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9962" version="3" class="vulnerability">
      <metadata>
        <title>scp in OpenSSH 4.2p1 allows attackers to execute arbitrary commands via filenames that contain shell metacharacters or spaces, which are expanded twice.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-0225" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0225"/>
        <description>scp in OpenSSH 4.2p1 allows attackers to execute arbitrary commands via filenames that contain shell metacharacters or spaces, which are expanded twice.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:23:20.355-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:15:12.374-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:16:20.913-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
          <criteria operator="OR">
            <criterion comment="openssh is earlier than 0:3.6.1p2-33.30.9" test_ref="oval:org.mitre.oval:tst:32634"/>
            <criterion comment="openssh-askpass is earlier than 0:3.6.1p2-33.30.9" test_ref="oval:org.mitre.oval:tst:32130"/>
            <criterion comment="openssh-server is earlier than 0:3.6.1p2-33.30.9" test_ref="oval:org.mitre.oval:tst:32453"/>
            <criterion comment="openssh-clients is earlier than 0:3.6.1p2-33.30.9" test_ref="oval:org.mitre.oval:tst:32516"/>
            <criterion comment="openssh-askpass-gnome is earlier than 0:3.6.1p2-33.30.9" test_ref="oval:org.mitre.oval:tst:32587"/>
          </criteria>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <criteria operator="OR">
            <criterion comment="openssh is earlier than 0:3.9p1-8.RHEL4.12" test_ref="oval:org.mitre.oval:tst:32475"/>
            <criterion comment="openssh-askpass is earlier than 0:3.9p1-8.RHEL4.12" test_ref="oval:org.mitre.oval:tst:32414"/>
            <criterion comment="openssh-server is earlier than 0:3.9p1-8.RHEL4.12" test_ref="oval:org.mitre.oval:tst:32296"/>
            <criterion comment="openssh-clients is earlier than 0:3.9p1-8.RHEL4.12" test_ref="oval:org.mitre.oval:tst:32306"/>
            <criterion comment="openssh-askpass-gnome is earlier than 0:3.9p1-8.RHEL4.12" test_ref="oval:org.mitre.oval:tst:32251"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9961" version="3" class="vulnerability">
      <metadata>
        <title>Firefox before 1.0.3, Mozilla Suite before 1.7.7, and Netscape 7.2 allows remote attackers to replace existing search plugins with malicious ones using sidebar.addSearchEngine and the same filename as the target engine, which may not be displayed in the GUI, which could then be used to execute malicious script, aka "Firesearching 2."</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1157" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1157"/>
        <description>Firefox before 1.0.3, Mozilla Suite before 1.7.7, and Netscape 7.2 allows remote attackers to replace existing search plugins with malicious ones using sidebar.addSearchEngine and the same filename as the target engine, which may not be displayed in the GUI, which could then be used to execute malicious script, aka "Firesearching 2."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:23:17.084-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:15:11.827-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:16:20.344-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
          <criteria operator="OR">
            <criterion comment="mozilla-js-debugger is earlier than 37:1.7.7-1.1.3.4" test_ref="oval:org.mitre.oval:tst:31283"/>
            <criterion comment="mozilla is earlier than 37:1.7.7-1.1.3.4" test_ref="oval:org.mitre.oval:tst:31520"/>
            <criterion comment="mozilla-chat is earlier than 37:1.7.7-1.1.3.4" test_ref="oval:org.mitre.oval:tst:31645"/>
            <criterion comment="mozilla-mail is earlier than 37:1.7.7-1.1.3.4" test_ref="oval:org.mitre.oval:tst:31516"/>
            <criterion comment="mozilla-dom-inspector is earlier than 37:1.7.7-1.1.3.4" test_ref="oval:org.mitre.oval:tst:31569"/>
            <criterion comment="mozilla-devel is earlier than 37:1.7.7-1.1.3.4" test_ref="oval:org.mitre.oval:tst:31143"/>
            <criterion comment="mozilla-nss is earlier than 37:1.7.7-1.1.3.4" test_ref="oval:org.mitre.oval:tst:31512"/>
            <criterion comment="mozilla-nss-devel is earlier than 37:1.7.7-1.1.3.4" test_ref="oval:org.mitre.oval:tst:31785"/>
            <criterion comment="mozilla-nspr is earlier than 37:1.7.7-1.1.3.4" test_ref="oval:org.mitre.oval:tst:31695"/>
            <criterion comment="mozilla-nspr-devel is earlier than 37:1.7.7-1.1.3.4" test_ref="oval:org.mitre.oval:tst:31626"/>
          </criteria>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <criteria operator="OR">
            <criterion comment="mozilla-js-debugger is earlier than 37:1.7.7-1.4.2" test_ref="oval:org.mitre.oval:tst:31478"/>
            <criterion comment="devhelp-devel is earlier than 0:0.9.2-2.4.4" test_ref="oval:org.mitre.oval:tst:31488"/>
            <criterion comment="mozilla is earlier than 37:1.7.7-1.4.2" test_ref="oval:org.mitre.oval:tst:31751"/>
            <criterion comment="mozilla-chat is earlier than 37:1.7.7-1.4.2" test_ref="oval:org.mitre.oval:tst:31647"/>
            <criterion comment="mozilla-mail is earlier than 37:1.7.7-1.4.2" test_ref="oval:org.mitre.oval:tst:30850"/>
            <criterion comment="mozilla-dom-inspector is earlier than 37:1.7.7-1.4.2" test_ref="oval:org.mitre.oval:tst:31749"/>
            <criterion comment="devhelp is earlier than 0:0.9.2-2.4.4" test_ref="oval:org.mitre.oval:tst:31658"/>
            <criterion comment="mozilla-nss is earlier than 37:1.7.7-1.4.2" test_ref="oval:org.mitre.oval:tst:31636"/>
            <criterion comment="mozilla-devel is earlier than 37:1.7.7-1.4.2" test_ref="oval:org.mitre.oval:tst:31780"/>
            <criterion comment="mozilla-nss-devel is earlier than 37:1.7.7-1.4.2" test_ref="oval:org.mitre.oval:tst:30828"/>
            <criterion comment="firefox is earlier than 0:1.0.3-1.4.1" test_ref="oval:org.mitre.oval:tst:31646"/>
            <criterion comment="mozilla-nspr is earlier than 37:1.7.7-1.4.2" test_ref="oval:org.mitre.oval:tst:31716"/>
            <criterion comment="mozilla-nspr-devel is earlier than 37:1.7.7-1.4.2" test_ref="oval:org.mitre.oval:tst:31758"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9959" version="3" class="vulnerability">
      <metadata>
        <title>Integer overflow in the (1) rb_ary_splice function in Ruby 1.8.4 and earlier, 1.8.5 before 1.8.5-p231, 1.8.6 before 1.8.6-p230, 1.8.7 before 1.8.7-p22, and 1.9.0 before 1.9.0-2; and (2) the rb_ary_replace function in 1.6.x allows context-dependent attackers to trigger memory corruption, aka the "beg + rlen" issue.  NOTE: as of 20080624, there has been inconsistent usage of multiple CVE identifiers related to Ruby. The CVE description should be regarded as authoritative, although it is likely to change.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-2726" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-2726"/>
        <description>Integer overflow in the (1) rb_ary_splice function in Ruby 1.8.4 and earlier, 1.8.5 before 1.8.5-p231, 1.8.6 before 1.8.6-p230, 1.8.7 before 1.8.7-p22, and 1.9.0 before 1.9.0-2; and (2) the rb_ary_replace function in 1.6.x allows context-dependent attackers to trigger memory corruption, aka the "beg + rlen" issue.  NOTE: as of 20080624, there has been inconsistent usage of multiple CVE identifiers related to Ruby. The CVE description should be regarded as authoritative, although it is likely to change.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:26:56.212-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:15:10.933-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:16:19.416-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
          <criteria operator="OR">
            <criterion comment="ruby-mode is earlier than 0:1.6.8-12.el3" test_ref="oval:org.mitre.oval:tst:36968"/>
            <criterion comment="ruby-docs is earlier than 0:1.6.8-12.el3" test_ref="oval:org.mitre.oval:tst:37000"/>
            <criterion comment="ruby-devel is earlier than 0:1.6.8-12.el3" test_ref="oval:org.mitre.oval:tst:36747"/>
            <criterion comment="ruby-tcltk is earlier than 0:1.6.8-12.el3" test_ref="oval:org.mitre.oval:tst:37140"/>
            <criterion comment="ruby is earlier than 0:1.6.8-12.el3" test_ref="oval:org.mitre.oval:tst:37342"/>
            <criterion comment="irb is earlier than 0:1.6.8-12.el3" test_ref="oval:org.mitre.oval:tst:37252"/>
            <criterion comment="ruby-libs is earlier than 0:1.6.8-12.el3" test_ref="oval:org.mitre.oval:tst:37305"/>
          </criteria>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <criteria operator="OR">
            <criterion comment="ruby-mode is earlier than 0:1.8.1-7.el4_6.1" test_ref="oval:org.mitre.oval:tst:37171"/>
            <criterion comment="ruby-docs is earlier than 0:1.8.1-7.el4_6.1" test_ref="oval:org.mitre.oval:tst:37242"/>
            <criterion comment="ruby-devel is earlier than 0:1.8.1-7.el4_6.1" test_ref="oval:org.mitre.oval:tst:36569"/>
            <criterion comment="ruby-tcltk is earlier than 0:1.8.1-7.el4_6.1" test_ref="oval:org.mitre.oval:tst:37296"/>
            <criterion comment="ruby is earlier than 0:1.8.1-7.el4_6.1" test_ref="oval:org.mitre.oval:tst:36468"/>
            <criterion comment="irb is earlier than 0:1.8.1-7.el4_6.1" test_ref="oval:org.mitre.oval:tst:36808"/>
            <criterion comment="ruby-libs is earlier than 0:1.8.1-7.el4_6.1" test_ref="oval:org.mitre.oval:tst:37219"/>
          </criteria>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criteria operator="OR">
            <criterion comment="ruby-ri is earlier than 0:1.8.5-5.el5_2.3" test_ref="oval:org.mitre.oval:tst:37199"/>
            <criterion comment="ruby-mode is earlier than 0:1.8.5-5.el5_2.3" test_ref="oval:org.mitre.oval:tst:36604"/>
            <criterion comment="ruby-docs is earlier than 0:1.8.5-5.el5_2.3" test_ref="oval:org.mitre.oval:tst:36516"/>
            <criterion comment="ruby-devel is earlier than 0:1.8.5-5.el5_2.3" test_ref="oval:org.mitre.oval:tst:36870"/>
            <criterion comment="ruby is earlier than 0:1.8.5-5.el5_2.3" test_ref="oval:org.mitre.oval:tst:36738"/>
            <criterion comment="ruby-libs is earlier than 0:1.8.5-5.el5_2.3" test_ref="oval:org.mitre.oval:tst:37119"/>
            <criterion comment="ruby-tcltk is earlier than 0:1.8.5-5.el5_2.3" test_ref="oval:org.mitre.oval:tst:37289"/>
            <criterion comment="ruby-irb is earlier than 0:1.8.5-5.el5_2.3" test_ref="oval:org.mitre.oval:tst:37148"/>
            <criterion comment="ruby-rdoc is earlier than 0:1.8.5-5.el5_2.3" test_ref="oval:org.mitre.oval:tst:37203"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9958" version="3" class="vulnerability">
      <metadata>
        <title>Multiple integer overflows in the Apache Portable Runtime (APR) library and the Apache Portable Utility library (aka APR-util) 0.9.x and 1.3.x allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via vectors that trigger crafted calls to the (1) allocator_alloc or (2) apr_palloc function in memory/unix/apr_pools.c in APR; or crafted calls to the (3) apr_rmm_malloc, (4) apr_rmm_calloc, or (5) apr_rmm_realloc function in misc/apr_rmm.c in APR-util; leading to buffer overflows.  NOTE: some of these details are obtained from third party information.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-2412" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2412"/>
        <description>Multiple integer overflows in the Apache Portable Runtime (APR) library and the Apache Portable Utility library (aka APR-util) 0.9.x and 1.3.x allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via vectors that trigger crafted calls to the (1) allocator_alloc or (2) apr_palloc function in memory/unix/apr_pools.c in APR; or crafted calls to the (3) apr_rmm_malloc, (4) apr_rmm_calloc, or (5) apr_rmm_realloc function in misc/apr_rmm.c in APR-util; leading to buffer overflows.  NOTE: some of these details are obtained from third party information.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:17:27.599-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:15:10.553-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:16:18.965-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
          <criteria operator="OR">
            <criterion comment="httpd-devel is earlier than 0:2.0.46-75.ent" test_ref="oval:org.mitre.oval:tst:39033"/>
            <criterion comment="mod_ssl is earlier than 0:2.0.46-75.ent" test_ref="oval:org.mitre.oval:tst:38392"/>
            <criterion comment="httpd is earlier than 0:2.0.46-75.ent" test_ref="oval:org.mitre.oval:tst:39071"/>
          </criteria>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <criteria operator="OR">
            <criterion comment="apr-devel is earlier than 0:0.9.4-24.9.el4_8.2" test_ref="oval:org.mitre.oval:tst:38759"/>
            <criterion comment="apr-util-devel is earlier than 0:0.9.4-22.el4_8.2" test_ref="oval:org.mitre.oval:tst:39047"/>
            <criterion comment="apr is earlier than 0:0.9.4-24.9.el4_8.2" test_ref="oval:org.mitre.oval:tst:39098"/>
            <criterion comment="apr-util is earlier than 0:0.9.4-22.el4_8.2" test_ref="oval:org.mitre.oval:tst:38182"/>
          </criteria>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criteria operator="OR">
            <criterion comment="apr-docs is earlier than 0:1.2.7-11.el5_3.1" test_ref="oval:org.mitre.oval:tst:38932"/>
            <criterion comment="apr-devel is earlier than 0:1.2.7-11.el5_3.1" test_ref="oval:org.mitre.oval:tst:39149"/>
            <criterion comment="apr-util-docs is earlier than 0:1.2.7-7.el5_3.2" test_ref="oval:org.mitre.oval:tst:38625"/>
            <criterion comment="apr-util-devel is earlier than 0:1.2.7-7.el5_3.2" test_ref="oval:org.mitre.oval:tst:38971"/>
            <criterion comment="apr is earlier than 0:1.2.7-11.el5_3.1" test_ref="oval:org.mitre.oval:tst:39108"/>
            <criterion comment="apr-util is earlier than 0:1.2.7-7.el5_3.2" test_ref="oval:org.mitre.oval:tst:38986"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9957" version="3" class="vulnerability">
      <metadata>
        <title>Integer overflow in the JBIG2 decoding feature in the SplashBitmap::SplashBitmap function in SplashBitmap.cc in Xpdf 3.x before 3.02pl4 and Poppler before 0.10.6, as used in GPdf and kdegraphics KPDF, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted PDF document.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-1188" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1188"/>
        <description>Integer overflow in the JBIG2 decoding feature in the SplashBitmap::SplashBitmap function in SplashBitmap.cc in Xpdf 3.x before 3.02pl4 and Poppler before 0.10.6, as used in GPdf and kdegraphics KPDF, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted PDF document.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:21:10.245-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:15:10.238-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:16:18.645-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <criteria operator="OR">
            <criterion comment="kdegraphics-devel is earlier than 7:3.3.1-15.el4_8.2" test_ref="oval:org.mitre.oval:tst:39438"/>
            <criterion comment="gpdf is earlier than 0:2.8.2-7.7.2.el4_8.5" test_ref="oval:org.mitre.oval:tst:39221"/>
            <criterion comment="xpdf is earlier than 1:3.00-22.el4_8.1" test_ref="oval:org.mitre.oval:tst:38963"/>
            <criterion comment="kdegraphics is earlier than 7:3.3.1-15.el4_8.2" test_ref="oval:org.mitre.oval:tst:39094"/>
          </criteria>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criteria operator="OR">
            <criterion comment="kdegraphics-devel is earlier than 7:3.5.4-15.el5_4.2" test_ref="oval:org.mitre.oval:tst:39062"/>
            <criterion comment="poppler-utils is earlier than 0:0.5.4-4.4.el5_3.9" test_ref="oval:org.mitre.oval:tst:38512"/>
            <criterion comment="poppler-devel is earlier than 0:0.5.4-4.4.el5_3.9" test_ref="oval:org.mitre.oval:tst:38500"/>
            <criterion comment="kdegraphics is earlier than 7:3.5.4-15.el5_4.2" test_ref="oval:org.mitre.oval:tst:39529"/>
            <criterion comment="poppler is earlier than 0:0.5.4-4.4.el5_3.9" test_ref="oval:org.mitre.oval:tst:38760"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9955" version="3" class="vulnerability">
      <metadata>
        <title>ACPI Event Daemon (acpid) before 1.0.10 allows remote attackers to cause a denial of service (CPU consumption and connectivity loss) by opening a large number of UNIX sockets without closing them, which triggers an infinite loop.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-0798" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0798"/>
        <description>ACPI Event Daemon (acpid) before 1.0.10 allows remote attackers to cause a denial of service (CPU consumption and connectivity loss) by opening a large number of UNIX sockets without closing them, which triggers an infinite loop.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:17:07.606-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:15:09.628-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:16:18.107-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
          <criterion comment="acpid is earlier than 0:1.0.2-4" test_ref="oval:org.mitre.oval:tst:38604"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <criterion comment="acpid is earlier than 0:1.0.3-2.el4_7.1" test_ref="oval:org.mitre.oval:tst:38456"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criterion comment="acpid is earlier than 0:1.0.4-7.el5_3.1" test_ref="oval:org.mitre.oval:tst:38613"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9954" version="3" class="vulnerability">
      <metadata>
        <title>Memory leak in the seq_file implemenetation in the SCSI procfs interface (sg.c) in Linux kernel 2.6.13 and earlier allows local users to cause a denial of service (memory consumption) via certain repeated reads from the /proc/scsi/sg/devices file, which is not properly handled when the next() iterator returns NULL or an error.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2800" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2800"/>
        <description>Memory leak in the seq_file implemenetation in the SCSI procfs interface (sg.c) in Linux kernel 2.6.13 and earlier allows local users to cause a denial of service (memory consumption) via certain repeated reads from the /proc/scsi/sg/devices file, which is not properly handled when the next() iterator returns NULL or an error.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:25:02.009-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:15:09.374-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:16:17.786-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
        <criteria operator="OR">
          <criterion comment="kernel-smp-devel is earlier than 0:2.6.9-22.0.2.EL" test_ref="oval:org.mitre.oval:tst:32415"/>
          <criterion comment="kernel-hugemem is earlier than 0:2.6.9-22.0.2.EL" test_ref="oval:org.mitre.oval:tst:32137"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.9-22.0.2.EL" test_ref="oval:org.mitre.oval:tst:32528"/>
          <criterion comment="kernel is earlier than 0:2.6.9-22.0.2.EL" test_ref="oval:org.mitre.oval:tst:32205"/>
          <criterion comment="kernel-hugemem-devel is earlier than 0:2.6.9-22.0.2.EL" test_ref="oval:org.mitre.oval:tst:31866"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.9-22.0.2.EL" test_ref="oval:org.mitre.oval:tst:32446"/>
          <criterion comment="kernel-smp is earlier than 0:2.6.9-22.0.2.EL" test_ref="oval:org.mitre.oval:tst:32450"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9953" version="3" class="vulnerability">
      <metadata>
        <title>The CIFS filesystem in the Linux kernel before 2.6.22, when Unix extension support is enabled, does not honor the umask of a process, which allows local users to gain privileges.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-3740" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3740"/>
        <description>The CIFS filesystem in the Linux kernel before 2.6.22, when Unix extension support is enabled, does not honor the umask of a process, which allows local users to gain privileges.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:19:36.571-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:15:08.852-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:16:17.310-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <criteria operator="OR">
            <criterion comment="kernel-xenU is earlier than 0:2.6.9-55.0.12.EL" test_ref="oval:org.mitre.oval:tst:34864"/>
            <criterion comment="kernel-hugemem is earlier than 0:2.6.9-55.0.12.EL" test_ref="oval:org.mitre.oval:tst:35017"/>
            <criterion comment="kernel-hugemem-devel is earlier than 0:2.6.9-55.0.12.EL" test_ref="oval:org.mitre.oval:tst:35145"/>
            <criterion comment="kernel-xenU-devel is earlier than 0:2.6.9-55.0.12.EL" test_ref="oval:org.mitre.oval:tst:34442"/>
            <criterion comment="kernel-smp-devel is earlier than 0:2.6.9-55.0.12.EL" test_ref="oval:org.mitre.oval:tst:35258"/>
            <criterion comment="kernel-largesmp-devel is earlier than 0:2.6.9-55.0.12.EL" test_ref="oval:org.mitre.oval:tst:35254"/>
            <criterion comment="kernel is earlier than 0:2.6.9-55.0.12.EL" test_ref="oval:org.mitre.oval:tst:35373"/>
            <criterion comment="kernel-devel is earlier than 0:2.6.9-55.0.12.EL" test_ref="oval:org.mitre.oval:tst:34480"/>
            <criterion comment="kernel-doc is earlier than 0:2.6.9-55.0.12.EL" test_ref="oval:org.mitre.oval:tst:34911"/>
            <criterion comment="kernel-largesmp is earlier than 0:2.6.9-55.0.12.EL" test_ref="oval:org.mitre.oval:tst:34923"/>
            <criterion comment="kernel-smp is earlier than 0:2.6.9-55.0.12.EL" test_ref="oval:org.mitre.oval:tst:35327"/>
          </criteria>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criteria operator="OR">
            <criterion comment="kernel-kdump is earlier than 0:2.6.18-8.1.10.el5" test_ref="oval:org.mitre.oval:tst:34804"/>
            <criterion comment="kernel-xen is earlier than 0:2.6.18-8.1.10.el5" test_ref="oval:org.mitre.oval:tst:34557"/>
            <criterion comment="kernel-headers is earlier than 0:2.6.18-8.1.10.el5" test_ref="oval:org.mitre.oval:tst:34837"/>
            <criterion comment="kernel-kdump-devel is earlier than 0:2.6.18-8.1.10.el5" test_ref="oval:org.mitre.oval:tst:34795"/>
            <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-8.1.10.el5" test_ref="oval:org.mitre.oval:tst:34562"/>
            <criterion comment="kernel is earlier than 0:2.6.18-8.1.10.el5" test_ref="oval:org.mitre.oval:tst:34357"/>
            <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-8.1.10.el5" test_ref="oval:org.mitre.oval:tst:34379"/>
            <criterion comment="kernel-devel is earlier than 0:2.6.18-8.1.10.el5" test_ref="oval:org.mitre.oval:tst:34873"/>
            <criterion comment="kernel-PAE is earlier than 0:2.6.18-8.1.10.el5" test_ref="oval:org.mitre.oval:tst:34870"/>
            <criterion comment="kernel-doc is earlier than 0:2.6.18-8.1.10.el5" test_ref="oval:org.mitre.oval:tst:34374"/>
            <criterion comment="kernel-debuginfo-common is earlier than 0:2.6.18-8.1.10.el5" test_ref="oval:org.mitre.oval:tst:34337"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9951" version="3" class="vulnerability">
      <metadata>
        <title>Unspecified vulnerability in the match_rule_equal function in bus/signals.c in D-Bus before 1.0.2 allows local applications to remove match rules for other applications and cause a denial of service (lost process messages).</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-6107" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-6107"/>
        <description>Unspecified vulnerability in the match_rule_equal function in bus/signals.c in D-Bus before 1.0.2 allows local applications to remove match rules for other applications and cause a denial of service (lost process messages).</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:26:02.643-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:15:08.408-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:16:16.794-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
        <criteria operator="OR">
          <criterion comment="dbus-glib is earlier than 0:0.22-12.EL.8" test_ref="oval:org.mitre.oval:tst:32768"/>
          <criterion comment="dbus-devel is earlier than 0:0.22-12.EL.8" test_ref="oval:org.mitre.oval:tst:33345"/>
          <criterion comment="dbus-x11 is earlier than 0:0.22-12.EL.8" test_ref="oval:org.mitre.oval:tst:33280"/>
          <criterion comment="dbus-python is earlier than 0:0.22-12.EL.8" test_ref="oval:org.mitre.oval:tst:32745"/>
          <criterion comment="dbus is earlier than 0:0.22-12.EL.8" test_ref="oval:org.mitre.oval:tst:33276"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9950" version="3" class="vulnerability">
      <metadata>
        <title>Mozilla Firefox before 2.0.0.17 and 3.x before 3.0.2, and SeaMonkey before 1.1.12, allow user-assisted remote attackers to move a window during a mouse click, and possibly force a file download or unspecified other drag-and-drop action, via a crafted onmousedown action that calls window.moveBy, a variant of CVE-2003-0823.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-3837" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-3837"/>
        <description>Mozilla Firefox before 2.0.0.17 and 3.x before 3.0.2, and SeaMonkey before 1.1.12, allow user-assisted remote attackers to move a window during a mouse click, and possibly force a file download or unspecified other drag-and-drop action, via a crafted onmousedown action that calls window.moveBy, a variant of CVE-2003-0823.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:22:29.260-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:15:07.762-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:16:16.188-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
          <criteria operator="OR">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.9-0.24.el3" test_ref="oval:org.mitre.oval:tst:37411"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-0.24.el3" test_ref="oval:org.mitre.oval:tst:36691"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.9-0.24.el3" test_ref="oval:org.mitre.oval:tst:37031"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-0.24.el3" test_ref="oval:org.mitre.oval:tst:37528"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.9-0.24.el3" test_ref="oval:org.mitre.oval:tst:36726"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-0.24.el3" test_ref="oval:org.mitre.oval:tst:37435"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-0.24.el3" test_ref="oval:org.mitre.oval:tst:37680"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-0.24.el3" test_ref="oval:org.mitre.oval:tst:36725"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-0.24.el3" test_ref="oval:org.mitre.oval:tst:37449"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.9-0.24.el3" test_ref="oval:org.mitre.oval:tst:37356"/>
          </criteria>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <criteria operator="OR">
            <criterion comment="devhelp-devel is earlier than 0:0.10-0.10.el4" test_ref="oval:org.mitre.oval:tst:37564"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-26.el4" test_ref="oval:org.mitre.oval:tst:36913"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-26.el4" test_ref="oval:org.mitre.oval:tst:37609"/>
            <criterion comment="devhelp is earlier than 0:0.10-0.10.el4" test_ref="oval:org.mitre.oval:tst:37306"/>
            <criterion comment="firefox is earlier than 0:3.0.2-3.el4" test_ref="oval:org.mitre.oval:tst:37195"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-26.el4" test_ref="oval:org.mitre.oval:tst:37499"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-26.el4" test_ref="oval:org.mitre.oval:tst:37444"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-26.el4" test_ref="oval:org.mitre.oval:tst:37543"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-26.el4" test_ref="oval:org.mitre.oval:tst:37552"/>
          </criteria>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criteria operator="OR">
            <criterion comment="devhelp-devel is earlier than 0:0.12-19.el5" test_ref="oval:org.mitre.oval:tst:37248"/>
            <criterion comment="nss-pkcs11-devel is earlier than 0:3.12.1.1-1.el5" test_ref="oval:org.mitre.oval:tst:37486"/>
            <criterion comment="xulrunner-devel is earlier than 0:1.9.0.2-5.el5" test_ref="oval:org.mitre.oval:tst:37495"/>
            <criterion comment="nss is earlier than 0:3.12.1.1-1.el5" test_ref="oval:org.mitre.oval:tst:37044"/>
            <criterion comment="xulrunner is earlier than 0:1.9.0.2-5.el5" test_ref="oval:org.mitre.oval:tst:37578"/>
            <criterion comment="yelp is earlier than 0:2.16.0-21.el5" test_ref="oval:org.mitre.oval:tst:37584"/>
            <criterion comment="devhelp is earlier than 0:0.12-19.el5" test_ref="oval:org.mitre.oval:tst:37353"/>
            <criterion comment="xulrunner-devel-unstable is earlier than 0:1.9.0.2-5.el5" test_ref="oval:org.mitre.oval:tst:37406"/>
            <criterion comment="firefox is earlier than 0:3.0.2-3.el5" test_ref="oval:org.mitre.oval:tst:37225"/>
            <criterion comment="nss-devel is earlier than 0:3.12.1.1-1.el5" test_ref="oval:org.mitre.oval:tst:36664"/>
            <criterion comment="nss-tools is earlier than 0:3.12.1.1-1.el5" test_ref="oval:org.mitre.oval:tst:37664"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9949" version="3" class="vulnerability">
      <metadata>
        <title>Linux kernel 2.6.x up to 2.6.18 and possibly other versions, when SELinux hooks are enabled, allows local users to cause a denial of service (crash) via a malformed file stream that triggers a NULL pointer dereference in the superblock_doinit function, as demonstrated using an HFS filesystem image.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-6056" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-6056"/>
        <description>Linux kernel 2.6.x up to 2.6.18 and possibly other versions, when SELinux hooks are enabled, allows local users to cause a denial of service (crash) via a malformed file stream that triggers a NULL pointer dereference in the superblock_doinit function, as demonstrated using an HFS filesystem image.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:22:45.646-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:15:07.485-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:16:15.848-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
        <criteria operator="OR">
          <criterion comment="kernel-hugemem is earlier than 0:2.6.9-42.0.8.EL" test_ref="oval:org.mitre.oval:tst:33204"/>
          <criterion comment="kernel-hugemem-devel is earlier than 0:2.6.9-42.0.8.EL" test_ref="oval:org.mitre.oval:tst:33278"/>
          <criterion comment="kernel-smp-devel is earlier than 0:2.6.9-42.0.8.EL" test_ref="oval:org.mitre.oval:tst:33306"/>
          <criterion comment="kernel-largesmp-devel is earlier than 0:2.6.9-42.0.8.EL" test_ref="oval:org.mitre.oval:tst:32378"/>
          <criterion comment="kernel is earlier than 0:2.6.9-42.0.8.EL" test_ref="oval:org.mitre.oval:tst:33145"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.9-42.0.8.EL" test_ref="oval:org.mitre.oval:tst:33107"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.9-42.0.8.EL" test_ref="oval:org.mitre.oval:tst:32620"/>
          <criterion comment="kernel-largesmp is earlier than 0:2.6.9-42.0.8.EL" test_ref="oval:org.mitre.oval:tst:32645"/>
          <criterion comment="kernel-smp is earlier than 0:2.6.9-42.0.8.EL" test_ref="oval:org.mitre.oval:tst:33057"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9947" version="3" class="vulnerability">
      <metadata>
        <title>PostgreSQL 8.1.x before 8.1.4, 8.0.x before 8.0.8, 7.4.x before 7.4.13, 7.3.x before 7.3.15, and earlier versions allows context-dependent attackers to bypass SQL injection protection methods in applications that use multibyte encodings that allow the "\" (backslash) byte 0x5c to be the trailing byte of a multibyte character, such as SJIS, BIG5, GBK, GB18030, and UHC, which cannot be handled correctly by a client that does not understand multibyte encodings, aka a second variant of "Encoding-Based SQL Injection." NOTE: it could be argued that this is a class of issue related to interaction errors between the client and PostgreSQL, but a CVE has been assigned since PostgreSQL is treating this as a preventative measure against this class of problem.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-2314" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-2314"/>
        <description>PostgreSQL 8.1.x before 8.1.4, 8.0.x before 8.0.8, 7.4.x before 7.4.13, 7.3.x before 7.3.15, and earlier versions allows context-dependent attackers to bypass SQL injection protection methods in applications that use multibyte encodings that allow the "\" (backslash) byte 0x5c to be the trailing byte of a multibyte character, such as SJIS, BIG5, GBK, GB18030, and UHC, which cannot be handled correctly by a client that does not understand multibyte encodings, aka a second variant of "Encoding-Based SQL Injection." NOTE: it could be argued that this is a class of issue related to interaction errors between the client and PostgreSQL, but a CVE has been assigned since PostgreSQL is treating this as a preventative measure against this class of problem.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:19:08.780-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:15:06.674-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:16:14.907-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
          <criteria operator="OR">
            <criterion comment="rh-postgresql-devel is earlier than 0:7.3.15-2" test_ref="oval:org.mitre.oval:tst:32465"/>
            <criterion comment="rh-postgresql-server is earlier than 0:7.3.15-2" test_ref="oval:org.mitre.oval:tst:32618"/>
            <criterion comment="rh-postgresql-python is earlier than 0:7.3.15-2" test_ref="oval:org.mitre.oval:tst:32497"/>
            <criterion comment="rh-postgresql-libs is earlier than 0:7.3.15-2" test_ref="oval:org.mitre.oval:tst:32527"/>
            <criterion comment="rh-postgresql-docs is earlier than 0:7.3.15-2" test_ref="oval:org.mitre.oval:tst:32392"/>
            <criterion comment="rh-postgresql-test is earlier than 0:7.3.15-2" test_ref="oval:org.mitre.oval:tst:32719"/>
            <criterion comment="rh-postgresql-pl is earlier than 0:7.3.15-2" test_ref="oval:org.mitre.oval:tst:32621"/>
            <criterion comment="rh-postgresql-tcl is earlier than 0:7.3.15-2" test_ref="oval:org.mitre.oval:tst:32195"/>
            <criterion comment="rh-postgresql is earlier than 0:7.3.15-2" test_ref="oval:org.mitre.oval:tst:32628"/>
            <criterion comment="rh-postgresql-contrib is earlier than 0:7.3.15-2" test_ref="oval:org.mitre.oval:tst:32601"/>
            <criterion comment="rh-postgresql-jdbc is earlier than 0:7.3.15-2" test_ref="oval:org.mitre.oval:tst:31936"/>
          </criteria>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <criteria operator="OR">
            <criterion comment="postgresql is earlier than 0:7.4.13-2.RHEL4.1" test_ref="oval:org.mitre.oval:tst:32101"/>
            <criterion comment="postgresql-docs is earlier than 0:7.4.13-2.RHEL4.1" test_ref="oval:org.mitre.oval:tst:31976"/>
            <criterion comment="postgresql-pl is earlier than 0:7.4.13-2.RHEL4.1" test_ref="oval:org.mitre.oval:tst:32564"/>
            <criterion comment="postgresql-tcl is earlier than 0:7.4.13-2.RHEL4.1" test_ref="oval:org.mitre.oval:tst:32038"/>
            <criterion comment="postgresql-libs is earlier than 0:7.4.13-2.RHEL4.1" test_ref="oval:org.mitre.oval:tst:32648"/>
            <criterion comment="postgresql-contrib is earlier than 0:7.4.13-2.RHEL4.1" test_ref="oval:org.mitre.oval:tst:31768"/>
            <criterion comment="postgresql-python is earlier than 0:7.4.13-2.RHEL4.1" test_ref="oval:org.mitre.oval:tst:32626"/>
            <criterion comment="postgresql-test is earlier than 0:7.4.13-2.RHEL4.1" test_ref="oval:org.mitre.oval:tst:31950"/>
            <criterion comment="postgresql-jdbc is earlier than 0:7.4.13-2.RHEL4.1" test_ref="oval:org.mitre.oval:tst:32604"/>
            <criterion comment="postgresql-server is earlier than 0:7.4.13-2.RHEL4.1" test_ref="oval:org.mitre.oval:tst:32472"/>
            <criterion comment="postgresql-devel is earlier than 0:7.4.13-2.RHEL4.1" test_ref="oval:org.mitre.oval:tst:32278"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9945" version="3" class="vulnerability">
      <metadata>
        <title>Integer overflow in wiretap/erf.c in Wireshark before 1.2.2 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted erf file, related to an "unsigned integer wrap vulnerability."</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-3829" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3829"/>
        <description>Integer overflow in wiretap/erf.c in Wireshark before 1.2.2 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted erf file, related to an "unsigned integer wrap vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:19:03.438-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:15:06.192-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:16:14.403-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
          <criteria operator="OR">
            <criterion comment="wireshark is earlier than 0:1.0.11-EL3.6" test_ref="oval:org.mitre.oval:tst:39600"/>
            <criterion comment="wireshark-gnome is earlier than 0:1.0.11-EL3.6" test_ref="oval:org.mitre.oval:tst:40430"/>
          </criteria>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <criteria operator="OR">
            <criterion comment="wireshark is earlier than 0:1.0.11-1.el4_8.5" test_ref="oval:org.mitre.oval:tst:40437"/>
            <criterion comment="wireshark-gnome is earlier than 0:1.0.11-1.el4_8.5" test_ref="oval:org.mitre.oval:tst:39877"/>
          </criteria>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criteria operator="OR">
            <criterion comment="wireshark is earlier than 0:1.0.11-1.el5_5.5" test_ref="oval:org.mitre.oval:tst:40351"/>
            <criterion comment="wireshark-gnome is earlier than 0:1.0.11-1.el5_5.5" test_ref="oval:org.mitre.oval:tst:40208"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9944" version="3" class="vulnerability">
      <metadata>
        <title>smbd in Samba 3.0 before 3.0.37, 3.2 before 3.2.15, 3.3 before 3.3.8, and 3.4 before 3.4.2 allows remote authenticated users to cause a denial of service (infinite loop) via an unanticipated oplock break notification reply packet.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-2906" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2906"/>
        <description>smbd in Samba 3.0 before 3.0.37, 3.2 before 3.2.15, 3.3 before 3.3.8, and 3.4 before 3.4.2 allows remote authenticated users to cause a denial of service (infinite loop) via an unanticipated oplock break notification reply packet.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:22:02.322-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:15:05.773-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:16:13.964-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
          <criteria operator="OR">
            <criterion comment="samba-common is earlier than 0:3.0.9-1.3E.16" test_ref="oval:org.mitre.oval:tst:39355"/>
            <criterion comment="samba-swat is earlier than 0:3.0.9-1.3E.16" test_ref="oval:org.mitre.oval:tst:39369"/>
            <criterion comment="samba-client is earlier than 0:3.0.9-1.3E.16" test_ref="oval:org.mitre.oval:tst:39545"/>
            <criterion comment="samba is earlier than 0:3.0.9-1.3E.16" test_ref="oval:org.mitre.oval:tst:39475"/>
          </criteria>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <criteria operator="OR">
            <criterion comment="samba-common is earlier than 0:3.0.33-0.18.el4_8" test_ref="oval:org.mitre.oval:tst:39162"/>
            <criterion comment="samba-swat is earlier than 0:3.0.33-0.18.el4_8" test_ref="oval:org.mitre.oval:tst:39589"/>
            <criterion comment="samba-client is earlier than 0:3.0.33-0.18.el4_8" test_ref="oval:org.mitre.oval:tst:39603"/>
            <criterion comment="samba is earlier than 0:3.0.33-0.18.el4_8" test_ref="oval:org.mitre.oval:tst:39658"/>
          </criteria>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criteria operator="OR">
            <criterion comment="samba-common is earlier than 0:3.0.33-3.15.el5_4" test_ref="oval:org.mitre.oval:tst:39633"/>
            <criterion comment="samba-swat is earlier than 0:3.0.33-3.15.el5_4" test_ref="oval:org.mitre.oval:tst:39222"/>
            <criterion comment="samba-client is earlier than 0:3.0.33-3.15.el5_4" test_ref="oval:org.mitre.oval:tst:39493"/>
            <criterion comment="samba is earlier than 0:3.0.33-3.15.el5_4" test_ref="oval:org.mitre.oval:tst:39205"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9942" version="3" class="vulnerability">
      <metadata>
        <title>Heap-based buffer overflow in the qtdemux_parse_samples function in gst/qtdemux/qtdemux.c in GStreamer Good Plug-ins (aka gst-plugins-good) 0.10.9 through 0.10.11, and GStreamer Plug-ins (aka gstreamer-plugins) 0.8.5, might allow remote attackers to execute arbitrary code via crafted Time-to-sample (aka stts) atom data in a malformed QuickTime media .mov file.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-0397" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0397"/>
        <description>Heap-based buffer overflow in the qtdemux_parse_samples function in gst/qtdemux/qtdemux.c in GStreamer Good Plug-ins (aka gst-plugins-good) 0.10.9 through 0.10.11, and GStreamer Plug-ins (aka gstreamer-plugins) 0.8.5, might allow remote attackers to execute arbitrary code via crafted Time-to-sample (aka stts) atom data in a malformed QuickTime media .mov file.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:22:11.244-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:15:04.911-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:16:13.114-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <criteria operator="OR">
            <criterion comment="gstreamer-plugins-devel is earlier than 0:0.8.5-1.EL.2" test_ref="oval:org.mitre.oval:tst:38235"/>
            <criterion comment="gstreamer-plugins is earlier than 0:0.8.5-1.EL.2" test_ref="oval:org.mitre.oval:tst:37467"/>
          </criteria>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criteria operator="OR">
            <criterion comment="gstreamer-plugins-good-devel is earlier than 0:0.10.9-1.el5_3.1" test_ref="oval:org.mitre.oval:tst:38180"/>
            <criterion comment="gstreamer-plugins-good is earlier than 0:0.10.9-1.el5_3.1" test_ref="oval:org.mitre.oval:tst:38318"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9941" version="3" class="vulnerability">
      <metadata>
        <title>Multiple integer overflows in the JBIG2 decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, and other products allow remote attackers to cause a denial of service (crash) via a crafted PDF file, related to (1) JBIG2Stream::readSymbolDictSeg, (2) JBIG2Stream::readSymbolDictSeg, and (3) JBIG2Stream::readGenericBitmap.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-0147" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0147"/>
        <description>Multiple integer overflows in the JBIG2 decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, and other products allow remote attackers to cause a denial of service (crash) via a crafted PDF file, related to (1) JBIG2Stream::readSymbolDictSeg, (2) JBIG2Stream::readSymbolDictSeg, and (3) JBIG2Stream::readGenericBitmap.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:21:46.519-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:15:04.319-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:16:12.464-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
          <criterion comment="xpdf is earlier than 1:2.02-14.el3" test_ref="oval:org.mitre.oval:tst:38322"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <criteria operator="OR">
            <criterion comment="tetex-latex is earlier than 0:2.0.2-22.0.1.EL4.16" test_ref="oval:org.mitre.oval:tst:40095"/>
            <criterion comment="kdegraphics-devel is earlier than 7:3.3.1-13.el4" test_ref="oval:org.mitre.oval:tst:38126"/>
            <criterion comment="tetex-dvips is earlier than 0:2.0.2-22.0.1.EL4.16" test_ref="oval:org.mitre.oval:tst:39528"/>
            <criterion comment="kdegraphics is earlier than 7:3.3.1-13.el4" test_ref="oval:org.mitre.oval:tst:38230"/>
            <criterion comment="tetex-fonts is earlier than 0:2.0.2-22.0.1.EL4.16" test_ref="oval:org.mitre.oval:tst:40473"/>
            <criterion comment="cups-libs is earlier than 1:1.1.22-0.rc1.9.27.el4_7.5" test_ref="oval:org.mitre.oval:tst:38481"/>
            <criterion comment="tetex is earlier than 0:2.0.2-22.0.1.EL4.16" test_ref="oval:org.mitre.oval:tst:40316"/>
            <criterion comment="gpdf is earlier than 0:2.8.2-7.7.2.el4_7.4" test_ref="oval:org.mitre.oval:tst:38436"/>
            <criterion comment="cups-devel is earlier than 1:1.1.22-0.rc1.9.27.el4_7.5" test_ref="oval:org.mitre.oval:tst:38145"/>
            <criterion comment="tetex-afm is earlier than 0:2.0.2-22.0.1.EL4.16" test_ref="oval:org.mitre.oval:tst:40209"/>
            <criterion comment="xpdf is earlier than 1:3.00-20.el4" test_ref="oval:org.mitre.oval:tst:38649"/>
            <criterion comment="tetex-xdvi is earlier than 0:2.0.2-22.0.1.EL4.16" test_ref="oval:org.mitre.oval:tst:40364"/>
            <criterion comment="tetex-doc is earlier than 0:2.0.2-22.0.1.EL4.16" test_ref="oval:org.mitre.oval:tst:40077"/>
            <criterion comment="cups is earlier than 1:1.1.22-0.rc1.9.27.el4_7.5" test_ref="oval:org.mitre.oval:tst:38607"/>
          </criteria>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criteria operator="OR">
            <criterion comment="kdegraphics-devel is earlier than 7:3.5.4-12.el5_3" test_ref="oval:org.mitre.oval:tst:38618"/>
            <criterion comment="cups-lpd is earlier than 1:1.3.7-8.el5_3.4" test_ref="oval:org.mitre.oval:tst:38471"/>
            <criterion comment="tetex-dvips is earlier than 0:3.0-33.8.el5_5.5" test_ref="oval:org.mitre.oval:tst:40312"/>
            <criterion comment="kdegraphics is earlier than 7:3.5.4-12.el5_3" test_ref="oval:org.mitre.oval:tst:38271"/>
            <criterion comment="poppler is earlier than 0:0.5.4-4.4.el5_3.9" test_ref="oval:org.mitre.oval:tst:38760"/>
            <criterion comment="tetex-fonts is earlier than 0:3.0-33.8.el5_5.5" test_ref="oval:org.mitre.oval:tst:40122"/>
            <criterion comment="cups-libs is earlier than 1:1.3.7-8.el5_3.4" test_ref="oval:org.mitre.oval:tst:38541"/>
            <criterion comment="tetex is earlier than 0:3.0-33.8.el5_5.5" test_ref="oval:org.mitre.oval:tst:40413"/>
            <criterion comment="tetex-doc is earlier than 0:3.0-33.8.el5_5.5" test_ref="oval:org.mitre.oval:tst:40398"/>
            <criterion comment="poppler-devel is earlier than 0:0.5.4-4.4.el5_3.9" test_ref="oval:org.mitre.oval:tst:38500"/>
            <criterion comment="tetex-latex is earlier than 0:3.0-33.8.el5_5.5" test_ref="oval:org.mitre.oval:tst:40444"/>
            <criterion comment="poppler-utils is earlier than 0:0.5.4-4.4.el5_3.9" test_ref="oval:org.mitre.oval:tst:38512"/>
            <criterion comment="cups-devel is earlier than 1:1.3.7-8.el5_3.4" test_ref="oval:org.mitre.oval:tst:37935"/>
            <criterion comment="tetex-afm is earlier than 0:3.0-33.8.el5_5.5" test_ref="oval:org.mitre.oval:tst:40008"/>
            <criterion comment="tetex-xdvi is earlier than 0:3.0-33.8.el5_5.5" test_ref="oval:org.mitre.oval:tst:39920"/>
            <criterion comment="cups is earlier than 1:1.3.7-8.el5_3.4" test_ref="oval:org.mitre.oval:tst:38334"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9939" version="3" class="vulnerability">
      <metadata>
        <title>Stack-based buffer overflow in the read_special_escape function in src/psgen.c in GNU Enscript 1.6.1 and 1.6.4 beta, when the -e (aka special escapes processing) option is enabled, allows user-assisted remote attackers to execute arbitrary code via a crafted ASCII file, related to the setfilename command.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-3863" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-3863"/>
        <description>Stack-based buffer overflow in the read_special_escape function in src/psgen.c in GNU Enscript 1.6.1 and 1.6.4 beta, when the -e (aka special escapes processing) option is enabled, allows user-assisted remote attackers to execute arbitrary code via a crafted ASCII file, related to the setfilename command.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:21:58.147-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:15:03.812-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:16:11.909-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
          <criterion comment="enscript is earlier than 0:1.6.1-24.7" test_ref="oval:org.mitre.oval:tst:37704"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <criterion comment="enscript is earlier than 0:1.6.1-33.el4_7.1" test_ref="oval:org.mitre.oval:tst:37804"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criterion comment="enscript is earlier than 0:1.6.4-4.1.1.el5_2" test_ref="oval:org.mitre.oval:tst:38101"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9938" version="3" class="vulnerability">
      <metadata>
        <title>Race condition in the rmtree function in the File::Path module in Perl 5.6.1 and 5.8.4 sets read/write permissions for the world, which allows local users to delete arbitrary files and directories, and possibly read files and directories, via a symlink attack.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0452" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0452"/>
        <description>Race condition in the rmtree function in the File::Path module in Perl 5.6.1 and 5.8.4 sets read/write permissions for the world, which allows local users to delete arbitrary files and directories, and possibly read files and directories, via a symlink attack.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:19:14.746-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:15:03.537-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:16:11.615-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
          <criteria operator="OR">
            <criterion comment="perl-suidperl is earlier than 2:5.8.0-89.10" test_ref="oval:org.mitre.oval:tst:31361"/>
            <criterion comment="perl is earlier than 2:5.8.0-89.10" test_ref="oval:org.mitre.oval:tst:30931"/>
            <criterion comment="perl-CPAN is earlier than 2:1.61-89.10" test_ref="oval:org.mitre.oval:tst:30901"/>
            <criterion comment="perl-CGI is earlier than 2:2.81-89.10" test_ref="oval:org.mitre.oval:tst:31227"/>
            <criterion comment="perl-DB_File is earlier than 2:1.804-89.10" test_ref="oval:org.mitre.oval:tst:30945"/>
          </criteria>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <criteria operator="OR">
            <criterion comment="perl-suidperl is earlier than 3:5.8.5-12.1.1" test_ref="oval:org.mitre.oval:tst:31049"/>
            <criterion comment="perl is earlier than 3:5.8.5-12.1" test_ref="oval:org.mitre.oval:tst:31120"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9937" version="3" class="vulnerability">
      <metadata>
        <title>verify.c in GnuTLS before 1.4.4, when using an RSA key with exponent 3, does not properly handle excess data in the digestAlgorithm.parameters field when generating a hash, which allows remote attackers to forge a PKCS #1 v1.5 signature that is signed by that RSA key and prevents GnuTLS from correctly verifying X.509 and other certificates that use PKCS, a variant of CVE-2006-4339.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-4790" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-4790"/>
        <description>verify.c in GnuTLS before 1.4.4, when using an RSA key with exponent 3, does not properly handle excess data in the digestAlgorithm.parameters field when generating a hash, which allows remote attackers to forge a PKCS #1 v1.5 signature that is signed by that RSA key and prevents GnuTLS from correctly verifying X.509 and other certificates that use PKCS, a variant of CVE-2006-4339.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:17:04.969-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:15:03.306-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:16:11.404-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
        <criteria operator="OR">
          <criterion comment="gnutls is earlier than 0:1.0.20-3.2.3" test_ref="oval:org.mitre.oval:tst:32934"/>
          <criterion comment="gnutls-devel is earlier than 0:1.0.20-3.2.3" test_ref="oval:org.mitre.oval:tst:32930"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9934" version="3" class="vulnerability">
      <metadata>
        <title>Multiple vulnerabilities in Mozilla Firefox before 1.5.0.5, Thunderbird before 1.5.0.5, and SeaMonkey before 1.0.3 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via Javascript that leads to memory corruption, including (1) nsListControlFrame::FireMenuItemActiveEvent, (2) buffer overflows in the string class in out-of-memory conditions, (3) table row and column groups, (4) "anonymous box selectors outside of UA stylesheets," (5) stale references to "removed nodes," and (6) running the crypto.generateCRMFRequest callback on deleted context.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-3811" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-3811"/>
        <description>Multiple vulnerabilities in Mozilla Firefox before 1.5.0.5, Thunderbird before 1.5.0.5, and SeaMonkey before 1.0.3 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via Javascript that leads to memory corruption, including (1) nsListControlFrame::FireMenuItemActiveEvent, (2) buffer overflows in the string class in out-of-memory conditions, (3) table row and column groups, (4) "anonymous box selectors outside of UA stylesheets," (5) stale references to "removed nodes," and (6) running the crypto.generateCRMFRequest callback on deleted context.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:19:21.415-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:15:02.264-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:16:10.308-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
          <criteria operator="OR">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.3-0.el3.1" test_ref="oval:org.mitre.oval:tst:32342"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.3-0.el3.1" test_ref="oval:org.mitre.oval:tst:32877"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.3-0.el3.1" test_ref="oval:org.mitre.oval:tst:31982"/>
            <criterion comment="seamonkey is earlier than 0:1.0.3-0.el3.1" test_ref="oval:org.mitre.oval:tst:32816"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.3-0.el3.1" test_ref="oval:org.mitre.oval:tst:32080"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.3-0.el3.1" test_ref="oval:org.mitre.oval:tst:32904"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.3-0.el3.1" test_ref="oval:org.mitre.oval:tst:32915"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.3-0.el3.1" test_ref="oval:org.mitre.oval:tst:32924"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.3-0.el3.1" test_ref="oval:org.mitre.oval:tst:32822"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.3-0.el3.1" test_ref="oval:org.mitre.oval:tst:32555"/>
          </criteria>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <criteria operator="OR">
            <criterion comment="devhelp-devel is earlier than 0:0.10-0.2.el4" test_ref="oval:org.mitre.oval:tst:32873"/>
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.3-0.el4.1" test_ref="oval:org.mitre.oval:tst:32693"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.3-0.el4.1" test_ref="oval:org.mitre.oval:tst:32886"/>
            <criterion comment="thunderbird is earlier than 0:1.5.0.5-0.el4.1" test_ref="oval:org.mitre.oval:tst:32810"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.3-0.el4.1" test_ref="oval:org.mitre.oval:tst:32418"/>
            <criterion comment="seamonkey is earlier than 0:1.0.3-0.el4.1" test_ref="oval:org.mitre.oval:tst:32496"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.3-0.el4.1" test_ref="oval:org.mitre.oval:tst:32929"/>
            <criterion comment="devhelp is earlier than 0:0.10-0.2.el4" test_ref="oval:org.mitre.oval:tst:32777"/>
            <criterion comment="firefox is earlier than 0:1.5.0.5-0.el4.1" test_ref="oval:org.mitre.oval:tst:32896"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.3-0.el4.1" test_ref="oval:org.mitre.oval:tst:32722"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.3-0.el4.1" test_ref="oval:org.mitre.oval:tst:32906"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.3-0.el4.1" test_ref="oval:org.mitre.oval:tst:32905"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.3-0.el4.1" test_ref="oval:org.mitre.oval:tst:32925"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.3-0.el4.1" test_ref="oval:org.mitre.oval:tst:32624"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9933" version="3" class="vulnerability">
      <metadata>
        <title>Multiple buffer overflows in the LWRES dissector in Wireshark 0.9.15 through 1.0.10 and 1.2.0 through 1.2.5 allow remote attackers to cause a denial of service (crash) via a malformed packet, as demonstrated using a stack-based buffer overflow to the dissect_getaddrsbyname_request function.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0304" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0304"/>
        <description>Multiple buffer overflows in the LWRES dissector in Wireshark 0.9.15 through 1.0.10 and 1.2.0 through 1.2.5 allow remote attackers to cause a denial of service (crash) via a malformed packet, as demonstrated using a stack-based buffer overflow to the dissect_getaddrsbyname_request function.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:19:24.618-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:15:01.902-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:16:09.964-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
          <criteria operator="OR">
            <criterion comment="wireshark is earlier than 0:1.0.11-EL3.6" test_ref="oval:org.mitre.oval:tst:39600"/>
            <criterion comment="wireshark-gnome is earlier than 0:1.0.11-EL3.6" test_ref="oval:org.mitre.oval:tst:40430"/>
          </criteria>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <criteria operator="OR">
            <criterion comment="wireshark is earlier than 0:1.0.11-1.el4_8.5" test_ref="oval:org.mitre.oval:tst:40437"/>
            <criterion comment="wireshark-gnome is earlier than 0:1.0.11-1.el4_8.5" test_ref="oval:org.mitre.oval:tst:39877"/>
          </criteria>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criteria operator="OR">
            <criterion comment="wireshark is earlier than 0:1.0.11-1.el5_5.5" test_ref="oval:org.mitre.oval:tst:40351"/>
            <criterion comment="wireshark-gnome is earlier than 0:1.0.11-1.el5_5.5" test_ref="oval:org.mitre.oval:tst:40208"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9932" version="3" class="vulnerability">
      <metadata>
        <title>The Linux Kernel before 2.6.15.5 allows local users to cause a denial of service (NFS client panic) via unknown attack vectors related to the use of O_DIRECT (direct I/O).</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-0555" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0555"/>
        <description>The Linux Kernel before 2.6.15.5 allows local users to cause a denial of service (NFS client panic) via unknown attack vectors related to the use of O_DIRECT (direct I/O).</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:19:06.862-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:15:01.619-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:16:09.674-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
        <criteria operator="OR">
          <criterion comment="kernel-hugemem is earlier than 0:2.6.9-34.0.1.EL" test_ref="oval:org.mitre.oval:tst:32235"/>
          <criterion comment="kernel-hugemem-devel is earlier than 0:2.6.9-34.0.1.EL" test_ref="oval:org.mitre.oval:tst:32371"/>
          <criterion comment="kernel-smp-devel is earlier than 0:2.6.9-34.0.1.EL" test_ref="oval:org.mitre.oval:tst:32703"/>
          <criterion comment="kernel-largesmp-devel is earlier than 0:2.6.9-34.0.1.EL" test_ref="oval:org.mitre.oval:tst:32314"/>
          <criterion comment="kernel is earlier than 0:2.6.9-34.0.1.EL" test_ref="oval:org.mitre.oval:tst:32614"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.9-34.0.1.EL" test_ref="oval:org.mitre.oval:tst:32295"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.9-34.0.1.EL" test_ref="oval:org.mitre.oval:tst:32310"/>
          <criterion comment="kernel-largesmp is earlier than 0:2.6.9-34.0.1.EL" test_ref="oval:org.mitre.oval:tst:32611"/>
          <criterion comment="kernel-smp is earlier than 0:2.6.9-34.0.1.EL" test_ref="oval:org.mitre.oval:tst:32305"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9929" version="3" class="vulnerability">
      <metadata>
        <title>Buffer overflow in the X render (Xrender) extension in X.org X server 6.8.0 up to allows attackers to cause a denial of service (crash), as demonstrated by the (1) XRenderCompositeTriStrip and (2) XRenderCompositeTriFan requests in the rendertest from XCB xcb/xcb-demo, which leads to an incorrect memory allocation due to a typo in an expression that uses a "" instead of a "*" operator. NOTE: the subject line of the original announcement used an incorrect CVE number for this issue.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-1526" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1526"/>
        <description>Buffer overflow in the X render (Xrender) extension in X.org X server 6.8.0 up to allows attackers to cause a denial of service (crash), as demonstrated by the (1) XRenderCompositeTriStrip and (2) XRenderCompositeTriFan requests in the rendertest from XCB xcb/xcb-demo, which leads to an incorrect memory allocation due to a typo in an expression that uses a "&amp;" instead of a "*" operator. NOTE: the subject line of the original announcement used an incorrect CVE number for this issue.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:21:13.621-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:15:00.756-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:16:08.776-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
        <criteria operator="OR">
          <criterion comment="xorg-x11-doc is earlier than 0:6.8.2-1.EL.13.25.1" test_ref="oval:org.mitre.oval:tst:31792"/>
          <criterion comment="xorg-x11-libs is earlier than 0:6.8.2-1.EL.13.25.1" test_ref="oval:org.mitre.oval:tst:32571"/>
          <criterion comment="xorg-x11-xauth is earlier than 0:6.8.2-1.EL.13.25.1" test_ref="oval:org.mitre.oval:tst:32223"/>
          <criterion comment="xorg-x11-Mesa-libGLU is earlier than 0:6.8.2-1.EL.13.25.1" test_ref="oval:org.mitre.oval:tst:32554"/>
          <criterion comment="xorg-x11-twm is earlier than 0:6.8.2-1.EL.13.25.1" test_ref="oval:org.mitre.oval:tst:32521"/>
          <criterion comment="xorg-x11-Mesa-libGL is earlier than 0:6.8.2-1.EL.13.25.1" test_ref="oval:org.mitre.oval:tst:32568"/>
          <criterion comment="xorg-x11-Xdmx is earlier than 0:6.8.2-1.EL.13.25.1" test_ref="oval:org.mitre.oval:tst:32369"/>
          <criterion comment="xorg-x11-xfs is earlier than 0:6.8.2-1.EL.13.25.1" test_ref="oval:org.mitre.oval:tst:31728"/>
          <criterion comment="xorg-x11-deprecated-libs-devel is earlier than 0:6.8.2-1.EL.13.25.1" test_ref="oval:org.mitre.oval:tst:32424"/>
          <criterion comment="xorg-x11-devel is earlier than 0:6.8.2-1.EL.13.25.1" test_ref="oval:org.mitre.oval:tst:32510"/>
          <criterion comment="xorg-x11-Xvfb is earlier than 0:6.8.2-1.EL.13.25.1" test_ref="oval:org.mitre.oval:tst:32532"/>
          <criterion comment="xorg-x11-deprecated-libs is earlier than 0:6.8.2-1.EL.13.25.1" test_ref="oval:org.mitre.oval:tst:32174"/>
          <criterion comment="xorg-x11-sdk is earlier than 0:6.8.2-1.EL.13.25.1" test_ref="oval:org.mitre.oval:tst:32670"/>
          <criterion comment="xorg-x11-xdm is earlier than 0:6.8.2-1.EL.13.25.1" test_ref="oval:org.mitre.oval:tst:32705"/>
          <criterion comment="xorg-x11-Xnest is earlier than 0:6.8.2-1.EL.13.25.1" test_ref="oval:org.mitre.oval:tst:32274"/>
          <criterion comment="xorg-x11 is earlier than 0:6.8.2-1.EL.13.25.1" test_ref="oval:org.mitre.oval:tst:32683"/>
          <criterion comment="xorg-x11-font-utils is earlier than 0:6.8.2-1.EL.13.25.1" test_ref="oval:org.mitre.oval:tst:32330"/>
          <criterion comment="xorg-x11-tools is earlier than 0:6.8.2-1.EL.13.25.1" test_ref="oval:org.mitre.oval:tst:32692"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9927" version="3" class="vulnerability">
      <metadata>
        <title>Certain modifications to the Linux kernel 2.6.16 and earlier do not add the appropriate Linux Security Modules (LSM) file_permission hooks to the (1) readv and (2) writev functions, which might allow attackers to bypass intended access restrictions.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-1856" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1856"/>
        <description>Certain modifications to the Linux kernel 2.6.16 and earlier do not add the appropriate Linux Security Modules (LSM) file_permission hooks to the (1) readv and (2) writev functions, which might allow attackers to bypass intended access restrictions.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:16:25.870-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:15:00.202-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:16:08.196-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
        <criteria operator="OR">
          <criterion comment="kernel-hugemem is earlier than 0:2.6.9-34.0.1.EL" test_ref="oval:org.mitre.oval:tst:32235"/>
          <criterion comment="kernel-hugemem-devel is earlier than 0:2.6.9-34.0.1.EL" test_ref="oval:org.mitre.oval:tst:32371"/>
          <criterion comment="kernel-smp-devel is earlier than 0:2.6.9-34.0.1.EL" test_ref="oval:org.mitre.oval:tst:32703"/>
          <criterion comment="kernel-largesmp-devel is earlier than 0:2.6.9-34.0.1.EL" test_ref="oval:org.mitre.oval:tst:32314"/>
          <criterion comment="kernel is earlier than 0:2.6.9-34.0.1.EL" test_ref="oval:org.mitre.oval:tst:32614"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.9-34.0.1.EL" test_ref="oval:org.mitre.oval:tst:32295"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.9-34.0.1.EL" test_ref="oval:org.mitre.oval:tst:32310"/>
          <criterion comment="kernel-largesmp is earlier than 0:2.6.9-34.0.1.EL" test_ref="oval:org.mitre.oval:tst:32611"/>
          <criterion comment="kernel-smp is earlier than 0:2.6.9-34.0.1.EL" test_ref="oval:org.mitre.oval:tst:32305"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9926" version="3" class="vulnerability">
      <metadata>
        <title>The JBIG2 decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, Poppler before 0.10.6, and other products allows remote attackers to execute arbitrary code via a crafted PDF file that triggers a free of invalid data.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-1180" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1180"/>
        <description>The JBIG2 decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, Poppler before 0.10.6, and other products allows remote attackers to execute arbitrary code via a crafted PDF file that triggers a free of invalid data.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:17:48.604-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:59.474-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:16:07.543-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
          <criterion comment="xpdf is earlier than 1:2.02-14.el3" test_ref="oval:org.mitre.oval:tst:38322"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <criteria operator="OR">
            <criterion comment="tetex-latex is earlier than 0:2.0.2-22.0.1.EL4.16" test_ref="oval:org.mitre.oval:tst:40095"/>
            <criterion comment="kdegraphics-devel is earlier than 7:3.3.1-13.el4" test_ref="oval:org.mitre.oval:tst:38126"/>
            <criterion comment="tetex-dvips is earlier than 0:2.0.2-22.0.1.EL4.16" test_ref="oval:org.mitre.oval:tst:39528"/>
            <criterion comment="kdegraphics is earlier than 7:3.3.1-13.el4" test_ref="oval:org.mitre.oval:tst:38230"/>
            <criterion comment="tetex-fonts is earlier than 0:2.0.2-22.0.1.EL4.16" test_ref="oval:org.mitre.oval:tst:40473"/>
            <criterion comment="cups-libs is earlier than 1:1.1.22-0.rc1.9.27.el4_7.5" test_ref="oval:org.mitre.oval:tst:38481"/>
            <criterion comment="tetex is earlier than 0:2.0.2-22.0.1.EL4.16" test_ref="oval:org.mitre.oval:tst:40316"/>
            <criterion comment="gpdf is earlier than 0:2.8.2-7.7.2.el4_7.4" test_ref="oval:org.mitre.oval:tst:38436"/>
            <criterion comment="cups-devel is earlier than 1:1.1.22-0.rc1.9.27.el4_7.5" test_ref="oval:org.mitre.oval:tst:38145"/>
            <criterion comment="tetex-afm is earlier than 0:2.0.2-22.0.1.EL4.16" test_ref="oval:org.mitre.oval:tst:40209"/>
            <criterion comment="xpdf is earlier than 1:3.00-20.el4" test_ref="oval:org.mitre.oval:tst:38649"/>
            <criterion comment="tetex-xdvi is earlier than 0:2.0.2-22.0.1.EL4.16" test_ref="oval:org.mitre.oval:tst:40364"/>
            <criterion comment="tetex-doc is earlier than 0:2.0.2-22.0.1.EL4.16" test_ref="oval:org.mitre.oval:tst:40077"/>
            <criterion comment="cups is earlier than 1:1.1.22-0.rc1.9.27.el4_7.5" test_ref="oval:org.mitre.oval:tst:38607"/>
          </criteria>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criteria operator="OR">
            <criterion comment="kdegraphics-devel is earlier than 7:3.5.4-12.el5_3" test_ref="oval:org.mitre.oval:tst:38618"/>
            <criterion comment="cups-lpd is earlier than 1:1.3.7-8.el5_3.4" test_ref="oval:org.mitre.oval:tst:38471"/>
            <criterion comment="tetex-dvips is earlier than 0:3.0-33.8.el5_5.5" test_ref="oval:org.mitre.oval:tst:40312"/>
            <criterion comment="kdegraphics is earlier than 7:3.5.4-12.el5_3" test_ref="oval:org.mitre.oval:tst:38271"/>
            <criterion comment="poppler is earlier than 0:0.5.4-4.4.el5_3.9" test_ref="oval:org.mitre.oval:tst:38760"/>
            <criterion comment="tetex-fonts is earlier than 0:3.0-33.8.el5_5.5" test_ref="oval:org.mitre.oval:tst:40122"/>
            <criterion comment="cups-libs is earlier than 1:1.3.7-8.el5_3.4" test_ref="oval:org.mitre.oval:tst:38541"/>
            <criterion comment="tetex is earlier than 0:3.0-33.8.el5_5.5" test_ref="oval:org.mitre.oval:tst:40413"/>
            <criterion comment="tetex-doc is earlier than 0:3.0-33.8.el5_5.5" test_ref="oval:org.mitre.oval:tst:40398"/>
            <criterion comment="poppler-devel is earlier than 0:0.5.4-4.4.el5_3.9" test_ref="oval:org.mitre.oval:tst:38500"/>
            <criterion comment="tetex-latex is earlier than 0:3.0-33.8.el5_5.5" test_ref="oval:org.mitre.oval:tst:40444"/>
            <criterion comment="poppler-utils is earlier than 0:0.5.4-4.4.el5_3.9" test_ref="oval:org.mitre.oval:tst:38512"/>
            <criterion comment="cups-devel is earlier than 1:1.3.7-8.el5_3.4" test_ref="oval:org.mitre.oval:tst:37935"/>
            <criterion comment="tetex-afm is earlier than 0:3.0-33.8.el5_5.5" test_ref="oval:org.mitre.oval:tst:40008"/>
            <criterion comment="tetex-xdvi is earlier than 0:3.0-33.8.el5_5.5" test_ref="oval:org.mitre.oval:tst:39920"/>
            <criterion comment="cups is earlier than 1:1.3.7-8.el5_3.4" test_ref="oval:org.mitre.oval:tst:38334"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9925" version="3" class="vulnerability">
      <metadata>
        <title>Double free vulnerability in the Adobe Acrobat Reader Plugin before 8.0.0, as used in Mozilla Firefox 1.5.0.7, allows remote attackers to execute arbitrary code by causing an error via a javascript: URI call to document.write in the (1) FDF, (2) XML, or (3) XFDF AJAX request parameters.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0005" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0005"/>
        <description>Heap-based buffer overflow in psd.c for ImageMagick 6.1.0, 6.1.7, and possibly earlier versions allows remote attackers to execute arbitrary code via a .PSD image file with a large number of layers.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:19:56.373-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:59.151-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:16:07.212-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
          <criteria operator="OR">
            <criterion comment="ImageMagick-c++-devel is earlier than 0:5.5.6-13" test_ref="oval:org.mitre.oval:tst:30471"/>
            <criterion comment="ImageMagick is earlier than 0:5.5.6-13" test_ref="oval:org.mitre.oval:tst:30355"/>
            <criterion comment="ImageMagick-perl is earlier than 0:5.5.6-13" test_ref="oval:org.mitre.oval:tst:30877"/>
            <criterion comment="ImageMagick-devel is earlier than 0:5.5.6-13" test_ref="oval:org.mitre.oval:tst:30918"/>
            <criterion comment="ImageMagick-c++ is earlier than 0:5.5.6-13" test_ref="oval:org.mitre.oval:tst:30938"/>
          </criteria>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <criteria operator="OR">
            <criterion comment="ImageMagick-c++-devel is earlier than 0:6.0.7.1-6" test_ref="oval:org.mitre.oval:tst:30872"/>
            <criterion comment="ImageMagick is earlier than 0:6.0.7.1-6" test_ref="oval:org.mitre.oval:tst:31137"/>
            <criterion comment="ImageMagick-perl is earlier than 0:6.0.7.1-6" test_ref="oval:org.mitre.oval:tst:31139"/>
            <criterion comment="ImageMagick-devel is earlier than 0:6.0.7.1-6" test_ref="oval:org.mitre.oval:tst:31140"/>
            <criterion comment="ImageMagick-c++ is earlier than 0:6.0.7.1-6" test_ref="oval:org.mitre.oval:tst:31337"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9924" version="3" class="vulnerability">
      <metadata>
        <title>Firefox before 1.0.1 and Mozilla before 1.7.6 truncates long sub-domains or paths for display, which may allow remote malicious web sites to spoof legitimate sites and facilitate phishing attacks.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0585" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0585"/>
        <description>Firefox before 1.0.1 and Mozilla before 1.7.6 truncates long sub-domains or paths for display, which may allow remote malicious web sites to spoof legitimate sites and facilitate phishing attacks.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:24:26.737-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:58.772-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:16:06.821-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
          <criteria operator="OR">
            <criterion comment="mozilla-js-debugger is earlier than 37:1.7.7-1.1.3.4" test_ref="oval:org.mitre.oval:tst:31283"/>
            <criterion comment="mozilla is earlier than 37:1.7.7-1.1.3.4" test_ref="oval:org.mitre.oval:tst:31520"/>
            <criterion comment="mozilla-chat is earlier than 37:1.7.7-1.1.3.4" test_ref="oval:org.mitre.oval:tst:31645"/>
            <criterion comment="mozilla-mail is earlier than 37:1.7.7-1.1.3.4" test_ref="oval:org.mitre.oval:tst:31516"/>
            <criterion comment="mozilla-dom-inspector is earlier than 37:1.7.7-1.1.3.4" test_ref="oval:org.mitre.oval:tst:31569"/>
            <criterion comment="mozilla-devel is earlier than 37:1.7.7-1.1.3.4" test_ref="oval:org.mitre.oval:tst:31143"/>
            <criterion comment="mozilla-nss is earlier than 37:1.7.7-1.1.3.4" test_ref="oval:org.mitre.oval:tst:31512"/>
            <criterion comment="mozilla-nss-devel is earlier than 37:1.7.7-1.1.3.4" test_ref="oval:org.mitre.oval:tst:31785"/>
            <criterion comment="mozilla-nspr is earlier than 37:1.7.7-1.1.3.4" test_ref="oval:org.mitre.oval:tst:31695"/>
            <criterion comment="mozilla-nspr-devel is earlier than 37:1.7.7-1.1.3.4" test_ref="oval:org.mitre.oval:tst:31626"/>
          </criteria>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <criterion comment="firefox is earlier than 0:1.0.1-1.4.3" test_ref="oval:org.mitre.oval:tst:31118"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9923" version="3" class="vulnerability">
      <metadata>
        <title>Directory traversal vulnerability in gftp before 2.0.18 for GTK+ allows remote malicious FTP servers to read arbitrary files via .. (dot dot) sequences in filenames returned from a LIST command.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0372" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0372"/>
        <description>Directory traversal vulnerability in gftp before 2.0.18 for GTK+ allows remote malicious FTP servers to read arbitrary files via .. (dot dot) sequences in filenames returned from a LIST command.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:22:07.106-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:58.549-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:16:06.592-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
          <criterion comment="gftp is earlier than 1:2.0.14-4" test_ref="oval:org.mitre.oval:tst:31807"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <criterion comment="gftp is earlier than 1:2.0.17-5" test_ref="oval:org.mitre.oval:tst:31775"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9922" version="3" class="vulnerability">
      <metadata>
        <title>Mozilla Firefox before 3.0.6 and SeaMonkey do not block links to the (1) about:plugins and (2) about:config URIs from .desktop files, which allows user-assisted remote attackers to bypass the Same Origin Policy and execute arbitrary code with chrome privileges via vectors involving the URL field in a Desktop Entry section of a .desktop file, related to representation of about: URIs as jar:file:// URIs.  NOTE: this issue exists because of an incomplete fix for CVE-2008-4582.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-0356" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0356"/>
        <description>Mozilla Firefox before 3.0.6 and SeaMonkey do not block links to the (1) about:plugins and (2) about:config URIs from .desktop files, which allows user-assisted remote attackers to bypass the Same Origin Policy and execute arbitrary code with chrome privileges via vectors involving the URL field in a Desktop Entry section of a .desktop file, related to representation of about: URIs as jar:file:// URIs.  NOTE: this issue exists because of an incomplete fix for CVE-2008-4582.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:17:19.288-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:58.214-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:16:06.246-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <criteria operator="OR">
            <criterion comment="nss-devel is earlier than 0:3.12.2.0-3.el4" test_ref="oval:org.mitre.oval:tst:37923"/>
            <criterion comment="firefox is earlier than 0:3.0.6-1.el4" test_ref="oval:org.mitre.oval:tst:37823"/>
            <criterion comment="nss is earlier than 0:3.12.2.0-3.el4" test_ref="oval:org.mitre.oval:tst:38343"/>
            <criterion comment="nss-tools is earlier than 0:3.12.2.0-3.el4" test_ref="oval:org.mitre.oval:tst:38172"/>
          </criteria>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criteria operator="OR">
            <criterion comment="nss-pkcs11-devel is earlier than 0:3.12.2.0-4.el5" test_ref="oval:org.mitre.oval:tst:37933"/>
            <criterion comment="xulrunner-devel is earlier than 0:1.9.0.6-1.el5" test_ref="oval:org.mitre.oval:tst:37808"/>
            <criterion comment="nss is earlier than 0:3.12.2.0-4.el5" test_ref="oval:org.mitre.oval:tst:37350"/>
            <criterion comment="xulrunner is earlier than 0:1.9.0.6-1.el5" test_ref="oval:org.mitre.oval:tst:37835"/>
            <criterion comment="xulrunner-devel-unstable is earlier than 0:1.9.0.6-1.el5" test_ref="oval:org.mitre.oval:tst:37556"/>
            <criterion comment="firefox is earlier than 0:3.0.6-1.el5" test_ref="oval:org.mitre.oval:tst:38272"/>
            <criterion comment="nss-devel is earlier than 0:3.12.2.0-4.el5" test_ref="oval:org.mitre.oval:tst:38040"/>
            <criterion comment="nss-tools is earlier than 0:3.12.2.0-4.el5" test_ref="oval:org.mitre.oval:tst:37867"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9921" version="3" class="vulnerability">
      <metadata>
        <title>net/unix/af_unix.c in the Linux kernel 2.6.31.4 and earlier allows local users to cause a denial of service (system hang) by creating an abstract-namespace AF_UNIX listening socket, performing a shutdown operation on this socket, and then performing a series of connect operations to this socket.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-3621" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3621"/>
        <description>net/unix/af_unix.c in the Linux kernel 2.6.31.4 and earlier allows local users to cause a denial of service (system hang) by creating an abstract-namespace AF_UNIX listening socket, performing a shutdown operation on this socket, and then performing a series of connect operations to this socket.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:21:02.374-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:57.700-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:16:05.730-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <criteria operator="OR">
            <criterion comment="kernel-xenU is earlier than 0:2.6.9-89.0.18.EL" test_ref="oval:org.mitre.oval:tst:39504"/>
            <criterion comment="kernel-hugemem is earlier than 0:2.6.9-89.0.18.EL" test_ref="oval:org.mitre.oval:tst:39362"/>
            <criterion comment="kernel-hugemem-devel is earlier than 0:2.6.9-89.0.18.EL" test_ref="oval:org.mitre.oval:tst:39704"/>
            <criterion comment="kernel-xenU-devel is earlier than 0:2.6.9-89.0.18.EL" test_ref="oval:org.mitre.oval:tst:39759"/>
            <criterion comment="kernel-smp-devel is earlier than 0:2.6.9-89.0.18.EL" test_ref="oval:org.mitre.oval:tst:39722"/>
            <criterion comment="kernel-largesmp-devel is earlier than 0:2.6.9-89.0.18.EL" test_ref="oval:org.mitre.oval:tst:39734"/>
            <criterion comment="kernel is earlier than 0:2.6.9-89.0.18.EL" test_ref="oval:org.mitre.oval:tst:39394"/>
            <criterion comment="kernel-devel is earlier than 0:2.6.9-89.0.18.EL" test_ref="oval:org.mitre.oval:tst:39578"/>
            <criterion comment="kernel-doc is earlier than 0:2.6.9-89.0.18.EL" test_ref="oval:org.mitre.oval:tst:39019"/>
            <criterion comment="kernel-largesmp is earlier than 0:2.6.9-89.0.18.EL" test_ref="oval:org.mitre.oval:tst:39604"/>
            <criterion comment="kernel-smp is earlier than 0:2.6.9-89.0.18.EL" test_ref="oval:org.mitre.oval:tst:39609"/>
          </criteria>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criteria operator="OR">
            <criterion comment="kernel-kdump is earlier than 0:2.6.18-164.9.1.el5" test_ref="oval:org.mitre.oval:tst:39674"/>
            <criterion comment="kernel-debug is earlier than 0:2.6.18-164.9.1.el5" test_ref="oval:org.mitre.oval:tst:39635"/>
            <criterion comment="kernel-xen is earlier than 0:2.6.18-164.9.1.el5" test_ref="oval:org.mitre.oval:tst:39630"/>
            <criterion comment="kernel-headers is earlier than 0:2.6.18-164.9.1.el5" test_ref="oval:org.mitre.oval:tst:39766"/>
            <criterion comment="kernel-kdump-devel is earlier than 0:2.6.18-164.9.1.el5" test_ref="oval:org.mitre.oval:tst:39742"/>
            <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-164.9.1.el5" test_ref="oval:org.mitre.oval:tst:39295"/>
            <criterion comment="kernel is earlier than 0:2.6.18-164.9.1.el5" test_ref="oval:org.mitre.oval:tst:38900"/>
            <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-164.9.1.el5" test_ref="oval:org.mitre.oval:tst:39772"/>
            <criterion comment="kernel-devel is earlier than 0:2.6.18-164.9.1.el5" test_ref="oval:org.mitre.oval:tst:39784"/>
            <criterion comment="kernel-PAE is earlier than 0:2.6.18-164.9.1.el5" test_ref="oval:org.mitre.oval:tst:39625"/>
            <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-164.9.1.el5" test_ref="oval:org.mitre.oval:tst:39731"/>
            <criterion comment="kernel-doc is earlier than 0:2.6.18-164.9.1.el5" test_ref="oval:org.mitre.oval:tst:39509"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9920" version="3" class="vulnerability">
      <metadata>
        <title>Unspecified vulnerability in Wireshark (formerly Ethereal) 0.99.6 through 1.0.2 allows attackers to cause a denial of service (crash) via a crafted Tektronix .rf5 file.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-3934" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-3934"/>
        <description>Unspecified vulnerability in Wireshark (formerly Ethereal) 0.99.6 through 1.0.2 allows attackers to cause a denial of service (crash) via a crafted Tektronix .rf5 file.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:20:56.398-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:57.409-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:16:05.422-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
          <criteria operator="OR">
            <criterion comment="wireshark is earlier than 0:1.0.3-EL3.3" test_ref="oval:org.mitre.oval:tst:37624"/>
            <criterion comment="wireshark-gnome is earlier than 0:1.0.3-EL3.3" test_ref="oval:org.mitre.oval:tst:37207"/>
          </criteria>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <criteria operator="OR">
            <criterion comment="wireshark is earlier than 0:1.0.3-3.el4_7" test_ref="oval:org.mitre.oval:tst:37249"/>
            <criterion comment="wireshark-gnome is earlier than 0:1.0.3-3.el4_7" test_ref="oval:org.mitre.oval:tst:37725"/>
          </criteria>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criteria operator="OR">
            <criterion comment="wireshark is earlier than 0:1.0.3-4.el5_2" test_ref="oval:org.mitre.oval:tst:37542"/>
            <criterion comment="wireshark-gnome is earlier than 0:1.0.3-4.el5_2" test_ref="oval:org.mitre.oval:tst:37460"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9918" version="3" class="vulnerability">
      <metadata>
        <title>The check_connection function in sql_parse.cc in MySQL 4.0.x up to 4.0.26, 4.1.x up to 4.1.18, and 5.0.x up to 5.0.20 allows remote attackers to read portions of memory via a username without a trailing null byte, which causes a buffer over-read.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-1516" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1516"/>
        <description>The check_connection function in sql_parse.cc in MySQL 4.0.x up to 4.0.26, 4.1.x up to 4.1.18, and 5.0.x up to 5.0.20 allows remote attackers to read portions of memory via a username without a trailing null byte, which causes a buffer over-read.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:16:00.621-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:56.902-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:16:04.911-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
        <criteria operator="OR">
          <criterion comment="mysql is earlier than 0:4.1.20-1.RHEL4.1" test_ref="oval:org.mitre.oval:tst:32252"/>
          <criterion comment="mysql-devel is earlier than 0:4.1.20-1.RHEL4.1" test_ref="oval:org.mitre.oval:tst:32551"/>
          <criterion comment="mysql-bench is earlier than 0:4.1.20-1.RHEL4.1" test_ref="oval:org.mitre.oval:tst:32245"/>
          <criterion comment="mysql-server is earlier than 0:4.1.20-1.RHEL4.1" test_ref="oval:org.mitre.oval:tst:32560"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9915" version="3" class="vulnerability">
      <metadata>
        <title>MySQL 5.0.18 and earlier allows local users to bypass logging mechanisms via SQL queries that contain the NULL character, which are not properly handled by the mysql_real_query function.  NOTE: this issue was originally reported for the mysql_query function, but the vendor states that since mysql_query expects a null character, this is not an issue for mysql_query.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-0903" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0903"/>
        <description>MySQL 5.0.18 and earlier allows local users to bypass logging mechanisms via SQL queries that contain the NULL character, which are not properly handled by the mysql_real_query function.  NOTE: this issue was originally reported for the mysql_query function, but the vendor states that since mysql_query expects a null character, this is not an issue for mysql_query.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:15:59.900-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:55.967-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:16:03.786-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <criteria operator="OR">
            <criterion comment="mysql is earlier than 0:4.1.20-1.RHEL4.1" test_ref="oval:org.mitre.oval:tst:32252"/>
            <criterion comment="mysql-devel is earlier than 0:4.1.20-1.RHEL4.1" test_ref="oval:org.mitre.oval:tst:32551"/>
            <criterion comment="mysql-bench is earlier than 0:4.1.20-1.RHEL4.1" test_ref="oval:org.mitre.oval:tst:32245"/>
            <criterion comment="mysql-server is earlier than 0:4.1.20-1.RHEL4.1" test_ref="oval:org.mitre.oval:tst:32560"/>
          </criteria>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criteria operator="OR">
            <criterion comment="mysql is earlier than 0:5.0.45-7.el5" test_ref="oval:org.mitre.oval:tst:36197"/>
            <criterion comment="mysql-devel is earlier than 0:5.0.45-7.el5" test_ref="oval:org.mitre.oval:tst:36749"/>
            <criterion comment="mysql-test is earlier than 0:5.0.45-7.el5" test_ref="oval:org.mitre.oval:tst:36750"/>
            <criterion comment="mysql-bench is earlier than 0:5.0.45-7.el5" test_ref="oval:org.mitre.oval:tst:36831"/>
            <criterion comment="mysql-server is earlier than 0:5.0.45-7.el5" test_ref="oval:org.mitre.oval:tst:36646"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9912" version="3" class="vulnerability">
      <metadata>
        <title>Mailman before 2.1.9rc1 allows remote attackers to cause a denial of service via unspecified vectors involving "standards-breaking RFC 2231 formatted headers".</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-2941" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-2941"/>
        <description>Mailman before 2.1.9rc1 allows remote attackers to cause a denial of service via unspecified vectors involving "standards-breaking RFC 2231 formatted headers".</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:16:01.286-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:54.841-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:16:02.664-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
          <criterion comment="mailman is earlier than 3:2.1.5.1-25.rhel3.7" test_ref="oval:org.mitre.oval:tst:32470"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <criterion comment="mailman is earlier than 3:2.1.5.1-34.rhel4.5" test_ref="oval:org.mitre.oval:tst:32787"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9911" version="3" class="vulnerability">
      <metadata>
        <title>Mozilla Firefox before 3.0.16 and 3.5.x before 3.5.6, and SeaMonkey before 2.0.1, allows remote attackers to associate spoofed content with an invalid URL by setting document.location to this URL, and then writing arbitrary web script or HTML to the associated blank document, a related issue to CVE-2009-2654.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-3985" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3985"/>
        <description>Mozilla Firefox before 3.0.16 and 3.5.x before 3.5.6, and SeaMonkey before 2.0.1, allows remote attackers to associate spoofed content with an invalid URL by setting document.location to this URL, and then writing arbitrary web script or HTML to the associated blank document, a related issue to CVE-2009-2654.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:20:30.778-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:54.584-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:16:02.400-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <criterion comment="firefox is earlier than 0:3.0.16-4.el4" test_ref="oval:org.mitre.oval:tst:39002"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criteria operator="OR">
            <criterion comment="xulrunner-devel-unstable is earlier than 0:1.9.0.16-2.el5_4" test_ref="oval:org.mitre.oval:tst:39838"/>
            <criterion comment="xulrunner-devel is earlier than 0:1.9.0.16-2.el5_4" test_ref="oval:org.mitre.oval:tst:39032"/>
            <criterion comment="firefox is earlier than 0:3.0.16-1.el5_4" test_ref="oval:org.mitre.oval:tst:39721"/>
            <criterion comment="xulrunner is earlier than 0:1.9.0.16-2.el5_4" test_ref="oval:org.mitre.oval:tst:39558"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9910" version="3" class="vulnerability">
      <metadata>
        <title>Heap-based buffer overflow in the PixarLog decoder in the TIFF library (libtiff) before 3.8.2 might allow context-dependent attackers to execute arbitrary code via unknown vectors.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-3461" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-3461"/>
        <description>Heap-based buffer overflow in the PixarLog decoder in the TIFF library (libtiff) before 3.8.2 might allow context-dependent attackers to execute arbitrary code via unknown vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:25:11.203-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:54.313-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:16:02.117-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
          <criteria operator="OR">
            <criterion comment="kdegraphics-devel is earlier than 7:3.1.3-3.10" test_ref="oval:org.mitre.oval:tst:32819"/>
            <criterion comment="libtiff is earlier than 0:3.5.7-25.el3.4" test_ref="oval:org.mitre.oval:tst:32069"/>
            <criterion comment="kdegraphics is earlier than 7:3.1.3-3.10" test_ref="oval:org.mitre.oval:tst:33012"/>
            <criterion comment="libtiff-devel is earlier than 0:3.5.7-25.el3.4" test_ref="oval:org.mitre.oval:tst:32843"/>
          </criteria>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <criteria operator="OR">
            <criterion comment="libtiff is earlier than 0:3.6.1-12" test_ref="oval:org.mitre.oval:tst:32922"/>
            <criterion comment="libtiff-devel is earlier than 0:3.6.1-12" test_ref="oval:org.mitre.oval:tst:32413"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9909" version="3" class="vulnerability">
      <metadata>
        <title>The strnlen_user function in Linux kernel before 2.6.16 on IBM S/390 can return an incorrect value, which allows local users to cause a denial of service via unknown vectors.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-0456" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0456"/>
        <description>The strnlen_user function in Linux kernel before 2.6.16 on IBM S/390 can return an incorrect value, which allows local users to cause a denial of service via unknown vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:23:17.573-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:53.991-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:16:01.775-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
        <criteria operator="OR">
          <criterion comment="kernel-hugemem is earlier than 0:2.6.9-42.EL" test_ref="oval:org.mitre.oval:tst:32335"/>
          <criterion comment="kernel-hugemem-devel is earlier than 0:2.6.9-42.EL" test_ref="oval:org.mitre.oval:tst:32833"/>
          <criterion comment="kernel-smp-devel is earlier than 0:2.6.9-42.EL" test_ref="oval:org.mitre.oval:tst:32825"/>
          <criterion comment="kernel-largesmp-devel is earlier than 0:2.6.9-42.EL" test_ref="oval:org.mitre.oval:tst:32836"/>
          <criterion comment="kernel is earlier than 0:2.6.9-42.EL" test_ref="oval:org.mitre.oval:tst:32736"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.9-42.EL" test_ref="oval:org.mitre.oval:tst:31931"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.9-42.EL" test_ref="oval:org.mitre.oval:tst:32361"/>
          <criterion comment="kernel-largesmp is earlier than 0:2.6.9-42.EL" test_ref="oval:org.mitre.oval:tst:32793"/>
          <criterion comment="kernel-smp is earlier than 0:2.6.9-42.EL" test_ref="oval:org.mitre.oval:tst:32795"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9908" version="3" class="vulnerability">
      <metadata>
        <title>Firefox 3.x before 3.0.4, Firefox 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13 allows remote attackers to bypass the protection mechanism for codebase principals and execute arbitrary script via the -moz-binding CSS property in a signed JAR file.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-5023" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-5023"/>
        <description>Firefox 3.x before 3.0.4, Firefox 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13 allows remote attackers to bypass the protection mechanism for codebase principals and execute arbitrary script via the -moz-binding CSS property in a signed JAR file.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:21:26.352-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:53.413-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:16:01.182-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
          <criteria operator="OR">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.9-0.25.el3" test_ref="oval:org.mitre.oval:tst:37159"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-0.25.el3" test_ref="oval:org.mitre.oval:tst:37875"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.9-0.25.el3" test_ref="oval:org.mitre.oval:tst:37293"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-0.25.el3" test_ref="oval:org.mitre.oval:tst:37934"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.9-0.25.el3" test_ref="oval:org.mitre.oval:tst:37671"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-0.25.el3" test_ref="oval:org.mitre.oval:tst:37932"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-0.25.el3" test_ref="oval:org.mitre.oval:tst:37970"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-0.25.el3" test_ref="oval:org.mitre.oval:tst:37357"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-0.25.el3" test_ref="oval:org.mitre.oval:tst:37852"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.9-0.25.el3" test_ref="oval:org.mitre.oval:tst:37844"/>
          </criteria>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <criteria operator="OR">
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-28.el4" test_ref="oval:org.mitre.oval:tst:37232"/>
            <criterion comment="nss is earlier than 0:3.12.1.1-3.el4" test_ref="oval:org.mitre.oval:tst:38065"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-28.el4" test_ref="oval:org.mitre.oval:tst:37914"/>
            <criterion comment="firefox is earlier than 0:3.0.4-1.el4" test_ref="oval:org.mitre.oval:tst:37904"/>
            <criterion comment="nss-devel is earlier than 0:3.12.1.1-3.el4" test_ref="oval:org.mitre.oval:tst:37840"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-28.el4" test_ref="oval:org.mitre.oval:tst:37991"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-28.el4" test_ref="oval:org.mitre.oval:tst:37955"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-28.el4" test_ref="oval:org.mitre.oval:tst:37777"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-28.el4" test_ref="oval:org.mitre.oval:tst:38009"/>
          </criteria>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criteria operator="OR">
            <criterion comment="devhelp-devel is earlier than 0:0.12-20.el5" test_ref="oval:org.mitre.oval:tst:37773"/>
            <criterion comment="nss-pkcs11-devel is earlier than 0:3.12.1.1-3.el5" test_ref="oval:org.mitre.oval:tst:37531"/>
            <criterion comment="xulrunner-devel is earlier than 0:1.9.0.4-1.el5" test_ref="oval:org.mitre.oval:tst:37899"/>
            <criterion comment="nss is earlier than 0:3.12.1.1-3.el5" test_ref="oval:org.mitre.oval:tst:37454"/>
            <criterion comment="xulrunner is earlier than 0:1.9.0.4-1.el5" test_ref="oval:org.mitre.oval:tst:38021"/>
            <criterion comment="yelp is earlier than 0:2.16.0-22.el5" test_ref="oval:org.mitre.oval:tst:37645"/>
            <criterion comment="devhelp is earlier than 0:0.12-20.el5" test_ref="oval:org.mitre.oval:tst:37958"/>
            <criterion comment="xulrunner-devel-unstable is earlier than 0:1.9.0.4-1.el5" test_ref="oval:org.mitre.oval:tst:37388"/>
            <criterion comment="firefox is earlier than 0:3.0.4-1.el5" test_ref="oval:org.mitre.oval:tst:37066"/>
            <criterion comment="nss-devel is earlier than 0:3.12.1.1-3.el5" test_ref="oval:org.mitre.oval:tst:37648"/>
            <criterion comment="nss-tools is earlier than 0:3.12.1.1-3.el5" test_ref="oval:org.mitre.oval:tst:37936"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9904" version="3" class="vulnerability">
      <metadata>
        <title>Header.pm in Net::DNS before 0.60, a Perl module, (1) generates predictable sequence IDs with a fixed increment and (2) can use the same starting ID for all child processes of a forking server, which allows remote attackers to spoof DNS responses, as originally reported for qpsmtp and spamassassin.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-3377" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3377"/>
        <description>Header.pm in Net::DNS before 0.60, a Perl module, (1) generates predictable sequence IDs with a fixed increment and (2) can use the same starting ID for all child processes of a forking server, which allows remote attackers to spoof DNS responses, as originally reported for qpsmtp and spamassassin.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:20:26.189-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:52.436-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:16:00.153-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
          <criterion comment="perl-Net-DNS is earlier than 0:0.31-4.el3" test_ref="oval:org.mitre.oval:tst:34732"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <criterion comment="perl-Net-DNS is earlier than 0:0.48-2.el4" test_ref="oval:org.mitre.oval:tst:34581"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criterion comment="perl-Net-DNS is earlier than 0:0.59-3.el5" test_ref="oval:org.mitre.oval:tst:34803"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9903" version="3" class="vulnerability">
      <metadata>
        <title>The IPv6 flow label handling code (ip6_flowlabel.c) in Linux kernels 2.4 up to 2.4.32 and 2.6 before 2.6.14 modifies the wrong variable in certain circumstances, which allows local users to corrupt kernel memory or cause a denial of service (crash) by triggering a free of non-allocated memory.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-3806" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-3806"/>
        <description>The IPv6 flow label handling code (ip6_flowlabel.c) in Linux kernels 2.4 up to 2.4.32 and 2.6 before 2.6.14 modifies the wrong variable in certain circumstances, which allows local users to corrupt kernel memory or cause a denial of service (crash) by triggering a free of non-allocated memory.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:19:54.626-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:51.984-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:59.686-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
          <criteria operator="OR">
            <criterion comment="kernel-BOOT is earlier than 0:2.4.21-37.0.1.EL" test_ref="oval:org.mitre.oval:tst:32525"/>
            <criterion comment="kernel-unsupported is earlier than 0:2.4.21-37.0.1.EL" test_ref="oval:org.mitre.oval:tst:32366"/>
            <criterion comment="kernel-smp-unsupported is earlier than 0:2.4.21-37.0.1.EL" test_ref="oval:org.mitre.oval:tst:32381"/>
            <criterion comment="kernel-hugemem-unsupported is earlier than 0:2.4.21-37.0.1.EL" test_ref="oval:org.mitre.oval:tst:32215"/>
            <criterion comment="kernel-hugemem is earlier than 0:2.4.21-37.0.1.EL" test_ref="oval:org.mitre.oval:tst:32464"/>
            <criterion comment="kernel is earlier than 0:2.4.21-37.0.1.EL" test_ref="oval:org.mitre.oval:tst:32288"/>
            <criterion comment="kernel-source is earlier than 0:2.4.21-37.0.1.EL" test_ref="oval:org.mitre.oval:tst:31978"/>
            <criterion comment="kernel-doc is earlier than 0:2.4.21-37.0.1.EL" test_ref="oval:org.mitre.oval:tst:32438"/>
            <criterion comment="kernel-smp is earlier than 0:2.4.21-37.0.1.EL" test_ref="oval:org.mitre.oval:tst:32070"/>
          </criteria>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <criteria operator="OR">
            <criterion comment="kernel-smp-devel is earlier than 0:2.6.9-22.0.2.EL" test_ref="oval:org.mitre.oval:tst:32415"/>
            <criterion comment="kernel-hugemem is earlier than 0:2.6.9-22.0.2.EL" test_ref="oval:org.mitre.oval:tst:32137"/>
            <criterion comment="kernel-devel is earlier than 0:2.6.9-22.0.2.EL" test_ref="oval:org.mitre.oval:tst:32528"/>
            <criterion comment="kernel is earlier than 0:2.6.9-22.0.2.EL" test_ref="oval:org.mitre.oval:tst:32205"/>
            <criterion comment="kernel-hugemem-devel is earlier than 0:2.6.9-22.0.2.EL" test_ref="oval:org.mitre.oval:tst:31866"/>
            <criterion comment="kernel-doc is earlier than 0:2.6.9-22.0.2.EL" test_ref="oval:org.mitre.oval:tst:32446"/>
            <criterion comment="kernel-smp is earlier than 0:2.6.9-22.0.2.EL" test_ref="oval:org.mitre.oval:tst:32450"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9902" version="3" class="vulnerability">
      <metadata>
        <title>Heap-based buffer overflow in the Key Distribution Center (KDC) in MIT Kerberos 5 (krb5) 1.4.1 and earlier allows remote attackers to cause a denial of service (apllication crash) and possibly execute arbitrary code via a certain valid TCP or UDP request.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1175" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1175"/>
        <description>Heap-based buffer overflow in the Key Distribution Center (KDC) in MIT Kerberos 5 (krb5) 1.4.1 and earlier allows remote attackers to cause a denial of service (apllication crash) and possibly execute arbitrary code via a certain valid TCP or UDP request.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:21:54.396-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:51.653-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:59.362-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
          <criteria operator="OR">
            <criterion comment="krb5-workstation is earlier than 0:1.2.7-47" test_ref="oval:org.mitre.oval:tst:31712"/>
            <criterion comment="krb5 is earlier than 0:1.2.7-47" test_ref="oval:org.mitre.oval:tst:31065"/>
            <criterion comment="krb5-libs is earlier than 0:1.2.7-47" test_ref="oval:org.mitre.oval:tst:31933"/>
            <criterion comment="krb5-server is earlier than 0:1.2.7-47" test_ref="oval:org.mitre.oval:tst:31927"/>
            <criterion comment="krb5-devel is earlier than 0:1.2.7-47" test_ref="oval:org.mitre.oval:tst:31772"/>
          </criteria>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <criteria operator="OR">
            <criterion comment="krb5-workstation is earlier than 0:1.3.4-17" test_ref="oval:org.mitre.oval:tst:31800"/>
            <criterion comment="krb5 is earlier than 0:1.3.4-17" test_ref="oval:org.mitre.oval:tst:31846"/>
            <criterion comment="krb5-libs is earlier than 0:1.3.4-17" test_ref="oval:org.mitre.oval:tst:31172"/>
            <criterion comment="krb5-server is earlier than 0:1.3.4-17" test_ref="oval:org.mitre.oval:tst:31706"/>
            <criterion comment="krb5-devel is earlier than 0:1.3.4-17" test_ref="oval:org.mitre.oval:tst:31781"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9901" version="3" class="vulnerability">
      <metadata>
        <title>Multiple buffer overflows in CIFS VFS in Linux kernel 2.6.23 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via long SMB responses that trigger the overflows in the SendReceive function.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-5904" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5904"/>
        <description>Multiple buffer overflows in CIFS VFS in Linux kernel 2.6.23 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via long SMB responses that trigger the overflows in the SendReceive function.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:19:15.902-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:51.155-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:58.817-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <criteria operator="OR">
            <criterion comment="kernel-xenU is earlier than 0:2.6.9-67.0.7.EL" test_ref="oval:org.mitre.oval:tst:36188"/>
            <criterion comment="kernel-hugemem is earlier than 0:2.6.9-67.0.7.EL" test_ref="oval:org.mitre.oval:tst:36478"/>
            <criterion comment="kernel-hugemem-devel is earlier than 0:2.6.9-67.0.7.EL" test_ref="oval:org.mitre.oval:tst:36125"/>
            <criterion comment="kernel-xenU-devel is earlier than 0:2.6.9-67.0.7.EL" test_ref="oval:org.mitre.oval:tst:36428"/>
            <criterion comment="kernel-smp-devel is earlier than 0:2.6.9-67.0.7.EL" test_ref="oval:org.mitre.oval:tst:35983"/>
            <criterion comment="kernel-largesmp-devel is earlier than 0:2.6.9-67.0.7.EL" test_ref="oval:org.mitre.oval:tst:36049"/>
            <criterion comment="kernel is earlier than 0:2.6.9-67.0.7.EL" test_ref="oval:org.mitre.oval:tst:36310"/>
            <criterion comment="kernel-devel is earlier than 0:2.6.9-67.0.7.EL" test_ref="oval:org.mitre.oval:tst:36246"/>
            <criterion comment="kernel-doc is earlier than 0:2.6.9-67.0.7.EL" test_ref="oval:org.mitre.oval:tst:36377"/>
            <criterion comment="kernel-largesmp is earlier than 0:2.6.9-67.0.7.EL" test_ref="oval:org.mitre.oval:tst:35967"/>
            <criterion comment="kernel-smp is earlier than 0:2.6.9-67.0.7.EL" test_ref="oval:org.mitre.oval:tst:36113"/>
          </criteria>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criteria operator="OR">
            <criterion comment="kernel-kdump is earlier than 0:2.6.18-53.1.6.el5" test_ref="oval:org.mitre.oval:tst:36030"/>
            <criterion comment="kernel-debug is earlier than 0:2.6.18-53.1.6.el5" test_ref="oval:org.mitre.oval:tst:35766"/>
            <criterion comment="kernel-xen is earlier than 0:2.6.18-53.1.6.el5" test_ref="oval:org.mitre.oval:tst:36138"/>
            <criterion comment="kernel-headers is earlier than 0:2.6.18-53.1.6.el5" test_ref="oval:org.mitre.oval:tst:36062"/>
            <criterion comment="kernel-kdump-devel is earlier than 0:2.6.18-53.1.6.el5" test_ref="oval:org.mitre.oval:tst:35611"/>
            <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-53.1.6.el5" test_ref="oval:org.mitre.oval:tst:35990"/>
            <criterion comment="kernel is earlier than 0:2.6.18-53.1.6.el5" test_ref="oval:org.mitre.oval:tst:35969"/>
            <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-53.1.6.el5" test_ref="oval:org.mitre.oval:tst:36085"/>
            <criterion comment="kernel-devel is earlier than 0:2.6.18-53.1.6.el5" test_ref="oval:org.mitre.oval:tst:36026"/>
            <criterion comment="kernel-PAE is earlier than 0:2.6.18-53.1.6.el5" test_ref="oval:org.mitre.oval:tst:36084"/>
            <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-53.1.6.el5" test_ref="oval:org.mitre.oval:tst:36097"/>
            <criterion comment="kernel-doc is earlier than 0:2.6.18-53.1.6.el5" test_ref="oval:org.mitre.oval:tst:36035"/>
            <criterion comment="kernel-debuginfo-common is earlier than 0:2.6.18-53.1.6.el5" test_ref="oval:org.mitre.oval:tst:35648"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9900" version="3" class="vulnerability">
      <metadata>
        <title>Mozilla Firefox before 2.0.0.16 and 3.x before 3.0.1, Thunderbird before 2.0.0.16, and SeaMonkey before 1.1.11 use an incorrect integer data type as a CSS object reference counter in the CSSValue array (aka nsCSSValue:Array) data structure, which allows remote attackers to execute arbitrary code via a large number of references to a common CSS object, leading to a counter overflow and a free of in-use memory, aka ZDI-CAN-349.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-2785" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-2785"/>
        <description>Mozilla Firefox before 2.0.0.16 and 3.x before 3.0.1, Thunderbird before 2.0.0.16, and SeaMonkey before 1.1.11 use an incorrect integer data type as a CSS object reference counter in the CSSValue array (aka nsCSSValue:Array) data structure, which allows remote attackers to execute arbitrary code via a large number of references to a common CSS object, leading to a counter overflow and a free of in-use memory, aka ZDI-CAN-349.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:24:45.937-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:50.451-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:58.182-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
          <criteria operator="OR">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.9-0.22.el3" test_ref="oval:org.mitre.oval:tst:37358"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-0.22.el3" test_ref="oval:org.mitre.oval:tst:37417"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.9-0.22.el3" test_ref="oval:org.mitre.oval:tst:37346"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-0.22.el3" test_ref="oval:org.mitre.oval:tst:36845"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.9-0.22.el3" test_ref="oval:org.mitre.oval:tst:37059"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-0.22.el3" test_ref="oval:org.mitre.oval:tst:37083"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-0.22.el3" test_ref="oval:org.mitre.oval:tst:36603"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-0.22.el3" test_ref="oval:org.mitre.oval:tst:37300"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-0.22.el3" test_ref="oval:org.mitre.oval:tst:37075"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.9-0.22.el3" test_ref="oval:org.mitre.oval:tst:37472"/>
          </criteria>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <criteria operator="OR">
            <criterion comment="devhelp-devel is earlier than 0:0.10-0.8.1.el4" test_ref="oval:org.mitre.oval:tst:36782"/>
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.9-16.4.el4_6" test_ref="oval:org.mitre.oval:tst:37402"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-16.4.el4_6" test_ref="oval:org.mitre.oval:tst:37430"/>
            <criterion comment="thunderbird is earlier than 0:1.5.0.12-14.el4" test_ref="oval:org.mitre.oval:tst:36999"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.9-16.4.el4_6" test_ref="oval:org.mitre.oval:tst:37439"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-16.4.el4_6" test_ref="oval:org.mitre.oval:tst:37337"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.9-16.4.el4_6" test_ref="oval:org.mitre.oval:tst:36865"/>
            <criterion comment="devhelp is earlier than 0:0.10-0.8.1.el4" test_ref="oval:org.mitre.oval:tst:36898"/>
            <criterion comment="firefox is earlier than 0:1.5.0.12-0.21.el4" test_ref="oval:org.mitre.oval:tst:36910"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-16.4.el4_6" test_ref="oval:org.mitre.oval:tst:37455"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-16.4.el4_6" test_ref="oval:org.mitre.oval:tst:36525"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.9-16.4.el4_6" test_ref="oval:org.mitre.oval:tst:37362"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-16.4.el4_6" test_ref="oval:org.mitre.oval:tst:36596"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-16.4.el4_6" test_ref="oval:org.mitre.oval:tst:37517"/>
          </criteria>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criteria operator="OR">
            <criterion comment="devhelp-devel is earlier than 0:0.12-18.el5" test_ref="oval:org.mitre.oval:tst:37176"/>
            <criterion comment="xulrunner-devel is earlier than 0:1.9.0.1-1.el5" test_ref="oval:org.mitre.oval:tst:37474"/>
            <criterion comment="thunderbird is earlier than 0:2.0.0.16-1.el5" test_ref="oval:org.mitre.oval:tst:37363"/>
            <criterion comment="xulrunner is earlier than 0:1.9.0.1-1.el5" test_ref="oval:org.mitre.oval:tst:37409"/>
            <criterion comment="devhelp is earlier than 0:0.12-18.el5" test_ref="oval:org.mitre.oval:tst:37522"/>
            <criterion comment="yelp is earlier than 0:2.16.0-20.el5" test_ref="oval:org.mitre.oval:tst:37008"/>
            <criterion comment="xulrunner-devel-unstable is earlier than 0:1.9.0.1-1.el5" test_ref="oval:org.mitre.oval:tst:37414"/>
            <criterion comment="firefox is earlier than 0:3.0.1-1.el5" test_ref="oval:org.mitre.oval:tst:37297"/>
            <criterion comment="nspluginwrapper is earlier than 0:0.9.91.5-22.el5" test_ref="oval:org.mitre.oval:tst:37422"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9897" version="3" class="vulnerability">
      <metadata>
        <title>Mozilla Firefox before 2.0.0.12, Thunderbird before 2.0.0.12, and SeaMonkey before 1.1.8 allows remote attackers to execute script outside of the sandbox and conduct cross-site scripting (XSS) attacks via multiple vectors including the XMLDocument.load function, aka "JavaScript privilege escalation bugs."</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-0415" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-0415"/>
        <description>Mozilla Firefox before 2.0.0.12, Thunderbird before 2.0.0.12, and SeaMonkey before 1.1.8 allows remote attackers to execute script outside of the sandbox and conduct cross-site scripting (XSS) attacks via multiple vectors including the XMLDocument.load function, aka "JavaScript privilege escalation bugs."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:18:31.823-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:49.161-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:56.950-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
          <criteria operator="OR">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.9-0.9.el3" test_ref="oval:org.mitre.oval:tst:36256"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-0.9.el3" test_ref="oval:org.mitre.oval:tst:36236"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.9-0.9.el3" test_ref="oval:org.mitre.oval:tst:35996"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-0.9.el3" test_ref="oval:org.mitre.oval:tst:36279"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.9-0.9.el3" test_ref="oval:org.mitre.oval:tst:36046"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-0.9.el3" test_ref="oval:org.mitre.oval:tst:36052"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-0.9.el3" test_ref="oval:org.mitre.oval:tst:36034"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-0.9.el3" test_ref="oval:org.mitre.oval:tst:36284"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-0.9.el3" test_ref="oval:org.mitre.oval:tst:35748"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.9-0.9.el3" test_ref="oval:org.mitre.oval:tst:35994"/>
          </criteria>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <criteria operator="OR">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.9-9.el4" test_ref="oval:org.mitre.oval:tst:36164"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-9.el4" test_ref="oval:org.mitre.oval:tst:36050"/>
            <criterion comment="thunderbird is earlier than 0:1.5.0.12-8.el4" test_ref="oval:org.mitre.oval:tst:36202"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.9-9.el4" test_ref="oval:org.mitre.oval:tst:36193"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-9.el4" test_ref="oval:org.mitre.oval:tst:36093"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.9-9.el4" test_ref="oval:org.mitre.oval:tst:36053"/>
            <criterion comment="firefox is earlier than 0:1.5.0.12-0.10.el4" test_ref="oval:org.mitre.oval:tst:35919"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-9.el4" test_ref="oval:org.mitre.oval:tst:35600"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-9.el4" test_ref="oval:org.mitre.oval:tst:36141"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.9-9.el4" test_ref="oval:org.mitre.oval:tst:35397"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-9.el4" test_ref="oval:org.mitre.oval:tst:35684"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-9.el4" test_ref="oval:org.mitre.oval:tst:36203"/>
          </criteria>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criteria operator="OR">
            <criterion comment="firefox-devel is earlier than 0:1.5.0.12-9.el5" test_ref="oval:org.mitre.oval:tst:36281"/>
            <criterion comment="firefox is earlier than 0:1.5.0.12-9.el5" test_ref="oval:org.mitre.oval:tst:35480"/>
            <criterion comment="thunderbird is earlier than 0:1.5.0.12-8.el5" test_ref="oval:org.mitre.oval:tst:35675"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9895" version="3" class="vulnerability">
      <metadata>
        <title>Multiple buffer overflows in ImageMagick before 6.2.9 allow user-assisted attackers to execute arbitrary code via crafted XCF images.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-3743" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-3743"/>
        <description>Multiple buffer overflows in ImageMagick before 6.2.9 allow user-assisted attackers to execute arbitrary code via crafted XCF images.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:17:04.556-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:48.550-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:56.382-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
          <criteria operator="OR">
            <criterion comment="ImageMagick-c++-devel is earlier than 0:5.5.6-20" test_ref="oval:org.mitre.oval:tst:32037"/>
            <criterion comment="ImageMagick is earlier than 0:5.5.6-20" test_ref="oval:org.mitre.oval:tst:32699"/>
            <criterion comment="ImageMagick-perl is earlier than 0:5.5.6-20" test_ref="oval:org.mitre.oval:tst:32588"/>
            <criterion comment="ImageMagick-devel is earlier than 0:5.5.6-20" test_ref="oval:org.mitre.oval:tst:32852"/>
            <criterion comment="ImageMagick-c++ is earlier than 0:5.5.6-20" test_ref="oval:org.mitre.oval:tst:32735"/>
          </criteria>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <criteria operator="OR">
            <criterion comment="ImageMagick-c++-devel is earlier than 0:6.0.7.1-16" test_ref="oval:org.mitre.oval:tst:32383"/>
            <criterion comment="ImageMagick is earlier than 0:6.0.7.1-16" test_ref="oval:org.mitre.oval:tst:32971"/>
            <criterion comment="ImageMagick-perl is earlier than 0:6.0.7.1-16" test_ref="oval:org.mitre.oval:tst:32748"/>
            <criterion comment="ImageMagick-devel is earlier than 0:6.0.7.1-16" test_ref="oval:org.mitre.oval:tst:32946"/>
            <criterion comment="ImageMagick-c++ is earlier than 0:6.0.7.1-16" test_ref="oval:org.mitre.oval:tst:32537"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9893" version="3" class="vulnerability">
      <metadata>
        <title>Multiple vulnerabilities in libtiff before 3.8.1 allow context-dependent attackers to cause a denial of service via a TIFF image that triggers errors in (1) the TIFFFetchAnyArray function in (a) tif_dirread.c; (2) certain "codec cleanup methods" in (b) tif_lzw.c, (c) tif_pixarlog.c, and (d) tif_zip.c; (3) and improper restoration of setfield and getfield methods in cleanup functions within (e) tif_jpeg.c, tif_pixarlog.c, (f) tif_fax3.c, and tif_zip.c.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-2024" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-2024"/>
        <description>Multiple vulnerabilities in libtiff before 3.8.1 allow context-dependent attackers to cause a denial of service via a TIFF image that triggers errors in (1) the TIFFFetchAnyArray function in (a) tif_dirread.c; (2) certain "codec cleanup methods" in (b) tif_lzw.c, (c) tif_pixarlog.c, and (d) tif_zip.c; (3) and improper restoration of setfield and getfield methods in cleanup functions within (e) tif_jpeg.c, tif_pixarlog.c, (f) tif_fax3.c, and tif_zip.c.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:24:49.067-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:48.008-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:55.834-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
          <criteria operator="OR">
            <criterion comment="libtiff is earlier than 0:3.5.7-25.el3.1" test_ref="oval:org.mitre.oval:tst:32689"/>
            <criterion comment="libtiff-devel is earlier than 0:3.5.7-25.el3.1" test_ref="oval:org.mitre.oval:tst:32435"/>
          </criteria>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <criteria operator="OR">
            <criterion comment="libtiff is earlier than 0:3.6.1-10" test_ref="oval:org.mitre.oval:tst:32329"/>
            <criterion comment="libtiff-devel is earlier than 0:3.6.1-10" test_ref="oval:org.mitre.oval:tst:32637"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9891" version="3" class="vulnerability">
      <metadata>
        <title>The ATI Rage 128 (aka r128) driver in the Linux kernel before 2.6.31-git11 does not properly verify Concurrent Command Engine (CCE) state initialization, which allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly gain privileges via unspecified ioctl calls.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-3620" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3620"/>
        <description>The ATI Rage 128 (aka r128) driver in the Linux kernel before 2.6.31-git11 does not properly verify Concurrent Command Engine (CCE) state initialization, which allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly gain privileges via unspecified ioctl calls.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:17:39.465-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:47.311-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:55.113-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <criteria operator="OR">
            <criterion comment="kernel-xenU is earlier than 0:2.6.9-89.0.18.EL" test_ref="oval:org.mitre.oval:tst:39504"/>
            <criterion comment="kernel-hugemem is earlier than 0:2.6.9-89.0.18.EL" test_ref="oval:org.mitre.oval:tst:39362"/>
            <criterion comment="kernel-hugemem-devel is earlier than 0:2.6.9-89.0.18.EL" test_ref="oval:org.mitre.oval:tst:39704"/>
            <criterion comment="kernel-xenU-devel is earlier than 0:2.6.9-89.0.18.EL" test_ref="oval:org.mitre.oval:tst:39759"/>
            <criterion comment="kernel-smp-devel is earlier than 0:2.6.9-89.0.18.EL" test_ref="oval:org.mitre.oval:tst:39722"/>
            <criterion comment="kernel-largesmp-devel is earlier than 0:2.6.9-89.0.18.EL" test_ref="oval:org.mitre.oval:tst:39734"/>
            <criterion comment="kernel is earlier than 0:2.6.9-89.0.18.EL" test_ref="oval:org.mitre.oval:tst:39394"/>
            <criterion comment="kernel-devel is earlier than 0:2.6.9-89.0.18.EL" test_ref="oval:org.mitre.oval:tst:39578"/>
            <criterion comment="kernel-doc is earlier than 0:2.6.9-89.0.18.EL" test_ref="oval:org.mitre.oval:tst:39019"/>
            <criterion comment="kernel-largesmp is earlier than 0:2.6.9-89.0.18.EL" test_ref="oval:org.mitre.oval:tst:39604"/>
            <criterion comment="kernel-smp is earlier than 0:2.6.9-89.0.18.EL" test_ref="oval:org.mitre.oval:tst:39609"/>
          </criteria>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criteria operator="OR">
            <criterion comment="kernel-kdump is earlier than 0:2.6.18-164.9.1.el5" test_ref="oval:org.mitre.oval:tst:39674"/>
            <criterion comment="kernel-debug is earlier than 0:2.6.18-164.9.1.el5" test_ref="oval:org.mitre.oval:tst:39635"/>
            <criterion comment="kernel-xen is earlier than 0:2.6.18-164.9.1.el5" test_ref="oval:org.mitre.oval:tst:39630"/>
            <criterion comment="kernel-headers is earlier than 0:2.6.18-164.9.1.el5" test_ref="oval:org.mitre.oval:tst:39766"/>
            <criterion comment="kernel-kdump-devel is earlier than 0:2.6.18-164.9.1.el5" test_ref="oval:org.mitre.oval:tst:39742"/>
            <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-164.9.1.el5" test_ref="oval:org.mitre.oval:tst:39295"/>
            <criterion comment="kernel is earlier than 0:2.6.18-164.9.1.el5" test_ref="oval:org.mitre.oval:tst:38900"/>
            <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-164.9.1.el5" test_ref="oval:org.mitre.oval:tst:39772"/>
            <criterion comment="kernel-devel is earlier than 0:2.6.18-164.9.1.el5" test_ref="oval:org.mitre.oval:tst:39784"/>
            <criterion comment="kernel-PAE is earlier than 0:2.6.18-164.9.1.el5" test_ref="oval:org.mitre.oval:tst:39625"/>
            <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-164.9.1.el5" test_ref="oval:org.mitre.oval:tst:39731"/>
            <criterion comment="kernel-doc is earlier than 0:2.6.18-164.9.1.el5" test_ref="oval:org.mitre.oval:tst:39509"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9890" version="3" class="vulnerability">
      <metadata>
        <title>Linux kernel 2.4.x and 2.6.x allows local users to cause a denial of service (CPU and memory consumption) and bypass RLIM_MEMLOCK limits via the mlockall call.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0179" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0179"/>
        <description>Linux kernel 2.4.x and 2.6.x allows local users to cause a denial of service (CPU and memory consumption) and bypass RLIM_MEMLOCK limits via the mlockall call.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:17:15.752-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:46.859-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:54.671-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
          <criteria operator="OR">
            <criterion comment="kernel-BOOT is earlier than 0:2.4.21-37.EL" test_ref="oval:org.mitre.oval:tst:31411"/>
            <criterion comment="kernel-unsupported is earlier than 0:2.4.21-37.EL" test_ref="oval:org.mitre.oval:tst:31953"/>
            <criterion comment="kernel-smp-unsupported is earlier than 0:2.4.21-37.EL" test_ref="oval:org.mitre.oval:tst:31879"/>
            <criterion comment="kernel-hugemem-unsupported is earlier than 0:2.4.21-37.EL" test_ref="oval:org.mitre.oval:tst:31990"/>
            <criterion comment="kernel-hugemem is earlier than 0:2.4.21-37.EL" test_ref="oval:org.mitre.oval:tst:31485"/>
            <criterion comment="kernel is earlier than 0:2.4.21-37.EL" test_ref="oval:org.mitre.oval:tst:32093"/>
            <criterion comment="kernel-source is earlier than 0:2.4.21-37.EL" test_ref="oval:org.mitre.oval:tst:31968"/>
            <criterion comment="kernel-doc is earlier than 0:2.4.21-37.EL" test_ref="oval:org.mitre.oval:tst:32148"/>
            <criterion comment="kernel-smp is earlier than 0:2.4.21-37.EL" test_ref="oval:org.mitre.oval:tst:31741"/>
          </criteria>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <criteria operator="OR">
            <criterion comment="kernel-smp-devel is earlier than 0:2.6.9-5.0.3.EL" test_ref="oval:org.mitre.oval:tst:30633"/>
            <criterion comment="kernel-hugemem is earlier than 0:2.6.9-5.0.3.EL" test_ref="oval:org.mitre.oval:tst:31009"/>
            <criterion comment="kernel-devel is earlier than 0:2.6.9-5.0.3.EL" test_ref="oval:org.mitre.oval:tst:30369"/>
            <criterion comment="kernel is earlier than 0:2.6.9-5.0.3.EL" test_ref="oval:org.mitre.oval:tst:31205"/>
            <criterion comment="kernel-hugemem-devel is earlier than 0:2.6.9-5.0.3.EL" test_ref="oval:org.mitre.oval:tst:30421"/>
            <criterion comment="kernel-doc is earlier than 0:2.6.9-5.0.3.EL" test_ref="oval:org.mitre.oval:tst:30594"/>
            <criterion comment="kernel-smp is earlier than 0:2.6.9-5.0.3.EL" test_ref="oval:org.mitre.oval:tst:30616"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9889" version="3" class="vulnerability">
      <metadata>
        <title>Mozilla Firefox before 2.0.0.13 and SeaMonkey before 1.1.9, when generating the HTTP Referer header, does not list the entire URL when it contains Basic Authentication credentials without a username, which makes it easier for remote attackers to bypass application protection mechanisms that rely on Referer headers, such as with some Cross-Site Request Forgery (CSRF) mechanisms.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-1238" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1238"/>
        <description>Mozilla Firefox before 2.0.0.13 and SeaMonkey before 1.1.9, when generating the HTTP Referer header, does not list the entire URL when it contains Basic Authentication credentials without a username, which makes it easier for remote attackers to bypass application protection mechanisms that rely on Referer headers, such as with some Cross-Site Request Forgery (CSRF) mechanisms.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:20:02.547-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:46.338-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:53.955-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
          <criteria operator="OR">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.9-0.16.el3" test_ref="oval:org.mitre.oval:tst:36547"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-0.16.el3" test_ref="oval:org.mitre.oval:tst:36570"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.9-0.16.el3" test_ref="oval:org.mitre.oval:tst:36574"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-0.16.el3" test_ref="oval:org.mitre.oval:tst:35661"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.9-0.16.el3" test_ref="oval:org.mitre.oval:tst:36605"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-0.16.el3" test_ref="oval:org.mitre.oval:tst:35672"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-0.16.el3" test_ref="oval:org.mitre.oval:tst:35874"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-0.16.el3" test_ref="oval:org.mitre.oval:tst:36533"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-0.16.el3" test_ref="oval:org.mitre.oval:tst:36355"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.9-0.16.el3" test_ref="oval:org.mitre.oval:tst:36379"/>
          </criteria>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <criteria operator="OR">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.9-15.el4" test_ref="oval:org.mitre.oval:tst:36587"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-15.el4" test_ref="oval:org.mitre.oval:tst:35752"/>
            <criterion comment="thunderbird is earlier than 0:1.5.0.12-10.el4" test_ref="oval:org.mitre.oval:tst:36259"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.9-15.el4" test_ref="oval:org.mitre.oval:tst:36586"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-15.el4" test_ref="oval:org.mitre.oval:tst:36333"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.9-15.el4" test_ref="oval:org.mitre.oval:tst:36500"/>
            <criterion comment="firefox is earlier than 0:1.5.0.12-0.14.el4" test_ref="oval:org.mitre.oval:tst:35884"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-15.el4" test_ref="oval:org.mitre.oval:tst:36540"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-15.el4" test_ref="oval:org.mitre.oval:tst:36602"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.9-15.el4" test_ref="oval:org.mitre.oval:tst:36557"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-15.el4" test_ref="oval:org.mitre.oval:tst:36511"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-15.el4" test_ref="oval:org.mitre.oval:tst:36221"/>
          </criteria>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criteria operator="OR">
            <criterion comment="firefox-devel is earlier than 0:1.5.0.12-14.el5_1" test_ref="oval:org.mitre.oval:tst:36566"/>
            <criterion comment="firefox is earlier than 0:1.5.0.12-14.el5_1" test_ref="oval:org.mitre.oval:tst:36305"/>
            <criterion comment="thunderbird is earlier than 0:1.5.0.12-11.el5_1" test_ref="oval:org.mitre.oval:tst:36619"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9888" version="3" class="vulnerability">
      <metadata>
        <title>Integer overflow in the xmlSAX2Characters function in libxml2 2.7.2 allows context-dependent attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via a large XML document.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-4226" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-4226"/>
        <description>Integer overflow in the xmlSAX2Characters function in libxml2 2.7.2 allows context-dependent attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via a large XML document.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:21:57.587-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:45.969-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:53.605-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
          <criteria operator="OR">
            <criterion comment="libxml2-devel is earlier than 0:2.5.10-14" test_ref="oval:org.mitre.oval:tst:37860"/>
            <criterion comment="libxml2-python is earlier than 0:2.5.10-14" test_ref="oval:org.mitre.oval:tst:37771"/>
            <criterion comment="libxml2 is earlier than 0:2.5.10-14" test_ref="oval:org.mitre.oval:tst:38036"/>
          </criteria>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <criteria operator="OR">
            <criterion comment="libxml2-devel is earlier than 0:2.6.16-12.6" test_ref="oval:org.mitre.oval:tst:37841"/>
            <criterion comment="libxml2-python is earlier than 0:2.6.16-12.6" test_ref="oval:org.mitre.oval:tst:37839"/>
            <criterion comment="libxml2 is earlier than 0:2.6.16-12.6" test_ref="oval:org.mitre.oval:tst:37940"/>
          </criteria>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criteria operator="OR">
            <criterion comment="libxml2-devel is earlier than 0:2.6.26-2.1.2.7" test_ref="oval:org.mitre.oval:tst:38044"/>
            <criterion comment="libxml2-python is earlier than 0:2.6.26-2.1.2.7" test_ref="oval:org.mitre.oval:tst:37640"/>
            <criterion comment="libxml2 is earlier than 0:2.6.26-2.1.2.7" test_ref="oval:org.mitre.oval:tst:37694"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9887" version="3" class="vulnerability">
      <metadata>
        <title>Firefox before 1.0.5 allows remote attackers to steal sensitive information by opening a malicious link in the Firefox sidebar using the _search target, then injecting script into other pages via a data: URL.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2264" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2264"/>
        <description>Firefox before 1.0.5 allows remote attackers to steal sensitive information by opening a malicious link in the Firefox sidebar using the _search target, then injecting script into other pages via a data: URL.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:16:35.727-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:45.787-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:53.405-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
        <criterion comment="firefox is earlier than 0:1.0.6-1.4.1" test_ref="oval:org.mitre.oval:tst:32167"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9885" version="3" class="vulnerability">
      <metadata>
        <title>The copy_from_user function in the uaccess code in Linux kernel 2.6 before 2.6.19-rc1, when running on s390, does not properly clear a kernel buffer, which allows local user space programs to read portions of kernel memory by "appending to a file from a bad address," which triggers a fault that prevents the unused memory from being cleared in the kernel buffer.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-5174" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-5174"/>
        <description>The copy_from_user function in the uaccess code in Linux kernel 2.6 before 2.6.19-rc1, when running on s390, does not properly clear a kernel buffer, which allows local user space programs to read portions of kernel memory by "appending to a file from a bad address," which triggers a fault that prevents the unused memory from being cleared in the kernel buffer.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:20:06.557-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:45.177-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:52.707-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
          <criteria operator="OR">
            <criterion comment="kernel-BOOT is earlier than 0:2.4.21-47.0.1.EL" test_ref="oval:org.mitre.oval:tst:33074"/>
            <criterion comment="kernel-unsupported is earlier than 0:2.4.21-47.0.1.EL" test_ref="oval:org.mitre.oval:tst:32633"/>
            <criterion comment="kernel-smp-unsupported is earlier than 0:2.4.21-47.0.1.EL" test_ref="oval:org.mitre.oval:tst:33103"/>
            <criterion comment="kernel-hugemem-unsupported is earlier than 0:2.4.21-47.0.1.EL" test_ref="oval:org.mitre.oval:tst:33001"/>
            <criterion comment="kernel-hugemem is earlier than 0:2.4.21-47.0.1.EL" test_ref="oval:org.mitre.oval:tst:32937"/>
            <criterion comment="kernel is earlier than 0:2.4.21-47.0.1.EL" test_ref="oval:org.mitre.oval:tst:32280"/>
            <criterion comment="kernel-source is earlier than 0:2.4.21-47.0.1.EL" test_ref="oval:org.mitre.oval:tst:33127"/>
            <criterion comment="kernel-doc is earlier than 0:2.4.21-47.0.1.EL" test_ref="oval:org.mitre.oval:tst:32855"/>
            <criterion comment="kernel-smp is earlier than 0:2.4.21-47.0.1.EL" test_ref="oval:org.mitre.oval:tst:33021"/>
          </criteria>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <criteria operator="OR">
            <criterion comment="kernel-hugemem is earlier than 0:2.6.9-42.0.8.EL" test_ref="oval:org.mitre.oval:tst:33204"/>
            <criterion comment="kernel-hugemem-devel is earlier than 0:2.6.9-42.0.8.EL" test_ref="oval:org.mitre.oval:tst:33278"/>
            <criterion comment="kernel-smp-devel is earlier than 0:2.6.9-42.0.8.EL" test_ref="oval:org.mitre.oval:tst:33306"/>
            <criterion comment="kernel-largesmp-devel is earlier than 0:2.6.9-42.0.8.EL" test_ref="oval:org.mitre.oval:tst:32378"/>
            <criterion comment="kernel is earlier than 0:2.6.9-42.0.8.EL" test_ref="oval:org.mitre.oval:tst:33145"/>
            <criterion comment="kernel-devel is earlier than 0:2.6.9-42.0.8.EL" test_ref="oval:org.mitre.oval:tst:33107"/>
            <criterion comment="kernel-doc is earlier than 0:2.6.9-42.0.8.EL" test_ref="oval:org.mitre.oval:tst:32620"/>
            <criterion comment="kernel-largesmp is earlier than 0:2.6.9-42.0.8.EL" test_ref="oval:org.mitre.oval:tst:32645"/>
            <criterion comment="kernel-smp is earlier than 0:2.6.9-42.0.8.EL" test_ref="oval:org.mitre.oval:tst:33057"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9884" version="3" class="vulnerability">
      <metadata>
        <title>browser.js in Mozilla Firefox 1.5.x before 1.5.0.10 and 2.x before 2.0.0.2, and SeaMonkey before 1.0.8 uses the requesting URI to identify child windows, which allows remote attackers to conduct cross-site scripting (XSS) attacks by opening a blocked popup originating from a javascript: URI in combination with multiple frames having the same data: URI.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-0780" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0780"/>
        <description>browser.js in Mozilla Firefox 1.5.x before 1.5.0.10 and 2.x before 2.0.0.2, and SeaMonkey before 1.0.8 uses the requesting URI to identify child windows, which allows remote attackers to conduct cross-site scripting (XSS) attacks by opening a blocked popup originating from a javascript: URI in combination with multiple frames having the same data: URI.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:20:19.280-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:44.545-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:52.104-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
          <criteria operator="OR">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.8-0.2.el3" test_ref="oval:org.mitre.oval:tst:33391"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.8-0.2.el3" test_ref="oval:org.mitre.oval:tst:33688"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.8-0.2.el3" test_ref="oval:org.mitre.oval:tst:33675"/>
            <criterion comment="seamonkey is earlier than 0:1.0.8-0.2.el3" test_ref="oval:org.mitre.oval:tst:33724"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.8-0.2.el3" test_ref="oval:org.mitre.oval:tst:33510"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.8-0.2.el3" test_ref="oval:org.mitre.oval:tst:33409"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.8-0.2.el3" test_ref="oval:org.mitre.oval:tst:33467"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.8-0.2.el3" test_ref="oval:org.mitre.oval:tst:33658"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.8-0.2.el3" test_ref="oval:org.mitre.oval:tst:33649"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.8-0.2.el3" test_ref="oval:org.mitre.oval:tst:33381"/>
          </criteria>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <criteria operator="OR">
            <criterion comment="devhelp-devel is earlier than 0:0.10-0.7.el4" test_ref="oval:org.mitre.oval:tst:32760"/>
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.8-0.2.el4" test_ref="oval:org.mitre.oval:tst:33554"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.8-0.2.el4" test_ref="oval:org.mitre.oval:tst:33648"/>
            <criterion comment="thunderbird is earlier than 0:1.5.0.10-0.1.el4" test_ref="oval:org.mitre.oval:tst:32765"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.8-0.2.el4" test_ref="oval:org.mitre.oval:tst:33712"/>
            <criterion comment="seamonkey is earlier than 0:1.0.8-0.2.el4" test_ref="oval:org.mitre.oval:tst:33705"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.8-0.2.el4" test_ref="oval:org.mitre.oval:tst:33379"/>
            <criterion comment="devhelp is earlier than 0:0.10-0.7.el4" test_ref="oval:org.mitre.oval:tst:33400"/>
            <criterion comment="firefox is earlier than 0:1.5.0.10-0.1.el4" test_ref="oval:org.mitre.oval:tst:33759"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.8-0.2.el4" test_ref="oval:org.mitre.oval:tst:33678"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.8-0.2.el4" test_ref="oval:org.mitre.oval:tst:33695"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.8-0.2.el4" test_ref="oval:org.mitre.oval:tst:33697"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.8-0.2.el4" test_ref="oval:org.mitre.oval:tst:33244"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.8-0.2.el4" test_ref="oval:org.mitre.oval:tst:33645"/>
          </criteria>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criteria operator="OR">
            <criterion comment="firefox-devel is earlier than 0:1.5.0.10-2.el5" test_ref="oval:org.mitre.oval:tst:33461"/>
            <criterion comment="yelp is earlier than 0:2.16.0-14.0.1.el5" test_ref="oval:org.mitre.oval:tst:33761"/>
            <criterion comment="devhelp-devel is earlier than 0:0.12-10.0.1.el5" test_ref="oval:org.mitre.oval:tst:33744"/>
            <criterion comment="devhelp is earlier than 0:0.12-10.0.1.el5" test_ref="oval:org.mitre.oval:tst:33415"/>
            <criterion comment="firefox is earlier than 0:1.5.0.10-2.el5" test_ref="oval:org.mitre.oval:tst:33616"/>
            <criterion comment="thunderbird is earlier than 0:1.5.0.10-1.el5" test_ref="oval:org.mitre.oval:tst:33493"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9880" version="3" class="vulnerability">
      <metadata>
        <title>The DCP ETSI dissector in Wireshark (formerly Ethereal) 0.99.6 allows remote attackers to cause a denial of service (long loop and resource consumption) via unknown vectors.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-6119" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6119"/>
        <description>The DCP ETSI dissector in Wireshark (formerly Ethereal) 0.99.6 allows remote attackers to cause a denial of service (long loop and resource consumption) via unknown vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:24:52.977-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:43.402-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:50.850-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <criteria operator="OR">
            <criterion comment="wireshark is earlier than 0:0.99.7-1.el4" test_ref="oval:org.mitre.oval:tst:36051"/>
            <criterion comment="wireshark-gnome is earlier than 0:0.99.7-1.el4" test_ref="oval:org.mitre.oval:tst:35980"/>
            <criterion comment="libsmi is earlier than 0:0.4.5-2.el4" test_ref="oval:org.mitre.oval:tst:35669"/>
            <criterion comment="libsmi-devel is earlier than 0:0.4.5-2.el4" test_ref="oval:org.mitre.oval:tst:35941"/>
          </criteria>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criteria operator="OR">
            <criterion comment="wireshark is earlier than 0:0.99.7-1.el5" test_ref="oval:org.mitre.oval:tst:35709"/>
            <criterion comment="wireshark-gnome is earlier than 0:0.99.7-1.el5" test_ref="oval:org.mitre.oval:tst:36120"/>
            <criterion comment="libsmi is earlier than 0:0.4.5-2.el5" test_ref="oval:org.mitre.oval:tst:35712"/>
            <criterion comment="libsmi-devel is earlier than 0:0.4.5-2.el5" test_ref="oval:org.mitre.oval:tst:35801"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9879" version="3" class="vulnerability">
      <metadata>
        <title>KDE Konqueror 3.5.7 allows remote attackers to spoof the URL address bar by calling setInterval with a small interval and changing the window.location property.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-4224" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4224"/>
        <description>KDE Konqueror 3.5.7 allows remote attackers to spoof the URL address bar by calling setInterval with a small interval and changing the window.location property.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:17:28.753-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:43.102-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:50.529-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <criteria operator="OR">
            <criterion comment="kdebase is earlier than 0:3.3.1-6.el4" test_ref="oval:org.mitre.oval:tst:34380"/>
            <criterion comment="kdebase-devel is earlier than 0:3.3.1-6.el4" test_ref="oval:org.mitre.oval:tst:35343"/>
            <criterion comment="kdelibs is earlier than 6:3.3.1-9.el4" test_ref="oval:org.mitre.oval:tst:35165"/>
            <criterion comment="kdelibs-devel is earlier than 6:3.3.1-9.el4" test_ref="oval:org.mitre.oval:tst:35252"/>
          </criteria>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criteria operator="OR">
            <criterion comment="kdebase is earlier than 0:3.5.4-15.el5" test_ref="oval:org.mitre.oval:tst:34844"/>
            <criterion comment="kdebase-devel is earlier than 0:3.5.4-15.el5" test_ref="oval:org.mitre.oval:tst:35321"/>
            <criterion comment="kdelibs-apidocs is earlier than 6:3.5.4-13.el5" test_ref="oval:org.mitre.oval:tst:35316"/>
            <criterion comment="kdelibs is earlier than 6:3.5.4-13.el5" test_ref="oval:org.mitre.oval:tst:35293"/>
            <criterion comment="kdelibs-devel is earlier than 6:3.5.4-13.el5" test_ref="oval:org.mitre.oval:tst:34994"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9878" version="4" class="vulnerability">
      <metadata>
        <title>Use-after-free vulnerability in net/ipv4/tcp_input.c in the Linux kernel 2.6 before 2.6.20, when IPV6_RECVPKTINFO is set on a listening socket, allows remote attackers to cause a denial of service (kernel panic) via a SYN packet while the socket is in a listening (TCP_LISTEN) state, which is not properly handled causes the skb structure to be freed.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-1188" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1188"/>
        <description>Use-after-free vulnerability in net/ipv4/tcp_input.c in the Linux kernel 2.6 before 2.6.20, when IPV6_RECVPKTINFO is set on a listening socket, allows remote attackers to cause a denial of service (kernel panic) via a SYN packet while the socket is in a listening (TCP_LISTEN) state, which is not properly handled and causes the skb structure to be freed.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:15:54.662-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:42.572-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:50.003-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <criteria operator="OR">
            <criterion comment="kernel-xenU is earlier than 0:2.6.9-89.0.25.EL" test_ref="oval:org.mitre.oval:tst:40272"/>
            <criterion comment="kernel-hugemem is earlier than 0:2.6.9-89.0.25.EL" test_ref="oval:org.mitre.oval:tst:40483"/>
            <criterion comment="kernel-hugemem-devel is earlier than 0:2.6.9-89.0.25.EL" test_ref="oval:org.mitre.oval:tst:40310"/>
            <criterion comment="kernel-xenU-devel is earlier than 0:2.6.9-89.0.25.EL" test_ref="oval:org.mitre.oval:tst:40062"/>
            <criterion comment="kernel-smp-devel is earlier than 0:2.6.9-89.0.25.EL" test_ref="oval:org.mitre.oval:tst:40096"/>
            <criterion comment="kernel-largesmp-devel is earlier than 0:2.6.9-89.0.25.EL" test_ref="oval:org.mitre.oval:tst:39895"/>
            <criterion comment="kernel is earlier than 0:2.6.9-89.0.25.EL" test_ref="oval:org.mitre.oval:tst:40165"/>
            <criterion comment="kernel-devel is earlier than 0:2.6.9-89.0.25.EL" test_ref="oval:org.mitre.oval:tst:40131"/>
            <criterion comment="kernel-doc is earlier than 0:2.6.9-89.0.25.EL" test_ref="oval:org.mitre.oval:tst:40380"/>
            <criterion comment="kernel-largesmp is earlier than 0:2.6.9-89.0.25.EL" test_ref="oval:org.mitre.oval:tst:39955"/>
            <criterion comment="kernel-smp is earlier than 0:2.6.9-89.0.25.EL" test_ref="oval:org.mitre.oval:tst:40115"/>
          </criteria>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criteria operator="OR">
            <criterion comment="kernel-kdump is earlier than 0:2.6.18-194.el5" test_ref="oval:org.mitre.oval:tst:39718"/>
            <criterion comment="kernel-debug is earlier than 0:2.6.18-194.el5" test_ref="oval:org.mitre.oval:tst:40363"/>
            <criterion comment="kernel-xen is earlier than 0:2.6.18-194.el5" test_ref="oval:org.mitre.oval:tst:40151"/>
            <criterion comment="kernel-headers is earlier than 0:2.6.18-194.el5" test_ref="oval:org.mitre.oval:tst:40182"/>
            <criterion comment="kernel-kdump-devel is earlier than 0:2.6.18-194.el5" test_ref="oval:org.mitre.oval:tst:40070"/>
            <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-194.el5" test_ref="oval:org.mitre.oval:tst:40313"/>
            <criterion comment="kernel is earlier than 0:2.6.18-194.el5" test_ref="oval:org.mitre.oval:tst:40302"/>
            <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-194.el5" test_ref="oval:org.mitre.oval:tst:39440"/>
            <criterion comment="kernel-devel is earlier than 0:2.6.18-194.el5" test_ref="oval:org.mitre.oval:tst:39472"/>
            <criterion comment="kernel-PAE is earlier than 0:2.6.18-194.el5" test_ref="oval:org.mitre.oval:tst:40090"/>
            <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-194.el5" test_ref="oval:org.mitre.oval:tst:39519"/>
            <criterion comment="kernel-doc is earlier than 0:2.6.18-194.el5" test_ref="oval:org.mitre.oval:tst:39840"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9875" version="3" class="vulnerability">
      <metadata>
        <title>Multiple unspecified vulnerabilities in Mozilla Firefox before 2.0.0.5 allow remote attackers to execute arbitrary code via a crafted XPCNativeWrapper.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-3738" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3738"/>
        <description>Multiple unspecified vulnerabilities in Mozilla Firefox before 2.0.0.5 allow remote attackers to execute arbitrary code via a crafted XPCNativeWrapper.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:16:42.973-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:41.545-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:48.915-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
          <criteria operator="OR">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.9-0.3.el3" test_ref="oval:org.mitre.oval:tst:33986"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-0.3.el3" test_ref="oval:org.mitre.oval:tst:34827"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.9-0.3.el3" test_ref="oval:org.mitre.oval:tst:34839"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-0.3.el3" test_ref="oval:org.mitre.oval:tst:34762"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.9-0.3.el3" test_ref="oval:org.mitre.oval:tst:34814"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-0.3.el3" test_ref="oval:org.mitre.oval:tst:34694"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-0.3.el3" test_ref="oval:org.mitre.oval:tst:34925"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-0.3.el3" test_ref="oval:org.mitre.oval:tst:34684"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-0.3.el3" test_ref="oval:org.mitre.oval:tst:34723"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.9-0.3.el3" test_ref="oval:org.mitre.oval:tst:34747"/>
          </criteria>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <criteria operator="OR">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.9-4.el4" test_ref="oval:org.mitre.oval:tst:34968"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-4.el4" test_ref="oval:org.mitre.oval:tst:34971"/>
            <criterion comment="thunderbird is earlier than 0:1.5.0.12-0.3.el4" test_ref="oval:org.mitre.oval:tst:34888"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.9-4.el4" test_ref="oval:org.mitre.oval:tst:34868"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-4.el4" test_ref="oval:org.mitre.oval:tst:34492"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.9-4.el4" test_ref="oval:org.mitre.oval:tst:34775"/>
            <criterion comment="firefox is earlier than 0:1.5.0.12-0.3.el4" test_ref="oval:org.mitre.oval:tst:34828"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-4.el4" test_ref="oval:org.mitre.oval:tst:34981"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-4.el4" test_ref="oval:org.mitre.oval:tst:34335"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.9-4.el4" test_ref="oval:org.mitre.oval:tst:34957"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-4.el4" test_ref="oval:org.mitre.oval:tst:34550"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-4.el4" test_ref="oval:org.mitre.oval:tst:34608"/>
          </criteria>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criteria operator="OR">
            <criterion comment="firefox-devel is earlier than 0:1.5.0.12-3.el5" test_ref="oval:org.mitre.oval:tst:34810"/>
            <criterion comment="firefox is earlier than 0:1.5.0.12-3.el5" test_ref="oval:org.mitre.oval:tst:34667"/>
            <criterion comment="thunderbird is earlier than 0:1.5.0.12-3.el5" test_ref="oval:org.mitre.oval:tst:34869"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9873" version="3" class="vulnerability">
      <metadata>
        <title>The jar protocol handler in Mozilla Firefox before 2.0.0.10 and SeaMonkey before 1.1.7 retrieves the inner URL regardless of its MIME type, and considers HTML documents within a jar archive to have the same origin as the inner URL, which allows remote attackers to conduct cross-site scripting (XSS) attacks via a jar: URI.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-5947" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5947"/>
        <description>The jar protocol handler in Mozilla Firefox before 2.0.0.10 and SeaMonkey before 1.1.7 retrieves the inner URL regardless of its MIME type, and considers HTML documents within a jar archive to have the same origin as the inner URL, which allows remote attackers to conduct cross-site scripting (XSS) attacks via a jar: URI.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:23:56.724-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:40.559-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:48.006-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
          <criteria operator="OR">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.9-0.7.el3" test_ref="oval:org.mitre.oval:tst:35246"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-0.7.el3" test_ref="oval:org.mitre.oval:tst:35338"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.9-0.7.el3" test_ref="oval:org.mitre.oval:tst:35812"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-0.7.el3" test_ref="oval:org.mitre.oval:tst:35754"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.9-0.7.el3" test_ref="oval:org.mitre.oval:tst:35763"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-0.7.el3" test_ref="oval:org.mitre.oval:tst:35809"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-0.7.el3" test_ref="oval:org.mitre.oval:tst:35651"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-0.7.el3" test_ref="oval:org.mitre.oval:tst:35146"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-0.7.el3" test_ref="oval:org.mitre.oval:tst:35423"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.9-0.7.el3" test_ref="oval:org.mitre.oval:tst:35775"/>
          </criteria>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <criteria operator="OR">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.9-7.el4" test_ref="oval:org.mitre.oval:tst:35664"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-7.el4" test_ref="oval:org.mitre.oval:tst:35628"/>
            <criterion comment="thunderbird is earlier than 0:1.5.0.12-7.el4" test_ref="oval:org.mitre.oval:tst:35520"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.9-7.el4" test_ref="oval:org.mitre.oval:tst:35267"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-7.el4" test_ref="oval:org.mitre.oval:tst:35702"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.9-7.el4" test_ref="oval:org.mitre.oval:tst:35858"/>
            <criterion comment="firefox is earlier than 0:1.5.0.12-0.8.el4" test_ref="oval:org.mitre.oval:tst:34811"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-7.el4" test_ref="oval:org.mitre.oval:tst:35499"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-7.el4" test_ref="oval:org.mitre.oval:tst:35523"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.9-7.el4" test_ref="oval:org.mitre.oval:tst:35602"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-7.el4" test_ref="oval:org.mitre.oval:tst:35697"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-7.el4" test_ref="oval:org.mitre.oval:tst:34917"/>
          </criteria>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criteria operator="OR">
            <criterion comment="firefox-devel is earlier than 0:1.5.0.12-7.el5" test_ref="oval:org.mitre.oval:tst:35421"/>
            <criterion comment="firefox is earlier than 0:1.5.0.12-7.el5" test_ref="oval:org.mitre.oval:tst:35528"/>
            <criterion comment="thunderbird is earlier than 0:1.5.0.12-7.el5" test_ref="oval:org.mitre.oval:tst:35742"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9872" version="3" class="vulnerability">
      <metadata>
        <title>The JavaScript engine in Mozilla Firefox 3.x before 3.0.4, Firefox 2.x before 2.0.0.18, Thunderbird 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13 allows remote attackers to cause a denial of service (crash) via vectors related to "insufficient class checking" in the Date class.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-5018" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-5018"/>
        <description>The JavaScript engine in Mozilla Firefox 3.x before 3.0.4, Firefox 2.x before 2.0.0.18, Thunderbird 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13 allows remote attackers to cause a denial of service (crash) via vectors related to "insufficient class checking" in the Date class.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:22:32.387-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:39.910-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:47.381-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
          <criteria operator="OR">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.9-0.25.el3" test_ref="oval:org.mitre.oval:tst:37159"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-0.25.el3" test_ref="oval:org.mitre.oval:tst:37875"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.9-0.25.el3" test_ref="oval:org.mitre.oval:tst:37293"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-0.25.el3" test_ref="oval:org.mitre.oval:tst:37934"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.9-0.25.el3" test_ref="oval:org.mitre.oval:tst:37671"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-0.25.el3" test_ref="oval:org.mitre.oval:tst:37932"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-0.25.el3" test_ref="oval:org.mitre.oval:tst:37970"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-0.25.el3" test_ref="oval:org.mitre.oval:tst:37357"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-0.25.el3" test_ref="oval:org.mitre.oval:tst:37852"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.9-0.25.el3" test_ref="oval:org.mitre.oval:tst:37844"/>
          </criteria>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <criteria operator="OR">
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-28.el4" test_ref="oval:org.mitre.oval:tst:37232"/>
            <criterion comment="nss is earlier than 0:3.12.1.1-3.el4" test_ref="oval:org.mitre.oval:tst:38065"/>
            <criterion comment="thunderbird is earlier than 0:1.5.0.12-17.el4" test_ref="oval:org.mitre.oval:tst:37872"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-28.el4" test_ref="oval:org.mitre.oval:tst:37914"/>
            <criterion comment="firefox is earlier than 0:3.0.4-1.el4" test_ref="oval:org.mitre.oval:tst:37904"/>
            <criterion comment="nss-devel is earlier than 0:3.12.1.1-3.el4" test_ref="oval:org.mitre.oval:tst:37840"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-28.el4" test_ref="oval:org.mitre.oval:tst:37991"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-28.el4" test_ref="oval:org.mitre.oval:tst:37955"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-28.el4" test_ref="oval:org.mitre.oval:tst:37777"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-28.el4" test_ref="oval:org.mitre.oval:tst:38009"/>
          </criteria>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criteria operator="OR">
            <criterion comment="devhelp-devel is earlier than 0:0.12-20.el5" test_ref="oval:org.mitre.oval:tst:37773"/>
            <criterion comment="nss-pkcs11-devel is earlier than 0:3.12.1.1-3.el5" test_ref="oval:org.mitre.oval:tst:37531"/>
            <criterion comment="xulrunner-devel is earlier than 0:1.9.0.4-1.el5" test_ref="oval:org.mitre.oval:tst:37899"/>
            <criterion comment="nss is earlier than 0:3.12.1.1-3.el5" test_ref="oval:org.mitre.oval:tst:37454"/>
            <criterion comment="thunderbird is earlier than 0:2.0.0.18-1.el5" test_ref="oval:org.mitre.oval:tst:38015"/>
            <criterion comment="xulrunner is earlier than 0:1.9.0.4-1.el5" test_ref="oval:org.mitre.oval:tst:38021"/>
            <criterion comment="yelp is earlier than 0:2.16.0-22.el5" test_ref="oval:org.mitre.oval:tst:37645"/>
            <criterion comment="devhelp is earlier than 0:0.12-20.el5" test_ref="oval:org.mitre.oval:tst:37958"/>
            <criterion comment="xulrunner-devel-unstable is earlier than 0:1.9.0.4-1.el5" test_ref="oval:org.mitre.oval:tst:37388"/>
            <criterion comment="firefox is earlier than 0:3.0.4-1.el5" test_ref="oval:org.mitre.oval:tst:37066"/>
            <criterion comment="nss-devel is earlier than 0:3.12.1.1-3.el5" test_ref="oval:org.mitre.oval:tst:37648"/>
            <criterion comment="nss-tools is earlier than 0:3.12.1.1-3.el5" test_ref="oval:org.mitre.oval:tst:37936"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9870" version="3" class="vulnerability">
      <metadata>
        <title>Integer overflow in sys_epoll_wait in eventpoll.c for Linux kernel 2.6 to 2.6.11 allows local users to overwrite kernel memory via a large number of events.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0736" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0736"/>
        <description>Integer overflow in sys_epoll_wait in eventpoll.c for Linux kernel 2.6 to 2.6.11 allows local users to overwrite kernel memory via a large number of events.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:22:15.376-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:39.212-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:46.691-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
          <criteria operator="OR">
            <criterion comment="kernel-BOOT is earlier than 0:2.4.21-27.0.4.EL" test_ref="oval:org.mitre.oval:tst:31148"/>
            <criterion comment="kernel-unsupported is earlier than 0:2.4.21-27.0.4.EL" test_ref="oval:org.mitre.oval:tst:31473"/>
            <criterion comment="kernel-smp-unsupported is earlier than 0:2.4.21-27.0.4.EL" test_ref="oval:org.mitre.oval:tst:31178"/>
            <criterion comment="kernel-hugemem-unsupported is earlier than 0:2.4.21-27.0.4.EL" test_ref="oval:org.mitre.oval:tst:31282"/>
            <criterion comment="kernel-hugemem is earlier than 0:2.4.21-27.0.4.EL" test_ref="oval:org.mitre.oval:tst:31565"/>
            <criterion comment="kernel is earlier than 0:2.4.21-27.0.4.EL" test_ref="oval:org.mitre.oval:tst:31562"/>
            <criterion comment="kernel-source is earlier than 0:2.4.21-27.0.4.EL" test_ref="oval:org.mitre.oval:tst:31582"/>
            <criterion comment="kernel-doc is earlier than 0:2.4.21-27.0.4.EL" test_ref="oval:org.mitre.oval:tst:30730"/>
            <criterion comment="kernel-smp is earlier than 0:2.4.21-27.0.4.EL" test_ref="oval:org.mitre.oval:tst:31534"/>
          </criteria>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <criteria operator="OR">
            <criterion comment="kernel-smp-devel is earlier than 0:2.6.9-5.0.5.EL" test_ref="oval:org.mitre.oval:tst:31545"/>
            <criterion comment="kernel-hugemem is earlier than 0:2.6.9-5.0.5.EL" test_ref="oval:org.mitre.oval:tst:31539"/>
            <criterion comment="kernel-devel is earlier than 0:2.6.9-5.0.5.EL" test_ref="oval:org.mitre.oval:tst:31661"/>
            <criterion comment="kernel is earlier than 0:2.6.9-5.0.5.EL" test_ref="oval:org.mitre.oval:tst:31482"/>
            <criterion comment="kernel-hugemem-devel is earlier than 0:2.6.9-5.0.5.EL" test_ref="oval:org.mitre.oval:tst:31112"/>
            <criterion comment="kernel-doc is earlier than 0:2.6.9-5.0.5.EL" test_ref="oval:org.mitre.oval:tst:31605"/>
            <criterion comment="kernel-smp is earlier than 0:2.6.9-5.0.5.EL" test_ref="oval:org.mitre.oval:tst:31330"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9869" version="3" class="vulnerability">
      <metadata>
        <title>Unspecified vulnerability in the SCSI dissector in Wireshark (formerly Ethereal) 0.99.2 allows remote attackers to cause a denial of service (crash) via unspecified vectors.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-4330" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-4330"/>
        <description>Unspecified vulnerability in the SCSI dissector in Wireshark (formerly Ethereal) 0.99.2 allows remote attackers to cause a denial of service (crash) via unspecified vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:20:26.391-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:38.933-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:46.432-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
          <criteria operator="OR">
            <criterion comment="wireshark is earlier than 0:0.99.3-EL3.2" test_ref="oval:org.mitre.oval:tst:33011"/>
            <criterion comment="wireshark-gnome is earlier than 0:0.99.3-EL3.2" test_ref="oval:org.mitre.oval:tst:32323"/>
          </criteria>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <criteria operator="OR">
            <criterion comment="wireshark is earlier than 0:0.99.3-EL4.2" test_ref="oval:org.mitre.oval:tst:33025"/>
            <criterion comment="wireshark-gnome is earlier than 0:0.99.3-EL4.2" test_ref="oval:org.mitre.oval:tst:32974"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9868" version="3" class="vulnerability">
      <metadata>
        <title>The wait_task_stopped function in the Linux kernel before 2.6.23.8 checks a TASK_TRACED bit instead of an exit_state value, which allows local users to cause a denial of service (machine crash) via unspecified vectors.  NOTE: some of these details are obtained from third party information.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-5500" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5500"/>
        <description>The wait_task_stopped function in the Linux kernel before 2.6.23.8 checks a TASK_TRACED bit instead of an exit_state value, which allows local users to cause a denial of service (machine crash) via unspecified vectors.  NOTE: some of these details are obtained from third party information.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:20:17.346-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:38.632-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:46.113-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
        <criteria operator="OR">
          <criterion comment="kernel-xenU is earlier than 0:2.6.9-67.0.4.EL" test_ref="oval:org.mitre.oval:tst:36090"/>
          <criterion comment="kernel-hugemem is earlier than 0:2.6.9-67.0.4.EL" test_ref="oval:org.mitre.oval:tst:35525"/>
          <criterion comment="kernel-hugemem-devel is earlier than 0:2.6.9-67.0.4.EL" test_ref="oval:org.mitre.oval:tst:35832"/>
          <criterion comment="kernel-xenU-devel is earlier than 0:2.6.9-67.0.4.EL" test_ref="oval:org.mitre.oval:tst:35126"/>
          <criterion comment="kernel-smp-devel is earlier than 0:2.6.9-67.0.4.EL" test_ref="oval:org.mitre.oval:tst:35901"/>
          <criterion comment="kernel-largesmp-devel is earlier than 0:2.6.9-67.0.4.EL" test_ref="oval:org.mitre.oval:tst:36007"/>
          <criterion comment="kernel is earlier than 0:2.6.9-67.0.4.EL" test_ref="oval:org.mitre.oval:tst:35982"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.9-67.0.4.EL" test_ref="oval:org.mitre.oval:tst:36072"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.9-67.0.4.EL" test_ref="oval:org.mitre.oval:tst:36041"/>
          <criterion comment="kernel-largesmp is earlier than 0:2.6.9-67.0.4.EL" test_ref="oval:org.mitre.oval:tst:35364"/>
          <criterion comment="kernel-smp is earlier than 0:2.6.9-67.0.4.EL" test_ref="oval:org.mitre.oval:tst:35662"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9866" version="3" class="vulnerability">
      <metadata>
        <title>Unknown vulnerability in the sFlow dissector in Ethereal 0.9.14 through 0.10.9 allows remote attackers to cause a denial of service (application crash).</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0766" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0766"/>
        <description>Unknown vulnerability in the sFlow dissector in Ethereal 0.9.14 through 0.10.9 allows remote attackers to cause a denial of service (application crash).</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:21:24.462-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:38.111-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:45.452-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
          <criteria operator="OR">
            <criterion comment="ethereal-gnome is earlier than 0:0.10.10-1.EL3.1" test_ref="oval:org.mitre.oval:tst:31514"/>
            <criterion comment="ethereal is earlier than 0:0.10.10-1.EL3.1" test_ref="oval:org.mitre.oval:tst:31448"/>
          </criteria>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <criteria operator="OR">
            <criterion comment="ethereal-gnome is earlier than 0:0.10.10-1.EL4.1" test_ref="oval:org.mitre.oval:tst:31593"/>
            <criterion comment="ethereal is earlier than 0:0.10.10-1.EL4.1" test_ref="oval:org.mitre.oval:tst:31548"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9865" version="3" class="vulnerability">
      <metadata>
        <title>The block reflow implementation in Mozilla Firefox before 2.0.0.15, Thunderbird 2.0.0.14 and earlier, and SeaMonkey before 1.1.10 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via an image whose display requires more pixels than nscoord_MAX, related to nsBlockFrame::DrainOverflowLines.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-2811" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-2811"/>
        <description>The block reflow implementation in Mozilla Firefox before 2.0.0.15, Thunderbird 2.0.0.14 and earlier, and SeaMonkey before 1.1.10 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via an image whose display requires more pixels than nscoord_MAX, related to nsBlockFrame::DrainOverflowLines.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:19:10.662-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:37.447-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:44.825-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
          <criteria operator="OR">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.9-0.20.el3" test_ref="oval:org.mitre.oval:tst:37286"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-0.20.el3" test_ref="oval:org.mitre.oval:tst:37033"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.9-0.20.el3" test_ref="oval:org.mitre.oval:tst:37126"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-0.20.el3" test_ref="oval:org.mitre.oval:tst:37105"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.9-0.20.el3" test_ref="oval:org.mitre.oval:tst:37271"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-0.20.el3" test_ref="oval:org.mitre.oval:tst:37279"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-0.20.el3" test_ref="oval:org.mitre.oval:tst:37060"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-0.20.el3" test_ref="oval:org.mitre.oval:tst:37189"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-0.20.el3" test_ref="oval:org.mitre.oval:tst:36476"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.9-0.20.el3" test_ref="oval:org.mitre.oval:tst:36916"/>
          </criteria>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <criteria operator="OR">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.9-16.3.el4_6" test_ref="oval:org.mitre.oval:tst:37236"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-16.3.el4_6" test_ref="oval:org.mitre.oval:tst:37192"/>
            <criterion comment="thunderbird is earlier than 0:1.5.0.12-14.el4" test_ref="oval:org.mitre.oval:tst:36999"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.9-16.3.el4_6" test_ref="oval:org.mitre.oval:tst:36886"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-16.3.el4_6" test_ref="oval:org.mitre.oval:tst:37331"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.9-16.3.el4_6" test_ref="oval:org.mitre.oval:tst:36365"/>
            <criterion comment="firefox is earlier than 0:1.5.0.12-0.19.el4" test_ref="oval:org.mitre.oval:tst:37174"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-16.3.el4_6" test_ref="oval:org.mitre.oval:tst:37226"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-16.3.el4_6" test_ref="oval:org.mitre.oval:tst:36766"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.9-16.3.el4_6" test_ref="oval:org.mitre.oval:tst:37320"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-16.3.el4_6" test_ref="oval:org.mitre.oval:tst:36826"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-16.3.el4_6" test_ref="oval:org.mitre.oval:tst:37274"/>
          </criteria>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criteria operator="OR">
            <criterion comment="devhelp-devel is earlier than 0:0.12-17.el5" test_ref="oval:org.mitre.oval:tst:37107"/>
            <criterion comment="xulrunner-devel is earlier than 0:1.9-1.el5" test_ref="oval:org.mitre.oval:tst:37351"/>
            <criterion comment="thunderbird is earlier than 0:2.0.0.16-1.el5" test_ref="oval:org.mitre.oval:tst:37363"/>
            <criterion comment="xulrunner is earlier than 0:1.9-1.el5" test_ref="oval:org.mitre.oval:tst:36984"/>
            <criterion comment="devhelp is earlier than 0:0.12-17.el5" test_ref="oval:org.mitre.oval:tst:37234"/>
            <criterion comment="yelp is earlier than 0:2.16.0-19.el5" test_ref="oval:org.mitre.oval:tst:37291"/>
            <criterion comment="xulrunner-devel-unstable is earlier than 0:1.9-1.el5" test_ref="oval:org.mitre.oval:tst:36436"/>
            <criterion comment="firefox is earlier than 0:3.0-2.el5" test_ref="oval:org.mitre.oval:tst:36814"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9863" version="3" class="vulnerability">
      <metadata>
        <title>Integer overflow in the rb_ary_fill function in array.c in Ruby before revision 17756 allows context-dependent attackers to cause a denial of service (crash) or possibly have unspecified other impact via a call to the Array#fill method with a start (aka beg) argument greater than ARY_MAX_SIZE.  NOTE: this issue exists because of an incomplete fix for other closely related integer overflows.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-2376" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-2376"/>
        <description>Integer overflow in the rb_ary_fill function in array.c in Ruby before revision 17756 allows context-dependent attackers to cause a denial of service (crash) or possibly have unspecified other impact via a call to the Array#fill method with a start (aka beg) argument greater than ARY_MAX_SIZE.  NOTE: this issue exists because of an incomplete fix for other closely related integer overflows.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:15:51.866-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:36.715-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:43.945-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
          <criteria operator="OR">
            <criterion comment="ruby-mode is earlier than 0:1.6.8-12.el3" test_ref="oval:org.mitre.oval:tst:36968"/>
            <criterion comment="ruby-docs is earlier than 0:1.6.8-12.el3" test_ref="oval:org.mitre.oval:tst:37000"/>
            <criterion comment="ruby-devel is earlier than 0:1.6.8-12.el3" test_ref="oval:org.mitre.oval:tst:36747"/>
            <criterion comment="ruby-tcltk is earlier than 0:1.6.8-12.el3" test_ref="oval:org.mitre.oval:tst:37140"/>
            <criterion comment="ruby is earlier than 0:1.6.8-12.el3" test_ref="oval:org.mitre.oval:tst:37342"/>
            <criterion comment="irb is earlier than 0:1.6.8-12.el3" test_ref="oval:org.mitre.oval:tst:37252"/>
            <criterion comment="ruby-libs is earlier than 0:1.6.8-12.el3" test_ref="oval:org.mitre.oval:tst:37305"/>
          </criteria>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <criteria operator="OR">
            <criterion comment="ruby-mode is earlier than 0:1.8.1-7.el4_6.1" test_ref="oval:org.mitre.oval:tst:37171"/>
            <criterion comment="ruby-docs is earlier than 0:1.8.1-7.el4_6.1" test_ref="oval:org.mitre.oval:tst:37242"/>
            <criterion comment="ruby-devel is earlier than 0:1.8.1-7.el4_6.1" test_ref="oval:org.mitre.oval:tst:36569"/>
            <criterion comment="ruby-tcltk is earlier than 0:1.8.1-7.el4_6.1" test_ref="oval:org.mitre.oval:tst:37296"/>
            <criterion comment="ruby is earlier than 0:1.8.1-7.el4_6.1" test_ref="oval:org.mitre.oval:tst:36468"/>
            <criterion comment="irb is earlier than 0:1.8.1-7.el4_6.1" test_ref="oval:org.mitre.oval:tst:36808"/>
            <criterion comment="ruby-libs is earlier than 0:1.8.1-7.el4_6.1" test_ref="oval:org.mitre.oval:tst:37219"/>
          </criteria>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criteria operator="OR">
            <criterion comment="ruby-ri is earlier than 0:1.8.5-5.el5_2.3" test_ref="oval:org.mitre.oval:tst:37199"/>
            <criterion comment="ruby-mode is earlier than 0:1.8.5-5.el5_2.3" test_ref="oval:org.mitre.oval:tst:36604"/>
            <criterion comment="ruby-docs is earlier than 0:1.8.5-5.el5_2.3" test_ref="oval:org.mitre.oval:tst:36516"/>
            <criterion comment="ruby-devel is earlier than 0:1.8.5-5.el5_2.3" test_ref="oval:org.mitre.oval:tst:36870"/>
            <criterion comment="ruby is earlier than 0:1.8.5-5.el5_2.3" test_ref="oval:org.mitre.oval:tst:36738"/>
            <criterion comment="ruby-libs is earlier than 0:1.8.5-5.el5_2.3" test_ref="oval:org.mitre.oval:tst:37119"/>
            <criterion comment="ruby-tcltk is earlier than 0:1.8.5-5.el5_2.3" test_ref="oval:org.mitre.oval:tst:37289"/>
            <criterion comment="ruby-irb is earlier than 0:1.8.5-5.el5_2.3" test_ref="oval:org.mitre.oval:tst:37148"/>
            <criterion comment="ruby-rdoc is earlier than 0:1.8.5-5.el5_2.3" test_ref="oval:org.mitre.oval:tst:37203"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9861" version="3" class="vulnerability">
      <metadata>
        <title>digestmd5.c in the CMU Cyrus Simple Authentication and Security Layer (SASL) library 2.1.18, and possibly other versions before 2.1.21, allows remote unauthenticated attackers to cause a denial of service (segmentation fault) via malformed inputs in DIGEST-MD5 negotiation.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-1721" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1721"/>
        <description>digestmd5.c in the CMU Cyrus Simple Authentication and Security Layer (SASL) library 2.1.18, and possibly other versions before 2.1.21, allows remote unauthenticated attackers to cause a denial of service (segmentation fault) via malformed inputs in DIGEST-MD5 negotiation.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:19:32.582-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:36.135-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:43.344-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
          <criteria operator="OR">
            <criterion comment="cyrus-sasl-plain is earlier than 0:2.1.15-15" test_ref="oval:org.mitre.oval:tst:35185"/>
            <criterion comment="cyrus-sasl-md5 is earlier than 0:2.1.15-15" test_ref="oval:org.mitre.oval:tst:35067"/>
            <criterion comment="cyrus-sasl-gssapi is earlier than 0:2.1.15-15" test_ref="oval:org.mitre.oval:tst:35028"/>
            <criterion comment="cyrus-sasl-devel is earlier than 0:2.1.15-15" test_ref="oval:org.mitre.oval:tst:34649"/>
            <criterion comment="cyrus-sasl is earlier than 0:2.1.15-15" test_ref="oval:org.mitre.oval:tst:35113"/>
          </criteria>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <criteria operator="OR">
            <criterion comment="cyrus-sasl-ntlm is earlier than 0:2.1.19-14" test_ref="oval:org.mitre.oval:tst:35092"/>
            <criterion comment="cyrus-sasl-sql is earlier than 0:2.1.19-14" test_ref="oval:org.mitre.oval:tst:35100"/>
            <criterion comment="cyrus-sasl-plain is earlier than 0:2.1.19-14" test_ref="oval:org.mitre.oval:tst:34748"/>
            <criterion comment="cyrus-sasl-md5 is earlier than 0:2.1.19-14" test_ref="oval:org.mitre.oval:tst:34948"/>
            <criterion comment="cyrus-sasl-gssapi is earlier than 0:2.1.19-14" test_ref="oval:org.mitre.oval:tst:35102"/>
            <criterion comment="cyrus-sasl-devel is earlier than 0:2.1.19-14" test_ref="oval:org.mitre.oval:tst:34645"/>
            <criterion comment="cyrus-sasl is earlier than 0:2.1.19-14" test_ref="oval:org.mitre.oval:tst:34338"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9860" version="3" class="vulnerability">
      <metadata>
        <title>Integer overflow in the netsnmp_create_subtree_cache function in agent/snmp_agent.c in net-snmp 5.4 before 5.4.2.1, 5.3 before 5.3.2.3, and 5.2 before 5.2.5.1 allows remote attackers to cause a denial of service (crash) via a crafted SNMP GETBULK request, which triggers a heap-based buffer overflow,  related to the number of responses or repeats.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-4309" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-4309"/>
        <description>Integer overflow in the netsnmp_create_subtree_cache function in agent/snmp_agent.c in net-snmp 5.4 before 5.4.2.1, 5.3 before 5.3.2.3, and 5.2 before 5.2.5.1 allows remote attackers to cause a denial of service (crash) via a crafted SNMP GETBULK request, which triggers a heap-based buffer overflow,  related to the number of responses or repeats.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:17:35.483-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:35.676-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:42.889-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
          <criteria operator="OR">
            <criterion comment="net-snmp-utils is earlier than 0:5.0.9-2.30E.25" test_ref="oval:org.mitre.oval:tst:37666"/>
            <criterion comment="net-snmp is earlier than 0:5.0.9-2.30E.25" test_ref="oval:org.mitre.oval:tst:37742"/>
            <criterion comment="net-snmp-libs is earlier than 0:5.0.9-2.30E.25" test_ref="oval:org.mitre.oval:tst:37538"/>
            <criterion comment="net-snmp-perl is earlier than 0:5.0.9-2.30E.25" test_ref="oval:org.mitre.oval:tst:37806"/>
            <criterion comment="net-snmp-devel is earlier than 0:5.0.9-2.30E.25" test_ref="oval:org.mitre.oval:tst:37593"/>
          </criteria>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <criteria operator="OR">
            <criterion comment="net-snmp-utils is earlier than 0:5.1.2-13.el4_7.2" test_ref="oval:org.mitre.oval:tst:37167"/>
            <criterion comment="net-snmp is earlier than 0:5.1.2-13.el4_7.2" test_ref="oval:org.mitre.oval:tst:37819"/>
            <criterion comment="net-snmp-libs is earlier than 0:5.1.2-13.el4_7.2" test_ref="oval:org.mitre.oval:tst:37707"/>
            <criterion comment="net-snmp-perl is earlier than 0:5.1.2-13.el4_7.2" test_ref="oval:org.mitre.oval:tst:37868"/>
            <criterion comment="net-snmp-devel is earlier than 0:5.1.2-13.el4_7.2" test_ref="oval:org.mitre.oval:tst:37115"/>
          </criteria>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criteria operator="OR">
            <criterion comment="net-snmp-utils is earlier than 1:5.3.1-24.el5_2.2" test_ref="oval:org.mitre.oval:tst:36966"/>
            <criterion comment="net-snmp is earlier than 1:5.3.1-24.el5_2.2" test_ref="oval:org.mitre.oval:tst:37758"/>
            <criterion comment="net-snmp-libs is earlier than 1:5.3.1-24.el5_2.2" test_ref="oval:org.mitre.oval:tst:37686"/>
            <criterion comment="net-snmp-perl is earlier than 1:5.3.1-24.el5_2.2" test_ref="oval:org.mitre.oval:tst:37927"/>
            <criterion comment="net-snmp-devel is earlier than 1:5.3.1-24.el5_2.2" test_ref="oval:org.mitre.oval:tst:37801"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9859" version="3" class="vulnerability">
      <metadata>
        <title>Buffer overflow in the SMB1 packet chaining implementation in the chain_reply function in process.c in smbd in Samba 3.0.x before 3.3.13 allows remote attackers to cause a denial of service (memory corruption and daemon crash) or possibly execute arbitrary code via a crafted field in a packet.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-2063" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2063"/>
        <description>Buffer overflow in the SMB1 packet chaining implementation in the chain_reply function in process.c in smbd in Samba 3.0.x before 3.3.13 allows remote attackers to cause a denial of service (memory corruption and daemon crash) or possibly execute arbitrary code via a crafted field in a packet.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:16:17.627-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:35.122-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:42.322-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
          <criteria operator="OR">
            <criterion comment="samba-common is earlier than 0:3.0.9-1.3E.17" test_ref="oval:org.mitre.oval:tst:40725"/>
            <criterion comment="samba-swat is earlier than 0:3.0.9-1.3E.17" test_ref="oval:org.mitre.oval:tst:40543"/>
            <criterion comment="samba-client is earlier than 0:3.0.9-1.3E.17" test_ref="oval:org.mitre.oval:tst:40781"/>
            <criterion comment="samba is earlier than 0:3.0.9-1.3E.17" test_ref="oval:org.mitre.oval:tst:40546"/>
          </criteria>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <criteria operator="OR">
            <criterion comment="samba-common is earlier than 0:3.0.33-0.19.el4_8.1" test_ref="oval:org.mitre.oval:tst:40212"/>
            <criterion comment="samba-swat is earlier than 0:3.0.33-0.19.el4_8.1" test_ref="oval:org.mitre.oval:tst:40761"/>
            <criterion comment="samba-client is earlier than 0:3.0.33-0.19.el4_8.1" test_ref="oval:org.mitre.oval:tst:40021"/>
            <criterion comment="samba is earlier than 0:3.0.33-0.19.el4_8.1" test_ref="oval:org.mitre.oval:tst:40520"/>
          </criteria>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criteria operator="OR">
            <criterion comment="tdb-tools is earlier than 0:3.3.8-0.52.el5_5" test_ref="oval:org.mitre.oval:tst:40785"/>
            <criterion comment="libtdb-devel is earlier than 0:3.3.8-0.52.el5_5" test_ref="oval:org.mitre.oval:tst:39928"/>
            <criterion comment="samba3x-winbind-devel is earlier than 0:3.3.8-0.52.el5_5" test_ref="oval:org.mitre.oval:tst:40808"/>
            <criterion comment="samba3x-common is earlier than 0:3.3.8-0.52.el5_5" test_ref="oval:org.mitre.oval:tst:40403"/>
            <criterion comment="libsmbclient is earlier than 0:3.0.33-3.29.el5_5" test_ref="oval:org.mitre.oval:tst:40124"/>
            <criterion comment="samba3x-doc is earlier than 0:3.3.8-0.52.el5_5" test_ref="oval:org.mitre.oval:tst:40792"/>
            <criterion comment="samba3x-domainjoin-gui is earlier than 0:3.3.8-0.52.el5_5" test_ref="oval:org.mitre.oval:tst:40636"/>
            <criterion comment="libtalloc-devel is earlier than 0:3.3.8-0.52.el5_5" test_ref="oval:org.mitre.oval:tst:40508"/>
            <criterion comment="libtdb is earlier than 0:3.3.8-0.52.el5_5" test_ref="oval:org.mitre.oval:tst:40589"/>
            <criterion comment="libsmbclient-devel is earlier than 0:3.0.33-3.29.el5_5" test_ref="oval:org.mitre.oval:tst:40500"/>
            <criterion comment="samba3x-client is earlier than 0:3.3.8-0.52.el5_5" test_ref="oval:org.mitre.oval:tst:40646"/>
            <criterion comment="samba3x is earlier than 0:3.3.8-0.52.el5_5" test_ref="oval:org.mitre.oval:tst:40660"/>
            <criterion comment="libtalloc is earlier than 0:3.3.8-0.52.el5_5" test_ref="oval:org.mitre.oval:tst:40439"/>
            <criterion comment="samba3x-swat is earlier than 0:3.3.8-0.52.el5_5" test_ref="oval:org.mitre.oval:tst:40724"/>
            <criterion comment="samba-common is earlier than 0:3.0.33-3.29.el5_5" test_ref="oval:org.mitre.oval:tst:40663"/>
            <criterion comment="samba-swat is earlier than 0:3.0.33-3.29.el5_5" test_ref="oval:org.mitre.oval:tst:40822"/>
            <criterion comment="samba-client is earlier than 0:3.0.33-3.29.el5_5" test_ref="oval:org.mitre.oval:tst:40799"/>
            <criterion comment="samba3x-winbind is earlier than 0:3.3.8-0.52.el5_5" test_ref="oval:org.mitre.oval:tst:40481"/>
            <criterion comment="samba is earlier than 0:3.0.33-3.29.el5_5" test_ref="oval:org.mitre.oval:tst:39867"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9858" version="3" class="vulnerability">
      <metadata>
        <title>Buffer overflow in the mail_valid_net_parse_work function in mail.c for Washington's IMAP Server (UW-IMAP) before imap-2004g allows remote attackers to execute arbitrary code via a mailbox name containing a single double-quote (") character without a closing quote, which causes bytes after the double-quote to be copied into a buffer indefinitely.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2933" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2933"/>
        <description>Buffer overflow in the mail_valid_net_parse_work function in mail.c for Washington's IMAP Server (UW-IMAP) before imap-2004g allows remote attackers to execute arbitrary code via a mailbox name containing a single double-quote (") character without a closing quote, which causes bytes after the double-quote to be copied into a buffer indefinitely.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:19:13.577-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:34.202-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:41.736-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
          <criteria operator="OR">
            <criterion comment="php-mysql is earlier than 0:4.3.2-30.ent" test_ref="oval:org.mitre.oval:tst:32711"/>
            <criterion comment="php-imap is earlier than 0:4.3.2-30.ent" test_ref="oval:org.mitre.oval:tst:32166"/>
            <criterion comment="imap is earlier than 1:2002d-12" test_ref="oval:org.mitre.oval:tst:31804"/>
            <criterion comment="imap-devel is earlier than 1:2002d-12" test_ref="oval:org.mitre.oval:tst:32091"/>
            <criterion comment="php is earlier than 0:4.3.2-30.ent" test_ref="oval:org.mitre.oval:tst:32579"/>
            <criterion comment="php-pgsql is earlier than 0:4.3.2-30.ent" test_ref="oval:org.mitre.oval:tst:32613"/>
            <criterion comment="imap-utils is earlier than 1:2002d-12" test_ref="oval:org.mitre.oval:tst:32441"/>
            <criterion comment="php-ldap is earlier than 0:4.3.2-30.ent" test_ref="oval:org.mitre.oval:tst:32425"/>
            <criterion comment="php-odbc is earlier than 0:4.3.2-30.ent" test_ref="oval:org.mitre.oval:tst:32107"/>
            <criterion comment="php-devel is earlier than 0:4.3.2-30.ent" test_ref="oval:org.mitre.oval:tst:32695"/>
          </criteria>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <criteria operator="OR">
            <criterion comment="php-xmlrpc is earlier than 0:4.3.9-3.12" test_ref="oval:org.mitre.oval:tst:31742"/>
            <criterion comment="php-snmp is earlier than 0:4.3.9-3.12" test_ref="oval:org.mitre.oval:tst:32509"/>
            <criterion comment="php-domxml is earlier than 0:4.3.9-3.12" test_ref="oval:org.mitre.oval:tst:32606"/>
            <criterion comment="php-mysql is earlier than 0:4.3.9-3.12" test_ref="oval:org.mitre.oval:tst:32503"/>
            <criterion comment="php-imap is earlier than 0:4.3.9-3.12" test_ref="oval:org.mitre.oval:tst:32185"/>
            <criterion comment="libc-client is earlier than 0:2002e-14" test_ref="oval:org.mitre.oval:tst:32375"/>
            <criterion comment="php-gd is earlier than 0:4.3.9-3.12" test_ref="oval:org.mitre.oval:tst:32639"/>
            <criterion comment="php is earlier than 0:4.3.9-3.12" test_ref="oval:org.mitre.oval:tst:32546"/>
            <criterion comment="php-mbstring is earlier than 0:4.3.9-3.12" test_ref="oval:org.mitre.oval:tst:32577"/>
            <criterion comment="php-pgsql is earlier than 0:4.3.9-3.12" test_ref="oval:org.mitre.oval:tst:32236"/>
            <criterion comment="php-pear is earlier than 0:4.3.9-3.12" test_ref="oval:org.mitre.oval:tst:32578"/>
            <criterion comment="php-ldap is earlier than 0:4.3.9-3.12" test_ref="oval:org.mitre.oval:tst:32591"/>
            <criterion comment="libc-client-devel is earlier than 0:2002e-14" test_ref="oval:org.mitre.oval:tst:32344"/>
            <criterion comment="php-odbc is earlier than 0:4.3.9-3.12" test_ref="oval:org.mitre.oval:tst:32707"/>
            <criterion comment="php-ncurses is earlier than 0:4.3.9-3.12" test_ref="oval:org.mitre.oval:tst:32547"/>
            <criterion comment="php-devel is earlier than 0:4.3.9-3.12" test_ref="oval:org.mitre.oval:tst:31727"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9857" version="3" class="vulnerability">
      <metadata>
        <title>The Internet Key Exchange version 1 (IKEv1) implementation (isakmp_agg.c) in racoon in ipsec-tools before 0.6.3, when running in aggressive mode, allows remote attackers to cause a denial of service (null dereference and crash) via crafted IKE packets, as demonstrated by the PROTOS ISAKMP Test Suite for IKEv1.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-3732" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-3732"/>
        <description>The Internet Key Exchange version 1 (IKEv1) implementation (isakmp_agg.c) in racoon in ipsec-tools before 0.6.3, when running in aggressive mode, allows remote attackers to cause a denial of service (null dereference and crash) via crafted IKE packets, as demonstrated by the PROTOS ISAKMP Test Suite for IKEv1.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:16:39.780-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:33.922-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:41.492-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
          <criterion comment="ipsec-tools is earlier than 0:0.2.5-0.7.rhel3.3" test_ref="oval:org.mitre.oval:tst:32025"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <criterion comment="ipsec-tools is earlier than 0:0.3.3-6.rhel4.1" test_ref="oval:org.mitre.oval:tst:32632"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9853" version="3" class="vulnerability">
      <metadata>
        <title>Multiple buffer overflows in the (1) SIP, (2) CMIP, (3) CMP, (4) CMS, (5) CRMF, (6) ESS, (7) OCSP, (8) X.509, (9) ISIS, (10) DISTCC, (11) FCELS, (12) Q.931, (13) NCP, (14) TCAP, (15) ISUP, (16) MEGACO, (17) PKIX1Explitit, (18) PKIX_Qualified, (19) Presentation dissectors in Ethereal before 0.10.11 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1461" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1461"/>
        <description>Multiple buffer overflows in the (1) SIP, (2) CMIP, (3) CMP, (4) CMS, (5) CRMF, (6) ESS, (7) OCSP, (8) X.509, (9) ISIS, (10) DISTCC, (11) FCELS, (12) Q.931, (13) NCP, (14) TCAP, (15) ISUP, (16) MEGACO, (17) PKIX1Explitit, (18) PKIX_Qualified, (19) Presentation dissectors in Ethereal before 0.10.11 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:24:12.258-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:33.072-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:40.507-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
          <criteria operator="OR">
            <criterion comment="ethereal-gnome is earlier than 0:0.10.11-1.EL3.1" test_ref="oval:org.mitre.oval:tst:31458"/>
            <criterion comment="ethereal is earlier than 0:0.10.11-1.EL3.1" test_ref="oval:org.mitre.oval:tst:31546"/>
          </criteria>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <criteria operator="OR">
            <criterion comment="ethereal-gnome is earlier than 0:0.10.11-1.EL4.1" test_ref="oval:org.mitre.oval:tst:31674"/>
            <criterion comment="ethereal is earlier than 0:0.10.11-1.EL4.1" test_ref="oval:org.mitre.oval:tst:31865"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9852" version="3" class="vulnerability">
      <metadata>
        <title>Multiple cross-site scripting (XSS) vulnerabilities in SquirrelMail 1.4.0 through 1.4.4 allow remote attackers to inject arbitrary web script or HTML via unknown attack vectors in (1) the URL or (2) an e-mail message.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1769" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1769"/>
        <description>Multiple cross-site scripting (XSS) vulnerabilities in SquirrelMail 1.4.0 through 1.4.4 allow remote attackers to inject arbitrary web script or HTML via unknown attack vectors in (1) the URL or (2) an e-mail message.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:17:17.382-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:32.818-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:40.279-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
          <criterion comment="squirrelmail is earlier than 0:1.4.3a-11.EL3" test_ref="oval:org.mitre.oval:tst:31585"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <criterion comment="squirrelmail is earlier than 0:1.4.3a-12.EL4" test_ref="oval:org.mitre.oval:tst:31556"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9851" version="3" class="vulnerability">
      <metadata>
        <title>Integer overflow in a certain quantvals and quantlist calculation in Xiph.org libvorbis 1.2.0 and earlier allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a crafted OGG file with a large virtual space for its codebook, which triggers a heap overflow.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-1423" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1423"/>
        <description>Integer overflow in a certain quantvals and quantlist calculation in Xiph.org libvorbis 1.2.0 and earlier allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a crafted OGG file with a large virtual space for its codebook, which triggers a heap overflow.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:15:32.959-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:32.531-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:39.925-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
          <criteria operator="OR">
            <criterion comment="libvorbis-devel is earlier than 1:1.0-10.el3" test_ref="oval:org.mitre.oval:tst:36659"/>
            <criterion comment="libvorbis is earlier than 1:1.0-10.el3" test_ref="oval:org.mitre.oval:tst:36699"/>
          </criteria>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <criteria operator="OR">
            <criterion comment="libvorbis-devel is earlier than 0:1.1.0-3.el4_6.1" test_ref="oval:org.mitre.oval:tst:36519"/>
            <criterion comment="libvorbis is earlier than 0:1.1.0-3.el4_6.1" test_ref="oval:org.mitre.oval:tst:36387"/>
          </criteria>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criteria operator="OR">
            <criterion comment="libvorbis-devel is earlier than 0:1.1.2-3.el5_1.2" test_ref="oval:org.mitre.oval:tst:36439"/>
            <criterion comment="libvorbis is earlier than 0:1.1.2-3.el5_1.2" test_ref="oval:org.mitre.oval:tst:36710"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9850" version="3" class="vulnerability">
      <metadata>
        <title>Multiple unspecified vulnerabilities in Ethereal 0.8.x up to 0.10.14 allow remote attackers to cause a denial of service (crash from null dereference) via the (1) Sniffer capture or (2) SMB PIPE dissector.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-1938" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1938"/>
        <description>Multiple unspecified vulnerabilities in Ethereal 0.8.x up to 0.10.14 allow remote attackers to cause a denial of service (crash from null dereference) via the (1) Sniffer capture or (2) SMB PIPE dissector.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:16:28.542-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:32.289-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:39.672-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
          <criteria operator="OR">
            <criterion comment="ethereal-gnome is earlier than 0:0.99.0-EL3.2" test_ref="oval:org.mitre.oval:tst:32590"/>
            <criterion comment="ethereal is earlier than 0:0.99.0-EL3.2" test_ref="oval:org.mitre.oval:tst:32631"/>
          </criteria>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <criteria operator="OR">
            <criterion comment="ethereal-gnome is earlier than 0:0.99.0-EL4.2" test_ref="oval:org.mitre.oval:tst:32299"/>
            <criterion comment="ethereal is earlier than 0:0.99.0-EL4.2" test_ref="oval:org.mitre.oval:tst:32238"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9849" version="3" class="vulnerability">
      <metadata>
        <title>Certain privileged UI code in Mozilla Firefox and Thunderbird before 1.5.0.4 calls content-defined setters on an object prototype, which allows remote attackers to execute code at a higher privilege than intended.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-2776" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-2776"/>
        <description>Certain privileged UI code in Mozilla Firefox and Thunderbird before 1.5.0.4 calls content-defined setters on an object prototype, which allows remote attackers to execute code at a higher privilege than intended.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:16:02.200-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:31.726-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:39.158-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
          <criteria operator="OR">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.2-0.1.0.EL3" test_ref="oval:org.mitre.oval:tst:32575"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.2-0.1.0.EL3" test_ref="oval:org.mitre.oval:tst:32674"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.2-0.1.0.EL3" test_ref="oval:org.mitre.oval:tst:32918"/>
            <criterion comment="seamonkey is earlier than 0:1.0.2-0.1.0.EL3" test_ref="oval:org.mitre.oval:tst:32919"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.2-0.1.0.EL3" test_ref="oval:org.mitre.oval:tst:32864"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.2-0.1.0.EL3" test_ref="oval:org.mitre.oval:tst:32659"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.2-0.1.0.EL3" test_ref="oval:org.mitre.oval:tst:32859"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.2-0.1.0.EL3" test_ref="oval:org.mitre.oval:tst:32511"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.2-0.1.0.EL3" test_ref="oval:org.mitre.oval:tst:32902"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.2-0.1.0.EL3" test_ref="oval:org.mitre.oval:tst:32837"/>
          </criteria>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <criteria operator="OR">
            <criterion comment="devhelp-devel is earlier than 0:0.10-0.2.el4" test_ref="oval:org.mitre.oval:tst:32873"/>
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.3-0.el4.1" test_ref="oval:org.mitre.oval:tst:32693"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.3-0.el4.1" test_ref="oval:org.mitre.oval:tst:32886"/>
            <criterion comment="thunderbird is earlier than 0:1.5.0.5-0.el4.1" test_ref="oval:org.mitre.oval:tst:32810"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.3-0.el4.1" test_ref="oval:org.mitre.oval:tst:32418"/>
            <criterion comment="seamonkey is earlier than 0:1.0.3-0.el4.1" test_ref="oval:org.mitre.oval:tst:32496"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.3-0.el4.1" test_ref="oval:org.mitre.oval:tst:32929"/>
            <criterion comment="devhelp is earlier than 0:0.10-0.2.el4" test_ref="oval:org.mitre.oval:tst:32777"/>
            <criterion comment="firefox is earlier than 0:1.5.0.5-0.el4.1" test_ref="oval:org.mitre.oval:tst:32896"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.3-0.el4.1" test_ref="oval:org.mitre.oval:tst:32722"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.3-0.el4.1" test_ref="oval:org.mitre.oval:tst:32906"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.3-0.el4.1" test_ref="oval:org.mitre.oval:tst:32905"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.3-0.el4.1" test_ref="oval:org.mitre.oval:tst:32925"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.3-0.el4.1" test_ref="oval:org.mitre.oval:tst:32624"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9846" version="3" class="vulnerability">
      <metadata>
        <title>Buffer overflow in the isdn_net_setcfg function in isdn_net.c in Linux kernel 2.6.23 allows local users to have an unknown impact via a crafted argument to the isdn_ioctl function.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-6063" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6063"/>
        <description>Buffer overflow in the isdn_net_setcfg function in isdn_net.c in Linux kernel 2.6.23 allows local users to have an unknown impact via a crafted argument to the isdn_ioctl function.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:16:29.687-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:30.659-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:38.052-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
          <criteria operator="OR">
            <criterion comment="kernel-BOOT is earlier than 0:2.4.21-58.EL" test_ref="oval:org.mitre.oval:tst:37931"/>
            <criterion comment="kernel-unsupported is earlier than 0:2.4.21-58.EL" test_ref="oval:org.mitre.oval:tst:37846"/>
            <criterion comment="kernel-smp-unsupported is earlier than 0:2.4.21-58.EL" test_ref="oval:org.mitre.oval:tst:37817"/>
            <criterion comment="kernel-hugemem-unsupported is earlier than 0:2.4.21-58.EL" test_ref="oval:org.mitre.oval:tst:37663"/>
            <criterion comment="kernel-hugemem is earlier than 0:2.4.21-58.EL" test_ref="oval:org.mitre.oval:tst:37799"/>
            <criterion comment="kernel is earlier than 0:2.4.21-58.EL" test_ref="oval:org.mitre.oval:tst:37028"/>
            <criterion comment="kernel-source is earlier than 0:2.4.21-58.EL" test_ref="oval:org.mitre.oval:tst:37885"/>
            <criterion comment="kernel-doc is earlier than 0:2.4.21-58.EL" test_ref="oval:org.mitre.oval:tst:37981"/>
            <criterion comment="kernel-smp is earlier than 0:2.4.21-58.EL" test_ref="oval:org.mitre.oval:tst:37117"/>
          </criteria>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <criteria operator="OR">
            <criterion comment="kernel-xenU is earlier than 0:2.6.9-67.0.4.EL" test_ref="oval:org.mitre.oval:tst:36090"/>
            <criterion comment="kernel-hugemem is earlier than 0:2.6.9-67.0.4.EL" test_ref="oval:org.mitre.oval:tst:35525"/>
            <criterion comment="kernel-hugemem-devel is earlier than 0:2.6.9-67.0.4.EL" test_ref="oval:org.mitre.oval:tst:35832"/>
            <criterion comment="kernel-xenU-devel is earlier than 0:2.6.9-67.0.4.EL" test_ref="oval:org.mitre.oval:tst:35126"/>
            <criterion comment="kernel-smp-devel is earlier than 0:2.6.9-67.0.4.EL" test_ref="oval:org.mitre.oval:tst:35901"/>
            <criterion comment="kernel-largesmp-devel is earlier than 0:2.6.9-67.0.4.EL" test_ref="oval:org.mitre.oval:tst:36007"/>
            <criterion comment="kernel is earlier than 0:2.6.9-67.0.4.EL" test_ref="oval:org.mitre.oval:tst:35982"/>
            <criterion comment="kernel-devel is earlier than 0:2.6.9-67.0.4.EL" test_ref="oval:org.mitre.oval:tst:36072"/>
            <criterion comment="kernel-doc is earlier than 0:2.6.9-67.0.4.EL" test_ref="oval:org.mitre.oval:tst:36041"/>
            <criterion comment="kernel-largesmp is earlier than 0:2.6.9-67.0.4.EL" test_ref="oval:org.mitre.oval:tst:35364"/>
            <criterion comment="kernel-smp is earlier than 0:2.6.9-67.0.4.EL" test_ref="oval:org.mitre.oval:tst:35662"/>
          </criteria>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criteria operator="OR">
            <criterion comment="kernel-kdump is earlier than 0:2.6.18-53.1.14.el5" test_ref="oval:org.mitre.oval:tst:36192"/>
            <criterion comment="kernel-debug is earlier than 0:2.6.18-53.1.14.el5" test_ref="oval:org.mitre.oval:tst:36176"/>
            <criterion comment="kernel-xen is earlier than 0:2.6.18-53.1.14.el5" test_ref="oval:org.mitre.oval:tst:36335"/>
            <criterion comment="kernel-headers is earlier than 0:2.6.18-53.1.14.el5" test_ref="oval:org.mitre.oval:tst:36430"/>
            <criterion comment="kernel-kdump-devel is earlier than 0:2.6.18-53.1.14.el5" test_ref="oval:org.mitre.oval:tst:35944"/>
            <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-53.1.14.el5" test_ref="oval:org.mitre.oval:tst:36215"/>
            <criterion comment="kernel is earlier than 0:2.6.18-53.1.14.el5" test_ref="oval:org.mitre.oval:tst:36409"/>
            <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-53.1.14.el5" test_ref="oval:org.mitre.oval:tst:35484"/>
            <criterion comment="kernel-devel is earlier than 0:2.6.18-53.1.14.el5" test_ref="oval:org.mitre.oval:tst:35974"/>
            <criterion comment="kernel-PAE is earlier than 0:2.6.18-53.1.14.el5" test_ref="oval:org.mitre.oval:tst:35791"/>
            <criterion comment="kernel-debug-devel is earlier than 0:2.6.18-53.1.14.el5" test_ref="oval:org.mitre.oval:tst:36150"/>
            <criterion comment="kernel-doc is earlier than 0:2.6.18-53.1.14.el5" test_ref="oval:org.mitre.oval:tst:36251"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9845" version="3" class="vulnerability">
      <metadata>
        <title>Format string vulnerability in gedit 2.10.2 may allow attackers to cause a denial of service (application crash) via a bin file with format string specifiers in the filename.  NOTE: while this issue is triggered on the command line by the gedit user, it has been reported that web browsers and email clients could be configured to provide a file name as an argument to gedit, so there is a valid attack that crosses security boundaries.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1686" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1686"/>
        <description>Format string vulnerability in gedit 2.10.2 may allow attackers to cause a denial of service (application crash) via a bin file with format string specifiers in the filename.  NOTE: while this issue is triggered on the command line by the gedit user, it has been reported that web browsers and email clients could be configured to provide a file name as an argument to gedit, so there is a valid attack that crosses security boundaries.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:16:01.759-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:30.427-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:37.774-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
          <criterion comment="gedit is earlier than 1:2.2.2-4.rhel3" test_ref="oval:org.mitre.oval:tst:31476"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <criteria operator="OR">
            <criterion comment="gedit is earlier than 1:2.8.1-4" test_ref="oval:org.mitre.oval:tst:31796"/>
            <criterion comment="gedit-devel is earlier than 1:2.8.1-4" test_ref="oval:org.mitre.oval:tst:31886"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9844" version="3" class="vulnerability">
      <metadata>
        <title>KDE Display Manager (KDM) in KDE 3.2.0 up to 3.5.3 allows local users to read arbitrary files via a symlink attack related to the session type for login.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-2449" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-2449"/>
        <description>KDE Display Manager (KDM) in KDE 3.2.0 up to 3.5.3 allows local users to read arbitrary files via a symlink attack related to the session type for login.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:15:45.232-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:30.235-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:37.569-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
        <criteria operator="OR">
          <criterion comment="kdebase is earlier than 6:3.3.1-5.12" test_ref="oval:org.mitre.oval:tst:32706"/>
          <criterion comment="kdebase-devel is earlier than 6:3.3.1-5.12" test_ref="oval:org.mitre.oval:tst:32662"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9843" version="3" class="vulnerability">
      <metadata>
        <title>Mozilla Firefox before 1.5.0.7 and SeaMonkey before 1.0.5 allows remote attackers to bypass the security model and inject content into the sub-frame of another site via targetWindow.frames[n].document.open(), which facilitates spoofing and other attacks.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-4568" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-4568"/>
        <description>Mozilla Firefox before 1.5.0.7 and SeaMonkey before 1.0.5 allows remote attackers to bypass the security model and inject content into the sub-frame of another site via targetWindow.frames[n].document.open(), which facilitates spoofing and other attacks.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:25:02.251-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:29.685-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:37.007-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
          <criteria operator="OR">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.5-0.1.el3" test_ref="oval:org.mitre.oval:tst:32759"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.5-0.1.el3" test_ref="oval:org.mitre.oval:tst:32989"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.5-0.1.el3" test_ref="oval:org.mitre.oval:tst:32809"/>
            <criterion comment="seamonkey is earlier than 0:1.0.5-0.1.el3" test_ref="oval:org.mitre.oval:tst:32779"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.5-0.1.el3" test_ref="oval:org.mitre.oval:tst:32954"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.5-0.1.el3" test_ref="oval:org.mitre.oval:tst:32668"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.5-0.1.el3" test_ref="oval:org.mitre.oval:tst:33010"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.5-0.1.el3" test_ref="oval:org.mitre.oval:tst:32811"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.5-0.1.el3" test_ref="oval:org.mitre.oval:tst:32981"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.5-0.1.el3" test_ref="oval:org.mitre.oval:tst:33061"/>
          </criteria>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <criteria operator="OR">
            <criterion comment="devhelp-devel is earlier than 0:0.10-0.4.el4" test_ref="oval:org.mitre.oval:tst:32072"/>
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.5-0.1.el4" test_ref="oval:org.mitre.oval:tst:33120"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.5-0.1.el4" test_ref="oval:org.mitre.oval:tst:32842"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.5-0.1.el4" test_ref="oval:org.mitre.oval:tst:32677"/>
            <criterion comment="seamonkey is earlier than 0:1.0.5-0.1.el4" test_ref="oval:org.mitre.oval:tst:32933"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.5-0.1.el4" test_ref="oval:org.mitre.oval:tst:32243"/>
            <criterion comment="devhelp is earlier than 0:0.10-0.4.el4" test_ref="oval:org.mitre.oval:tst:33062"/>
            <criterion comment="firefox is earlier than 0:1.5.0.7-0.1.el4" test_ref="oval:org.mitre.oval:tst:32951"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.5-0.1.el4" test_ref="oval:org.mitre.oval:tst:32978"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.5-0.1.el4" test_ref="oval:org.mitre.oval:tst:33072"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.5-0.1.el4" test_ref="oval:org.mitre.oval:tst:33079"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.5-0.1.el4" test_ref="oval:org.mitre.oval:tst:32121"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.5-0.1.el4" test_ref="oval:org.mitre.oval:tst:33077"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9842" version="3" class="vulnerability">
      <metadata>
        <title>gtkimhtml.c in Pidgin before 2.6.6 allows remote attackers to cause a denial of service (CPU consumption and application hang) by sending many smileys in a (1) IM or (2) chat.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0423" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0423"/>
        <description>gtkimhtml.c in Pidgin before 2.6.6 allows remote attackers to cause a denial of service (CPU consumption and application hang) by sending many smileys in a (1) IM or (2) chat.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:18:45.283-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:29.269-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:36.580-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <criteria operator="OR">
            <criterion comment="finch-devel is earlier than 0:2.6.6-1.el4" test_ref="oval:org.mitre.oval:tst:39911"/>
            <criterion comment="libpurple is earlier than 0:2.6.6-1.el4" test_ref="oval:org.mitre.oval:tst:40093"/>
            <criterion comment="libpurple-perl is earlier than 0:2.6.6-1.el4" test_ref="oval:org.mitre.oval:tst:40218"/>
            <criterion comment="libpurple-tcl is earlier than 0:2.6.6-1.el4" test_ref="oval:org.mitre.oval:tst:40181"/>
            <criterion comment="pidgin-devel is earlier than 0:2.6.6-1.el4" test_ref="oval:org.mitre.oval:tst:40052"/>
            <criterion comment="libpurple-devel is earlier than 0:2.6.6-1.el4" test_ref="oval:org.mitre.oval:tst:39983"/>
            <criterion comment="finch is earlier than 0:2.6.6-1.el4" test_ref="oval:org.mitre.oval:tst:39933"/>
            <criterion comment="pidgin-perl is earlier than 0:2.6.6-1.el4" test_ref="oval:org.mitre.oval:tst:40004"/>
            <criterion comment="pidgin is earlier than 0:2.6.6-1.el4" test_ref="oval:org.mitre.oval:tst:40214"/>
          </criteria>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criteria operator="OR">
            <criterion comment="finch-devel is earlier than 0:2.6.6-1.el5" test_ref="oval:org.mitre.oval:tst:39974"/>
            <criterion comment="libpurple is earlier than 0:2.6.6-1.el5" test_ref="oval:org.mitre.oval:tst:40080"/>
            <criterion comment="libpurple-perl is earlier than 0:2.6.6-1.el5" test_ref="oval:org.mitre.oval:tst:40176"/>
            <criterion comment="libpurple-tcl is earlier than 0:2.6.6-1.el5" test_ref="oval:org.mitre.oval:tst:40248"/>
            <criterion comment="pidgin-devel is earlier than 0:2.6.6-1.el5" test_ref="oval:org.mitre.oval:tst:40202"/>
            <criterion comment="libpurple-devel is earlier than 0:2.6.6-1.el5" test_ref="oval:org.mitre.oval:tst:40141"/>
            <criterion comment="finch is earlier than 0:2.6.6-1.el5" test_ref="oval:org.mitre.oval:tst:39917"/>
            <criterion comment="pidgin-perl is earlier than 0:2.6.6-1.el5" test_ref="oval:org.mitre.oval:tst:40306"/>
            <criterion comment="pidgin is earlier than 0:2.6.6-1.el5" test_ref="oval:org.mitre.oval:tst:39993"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9841" version="3" class="vulnerability">
      <metadata>
        <title>Integer signedness error in the DNP3 dissector in Wireshark (formerly Ethereal) 0.10.12 to 0.99.6 allows remote attackers to cause a denial of service (long loop) via a malformed DNP3 packet.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-6113" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6113"/>
        <description>Integer signedness error in the DNP3 dissector in Wireshark (formerly Ethereal) 0.10.12 to 0.99.6 allows remote attackers to cause a denial of service (long loop) via a malformed DNP3 packet.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:20:20.400-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:28.758-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:36.202-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
          <criteria operator="OR">
            <criterion comment="wireshark is earlier than 0:0.99.7-EL3.1" test_ref="oval:org.mitre.oval:tst:36111"/>
            <criterion comment="wireshark-gnome is earlier than 0:0.99.7-EL3.1" test_ref="oval:org.mitre.oval:tst:36043"/>
            <criterion comment="libsmi is earlier than 0:0.4.5-3.el3" test_ref="oval:org.mitre.oval:tst:35411"/>
            <criterion comment="libsmi-devel is earlier than 0:0.4.5-3.el3" test_ref="oval:org.mitre.oval:tst:36140"/>
          </criteria>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <criteria operator="OR">
            <criterion comment="wireshark is earlier than 0:0.99.7-1.el4" test_ref="oval:org.mitre.oval:tst:36051"/>
            <criterion comment="wireshark-gnome is earlier than 0:0.99.7-1.el4" test_ref="oval:org.mitre.oval:tst:35980"/>
            <criterion comment="libsmi is earlier than 0:0.4.5-2.el4" test_ref="oval:org.mitre.oval:tst:35669"/>
            <criterion comment="libsmi-devel is earlier than 0:0.4.5-2.el4" test_ref="oval:org.mitre.oval:tst:35941"/>
          </criteria>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criteria operator="OR">
            <criterion comment="wireshark is earlier than 0:0.99.7-1.el5" test_ref="oval:org.mitre.oval:tst:35709"/>
            <criterion comment="wireshark-gnome is earlier than 0:0.99.7-1.el5" test_ref="oval:org.mitre.oval:tst:36120"/>
            <criterion comment="libsmi is earlier than 0:0.4.5-2.el5" test_ref="oval:org.mitre.oval:tst:35712"/>
            <criterion comment="libsmi-devel is earlier than 0:0.4.5-2.el5" test_ref="oval:org.mitre.oval:tst:35801"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9839" version="3" class="vulnerability">
      <metadata>
        <title>Heap-based buffer overflow in the CCITTFaxStream::lookChar method in xpdf/Stream.cc in Xpdf 3.02p11 allows remote attackers to execute arbitrary code via a PDF file that contains a crafted CCITTFaxDecode filter.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-5393" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5393"/>
        <description>Heap-based buffer overflow in the CCITTFaxStream::lookChar method in xpdf/Stream.cc in Xpdf 3.02p11 allows remote attackers to execute arbitrary code via a PDF file that contains a crafted CCITTFaxDecode filter.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:21:25.655-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:27.692-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:35.083-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
          <criteria operator="OR">
            <criterion comment="tetex-latex is earlier than 0:1.0.7-67.11" test_ref="oval:org.mitre.oval:tst:35542"/>
            <criterion comment="tetex-dvips is earlier than 0:1.0.7-67.11" test_ref="oval:org.mitre.oval:tst:35314"/>
            <criterion comment="tetex-fonts is earlier than 0:1.0.7-67.11" test_ref="oval:org.mitre.oval:tst:35233"/>
            <criterion comment="cups-libs is earlier than 0:1.1.17-13.3.46" test_ref="oval:org.mitre.oval:tst:35218"/>
            <criterion comment="tetex is earlier than 0:1.0.7-67.11" test_ref="oval:org.mitre.oval:tst:35248"/>
            <criterion comment="cups-devel is earlier than 0:1.1.17-13.3.46" test_ref="oval:org.mitre.oval:tst:35491"/>
            <criterion comment="tetex-afm is earlier than 0:1.0.7-67.11" test_ref="oval:org.mitre.oval:tst:34644"/>
            <criterion comment="xpdf is earlier than 0:2.02-11.el3" test_ref="oval:org.mitre.oval:tst:35634"/>
            <criterion comment="tetex-xdvi is earlier than 0:1.0.7-67.11" test_ref="oval:org.mitre.oval:tst:35275"/>
            <criterion comment="cups is earlier than 0:1.1.17-13.3.46" test_ref="oval:org.mitre.oval:tst:35533"/>
          </criteria>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <criteria operator="OR">
            <criterion comment="tetex-latex is earlier than 0:2.0.2-22.0.1.EL4.10" test_ref="oval:org.mitre.oval:tst:34998"/>
            <criterion comment="kdegraphics-devel is earlier than 7:3.3.1-6.el4_5" test_ref="oval:org.mitre.oval:tst:35446"/>
            <criterion comment="tetex-dvips is earlier than 0:2.0.2-22.0.1.EL4.10" test_ref="oval:org.mitre.oval:tst:35156"/>
            <criterion comment="kdegraphics is earlier than 7:3.3.1-6.el4_5" test_ref="oval:org.mitre.oval:tst:35404"/>
            <criterion comment="tetex-fonts is earlier than 0:2.0.2-22.0.1.EL4.10" test_ref="oval:org.mitre.oval:tst:35455"/>
            <criterion comment="cups-libs is earlier than 0:1.1.22-0.rc1.9.20.2.el4_5.2" test_ref="oval:org.mitre.oval:tst:35415"/>
            <criterion comment="tetex is earlier than 0:2.0.2-22.0.1.EL4.10" test_ref="oval:org.mitre.oval:tst:35178"/>
            <criterion comment="gpdf is earlier than 0:2.8.2-7.7.1" test_ref="oval:org.mitre.oval:tst:35574"/>
            <criterion comment="cups-devel is earlier than 0:1.1.22-0.rc1.9.20.2.el4_5.2" test_ref="oval:org.mitre.oval:tst:34735"/>
            <criterion comment="tetex-afm is earlier than 0:2.0.2-22.0.1.EL4.10" test_ref="oval:org.mitre.oval:tst:35585"/>
            <criterion comment="xpdf is earlier than 1:3.00-14.el4" test_ref="oval:org.mitre.oval:tst:35315"/>
            <criterion comment="tetex-xdvi is earlier than 0:2.0.2-22.0.1.EL4.10" test_ref="oval:org.mitre.oval:tst:35591"/>
            <criterion comment="tetex-doc is earlier than 0:2.0.2-22.0.1.EL4.10" test_ref="oval:org.mitre.oval:tst:35283"/>
            <criterion comment="cups is earlier than 0:1.1.22-0.rc1.9.20.2.el4_5.2" test_ref="oval:org.mitre.oval:tst:35537"/>
          </criteria>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criteria operator="OR">
            <criterion comment="kdegraphics-devel is earlier than 7:3.5.4-5.el5_1" test_ref="oval:org.mitre.oval:tst:35714"/>
            <criterion comment="cups-lpd is earlier than 0:1.2.4-11.14.el5_1.3" test_ref="oval:org.mitre.oval:tst:35274"/>
            <criterion comment="tetex-dvips is earlier than 0:3.0-33.2.el5_1.2" test_ref="oval:org.mitre.oval:tst:35509"/>
            <criterion comment="kdegraphics is earlier than 7:3.5.4-5.el5_1" test_ref="oval:org.mitre.oval:tst:35722"/>
            <criterion comment="poppler is earlier than 0:0.5.4-4.3.el5_1" test_ref="oval:org.mitre.oval:tst:35549"/>
            <criterion comment="tetex-fonts is earlier than 0:3.0-33.2.el5_1.2" test_ref="oval:org.mitre.oval:tst:35527"/>
            <criterion comment="cups-libs is earlier than 0:1.2.4-11.14.el5_1.3" test_ref="oval:org.mitre.oval:tst:35427"/>
            <criterion comment="tetex is earlier than 0:3.0-33.2.el5_1.2" test_ref="oval:org.mitre.oval:tst:35459"/>
            <criterion comment="tetex-doc is earlier than 0:3.0-33.2.el5_1.2" test_ref="oval:org.mitre.oval:tst:34727"/>
            <criterion comment="poppler-devel is earlier than 0:0.5.4-4.3.el5_1" test_ref="oval:org.mitre.oval:tst:35496"/>
            <criterion comment="tetex-latex is earlier than 0:3.0-33.2.el5_1.2" test_ref="oval:org.mitre.oval:tst:35498"/>
            <criterion comment="poppler-utils is earlier than 0:0.5.4-4.3.el5_1" test_ref="oval:org.mitre.oval:tst:35147"/>
            <criterion comment="cups-devel is earlier than 0:1.2.4-11.14.el5_1.3" test_ref="oval:org.mitre.oval:tst:35508"/>
            <criterion comment="tetex-afm is earlier than 0:3.0-33.2.el5_1.2" test_ref="oval:org.mitre.oval:tst:35407"/>
            <criterion comment="tetex-xdvi is earlier than 0:3.0-33.2.el5_1.2" test_ref="oval:org.mitre.oval:tst:34618"/>
            <criterion comment="cups is earlier than 0:1.2.4-11.14.el5_1.3" test_ref="oval:org.mitre.oval:tst:35530"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9838" version="3" class="vulnerability">
      <metadata>
        <title>The ipt_recent kernel module (ipt_recent.c) in Linux kernel 2.6.12 and earlier does not properly perform certain time tests when the jiffies value is greater than LONG_MAX, which can cause ipt_recent netfilter rules to block too early, a different vulnerability than CVE-2005-2872.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2873" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2873"/>
        <description>The ipt_recent kernel module (ipt_recent.c) in Linux kernel 2.6.12 and earlier does not properly perform certain time tests when the jiffies value is greater than LONG_MAX, which can cause ipt_recent netfilter rules to block too early, a different vulnerability than CVE-2005-2872.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:19:39.562-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:27.383-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:34.705-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
        <criteria operator="OR">
          <criterion comment="kernel-xenU is earlier than 0:2.6.9-55.EL" test_ref="oval:org.mitre.oval:tst:30189"/>
          <criterion comment="kernel-hugemem is earlier than 0:2.6.9-55.EL" test_ref="oval:org.mitre.oval:tst:30542"/>
          <criterion comment="kernel-hugemem-devel is earlier than 0:2.6.9-55.EL" test_ref="oval:org.mitre.oval:tst:30504"/>
          <criterion comment="kernel-xenU-devel is earlier than 0:2.6.9-55.EL" test_ref="oval:org.mitre.oval:tst:30169"/>
          <criterion comment="kernel-smp-devel is earlier than 0:2.6.9-55.EL" test_ref="oval:org.mitre.oval:tst:29589"/>
          <criterion comment="kernel-largesmp-devel is earlier than 0:2.6.9-55.EL" test_ref="oval:org.mitre.oval:tst:30432"/>
          <criterion comment="kernel is earlier than 0:2.6.9-55.EL" test_ref="oval:org.mitre.oval:tst:29669"/>
          <criterion comment="kernel-devel is earlier than 0:2.6.9-55.EL" test_ref="oval:org.mitre.oval:tst:30424"/>
          <criterion comment="kernel-doc is earlier than 0:2.6.9-55.EL" test_ref="oval:org.mitre.oval:tst:30299"/>
          <criterion comment="kernel-largesmp is earlier than 0:2.6.9-55.EL" test_ref="oval:org.mitre.oval:tst:30268"/>
          <criterion comment="kernel-smp is earlier than 0:2.6.9-55.EL" test_ref="oval:org.mitre.oval:tst:30561"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9837" version="3" class="vulnerability">
      <metadata>
        <title>Multiple stack-based buffer overflows in the putstring function in find.c in Cscope before 15.6 allow user-assisted remote attackers to execute arbitrary code via a long (1) function name or (2) symbol in a source-code file.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-1577" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1577"/>
        <description>Multiple stack-based buffer overflows in the putstring function in find.c in Cscope before 15.6 allow user-assisted remote attackers to execute arbitrary code via a long (1) function name or (2) symbol in a source-code file.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:15:55.117-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:27.162-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:34.470-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
          <criterion comment="cscope is earlier than 0:15.5-16.RHEL3" test_ref="oval:org.mitre.oval:tst:38743"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <criterion comment="cscope is earlier than 0:15.5-10.RHEL4.3" test_ref="oval:org.mitre.oval:tst:38662"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9836" version="3" class="vulnerability">
      <metadata>
        <title>Multiple buffer overflows in Ethereal 0.10.12 and earlier might allow remote attackers to execute arbitrary code via unknown vectors in the (1) SLIMP3 and (2) AgentX dissector.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-3243" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-3243"/>
        <description>Multiple buffer overflows in Ethereal 0.10.12 and earlier might allow remote attackers to execute arbitrary code via unknown vectors in the (1) SLIMP3 and (2) AgentX dissector.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:16:11.872-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:26.876-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:34.146-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
          <criteria operator="OR">
            <criterion comment="ethereal-gnome is earlier than 0:0.10.13-1.EL3.1" test_ref="oval:org.mitre.oval:tst:32189"/>
            <criterion comment="ethereal is earlier than 0:0.10.13-1.EL3.1" test_ref="oval:org.mitre.oval:tst:32138"/>
          </criteria>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <criteria operator="OR">
            <criterion comment="ethereal-gnome is earlier than 0:0.10.13-1.EL4.1" test_ref="oval:org.mitre.oval:tst:32341"/>
            <criterion comment="ethereal is earlier than 0:0.10.13-1.EL4.1" test_ref="oval:org.mitre.oval:tst:32202"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9835" version="3" class="vulnerability">
      <metadata>
        <title>The browser engine in Mozilla Firefox 3.0.x before 3.0.18, 3.5.x before 3.5.8, and 3.6.x before 3.6.2; Thunderbird before 3.0.2; and SeaMonkey before 2.0.3 allows remote attackers to cause a denial of service (memory corruption and application crash) and possibly execute arbitrary code via vectors related to (1) layout/generic/nsBlockFrame.cpp and (2) the _evaluate function in modules/plugin/base/src/nsNPAPIPlugin.cpp.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0167" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0167"/>
        <description>The browser engine in Mozilla Firefox 3.0.x before 3.0.18, 3.5.x before 3.5.8, and 3.6.x before 3.6.2; Thunderbird before 3.0.2; and SeaMonkey before 2.0.3 allows remote attackers to cause a denial of service (memory corruption and application crash) and possibly execute arbitrary code via vectors related to (1) layout/generic/nsBlockFrame.cpp and (2) the _evaluate function in modules/plugin/base/src/nsNPAPIPlugin.cpp.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:16:00.189-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:26.620-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:33.827-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <criterion comment="firefox is earlier than 0:3.0.18-1.el4" test_ref="oval:org.mitre.oval:tst:39897"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criteria operator="OR">
            <criterion comment="xulrunner-devel-unstable is earlier than 0:1.9.0.18-1.el5_4" test_ref="oval:org.mitre.oval:tst:39323"/>
            <criterion comment="xulrunner-devel is earlier than 0:1.9.0.18-1.el5_4" test_ref="oval:org.mitre.oval:tst:40174"/>
            <criterion comment="firefox is earlier than 0:3.0.18-1.el5_4" test_ref="oval:org.mitre.oval:tst:40301"/>
            <criterion comment="xulrunner is earlier than 0:1.9.0.18-1.el5_4" test_ref="oval:org.mitre.oval:tst:39533"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9834" version="3" class="vulnerability">
      <metadata>
        <title>Use-after-free vulnerability in the nsTreeSelection implementation in Mozilla Firefox before 3.0.19 and 3.5.x before 3.5.9, Thunderbird before 3.0.4, and SeaMonkey before 2.0.4 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via unspecified vectors that trigger a call to the handler for the select event for XUL tree items.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0175" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0175"/>
        <description>Use-after-free vulnerability in the nsTreeSelection implementation in Mozilla Firefox before 3.0.19 and 3.5.x before 3.5.9, Thunderbird before 3.0.4, and SeaMonkey before 2.0.4 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via unspecified vectors that trigger a call to the handler for the select event for XUL tree items.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:19:58.954-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:26.140-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:33.343-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
          <criteria operator="OR">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.9-0.52.el3" test_ref="oval:org.mitre.oval:tst:40246"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-0.52.el3" test_ref="oval:org.mitre.oval:tst:39934"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.9-0.52.el3" test_ref="oval:org.mitre.oval:tst:40184"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-0.52.el3" test_ref="oval:org.mitre.oval:tst:40133"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.9-0.52.el3" test_ref="oval:org.mitre.oval:tst:39775"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-0.52.el3" test_ref="oval:org.mitre.oval:tst:40360"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-0.52.el3" test_ref="oval:org.mitre.oval:tst:40059"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-0.52.el3" test_ref="oval:org.mitre.oval:tst:39946"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-0.52.el3" test_ref="oval:org.mitre.oval:tst:40114"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.9-0.52.el3" test_ref="oval:org.mitre.oval:tst:39403"/>
          </criteria>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <criteria operator="OR">
            <criterion comment="firefox is earlier than 0:3.0.19-1.el4" test_ref="oval:org.mitre.oval:tst:40284"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-54.el4_8" test_ref="oval:org.mitre.oval:tst:40081"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-54.el4_8" test_ref="oval:org.mitre.oval:tst:40250"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-54.el4_8" test_ref="oval:org.mitre.oval:tst:40304"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-54.el4_8" test_ref="oval:org.mitre.oval:tst:40345"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-54.el4_8" test_ref="oval:org.mitre.oval:tst:40183"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-54.el4_8" test_ref="oval:org.mitre.oval:tst:39945"/>
          </criteria>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criteria operator="OR">
            <criterion comment="xulrunner-devel-unstable is earlier than 0:1.9.0.19-1.el5_5" test_ref="oval:org.mitre.oval:tst:40265"/>
            <criterion comment="xulrunner-devel is earlier than 0:1.9.0.19-1.el5_5" test_ref="oval:org.mitre.oval:tst:39621"/>
            <criterion comment="firefox is earlier than 0:3.0.19-1.el5_5" test_ref="oval:org.mitre.oval:tst:40064"/>
            <criterion comment="xulrunner is earlier than 0:1.9.0.19-1.el5_5" test_ref="oval:org.mitre.oval:tst:40164"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9833" version="3" class="vulnerability">
      <metadata>
        <title>Argument injection vulnerability in login (login-utils/login.c) in util-linux-ng 2.14 and earlier makes it easier for remote attackers to hide activities by modifying portions of log events, as demonstrated by appending an "addr=" statement to the login name, aka "audit log injection."</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-1926" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1926"/>
        <description>Argument injection vulnerability in login (login-utils/login.c) in util-linux-ng 2.14 and earlier makes it easier for remote attackers to hide activities by modifying portions of log events, as demonstrated by appending an "addr=" statement to the login name, aka "audit log injection."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:15:38.580-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:25.908-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:33.147-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
        <criterion comment="util-linux is earlier than 0:2.12a-24.el4" test_ref="oval:org.mitre.oval:tst:38784"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9830" version="3" class="vulnerability">
      <metadata>
        <title>Wget 1.9 and 1.9.1 allows local users to overwrite arbitrary files via a symlink attack on the name of the file being downloaded.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-2014" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-2014"/>
        <description>Wget 1.9 and 1.9.1 allows local users to overwrite arbitrary files via a symlink attack on the name of the file being downloaded.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:25:25.497-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:25.002-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:31.815-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
          <criterion comment="wget is earlier than 0:1.10.1-1.30E.1" test_ref="oval:org.mitre.oval:tst:31680"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <criterion comment="wget is earlier than 0:1.10.1-2.4E.1" test_ref="oval:org.mitre.oval:tst:31717"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9829" version="3" class="vulnerability">
      <metadata>
        <title>The key serial number collision avoidance code in the key_alloc_serial function in Linux kernel 2.6.9 up to 2.6.20 allows local users to cause a denial of service (crash) via vectors that trigger a null dereference, as originally reported as "spinlock CPU recursion."</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-0006" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0006"/>
        <description>The key serial number collision avoidance code in the key_alloc_serial function in Linux kernel 2.6.9 up to 2.6.20 allows local users to cause a denial of service (crash) via vectors that trigger a null dereference, as originally reported as "spinlock CPU recursion."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:16:42.131-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:24.559-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:31.372-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <criteria operator="OR">
            <criterion comment="kernel-hugemem is earlier than 0:2.6.9-42.0.10.EL" test_ref="oval:org.mitre.oval:tst:33775"/>
            <criterion comment="kernel-hugemem-devel is earlier than 0:2.6.9-42.0.10.EL" test_ref="oval:org.mitre.oval:tst:33751"/>
            <criterion comment="kernel-smp-devel is earlier than 0:2.6.9-42.0.10.EL" test_ref="oval:org.mitre.oval:tst:33264"/>
            <criterion comment="kernel-largesmp-devel is earlier than 0:2.6.9-42.0.10.EL" test_ref="oval:org.mitre.oval:tst:33777"/>
            <criterion comment="kernel is earlier than 0:2.6.9-42.0.10.EL" test_ref="oval:org.mitre.oval:tst:33668"/>
            <criterion comment="kernel-devel is earlier than 0:2.6.9-42.0.10.EL" test_ref="oval:org.mitre.oval:tst:33639"/>
            <criterion comment="kernel-doc is earlier than 0:2.6.9-42.0.10.EL" test_ref="oval:org.mitre.oval:tst:33564"/>
            <criterion comment="kernel-largesmp is earlier than 0:2.6.9-42.0.10.EL" test_ref="oval:org.mitre.oval:tst:33538"/>
            <criterion comment="kernel-smp is earlier than 0:2.6.9-42.0.10.EL" test_ref="oval:org.mitre.oval:tst:33494"/>
          </criteria>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criteria operator="OR">
            <criterion comment="kernel-kdump is earlier than 0:2.6.18-8.1.1.el5" test_ref="oval:org.mitre.oval:tst:33717"/>
            <criterion comment="kernel-xen is earlier than 0:2.6.18-8.1.1.el5" test_ref="oval:org.mitre.oval:tst:33839"/>
            <criterion comment="kernel-headers is earlier than 0:2.6.18-8.1.1.el5" test_ref="oval:org.mitre.oval:tst:33412"/>
            <criterion comment="kernel-kdump-devel is earlier than 0:2.6.18-8.1.1.el5" test_ref="oval:org.mitre.oval:tst:33730"/>
            <criterion comment="kernel-xen-devel is earlier than 0:2.6.18-8.1.1.el5" test_ref="oval:org.mitre.oval:tst:33902"/>
            <criterion comment="kernel is earlier than 0:2.6.18-8.1.1.el5" test_ref="oval:org.mitre.oval:tst:33740"/>
            <criterion comment="kernel-PAE-devel is earlier than 0:2.6.18-8.1.1.el5" test_ref="oval:org.mitre.oval:tst:33736"/>
            <criterion comment="kernel-devel is earlier than 0:2.6.18-8.1.1.el5" test_ref="oval:org.mitre.oval:tst:33914"/>
            <criterion comment="kernel-PAE is earlier than 0:2.6.18-8.1.1.el5" test_ref="oval:org.mitre.oval:tst:33489"/>
            <criterion comment="kernel-doc is earlier than 0:2.6.18-8.1.1.el5" test_ref="oval:org.mitre.oval:tst:33621"/>
            <criterion comment="kernel-debuginfo-common is earlier than 0:2.6.18-8.1.1.el5" test_ref="oval:org.mitre.oval:tst:33879"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9827" version="3" class="vulnerability">
      <metadata>
        <title>Format string vulnerability in time.cc in MySQL Server 4.1 before 4.1.21 and 5.0 before 1 April 2006 allows remote authenticated users to cause a denial of service (crash) via a format string instead of a date as the first parameter to the date_format function, which is later used in a formatted print call to display the error message.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-3469" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-3469"/>
        <description>Format string vulnerability in time.cc in MySQL Server 4.1 before 4.1.21 and 5.0 before 1 April 2006 allows remote authenticated users to cause a denial of service (crash) via a format string instead of a date as the first parameter to the date_format function, which is later used in a formatted print call to display the error message.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:21:39.932-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:24.090-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:30.859-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
        <criteria operator="OR">
          <criterion comment="mysql is earlier than 0:4.1.22-2.el4" test_ref="oval:org.mitre.oval:tst:37045"/>
          <criterion comment="mysql-devel is earlier than 0:4.1.22-2.el4" test_ref="oval:org.mitre.oval:tst:37456"/>
          <criterion comment="mysql-bench is earlier than 0:4.1.22-2.el4" test_ref="oval:org.mitre.oval:tst:36967"/>
          <criterion comment="mysql-server is earlier than 0:4.1.22-2.el4" test_ref="oval:org.mitre.oval:tst:37224"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9825" version="3" class="vulnerability">
      <metadata>
        <title>Multiple unknown vulnerabilities in the (1) AIM, (2) LDAP, (3) FibreChannel, (4) GSM_MAP, (5) SRVLOC, and (6) NTLMSSP dissectors in Ethereal before 0.10.11 allow remote attackers to cause a denial of service (crash).</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1457" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1457"/>
        <description>Multiple unknown vulnerabilities in the (1) AIM, (2) LDAP, (3) FibreChannel, (4) GSM_MAP, (5) SRVLOC, and (6) NTLMSSP dissectors in Ethereal before 0.10.11 allow remote attackers to cause a denial of service (crash).</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:15:01.294-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:23.494-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:30.308-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
          <criteria operator="OR">
            <criterion comment="ethereal-gnome is earlier than 0:0.10.11-1.EL3.1" test_ref="oval:org.mitre.oval:tst:31458"/>
            <criterion comment="ethereal is earlier than 0:0.10.11-1.EL3.1" test_ref="oval:org.mitre.oval:tst:31546"/>
          </criteria>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <criteria operator="OR">
            <criterion comment="ethereal-gnome is earlier than 0:0.10.11-1.EL4.1" test_ref="oval:org.mitre.oval:tst:31674"/>
            <criterion comment="ethereal is earlier than 0:0.10.11-1.EL4.1" test_ref="oval:org.mitre.oval:tst:31865"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9824" version="3" class="vulnerability">
      <metadata>
        <title>cache_util.c in the mod_cache module in Apache HTTP Server (httpd), when caching is enabled and a threaded Multi-Processing Module (MPM) is used, allows remote attackers to cause a denial of service (child processing handler crash) via a request with the (1) s-maxage, (2) max-age, (3) min-fresh, or (4) max-stale Cache-Control headers without a value.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-1863" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1863"/>
        <description>cache_util.c in the mod_cache module in Apache HTTP Server (httpd), when caching is enabled and a threaded Multi-Processing Module (MPM) is used, allows remote attackers to cause a denial of service (child processing handler crash) via a request with the (1) s-maxage, (2) max-age, (3) min-fresh, or (4) max-stale Cache-Control headers without a value.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:16:19.575-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:23.126-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:29.870-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
          <criteria operator="OR">
            <criterion comment="httpd-devel is earlier than 0:2.0.46-67.ent" test_ref="oval:org.mitre.oval:tst:34223"/>
            <criterion comment="mod_ssl is earlier than 1:2.0.46-67.ent" test_ref="oval:org.mitre.oval:tst:34500"/>
            <criterion comment="httpd is earlier than 0:2.0.46-67.ent" test_ref="oval:org.mitre.oval:tst:34481"/>
          </criteria>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <criteria operator="OR">
            <criterion comment="httpd-suexec is earlier than 0:2.0.52-32.2.ent" test_ref="oval:org.mitre.oval:tst:34166"/>
            <criterion comment="httpd-manual is earlier than 0:2.0.52-32.2.ent" test_ref="oval:org.mitre.oval:tst:34468"/>
            <criterion comment="httpd-devel is earlier than 0:2.0.52-32.2.ent" test_ref="oval:org.mitre.oval:tst:34603"/>
            <criterion comment="mod_ssl is earlier than 1:2.0.52-32.2.ent" test_ref="oval:org.mitre.oval:tst:34461"/>
            <criterion comment="httpd is earlier than 0:2.0.52-32.2.ent" test_ref="oval:org.mitre.oval:tst:34632"/>
          </criteria>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criteria operator="OR">
            <criterion comment="httpd-manual is earlier than 0:2.2.3-7.el5" test_ref="oval:org.mitre.oval:tst:34730"/>
            <criterion comment="httpd-devel is earlier than 0:2.2.3-7.el5" test_ref="oval:org.mitre.oval:tst:34677"/>
            <criterion comment="mod_ssl is earlier than 1:2.2.3-7.el5" test_ref="oval:org.mitre.oval:tst:34399"/>
            <criterion comment="httpd is earlier than 0:2.2.3-7.el5" test_ref="oval:org.mitre.oval:tst:34605"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9823" version="3" class="vulnerability">
      <metadata>
        <title>Off-by-one error in the OID printing routine in Ethereal 0.10.x up to 0.10.14 has unknown impact and remote attack vectors.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-1932" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1932"/>
        <description>Off-by-one error in the OID printing routine in Ethereal 0.10.x up to 0.10.14 has unknown impact and remote attack vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:20:21.198-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:22.833-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:29.611-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
          <criteria operator="OR">
            <criterion comment="ethereal-gnome is earlier than 0:0.99.0-EL3.2" test_ref="oval:org.mitre.oval:tst:32590"/>
            <criterion comment="ethereal is earlier than 0:0.99.0-EL3.2" test_ref="oval:org.mitre.oval:tst:32631"/>
          </criteria>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <criteria operator="OR">
            <criterion comment="ethereal-gnome is earlier than 0:0.99.0-EL4.2" test_ref="oval:org.mitre.oval:tst:32299"/>
            <criterion comment="ethereal is earlier than 0:0.99.0-EL4.2" test_ref="oval:org.mitre.oval:tst:32238"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9821" version="3" class="vulnerability">
      <metadata>
        <title>The dissect_btacl function in packet-bthci_acl.c in the Bluetooth ACL dissector in Wireshark 0.99.2 through 1.0.3 allows remote attackers to cause a denial of service (application crash or abort) via a packet with an invalid length, related to an erroneous tvb_memcpy call.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-4683" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-4683"/>
        <description>The dissect_btacl function in packet-bthci_acl.c in the Bluetooth ACL dissector in Wireshark 0.99.2 through 1.0.3 allows remote attackers to cause a denial of service (application crash or abort) via a packet with an invalid length, related to an erroneous tvb_memcpy call.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:17:21.139-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:22.218-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:28.933-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
          <criteria operator="OR">
            <criterion comment="wireshark is earlier than 0:1.0.6-EL3.3" test_ref="oval:org.mitre.oval:tst:38023"/>
            <criterion comment="wireshark-gnome is earlier than 0:1.0.6-EL3.3" test_ref="oval:org.mitre.oval:tst:38321"/>
          </criteria>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <criteria operator="OR">
            <criterion comment="wireshark is earlier than 0:1.0.6-2.el4_7" test_ref="oval:org.mitre.oval:tst:38000"/>
            <criterion comment="wireshark-gnome is earlier than 0:1.0.6-2.el4_7" test_ref="oval:org.mitre.oval:tst:38041"/>
          </criteria>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criteria operator="OR">
            <criterion comment="wireshark is earlier than 0:1.0.6-2.el5_3" test_ref="oval:org.mitre.oval:tst:38236"/>
            <criterion comment="wireshark-gnome is earlier than 0:1.0.6-2.el5_3" test_ref="oval:org.mitre.oval:tst:38085"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9820" version="3" class="vulnerability">
      <metadata>
        <title>The JavaScript engine in Mozilla Firefox before 3.0.12 and Thunderbird allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors related to (1) nsDOMClassInfo.cpp, (2) JS_HashTableRawLookup, and (3) MirrorWrappedNativeParent and js_LockGCThingRT.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-2466" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2466"/>
        <description>The JavaScript engine in Mozilla Firefox before 3.0.12 and Thunderbird allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors related to (1) nsDOMClassInfo.cpp, (2) JS_HashTableRawLookup, and (3) MirrorWrappedNativeParent and js_LockGCThingRT.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:25:30.780-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:21.658-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:28.429-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
          <criteria operator="OR">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.9-0.40.el3" test_ref="oval:org.mitre.oval:tst:38881"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-0.40.el3" test_ref="oval:org.mitre.oval:tst:38851"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.9-0.40.el3" test_ref="oval:org.mitre.oval:tst:38690"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-0.40.el3" test_ref="oval:org.mitre.oval:tst:38366"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.9-0.40.el3" test_ref="oval:org.mitre.oval:tst:38475"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-0.40.el3" test_ref="oval:org.mitre.oval:tst:38924"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-0.40.el3" test_ref="oval:org.mitre.oval:tst:38923"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-0.40.el3" test_ref="oval:org.mitre.oval:tst:38918"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-0.40.el3" test_ref="oval:org.mitre.oval:tst:38811"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.9-0.40.el3" test_ref="oval:org.mitre.oval:tst:38644"/>
          </criteria>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <criteria operator="OR">
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-45.el4_8" test_ref="oval:org.mitre.oval:tst:38772"/>
            <criterion comment="thunderbird is earlier than 0:1.5.0.12-25.el4" test_ref="oval:org.mitre.oval:tst:40299"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-45.el4_8" test_ref="oval:org.mitre.oval:tst:37948"/>
            <criterion comment="firefox is earlier than 0:3.0.12-1.el4" test_ref="oval:org.mitre.oval:tst:38809"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-45.el4_8" test_ref="oval:org.mitre.oval:tst:38947"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-45.el4_8" test_ref="oval:org.mitre.oval:tst:38194"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-45.el4_8" test_ref="oval:org.mitre.oval:tst:38876"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-45.el4_8" test_ref="oval:org.mitre.oval:tst:38504"/>
          </criteria>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criteria operator="OR">
            <criterion comment="xulrunner-devel-unstable is earlier than 0:1.9.0.12-1.el5_3" test_ref="oval:org.mitre.oval:tst:38249"/>
            <criterion comment="xulrunner-devel is earlier than 0:1.9.0.12-1.el5_3" test_ref="oval:org.mitre.oval:tst:38575"/>
            <criterion comment="firefox is earlier than 0:3.0.12-1.el5_3" test_ref="oval:org.mitre.oval:tst:38853"/>
            <criterion comment="thunderbird is earlier than 0:2.0.0.24-2.el5_4" test_ref="oval:org.mitre.oval:tst:40249"/>
            <criterion comment="xulrunner is earlier than 0:1.9.0.12-1.el5_3" test_ref="oval:org.mitre.oval:tst:38563"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9819" version="3" class="vulnerability">
      <metadata>
        <title>Double free vulnerability in the krb5_recvauth function in MIT Kerberos 5 (krb5) 1.4.1 and earlier allows remote attackers to execute arbitrary code via certain error conditions.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1689" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1689"/>
        <description>Double free vulnerability in the krb5_recvauth function in MIT Kerberos 5 (krb5) 1.4.1 and earlier allows remote attackers to execute arbitrary code via certain error conditions.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:23:44.542-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:21.337-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:28.103-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
          <criteria operator="OR">
            <criterion comment="krb5-workstation is earlier than 0:1.2.7-47" test_ref="oval:org.mitre.oval:tst:31712"/>
            <criterion comment="krb5 is earlier than 0:1.2.7-47" test_ref="oval:org.mitre.oval:tst:31065"/>
            <criterion comment="krb5-libs is earlier than 0:1.2.7-47" test_ref="oval:org.mitre.oval:tst:31933"/>
            <criterion comment="krb5-server is earlier than 0:1.2.7-47" test_ref="oval:org.mitre.oval:tst:31927"/>
            <criterion comment="krb5-devel is earlier than 0:1.2.7-47" test_ref="oval:org.mitre.oval:tst:31772"/>
          </criteria>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <criteria operator="OR">
            <criterion comment="krb5-workstation is earlier than 0:1.3.4-17" test_ref="oval:org.mitre.oval:tst:31800"/>
            <criterion comment="krb5 is earlier than 0:1.3.4-17" test_ref="oval:org.mitre.oval:tst:31846"/>
            <criterion comment="krb5-libs is earlier than 0:1.3.4-17" test_ref="oval:org.mitre.oval:tst:31172"/>
            <criterion comment="krb5-server is earlier than 0:1.3.4-17" test_ref="oval:org.mitre.oval:tst:31706"/>
            <criterion comment="krb5-devel is earlier than 0:1.3.4-17" test_ref="oval:org.mitre.oval:tst:31781"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9818" version="3" class="vulnerability">
      <metadata>
        <title>Mozilla Firefox before 3.0.9 and SeaMonkey 1.1.17 do not block javascript: URIs in Refresh headers in HTTP responses, which allows remote attackers to conduct cross-site scripting (XSS) attacks via vectors related to (1) injecting a Refresh header or (2) specifying the content of a Refresh header. NOTE: it was later reported that Firefox 3.6 a1 pre and Mozilla 1.7.x and earlier are also affected.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-1312" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1312"/>
        <description>Mozilla Firefox before 3.0.9 and SeaMonkey 1.1.17 do not block javascript: URIs in Refresh headers in HTTP responses, which allows remote attackers to conduct cross-site scripting (XSS) attacks via vectors related to (1) injecting a Refresh header or (2) specifying the content of a Refresh header. NOTE: it was later reported that Firefox 3.6 a1 pre and Mozilla 1.7.x and earlier are also affected.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:19:59.412-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:20.808-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:27.568-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
          <criteria operator="OR">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.9-0.37.el3" test_ref="oval:org.mitre.oval:tst:38597"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-0.37.el3" test_ref="oval:org.mitre.oval:tst:38375"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.9-0.37.el3" test_ref="oval:org.mitre.oval:tst:38403"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-0.37.el3" test_ref="oval:org.mitre.oval:tst:38521"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.9-0.37.el3" test_ref="oval:org.mitre.oval:tst:38542"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-0.37.el3" test_ref="oval:org.mitre.oval:tst:37726"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-0.37.el3" test_ref="oval:org.mitre.oval:tst:38677"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-0.37.el3" test_ref="oval:org.mitre.oval:tst:38096"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-0.37.el3" test_ref="oval:org.mitre.oval:tst:38577"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.9-0.37.el3" test_ref="oval:org.mitre.oval:tst:38540"/>
          </criteria>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <criteria operator="OR">
            <criterion comment="firefox is earlier than 0:3.0.9-1.el4" test_ref="oval:org.mitre.oval:tst:38379"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-41.el4" test_ref="oval:org.mitre.oval:tst:38716"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-41.el4" test_ref="oval:org.mitre.oval:tst:38634"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-41.el4" test_ref="oval:org.mitre.oval:tst:38190"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-41.el4" test_ref="oval:org.mitre.oval:tst:38596"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-41.el4" test_ref="oval:org.mitre.oval:tst:38685"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-41.el4" test_ref="oval:org.mitre.oval:tst:38697"/>
          </criteria>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criteria operator="OR">
            <criterion comment="xulrunner-devel-unstable is earlier than 0:1.9.0.9-1.el5" test_ref="oval:org.mitre.oval:tst:38308"/>
            <criterion comment="xulrunner-devel is earlier than 0:1.9.0.9-1.el5" test_ref="oval:org.mitre.oval:tst:38633"/>
            <criterion comment="firefox is earlier than 0:3.0.9-1.el5" test_ref="oval:org.mitre.oval:tst:38370"/>
            <criterion comment="xulrunner is earlier than 0:1.9.0.9-1.el5" test_ref="oval:org.mitre.oval:tst:38462"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9817" version="3" class="vulnerability">
      <metadata>
        <title>The CSS border-rendering code in Mozilla Firefox and Thunderbird 1.x before 1.5 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via certain Cascading Style Sheets (CSS) that causes an out-of-bounds array write and buffer overflow.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-1739" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1739"/>
        <description>The CSS border-rendering code in Mozilla Firefox and Thunderbird 1.x before 1.5 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via certain Cascading Style Sheets (CSS) that causes an out-of-bounds array write and buffer overflow.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:21:40.844-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:20.317-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:27.070-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
          <criteria operator="OR">
            <criterion comment="mozilla-js-debugger is earlier than 37:1.7.13-1.1.3.1" test_ref="oval:org.mitre.oval:tst:32663"/>
            <criterion comment="mozilla is earlier than 37:1.7.13-1.1.3.1" test_ref="oval:org.mitre.oval:tst:32326"/>
            <criterion comment="mozilla-chat is earlier than 37:1.7.13-1.1.3.1" test_ref="oval:org.mitre.oval:tst:31987"/>
            <criterion comment="mozilla-mail is earlier than 37:1.7.13-1.1.3.1" test_ref="oval:org.mitre.oval:tst:32451"/>
            <criterion comment="mozilla-dom-inspector is earlier than 37:1.7.13-1.1.3.1" test_ref="oval:org.mitre.oval:tst:32697"/>
            <criterion comment="mozilla-devel is earlier than 37:1.7.13-1.1.3.1" test_ref="oval:org.mitre.oval:tst:32558"/>
            <criterion comment="mozilla-nss is earlier than 37:1.7.13-1.1.3.1" test_ref="oval:org.mitre.oval:tst:32427"/>
            <criterion comment="mozilla-nss-devel is earlier than 37:1.7.13-1.1.3.1" test_ref="oval:org.mitre.oval:tst:32671"/>
            <criterion comment="mozilla-nspr is earlier than 37:1.7.13-1.1.3.1" test_ref="oval:org.mitre.oval:tst:32666"/>
            <criterion comment="mozilla-nspr-devel is earlier than 37:1.7.13-1.1.3.1" test_ref="oval:org.mitre.oval:tst:32561"/>
          </criteria>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <criteria operator="OR">
            <criterion comment="mozilla-js-debugger is earlier than 37:1.7.13-1.4.1" test_ref="oval:org.mitre.oval:tst:32593"/>
            <criterion comment="devhelp-devel is earlier than 0:0.9.2-2.4.8" test_ref="oval:org.mitre.oval:tst:32679"/>
            <criterion comment="mozilla is earlier than 37:1.7.13-1.4.1" test_ref="oval:org.mitre.oval:tst:32133"/>
            <criterion comment="thunderbird is earlier than 0:1.0.8-1.4.1" test_ref="oval:org.mitre.oval:tst:32204"/>
            <criterion comment="mozilla-chat is earlier than 37:1.7.13-1.4.1" test_ref="oval:org.mitre.oval:tst:32701"/>
            <criterion comment="mozilla-mail is earlier than 37:1.7.13-1.4.1" test_ref="oval:org.mitre.oval:tst:32428"/>
            <criterion comment="mozilla-dom-inspector is earlier than 37:1.7.13-1.4.1" test_ref="oval:org.mitre.oval:tst:32557"/>
            <criterion comment="devhelp is earlier than 0:0.9.2-2.4.8" test_ref="oval:org.mitre.oval:tst:32229"/>
            <criterion comment="mozilla-nss is earlier than 37:1.7.13-1.4.1" test_ref="oval:org.mitre.oval:tst:32349"/>
            <criterion comment="mozilla-devel is earlier than 37:1.7.13-1.4.1" test_ref="oval:org.mitre.oval:tst:32644"/>
            <criterion comment="mozilla-nss-devel is earlier than 37:1.7.13-1.4.1" test_ref="oval:org.mitre.oval:tst:32440"/>
            <criterion comment="firefox is earlier than 0:1.0.8-1.4.1" test_ref="oval:org.mitre.oval:tst:32219"/>
            <criterion comment="mozilla-nspr is earlier than 37:1.7.13-1.4.1" test_ref="oval:org.mitre.oval:tst:32598"/>
            <criterion comment="mozilla-nspr-devel is earlier than 37:1.7.13-1.4.1" test_ref="oval:org.mitre.oval:tst:32717"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9815" version="3" class="vulnerability">
      <metadata>
        <title>js/src/xpconnect/src/xpcwrappedjsclass.cpp in Mozilla Firefox before 3.0.11, Thunderbird before 2.0.0.22, and SeaMonkey before 1.1.17 allows remote attackers to execute arbitrary web script with the privileges of a chrome object, as demonstrated by the browser sidebar and the FeedWriter.</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-1841" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1841"/>
        <description>js/src/xpconnect/src/xpcwrappedjsclass.cpp in Mozilla Firefox before 3.0.11, Thunderbird before 2.0.0.22, and SeaMonkey before 1.1.17 allows remote attackers to execute arbitrary web script with the privileges of a chrome object, as demonstrated by the browser sidebar and the FeedWriter.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:20:17.588-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:19.589-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:26.339-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
          <criteria operator="OR">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.9-0.38.el3" test_ref="oval:org.mitre.oval:tst:38336"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-0.38.el3" test_ref="oval:org.mitre.oval:tst:38452"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.9-0.38.el3" test_ref="oval:org.mitre.oval:tst:38736"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-0.38.el3" test_ref="oval:org.mitre.oval:tst:38742"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.9-0.38.el3" test_ref="oval:org.mitre.oval:tst:38069"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-0.38.el3" test_ref="oval:org.mitre.oval:tst:38264"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-0.38.el3" test_ref="oval:org.mitre.oval:tst:38724"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-0.38.el3" test_ref="oval:org.mitre.oval:tst:38791"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-0.38.el3" test_ref="oval:org.mitre.oval:tst:38432"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.9-0.38.el3" test_ref="oval:org.mitre.oval:tst:37902"/>
          </criteria>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <criteria operator="OR">
            <criterion comment="firefox is earlier than 0:3.0.11-4.el4" test_ref="oval:org.mitre.oval:tst:38689"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-43.el4_8" test_ref="oval:org.mitre.oval:tst:38280"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-43.el4_8" test_ref="oval:org.mitre.oval:tst:38793"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-43.el4_8" test_ref="oval:org.mitre.oval:tst:38531"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-43.el4_8" test_ref="oval:org.mitre.oval:tst:38655"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-43.el4_8" test_ref="oval:org.mitre.oval:tst:38828"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-43.el4_8" test_ref="oval:org.mitre.oval:tst:38213"/>
          </criteria>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criteria operator="OR">
            <criterion comment="xulrunner-devel-unstable is earlier than 0:1.9.0.11-3.el5_3" test_ref="oval:org.mitre.oval:tst:38771"/>
            <criterion comment="xulrunner-devel is earlier than 0:1.9.0.11-3.el5_3" test_ref="oval:org.mitre.oval:tst:38371"/>
            <criterion comment="firefox is earlier than 0:3.0.11-2.el5_3" test_ref="oval:org.mitre.oval:tst:38682"/>
            <criterion comment="xulrunner is earlier than 0:1.9.0.11-3.el5_3" test_ref="oval:org.mitre.oval:tst:38718"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9814" version="3" class="vulnerability">
      <metadata>
        <title>Multiple unspecified vulnerabilities in Mozilla Firefox 3.x before 3.0.5 and 2.x before 2.0.0.19, Thunderbird 2.x before 2.0.0.19, and SeaMonkey 1.x before 1.1.14 allow remote attackers to run arbitrary JavaScript with chrome privileges via unknown vectors in which "page content can pollute XPCNativeWrappers."</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <platform>Red Hat Enterprise Linux 5</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-5512" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-5512"/>
        <description>Multiple unspecified vulnerabilities in Mozilla Firefox 3.x before 3.0.5 and 2.x before 2.0.0.19, Thunderbird 2.x before 2.0.0.19, and SeaMonkey 1.x before 1.1.14 allow remote attackers to run arbitrary JavaScript with chrome privileges via unknown vectors in which "page content can pollute XPCNativeWrappers."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-07-09T03:56:16-04:00">
              <contributor organization="SCAP.com, LLC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2010-07-28T14:15:59.318-04:00">DRAFT</status_change>
            <status_change date="2010-08-16T04:14:18.500-04:00">INTERIM</status_change>
            <status_change date="2010-09-06T04:15:25.657-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3" definition_ref="oval:org.mitre.oval:def:11782"/>
          <criteria operator="OR">
            <criterion comment="seamonkey-nspr is earlier than 0:1.0.9-0.29.el3" test_ref="oval:org.mitre.oval:tst:38137"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-0.29.el3" test_ref="oval:org.mitre.oval:tst:37886"/>
            <criterion comment="seamonkey-nss-devel is earlier than 0:1.0.9-0.29.el3" test_ref="oval:org.mitre.oval:tst:37999"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-0.29.el3" test_ref="oval:org.mitre.oval:tst:37907"/>
            <criterion comment="seamonkey-nspr-devel is earlier than 0:1.0.9-0.29.el3" test_ref="oval:org.mitre.oval:tst:37709"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-0.29.el3" test_ref="oval:org.mitre.oval:tst:38092"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-0.29.el3" test_ref="oval:org.mitre.oval:tst:37745"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-0.29.el3" test_ref="oval:org.mitre.oval:tst:38039"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-0.29.el3" test_ref="oval:org.mitre.oval:tst:38062"/>
            <criterion comment="seamonkey-nss is earlier than 0:1.0.9-0.29.el3" test_ref="oval:org.mitre.oval:tst:38073"/>
          </criteria>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4" definition_ref="oval:org.mitre.oval:def:11831"/>
          <criteria operator="OR">
            <criterion comment="nspr is earlier than 0:4.7.3-1.el4" test_ref="oval:org.mitre.oval:tst:37574"/>
            <criterion comment="seamonkey-js-debugger is earlier than 0:1.0.9-32.el4" test_ref="oval:org.mitre.oval:tst:38071"/>
            <criterion comment="nss is earlier than 0:3.12.2.0-1.el4" test_ref="oval:org.mitre.oval:tst:37857"/>
            <criterion comment="thunderbird is earlier than 0:1.5.0.12-18.el4" test_ref="oval:org.mitre.oval:tst:37200"/>
            <criterion comment="nspr-devel is earlier than 0:4.7.3-1.el4" test_ref="oval:org.mitre.oval:tst:37918"/>
            <criterion comment="seamonkey is earlier than 0:1.0.9-32.el4" test_ref="oval:org.mitre.oval:tst:37812"/>
            <criterion comment="firefox is earlier than 0:3.0.5-1.el4" test_ref="oval:org.mitre.oval:tst:38080"/>
            <criterion comment="nss-devel is earlier than 0:3.12.2.0-1.el4" test_ref="oval:org.mitre.oval:tst:37139"/>
            <criterion comment="seamonkey-mail is earlier than 0:1.0.9-32.el4" test_ref="oval:org.mitre.oval:tst:37869"/>
            <criterion comment="seamonkey-chat is earlier than 0:1.0.9-32.el4" test_ref="oval:org.mitre.oval:tst:37789"/>
            <criterion comment="seamonkey-dom-inspector is earlier than 0:1.0.9-32.el4" test_ref="oval:org.mitre.oval:tst:37395"/>
            <criterion comment="seamonkey-devel is earlier than 0:1.0.9-32.el4" test_ref="oval:org.mitre.oval:tst:38118"/>
          </criteria>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 5" definition_ref="oval:org.mitre.oval:def:11414"/>
          <criteria operator="OR">
            <criterion comment="nss-pkcs11-devel is earlier than 0:3.12.2.0-2.el5" test_ref="oval:org.mitre.oval:tst:38072"/>
            <criterion comment="xulrunner-devel is earlier than 0:1.9.0.5-1.el5_2" test_ref="oval:org.mitre.oval:tst:38037"/>
            <criterion comment="nspr is earlier than 0:4.7.3-2.el5" test_ref="oval:org.mitre.oval:tst:37420"/>
            <criterion comment="nss is earlier than 0:3.12.2.0-2.el5" test_ref="oval:org.mitre.oval:tst:37854"/>
            <criterion comment="thunderbird is earlier than 0:2.0.0.19-1.el5_2" test_ref="oval:org.mitre.oval:tst:38053"/>
            <criterion comment="nspr-devel is earlier than 0:4.7.3-2.el5" test_ref="oval:org.mitre.oval:tst:37419"/>
            <criterion comment="xulrunner is earlier than 0:1.9.0.5-1.el5_2" test_ref="oval:org.mitre.oval:tst:38083"/>
            <criterion comment="xulrunner-devel-unstable is earlier than 0:1.9.0.5-1.el5_2" test_ref="oval:org.mitre.o
