<?xml version="1.0" encoding="UTF-8"?>
<oval_definitions xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-definitions-5 oval-definitions-schema.xsd http://oval.mitre.org/XMLSchema/oval-definitions-5#linux linux-definitions-schema.xsd http://oval.mitre.org/XMLSchema/oval-common-5 oval-common-schema.xsd http://oval.mitre.org/XMLSchema/oval-definitions-5#unix unix-definitions-schema.xsd" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:oval="http://oval.mitre.org/XMLSchema/oval-common-5" xmlns:oval-def="http://oval.mitre.org/XMLSchema/oval-definitions-5">
  <generator>
    <oval:product_name>The OVAL Repository</oval:product_name>
    <oval:schema_version>5.6</oval:schema_version>
    <oval:timestamp>2009-11-20T04:32:17.703-05:00</oval:timestamp>
  </generator>
  <definitions>
    <definition id="oval:org.mitre.oval:def:1415" version="1" class="vulnerability">
      <metadata>
        <title>RHE4 Mozilla top.focus() Cross-Site Scripting Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <product>mozilla</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2266" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2266"/>
        <description>Firefox before 1.0.5 and Mozilla before 1.7.9 allows a child frame to call top.focus and other methods in a parent frame, even when the parent is in a different domain, which violates the same origin policy and allows remote attackers to steal sensitive information such as cookies and passwords from web sites whose child frames do not verify that they are in the same domain as their parents.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-08-15T04:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2005-08-19T10:05:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-09-21T01:33:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat Enterprise 4 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2652"/>
          <criterion comment="mozilla RPM is earlier than 37:1.7.10-1.4.1" negate="false" test_ref="oval:org.mitre.oval:tst:2651"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="/usr/bin/mozilla is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2650"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1313" version="1" class="vulnerability">
      <metadata>
        <title>RHE4 Firefox and Mozilla Javascript Dialog Box Spoofing</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <product>mozilla</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2268" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2268"/>
        <description>Firefox before 1.0.5 and Mozilla before 1.7.9 does not clearly associate a Javascript dialog box with the web page that generated it, which allows remote attackers to spoof a dialog box from a trusted site and facilitates phishing attacks, aka the "Dialog Origin Spoofing Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2005-08-15T04:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2005-08-19T10:05:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-09-21T01:33:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat Enterprise 4 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2652"/>
          <criterion comment="mozilla RPM is earlier than 37:1.7.10-1.4.1" negate="false" test_ref="oval:org.mitre.oval:tst:2651"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="/usr/bin/mozilla is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2650"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1311" version="1" class="vulnerability">
      <metadata>
        <title>RHE4 Firefox InstallTrigger Callback Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2263" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2263"/>
        <description>The InstallTrigger.install method in Firefox before 1.0.5 and Mozilla before 1.7.9 allows remote attackers to execute a callback function in the context of another domain by forcing a page navigation after the install method has been called, which causes the callback to be run in the context of the new page and results in a same origin violation.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-08-15T04:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2005-08-19T10:05:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-09-21T01:33:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat Enterprise 4 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2652"/>
          <criterion comment="mozilla RPM is earlier than 37:1.7.10-1.4.1" negate="false" test_ref="oval:org.mitre.oval:tst:2651"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="/usr/bin/mozilla is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2650"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1226" version="1" class="vulnerability">
      <metadata>
        <title>RHE4 Improper Handling of Synthetic Events in Mozilla</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <product>mozilla</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2260" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2260"/>
        <description>The browser user interface in Firefox before 1.0.5, Mozilla before 1.7.9, and Netscape 8.0.2 and 7.2 does not properly distinguish between user-generated events and untrusted synthetic events, which makes it easier for remote attackers to perform dangerous actions that normally could only be performed manually by the user.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-08-15T04:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2005-08-19T10:05:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-09-21T01:33:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat Enterprise 4 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2652"/>
          <criterion comment="mozilla RPM is earlier than 37:1.7.10-1.4.1" negate="false" test_ref="oval:org.mitre.oval:tst:2651"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="/usr/bin/mozilla is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2650"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1124" version="1" class="vulnerability">
      <metadata>
        <title>RHE4 Fetchmail Buffer Overflow via Long UIDL Responses</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <product>fetchmail</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2335" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2335"/>
        <description>Buffer overflow in the POP3 client in Fetchmail before 6.2.5.2 allows remote POP3 servers to cause a denial of service and possibly execute arbitrary code via long UIDL responses.  NOTE: a typo in an advisory accidentally used the wrong CVE identifier for the Fetchmail issue. This is the correct identifier.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-08-15T04:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2005-08-19T10:05:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-09-21T01:33:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat Enterprise 4 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2652"/>
          <criterion comment="fetchmail RPM earlier than 0:6.2.5-6.el4.2" negate="false" test_ref="oval:org.mitre.oval:tst:1144"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="/usr/bin/fetchmail is executable by any user" negate="false" test_ref="oval:org.mitre.oval:tst:1261"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1073" version="1" class="vulnerability">
      <metadata>
        <title>RHE4 Firefox External App Code Acceptance Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <product>mozilla</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2267" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2267"/>
        <description>Firefox before 1.0.5 allows remote attackers to steal information and possibly execute arbitrary code by using standalone applications such as Flash and QuickTime to open a javascript: URL, which is run in the context of the previous page, and may lead to code execution if the standalone application loads a privileged chrome: URL.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-08-15T04:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2005-08-19T10:05:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-09-21T01:33:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="mozilla RPM is earlier than 37:1.7.10-1.4.1" negate="false" test_ref="oval:org.mitre.oval:tst:2651"/>
          <criterion comment="Red Hat Enterprise 4 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2652"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="/usr/bin/mozilla is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2650"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:808" version="1" class="vulnerability">
      <metadata>
        <title>RHE4 XBL Script Security Bypass Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <product>mozilla</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2261" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2261"/>
        <description>Firefox before 1.0.5, Thunderbird before 1.0.5, Mozilla before 1.7.9, Netscape 8.0.2, and K-Meleon 0.9 runs XBL scripts even when Javascript has been disabled, which makes it easier for remote attackers to bypass such protection.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-08-15T04:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2005-08-19T10:05:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-09-21T01:33:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat Enterprise 4 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2652"/>
          <criterion comment="mozilla RPM is earlier than 37:1.7.10-1.4.1" negate="false" test_ref="oval:org.mitre.oval:tst:2651"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="/usr/bin/mozilla is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2650"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:759" version="1" class="vulnerability">
      <metadata>
        <title>RHE4 Firefox and Mozilla Framed Site Spoofing Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <product>mozilla</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1937" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1937"/>
        <description>A regression error in Firefox 1.0.3 and Mozilla 1.7.7 allows remote attackers to inject arbitrary Javascript from one page into the frameset of another site, aka the frame injection spoofing vulnerability, a re-introduction of a vulnerability that was originally identified and addressed by CVE-2004-0718.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-08-15T04:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2005-08-19T10:05:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-09-21T01:33:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat Enterprise 4 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2652"/>
          <criterion comment="mozilla RPM is earlier than 37:1.7.10-1.4.1" negate="false" test_ref="oval:org.mitre.oval:tst:2651"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="/usr/bin/mozilla is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2650"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:729" version="1" class="vulnerability">
      <metadata>
        <title>RHE4 Firefox and Mozilla DOM Node Spoofing</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <product>mozilla</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2269" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2269"/>
        <description>Firefox before 1.0.5, Mozilla before 1.7.9, and Netscape 8.0.2 does not properly verify the associated types of DOM node names within the context of their namespaces, which allows remote attackers to modify certain tag properties, possibly leading to execution of arbitrary script or code, as demonstrated using an XHTML document with IMG tags with custom properties ("XHTML node spoofing").</description>
        <oval_repository>
          <dates>
            <submitted date="2005-08-15T04:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2005-08-19T10:05:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-09-21T01:33:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat Enterprise 4 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2652"/>
          <criterion comment="mozilla RPM is earlier than 37:1.7.10-1.4.1" negate="false" test_ref="oval:org.mitre.oval:tst:2651"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="/usr/bin/mozilla is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2650"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:550" version="1" class="vulnerability">
      <metadata>
        <title>RHE4 Firefox and Mozilla Shared Object Code Execution</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <product>mozilla</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2270" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2270"/>
        <description>Firefox before 1.0.5 and Mozilla before 1.7.9 does not properly clone base objects, which allows remote attackers to execute arbitrary code by navigating the prototype chain to reach a privileged object.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-08-15T04:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2005-08-19T10:05:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-09-21T01:33:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat Enterprise 4 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2652"/>
          <criterion comment="mozilla RPM is earlier than 37:1.7.10-1.4.1" negate="false" test_ref="oval:org.mitre.oval:tst:2651"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="/usr/bin/mozilla is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2650"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:417" version="1" class="vulnerability">
      <metadata>
        <title>RHE4 InstallVersion.compareTo() DoS and Code Execution Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <product>mozilla</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2265" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2265"/>
        <description>Firefox before 1.0.5, Mozilla before 1.7.9, and Netscape 8.0.2 and 7.2 allows remote attackers to cause a denial of service (access violation and crash), and possibly execute arbitrary code, by calling InstallVersion.compareTo with an object instead of a string.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-08-15T04:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2005-08-19T10:05:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-09-21T01:33:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat Enterprise 4 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2652"/>
          <criterion comment="mozilla RPM is earlier than 37:1.7.10-1.4.1" negate="false" test_ref="oval:org.mitre.oval:tst:2651"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="/usr/bin/mozilla is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2650"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1689" version="3" class="vulnerability">
      <metadata>
        <title>Sendmail setjmp longjmp bo (Red Hat Internal)</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <product>Sendmail</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-0058" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0058"/>
        <description>Signal handler race condition in Sendmail 8.13.x before 8.13.6 allows remote attackers to execute arbitrary code by triggering timeouts in a way that causes the setjmp and longjmp function calls to be interrupted and modify unexpected memory locations.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-03-27T09:51:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-04-06T06:30:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-05-03T10:06:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-05-31T09:45:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex in ste:694. Implemented by Jon Baker of The MITRE Corporation." date="2007-05-01T15:07:00.947-04:00">
              <contributor organization="DSCI Contractor">Vladimir Giszpenc</contributor>
            </modified>
            <status_change date="2007-05-01T15:08:55.075-04:00">INTERIM</status_change>
            <status_change date="2007-05-23T15:05:31.387-04:00">ACCEPTED</status_change>
            <modified comment="Corrected vulnerability information for Redhat 3 and Redhat 4" date="2008-01-15T11:57:00-04:00">
              <contributor organization="Secure Elements, Inc.">Sudhir Gandhe</contributor>
            </modified>
            <status_change date="2008-01-17T12:05:31.387-04:00">INTERIM</status_change>
            <status_change date="2008-02-04T04:00:06.233-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software section">
        <criteria operator="AND" comment="Sendmail on Redhat 4">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4 for x86" definition_ref="oval:org.mitre.oval:def:1734"/>
          <criterion comment="sendmail version is less than 8.13.1-3" test_ref="oval:org.mitre.oval:tst:7716"/>
        </criteria>
        <criteria operator="AND" comment="Sendmail on Redhat 3">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3 for x86" definition_ref="oval:org.mitre.oval:def:5537"/>
          <criterion comment="sendmail version is less than 8.12.11-4" test_ref="oval:org.mitre.oval:tst:7751"/>
        </criteria>
        <criteria operator="AND" comment="Sendmail on other flavors of redhat">
          <extend_definition negate="true" comment="The operating system installed on the system is Red Hat Enterprise Linux 3 for x86" definition_ref="oval:org.mitre.oval:def:5537"/>
          <extend_definition negate="true" comment="The operating system installed on the system is Red Hat Enterprise Linux 4 for x86" definition_ref="oval:org.mitre.oval:def:1734"/>
          <criteria operator="OR" comment="vulnerable version of sendmail">
            <criterion comment="sendmail before 8.12.x is installed" test_ref="oval:org.mitre.oval:tst:774"/>
            <criterion comment="sendmail 8.12.x before 8.12.11 is installed" test_ref="oval:org.mitre.oval:tst:773"/>
            <criterion comment="sendmail 8.13.x before 8.13.6 is installed" test_ref="oval:org.mitre.oval:tst:772"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5537" version="1" class="inventory">
      <metadata>
        <title>The operating system installed on the system is Red Hat Enterprise Linux 3 for x86</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/o:redhat:enterprise_linux:3::ix86"/>
        <description>The operating system installed on the system is Red Hat Enterprise Linux 4 for x86.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-01-12T14:07:00">
              <contributor organization="Secure Elements, Inc.">Sudhir Gandhe</contributor>
            </submitted>
            <status_change date="2008-01-17T13:56:57.725-05:00">DRAFT</status_change>
            <status_change date="2008-02-04T04:00:08.231-05:00">INTERIM</status_change>
            <status_change date="2008-02-25T04:00:11.758-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="Red Hat Enterprise 3 is installed" test_ref="oval:org.mitre.oval:tst:7836"/>
        <criterion comment="ix86 architecture" test_ref="oval:org.mitre.oval:tst:3912"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1734" version="1" class="inventory">
      <metadata>
        <title>The operating system installed on the system is Red Hat Enterprise Linux 4 for x86</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/o:redhat:enterprise_linux:4::ix86"/>
        <description>The operating system installed on the system is Red Hat Enterprise Linux 4 for x86.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-07-27T12:00:00.000-06:00">
              <contributor organization="McAfee, Inc.">Mark Villanova</contributor>
            </submitted>
            <status_change date="2007-08-14T21:26:14.122-04:00">DRAFT</status_change>
            <status_change date="2007-09-06T09:13:28.105-04:00">INTERIM</status_change>
            <status_change date="2007-09-27T08:57:41.206-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="Red Hat Enterprise 4 is installed" test_ref="oval:org.mitre.oval:tst:2652"/>
        <criterion comment="ix86 architecture" test_ref="oval:org.mitre.oval:tst:3912"/>
      </criteria>
    </definition>
  </definitions>
  <tests>
    <file_test id="oval:org.mitre.oval:tst:1261" version="1" check="all" comment="/usr/bin/fetchmail is executable by any user" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:879"/>
      <state state_ref="oval:org.mitre.oval:ste:1131"/>
    </file_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:1144" version="1" check="all" comment="fetchmail RPM earlier than 0:6.2.5-6.el4.2" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:819"/>
      <state state_ref="oval:org.mitre.oval:ste:1024"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:2651" version="1" check="all" comment="mozilla RPM is earlier than 37:1.7.10-1.4.1" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <oval-def:notes xmlns:oval1="http://oval.mitre.org/XMLSchema/oval-definitions-5">
        <oval-def:note>Multiple RPMs were updated in this release, but all but mozilla-nspr have mozilla-with-their-same-version as an installation dependency.  So, if mozilla is up to date, mozilla-chat, mozilla-devel, ... , mozilla-js-debugger are all up to date.  Mozilla itself requires that mozilla-nspr and mozilla-nss be installed with the same version as itself.  This closes the loop -- if mozilla is up to date, so are the other mozilla-FOO RPMs.</oval-def:note>
      </oval-def:notes>
      <object object_ref="oval:org.mitre.oval:obj:1519"/>
      <state state_ref="oval:org.mitre.oval:ste:2476"/>
    </rpminfo_test>
    <file_test id="oval:org.mitre.oval:tst:2650" version="1" check="all" comment="/usr/bin/mozilla is executable" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1030"/>
      <state state_ref="oval:org.mitre.oval:ste:2475"/>
    </file_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:7836" version="1" comment="Red Hat Enterprise 3 is installed" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:1414"/>
      <state state_ref="oval:org.mitre.oval:ste:3446"/>
    </rpminfo_test>
    <uname_test id="oval:org.mitre.oval:tst:3912" version="1" comment="ix86 architecture" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:2759"/>
      <state state_ref="oval:org.mitre.oval:ste:3443"/>
    </uname_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:2652" version="1" comment="Red Hat Enterprise 4 is installed" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:1414"/>
      <state state_ref="oval:org.mitre.oval:ste:2477"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:7751" version="1" comment="sendmail version is less than 8.12.11-4" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:587"/>
      <state state_ref="oval:org.mitre.oval:ste:3042"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:774" version="2" comment="sendmail before 8.12.x is installed" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:587"/>
      <state state_ref="oval:org.mitre.oval:ste:694"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:773" version="1" comment="sendmail 8.12.x before 8.12.11 is installed" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:587"/>
      <state state_ref="oval:org.mitre.oval:ste:693"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:772" version="1" comment="sendmail 8.13.x before 8.13.6 is installed" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:587"/>
      <state state_ref="oval:org.mitre.oval:ste:692"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:7716" version="1" comment="sendmail version is less than 8.13.1-3" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:587"/>
      <state state_ref="oval:org.mitre.oval:ste:3851"/>
    </rpminfo_test>
  </tests>
  <objects>
    <file_object id="oval:org.mitre.oval:obj:879" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/bin</path>
      <filename>fetchmail</filename>
    </file_object>
    <rpminfo_object id="oval:org.mitre.oval:obj:819" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>fetchmail</name>
    </rpminfo_object>
    <rpminfo_object id="oval:org.mitre.oval:obj:1519" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>mozilla</name>
    </rpminfo_object>
    <file_object id="oval:org.mitre.oval:obj:1030" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/bin</path>
      <filename>mozilla</filename>
    </file_object>
    <uname_object id="oval:org.mitre.oval:obj:2759" version="1" comment="The single uname object." xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix"/>
    <rpminfo_object id="oval:org.mitre.oval:obj:1414" version="1" comment="the redhat-release rpm" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>redhat-release</name>
    </rpminfo_object>
    <rpminfo_object id="oval:org.mitre.oval:obj:587" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>sendmail</name>
    </rpminfo_object>
  </objects>
  <states>
    <file_state id="oval:org.mitre.oval:ste:1131" version="1" operator="OR" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
      <gexec operation="equals" datatype="boolean">true</gexec>
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <rpminfo_state id="oval:org.mitre.oval:ste:1024" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:6.2.5-6.el4.2</evr>
    </rpminfo_state>
    <rpminfo_state id="oval:org.mitre.oval:ste:2476" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">37:1.7.10-1.4.1</evr>
    </rpminfo_state>
    <file_state id="oval:org.mitre.oval:ste:2475" version="1" operator="OR" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
      <gexec operation="equals" datatype="boolean">true</gexec>
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <rpminfo_state id="oval:org.mitre.oval:ste:3446" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <version operation="pattern match">^.*3.S</version>
    </rpminfo_state>
    <uname_state id="oval:org.mitre.oval:ste:3443" version="1" comment="processor type is ix86" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <processor_type operation="pattern match">^i.*86</processor_type>
    </uname_state>
    <rpminfo_state id="oval:org.mitre.oval:ste:2477" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <version operation="pattern match">^.*4.S</version>
    </rpminfo_state>
    <rpminfo_state id="oval:org.mitre.oval:ste:3042" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:8.12.11-4.RHEL3.4</evr>
    </rpminfo_state>
    <rpminfo_state id="oval:org.mitre.oval:ste:694" version="2" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <version operation="pattern match">^([0-7].*)|(8\.([0-9]|1[01]))$</version>
    </rpminfo_state>
    <rpminfo_state id="oval:org.mitre.oval:ste:693" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <version operation="pattern match">8\.12\.([0-9]|10)</version>
    </rpminfo_state>
    <rpminfo_state id="oval:org.mitre.oval:ste:692" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <version operation="pattern match">8\.13\.[0-5]</version>
    </rpminfo_state>
    <rpminfo_state id="oval:org.mitre.oval:ste:3851" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:8.13.1-3.RHEL4.3</evr>
    </rpminfo_state>
  </states>
</oval_definitions>