<?xml version="1.0" encoding="UTF-8"?>
<oval_definitions xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-definitions-5 oval-definitions-schema.xsd http://oval.mitre.org/XMLSchema/oval-definitions-5#linux linux-definitions-schema.xsd http://oval.mitre.org/XMLSchema/oval-common-5 oval-common-schema.xsd http://oval.mitre.org/XMLSchema/oval-definitions-5#unix unix-definitions-schema.xsd" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:oval="http://oval.mitre.org/XMLSchema/oval-common-5" xmlns:oval-def="http://oval.mitre.org/XMLSchema/oval-definitions-5">
  <generator>
    <oval:product_name>The OVAL Repository</oval:product_name>
    <oval:schema_version>5.6</oval:schema_version>
    <oval:timestamp>2009-11-20T04:32:17.778-05:00</oval:timestamp>
  </generator>
  <definitions>
    <definition id="oval:org.mitre.oval:def:101" version="2" class="vulnerability">
      <metadata>
        <title>Ethereal 0-Length Buffer Size Vulnerability in tvb_get_nstring0()</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>Ethereal</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0431" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0431"/>
        <description>The tvb_get_nstringz0 function in Ethereal 0.9.12 and earlier does not properly handle a zero-length buffer size, with unknown consequences.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-08-29T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-03-25T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:32.254-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:52:11.910-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
        <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
        <criteria operator="OR" comment="Vulnerable Config">
          <criterion comment="ethereal version is less than 0.9.13-1.90.1" negate="false" test_ref="oval:org.mitre.oval:tst:2985"/>
          <criterion comment="ethereal-gnome version is less than 0.9.13-1.90.1" negate="false" test_ref="oval:org.mitre.oval:tst:2984"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1049" version="2" class="vulnerability">
      <metadata>
        <title>Red Hat OpenSSL Kerberos Handshake Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>OpenSSL</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0112" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0112"/>
        <description>The SSL/TLS handshaking code in OpenSSL 0.9.7a, 0.9.7b, and 0.9.7c, when using Kerberos ciphersuites, does not properly check the length of Kerberos tickets during a handshake, which allows remote attackers to cause a denial of service (crash) via a crafted SSL/TLS handshake that causes an out-of-bounds read.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-03-20T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Matt Busby</contributor>
            </submitted>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="The MITRE Corporation">Matt Busby</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-06-16T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:58.457-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:52:12.895-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
        <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
        <criterion comment="openssl version is less than 0.9.7a-20" negate="false" test_ref="oval:org.mitre.oval:tst:1484"/>
        <criterion comment="openssl-devel version is less than 0.9.7a-20" negate="false" test_ref="oval:org.mitre.oval:tst:1483"/>
        <criterion comment="openssl-perl version is less than 0.9.7a-20" negate="false" test_ref="oval:org.mitre.oval:tst:1482"/>
        <criterion comment="openssl096 version is less than 0.9.6-25.9" negate="false" test_ref="oval:org.mitre.oval:tst:1481"/>
        <criterion comment="openssl096b version is less than 0.9.6b-15" negate="false" test_ref="oval:org.mitre.oval:tst:1480"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:106" version="2" class="vulnerability">
      <metadata>
        <title>Various Ethereal Dissector Vulnerabilities</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>Ethereal</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0432" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0432"/>
        <description>Ethereal 0.9.12 and earlier does not handle certain strings properly, with unknown consequences, in the (1) BGP, (2) WTP, (3) DNS, (4) 802.11, (5) ISAKMP, (6) WSP, (7) CLNP, (8) ISIS, and (9) RMI dissectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-08-29T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-03-25T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:23.407-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:52:13.077-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
        <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
        <criteria operator="OR" comment="Vulnerable Config">
          <criterion comment="ethereal version is less than 0.9.13-1.90.1" negate="false" test_ref="oval:org.mitre.oval:tst:2985"/>
          <criterion comment="ethereal-gnome version is less than 0.9.13-1.90.1" negate="false" test_ref="oval:org.mitre.oval:tst:2984"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:107" version="2" class="vulnerability">
      <metadata>
        <title>Ximian Evolution Mail User Agent uuencoded header Denial of Service</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>Ximian Evolution</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0128" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0128"/>
        <description>The try_uudecoding function in mail-format.c for Ximian Evolution Mail User Agent 1.2.2 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a malicious uuencoded (UUE) header, possibly triggering a heap-based buffer overflow.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-08-11T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-03-25T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:31.903-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:52:13.800-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
        <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
        <criterion comment="evolution version is less than 1.2.2-5" negate="false" test_ref="oval:org.mitre.oval:tst:2939"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:108" version="2" class="vulnerability">
      <metadata>
        <title>Ximian Evolution User Agent Multiple uuencoding Denial of Service</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>Ximian Evolution</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0129" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0129"/>
        <description>Ximian Evolution Mail User Agent 1.2.2 and earlier allows remote attackers to cause a denial of service (memory consumption) via a mail message that is uuencoded multiple times.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-08-11T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-03-25T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:53.657-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:52:13.970-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
        <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
        <criterion comment="evolution version is less than 1.2.2-5" negate="false" test_ref="oval:org.mitre.oval:tst:2939"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:111" version="2" class="vulnerability">
      <metadata>
        <title>Ximian Evolution MIME-encoded Image Buffer Overflow</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>Ximian Evolution</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0130" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0130"/>
        <description>The handle_image function in mail-format.c for Ximian Evolution Mail User Agent 1.2.2 and earlier does not properly escape HTML characters, which allows remote attackers inject arbitrary data and HTML via a MIME Content-ID header in a MIME-encoded image.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-08-11T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-03-25T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:45.083-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:52:14.348-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
        <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
        <criterion comment="evolution version is less than 1.2.2-5" negate="false" test_ref="oval:org.mitre.oval:tst:2939"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:112" version="2" class="vulnerability">
      <metadata>
        <title>GDM Examine Errors Symlink Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>GDM</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0547" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0547"/>
        <description>GDM before 2.4.1.6, when using the "examine session errors" feature, allows local users to read arbitrary files via a symlink attack on the ~/.xsession-errors file.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-09-04T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-03-25T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-05-05T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:43.511-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:52:14.522-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
        <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
        <criterion comment="gdm version is less than 2.4.1.3-5.1" negate="false" test_ref="oval:org.mitre.oval:tst:2936"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:113" version="2" class="vulnerability">
      <metadata>
        <title>X Display Manager Control Protocol Denial of Service</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>GDM</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0548" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0548"/>
        <description>The X Display Manager Control Protocol (XDMCP) support for GDM before 2.4.1.6 allows attackers to cause a denial of service (daemon crash) when a chosen host expires, a different issue than CVE-2003-0549.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-09-04T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-03-25T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-05-05T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:38.828-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:52:14.680-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
        <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
        <criterion comment="gdm version is less than 2.4.1.3-5.1" negate="false" test_ref="oval:org.mitre.oval:tst:2936"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:129" version="2" class="vulnerability">
      <metadata>
        <title>GDM X Display Manager Authorization Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>GDM</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0549" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0549"/>
        <description>The X Display Manager Control Protocol (XDMCP) support for GDM before 2.4.1.6 allows attackers to cause a denial of service (daemon crash) via a short authorization key name.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-09-04T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-03-25T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-05-05T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:33.855-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:52:15.558-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
        <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
        <criterion comment="gdm version is less than 2.4.1.3-5.1" negate="false" test_ref="oval:org.mitre.oval:tst:2936"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:133" version="2" class="vulnerability">
      <metadata>
        <title>GNU Ghostscript -dSAFER Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>GNU Ghostscript</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0354" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0354"/>
        <description>Unknown vulnerability in GNU Ghostscript before 7.07 allows attackers to execute arbitrary commands, even when -dSAFER is enabled, via a PostScript file that causes the commands to be executed from a malicious print job.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-08-20T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-03-25T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:42.628-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:52:15.718-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criterion comment="ghostscript version is less than 7.05-32.1" negate="false" test_ref="oval:org.mitre.oval:tst:2911"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="/usr/bin/gs is executable">
            <criterion comment="/usr/bin/gs is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2910"/>
            <criterion comment="/usr/bin/gs is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2909"/>
            <criterion comment="/usr/bin/gs is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2908"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:135" version="2" class="vulnerability">
      <metadata>
        <title>GnuPG Invalid User ID Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>GnuPG</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0255" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0255"/>
        <description>The key validation code in GnuPG before 1.2.2 does not properly determine the validity of keys with multiple user IDs and assigns the greatest validity of the most valid user ID, which prevents GnuPG from warning the encrypting user when a user ID does not have a trusted path.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-08-19T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-03-25T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:25.989-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:52:15.914-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criterion comment="gnupg version is less than 1.2.1-4" negate="false" test_ref="oval:org.mitre.oval:tst:2901"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="/usr/bin/gnupg is executable">
            <criterion comment="/usr/bin/gnupg is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2900"/>
            <criterion comment="/usr/bin/gnupg is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2899"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:138" version="2" class="vulnerability">
      <metadata>
        <title>Evolution GtkHTML DoS via Malformed Message</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>GtkHTML</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0133" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0133"/>
        <description>GtkHTML, as included in Evolution before 1.2.4, allows remote attackers to cause a denial of service (crash) via certain malformed messages.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-09-02T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-03-25T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-05-05T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:41.366-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:52:16.094-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
        <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
        <criterion comment="gtkhtml version is less than 1.1.9-0.9" negate="false" test_ref="oval:org.mitre.oval:tst:2897"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:148" version="2" class="vulnerability">
      <metadata>
        <title>Evolution GtkHTML DoS via null Pointer Dereference</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>GtkHTML</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0541" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0541"/>
        <description>gtkhtml before 1.1.10, as used in Evolution, allows remote attackers to cause a denial of service (crash) via a malformed message that causes a null pointer dereference.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-09-10T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-03-25T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:54.285-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:52:16.578-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criterion comment="gtkhtml version is less than 1.1.9-0.9.1" negate="false" test_ref="oval:org.mitre.oval:tst:2877"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="/usr/bin/evolution is executable">
            <criterion comment="/usr/bin/evolution is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2876"/>
            <criterion comment="/usr/bin/evolution is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2875"/>
            <criterion comment="/usr/bin/evolution is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2874"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:150" version="2" class="vulnerability">
      <metadata>
        <title>Apache Terminal Escape Sequence Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>Apache</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0020" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0020"/>
        <description>Apache does not filter terminal escape sequences from its error logs, which could make it easier for attackers to insert those sequences into terminal emulators containing vulnerabilities related to escape sequences.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-08-17T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-03-25T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:42:05.140-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:52:17.141-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criterion comment="httpd version is less than 2.0.40-21.1" negate="false" test_ref="oval:org.mitre.oval:tst:2866"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="httpd listening on the network" negate="false" test_ref="oval:org.mitre.oval:tst:2865"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:151" version="2" class="vulnerability">
      <metadata>
        <title>Apache Terminal Escape Sequence Vulnerability II</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>Apache</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0083" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0083"/>
        <description>Apache 1.3 before 1.3.25 and Apache 2.0 before version 2.0.46 does not filter terminal escape sequences from its access logs, which could make it easier for attackers to insert those sequences into terminal emulators containing vulnerabilities related to escape sequences, a different vulnerability than CVE-2003-0020.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-08-17T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-03-25T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:52.521-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:52:17.297-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criterion comment="httpd version is less than 2.0.40-21.1" negate="false" test_ref="oval:org.mitre.oval:tst:2866"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="httpd listening on the network" negate="false" test_ref="oval:org.mitre.oval:tst:2865"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:156" version="2" class="vulnerability">
      <metadata>
        <title>Apache Linefeed Allocation Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>Apache</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0132" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0132"/>
        <description>A memory leak in Apache 2.0 through 2.0.44 allows remote attackers to cause a denial of service (memory consumption) via large chunks of linefeed characters, which causes Apache to allocate 80 bytes for each linefeed.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-08-17T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-03-25T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:57.345-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:52:17.673-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criterion comment="httpd version is less than 2.0.40-21.1" negate="false" test_ref="oval:org.mitre.oval:tst:2866"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="httpd listening on the network" negate="false" test_ref="oval:org.mitre.oval:tst:2865"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:169" version="2" class="vulnerability">
      <metadata>
        <title>Apache Weak Cipher Suite Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>Apache</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0192" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0192"/>
        <description>Apache 2 before 2.0.47, and certain versions of mod_ssl for Apache 1.3, do not properly handle "certain sequences of per-directory renegotiations and the SSLCipherSuite directive being used to upgrade from a weak ciphersuite to a strong one," which could cause Apache to use the weak ciphersuite.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-09-05T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-03-25T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:58.877-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:52:18.366-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criterion comment="httpd version is less than 2.0.40-21.5" negate="false" test_ref="oval:org.mitre.oval:tst:2852"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="httpd.worker is listening on the network" negate="false" test_ref="oval:org.mitre.oval:tst:2851"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:173" version="2" class="vulnerability">
      <metadata>
        <title>Apache prefork MPM Denial of Service</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>Apache</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0253" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0253"/>
        <description>The prefork MPM in Apache 2 before 2.0.47 does not properly handle certain errors from accept, which could lead to a denial of service.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-09-05T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-03-25T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:50.575-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:52:18.541-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criterion comment="httpd version is less than 2.0.40-21.5" negate="false" test_ref="oval:org.mitre.oval:tst:2852"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="httpd listening on the network" negate="false" test_ref="oval:org.mitre.oval:tst:2865"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:183" version="2" class="vulnerability">
      <metadata>
        <title>Apache IPv6 Socket Failure Denial of Service</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>Apache</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0254" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0254"/>
        <description>Apache 2 before 2.0.47, when running on an IPv6 host, allows attackers to cause a denial of service (CPU consumption by infinite loop) when the FTP proxy server fails to create an IPv6 socket.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-09-05T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-03-25T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:41.547-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:52:20.097-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criterion comment="httpd version is less than 2.0.40-21.5" negate="false" test_ref="oval:org.mitre.oval:tst:2852"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="httpd listening on the network" negate="false" test_ref="oval:org.mitre.oval:tst:2865"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:193" version="2" class="vulnerability">
      <metadata>
        <title>KDM pam_setcred Privilege Escalation Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>KDM</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0690" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0690"/>
        <description>KDM in KDE 3.1.3 and earlier does not verify whether the pam_setcred function call succeeds, which may allow attackers to gain root privileges by triggering error conditions within PAM modules, as demonstrated in certain configurations of the MIT pam_krb5 module.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-09-21T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-03-25T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-05-05T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:36.443-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:52:21.414-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criterion comment="kdebase version is less than 3.1-15" negate="false" test_ref="oval:org.mitre.oval:tst:2826"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="/usr/bin/kdm is executable">
            <criterion comment="/usr/bin/kdm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2825"/>
            <criterion comment="/usr/bin/kdm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2824"/>
            <criterion comment="/usr/bin/kdm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2823"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:2" version="2" class="vulnerability">
      <metadata>
        <title>Mutt BO Vulnerability in balsa</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>Mutt</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0140" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0140"/>
        <description>Buffer overflow in Mutt 1.4.0 and possibly earlier versions, 1.5.x up to 1.5.3, and other programs that use Mutt code such as Balsa before 2.0.10, allows a remote malicious IMAP server to cause a denial of service (crash) and possibly execute arbitrary code via a crafted folder.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-08-18T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-03-25T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:42:05.738-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:52:22.102-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criterion comment="balsa version is less than 2.0.6-2" negate="false" test_ref="oval:org.mitre.oval:tst:3151"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="/usr/bin/balsa is executable">
            <criterion comment="/usr/bin/balsa is executable" negate="false" test_ref="oval:org.mitre.oval:tst:3150"/>
            <criterion comment="/usr/bin/balsa is executable" negate="false" test_ref="oval:org.mitre.oval:tst:3149"/>
            <criterion comment="/usr/bin/balsa is executable" negate="false" test_ref="oval:org.mitre.oval:tst:3148"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:215" version="2" class="vulnerability">
      <metadata>
        <title>KDM Weak Cookie Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>KDM</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0692" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0692"/>
        <description>KDM in KDE 3.1.3 and earlier uses a weak session cookie generation algorithm that does not provide 128 bits of entropy, which allows attackers to guess session cookies via brute force methods and gain access to the user session.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-09-21T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-03-25T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-05-05T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:47.959-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:52:23.173-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criterion comment="kdebase version is less than 3.1-15" negate="false" test_ref="oval:org.mitre.oval:tst:2826"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="/usr/bin/kdm is executable">
            <criterion comment="/usr/bin/kdm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2825"/>
            <criterion comment="/usr/bin/kdm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2824"/>
            <criterion comment="/usr/bin/kdm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2823"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:230" version="2" class="vulnerability">
      <metadata>
        <title>xdrmem_bytes() Integer Overflow Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>krb5</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0028" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0028"/>
        <description>Integer overflow in the xdrmem_getbytes() function, and possibly other functions, of XDR (external data representation) libraries derived from SunRPC, including libnsl, libc, glibc, and dietlibc, allows remote attackers to execute arbitrary code via certain integer values in length fields, a different vulnerability than CVE-2002-0391.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-08-14T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-03-25T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:22.838-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:52:23.324-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
        <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
        <criterion comment="krb5-server version is less than 1.2.7-14" negate="false" test_ref="oval:org.mitre.oval:tst:2785"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:244" version="2" class="vulnerability">
      <metadata>
        <title>Kerberos KDC Heap Corruption Denial of Service</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>krb5</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0082" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0082"/>
        <description>The Key Distribution Center (KDC) in Kerberos 5 (krb5) 1.2.7 and earlier allows remote, authenticated attackers to cause a denial of service (crash) on KDCs within the same realm using a certain protocol request that causes the KDC to corrupt its heap (aka "buffer underrun").</description>
        <oval_repository>
          <dates>
            <submitted date="2003-08-14T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-03-25T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:25.682-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:52:23.488-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
        <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
        <criterion comment="krb5-server version is less than 1.2.7-14" negate="false" test_ref="oval:org.mitre.oval:tst:2785"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:248" version="2" class="vulnerability">
      <metadata>
        <title>Kerberos krb4 Plaintext Attack Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>krb5</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0138" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0138"/>
        <description>Version 4 of the Kerberos protocol (krb4), as used in Heimdal and other packages, allows an attacker to impersonate any principal in a realm via a chosen-plaintext attack.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-08-14T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-03-25T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:23.753-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:52:23.652-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
        <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
        <criterion comment="krb5-libs version is less than 1.2.7-14" negate="false" test_ref="oval:org.mitre.oval:tst:2756"/>
        <criteria operator="OR" comment="krb5-server or krb5-workstation installed">
          <criterion comment="krb5-server version is less than 1.2.7-14" negate="false" test_ref="oval:org.mitre.oval:tst:2785"/>
          <criterion comment="krb5-workstation version is less than 1.2.7-14" negate="false" test_ref="oval:org.mitre.oval:tst:2755"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:250" version="2" class="vulnerability">
      <metadata>
        <title>Kerberos krb4 Ticket Splicing Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>krb5</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0139" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0139"/>
        <description>Certain weaknesses in the implementation of version 4 of the Kerberos protocol (krb4) in the krb5 distribution, when triple-DES keys are used to key krb4 services, allow an attacker to create krb4 tickets for unauthorized principals using a cut-and-paste attack and "ticket splicing."</description>
        <oval_repository>
          <dates>
            <submitted date="2003-08-14T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-03-25T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:52.850-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:52:23.823-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
        <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
        <criterion comment="krb5-libs version is less than 1.2.7-14" negate="false" test_ref="oval:org.mitre.oval:tst:2756"/>
        <criteria operator="OR" comment="krb5-server or krb5-workstation installed">
          <criterion comment="krb5-server version is less than 1.2.7-14" negate="false" test_ref="oval:org.mitre.oval:tst:2785"/>
          <criterion comment="krb5-workstation version is less than 1.2.7-14" negate="false" test_ref="oval:org.mitre.oval:tst:2755"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:254" version="2" class="vulnerability">
      <metadata>
        <title>Linux Kernel ptrace Privilege Escalation Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>Linux kernel</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0127" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0127"/>
        <description>The kernel module loader in Linux kernel 2.2.x before 2.2.25, and 2.4.x before 2.4.21, allows local users to gain root privileges by using ptrace to attach to a child process that is spawned by the kernel.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-09-25T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-03-25T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:21.400-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:52:23.998-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criterion comment="kernel version = 2.4.20-6" negate="false" test_ref="oval:org.mitre.oval:tst:2753"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="kernel 2.4.20-6 or earlier is running" negate="false" test_ref="oval:org.mitre.oval:tst:2752"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:260" version="2" class="vulnerability">
      <metadata>
        <title>Netfilter Denial of Service</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>Netfilter</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0187" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0187"/>
        <description>The connection tracking core of Netfilter for Linux 2.4.20, with CONFIG_IP_NF_CONNTRACK enabled or the ip_conntrack module loaded, allows remote attackers to cause a denial of service (resource consumption) due to an inconsistency with Linux 2.4.20's support of linked lists, which causes Netfilter to fail to identify connections with an UNCONFIRMED status and use large timeouts.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-09-25T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-03-25T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:38.425-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:52:24.425-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
        <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
        <criterion comment="kernel version is less than 2.4.20-13.9" negate="false" test_ref="oval:org.mitre.oval:tst:2742"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:261" version="2" class="vulnerability">
      <metadata>
        <title>Linux Route Cache / Netfilter Denial of Service</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>Netfilter</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0244" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0244"/>
        <description>The route cache implementation in Linux 2.4, and the Netfilter IP conntrack module, allows remote attackers to cause a denial of service (CPU consumption) via packets with forged source addresses that cause a large number of hash table collisions.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-09-25T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-03-25T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:41.931-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:52:24.590-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
        <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
        <criterion comment="kernel version is less than 2.4.20-13.9" negate="false" test_ref="oval:org.mitre.oval:tst:2742"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:278" version="2" class="vulnerability">
      <metadata>
        <title>Linux ioperm Privilege Restriction Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>Linux kernel</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0246" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0246"/>
        <description>The ioperm system call in Linux kernel 2.4.20 and earlier does not properly restrict privileges, which allows local users to gain read or write access to certain I/O ports.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-09-25T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-03-25T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:56.655-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:52:25.107-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
        <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
        <criterion comment="kernel version is less than 2.4.20-13.9" negate="false" test_ref="oval:org.mitre.oval:tst:2742"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28" version="2" class="vulnerability">
      <metadata>
        <title>SKK/DDSKK Insecure Temporary File Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>skk</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0539" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0539"/>
        <description>skk (Simple Kana to Kanji conversion program) 12.1 and earlier, and the ddskk package which is based on skk, creates temporary files insecurely, which allows local users to overwrite arbitrary files.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-09-04T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-03-25T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:59.552-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:52:25.291-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
        <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
        <criteria operator="OR" comment="Vulnerable config">
          <criterion comment="ddskk version is less than 11.6.0-11.90" negate="false" test_ref="oval:org.mitre.oval:tst:3061"/>
          <criterion comment="ddskk-xemacs version is less than 11.6.0-11.90" negate="false" test_ref="oval:org.mitre.oval:tst:3060"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:284" version="2" class="vulnerability">
      <metadata>
        <title>Linux Kernel TTY Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>Linux kernel</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0247" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0247"/>
        <description>Unknown vulnerability in the TTY layer of the Linux kernel 2.4 allows attackers to cause a denial of service ("kernel oops").</description>
        <oval_repository>
          <dates>
            <submitted date="2003-09-26T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-03-25T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:42:05.289-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:52:25.727-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
        <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
        <criterion comment="kernel version is less than 2.4.20-18.9" negate="false" test_ref="oval:org.mitre.oval:tst:2721"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:292" version="2" class="vulnerability">
      <metadata>
        <title>Linux Kernel mxcsr Code Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>Linux kernel</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0248" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0248"/>
        <description>The mxcsr code in Linux kernel 2.4 allows attackers to modify CPU state registers via a malformed address.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-09-26T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-03-25T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:46.889-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:52:25.916-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
        <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
        <criterion comment="kernel version is less than 2.4.20-18.9" negate="false" test_ref="oval:org.mitre.oval:tst:2721"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:295" version="2" class="vulnerability">
      <metadata>
        <title>Linux Kernel TCP/IP Fragment Reassembly Denial of Service</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>Linux kernel</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0364" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0364"/>
        <description>The TCP/IP fragment reassembly handling in the Linux kernel 2.4 allows remote attackers to cause a denial of service (CPU consumption) via certain packets that cause a large number of hash table collisions.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-09-26T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-03-25T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:22.189-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:52:26.134-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
        <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
        <criterion comment="kernel version is less than 2.4.20-18.9" negate="false" test_ref="oval:org.mitre.oval:tst:2721"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:304" version="2" class="vulnerability">
      <metadata>
        <title>Red Hat Linux Kernel Serial Link Information Disclosure Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0461" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0461"/>
        <description>/proc/tty/driver/serial in Linux 2.4.x reveals the exact number of characters used in serial links, which could allow local users to obtain potentially sensitive information such as the length of passwords.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-09-26T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-03-25T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:50.987-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:52:26.364-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
        <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
        <criterion comment="kernel version is less than 2.4.20-19.9" negate="false" test_ref="oval:org.mitre.oval:tst:2709"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:309" version="2" class="vulnerability">
      <metadata>
        <title>Linux Kernel execve Race Condition Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>Linux kernel</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0462" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0462"/>
        <description>A race condition in the way env_start and env_end pointers are initialized in the execve system call and used in fs/proc/base.c on Linux 2.4 allows local users to cause a denial of service (crash).</description>
        <oval_repository>
          <dates>
            <submitted date="2003-09-26T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-03-25T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:34.404-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:52:26.586-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
        <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
        <criterion comment="kernel version is less than 2.4.20-19.9" negate="false" test_ref="oval:org.mitre.oval:tst:2709"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:311" version="2" class="vulnerability">
      <metadata>
        <title>Linux Kernel Reuse Flag Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>Linux kernel</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0464" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0464"/>
        <description>The RPC code in Linux kernel 2.4 sets the reuse flag when sockets are created, which could allow local users to bind to UDP ports that are used by privileged services such as nfsd.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-09-26T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-03-25T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:53.493-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:52:27.102-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
        <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
        <criterion comment="kernel version is less than 2.4.20-19.9" negate="false" test_ref="oval:org.mitre.oval:tst:2709"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:327" version="2" class="vulnerability">
      <metadata>
        <title>Linux Kernel execve Read Acces to Restricted File Descriptors</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>Linux kernel</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0476" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0476"/>
        <description>The execve system call in Linux 2.4.x records the file descriptor of the executable process in the file table of the calling process, which allows local users to gain read access to restricted file descriptors.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-09-26T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-03-25T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:40.650-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:52:27.328-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
        <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
        <criterion comment="kernel version is less than 2.4.20-19.9" negate="false" test_ref="oval:org.mitre.oval:tst:2709"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:328" version="2" class="vulnerability">
      <metadata>
        <title>Linux Kernel /proc/self setuid Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>Linux kernel</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0501" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0501"/>
        <description>The /proc filesystem in Linux allows local users to obtain sensitive information by opening various entries in /proc/self before executing a setuid program, which causes the program to fail to change the ownership and permissions of those entries.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-09-26T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-03-25T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:57.895-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:52:27.525-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
        <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
        <criterion comment="kernel version is less than 2.4.20-19.9" negate="false" test_ref="oval:org.mitre.oval:tst:2709"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:380" version="2" class="vulnerability">
      <metadata>
        <title>Insecure Design of the STP Protocol</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>Linux kernel</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0550" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0550"/>
        <description>The STP protocol, as enabled in Linux 2.4.x, does not provide sufficient security by design, which allows attackers to modify the bridge topology.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-09-26T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-03-25T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:59.904-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:52:27.798-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
        <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
        <criterion comment="kernel version is less than 2.4.20-19.9" negate="false" test_ref="oval:org.mitre.oval:tst:2709"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:384" version="2" class="vulnerability">
      <metadata>
        <title>STP Protocol Length Verification Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>Linux kernel</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0551" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0551"/>
        <description>The STP protocol implementation in Linux 2.4.x does not properly verify certain lengths, which could allow attackers to cause a denial of service.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-09-26T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-03-25T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:41.192-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:52:27.991-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
        <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
        <criterion comment="kernel version is less than 2.4.20-19.9" negate="false" test_ref="oval:org.mitre.oval:tst:2709"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:385" version="2" class="vulnerability">
      <metadata>
        <title>Linux Kernel Bridge Forwarding Table Spoof Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>Linux kernel</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0552" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0552"/>
        <description>Linux 2.4.x allows remote attackers to spoof the bridge Forwarding table via forged packets whose source addresses are the same as the target.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-09-26T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-03-25T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:49.252-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:52:28.196-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
        <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
        <criterion comment="kernel version is less than 2.4.20-19.9" negate="false" test_ref="oval:org.mitre.oval:tst:2709"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:386" version="2" class="vulnerability">
      <metadata>
        <title>Lunix Kernel NFSv3 Procedure Kernel Panic Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>Linux kernel</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0619" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0619"/>
        <description>Integer signedness error in the decode_fh function of nfs3xdr.c in Linux kernel before 2.4.21 allows remote attackers to cause a denial of service (kernel panic) via a negative size value within XDR data of an NFSv3 procedure call.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-09-25T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-03-25T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:42.165-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:52:28.400-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
        <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
        <criterion comment="kernel version is less than 2.4.20-13.9" negate="false" test_ref="oval:org.mitre.oval:tst:2742"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:387" version="2" class="vulnerability">
      <metadata>
        <title>C-Media Sound Driver Userspace Access Vulnerability II</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>Linux kernel</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0699" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0699"/>
        <description>The C-Media PCI sound driver in Linux before 2.4.21 does not use the get_user function to access userspace, which crosses security boundaries and may facilitate the exploitation of vulnerabilities, a different vulnerability than CVE-2003-0700.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-09-26T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-03-25T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:35.221-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:52:28.596-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
        <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
        <criterion comment="kernel version is less than 2.4.20-19.9" negate="false" test_ref="oval:org.mitre.oval:tst:2709"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:401" version="2" class="vulnerability">
      <metadata>
        <title>C-Media Sound Driver Userspace Access Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>Linux kernel</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0700" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0700"/>
        <description>The C-Media PCI sound driver in Linux before 2.4.22 does not use the get_user function to access userspace in certain conditions, which crosses security boundaries and may facilitate the exploitation of vulnerabilities, a different vulnerability than CVE-2003-0699.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-09-26T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-03-25T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:23.972-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:52:28.781-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
        <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
        <criterion comment="kernel version is less than 2.4.20-19.9" negate="false" test_ref="oval:org.mitre.oval:tst:2709"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:411" version="2" class="vulnerability">
      <metadata>
        <title>KDE Konqueror Userid/Password Disclosure Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>Konqueror</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0459" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0459"/>
        <description>KDE Konqueror for KDE 3.1.2 and earlier does not remove authentication credentials from URLs of the "user:password@host" form in the HTTP-Referer header, which could allow remote web sites to steal the credentials for pages that link to the sites.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-09-04T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-03-25T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-05-05T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:36.910-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:52:29.267-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criterion comment="kdelibs version is less than 3.1-12" negate="false" test_ref="oval:org.mitre.oval:tst:2656"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="/usr/bin/konqueror is executable">
            <criterion comment="/usr/bin/konqueror is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2655"/>
            <criterion comment="/usr/bin/konqueror is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2654"/>
            <criterion comment="/usr/bin/konqueror is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2653"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:423" version="2" class="vulnerability">
      <metadata>
        <title>LPRng Symbolic Link Attack Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>LPRng</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0136" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0136"/>
        <description>psbanner in the LPRng package allows local users to overwrite arbitrary files via a symbolic link attack on the /tmp/before file.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-08-17T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-03-25T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:58.226-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:52:29.837-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criterion comment="lprng version is less than 3.8.19-3.1" negate="false" test_ref="oval:org.mitre.oval:tst:2647"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="psbanner is world-executable" negate="false" test_ref="oval:org.mitre.oval:tst:2646"/>
          <criterion comment="lpd listening on the network" negate="false" test_ref="oval:org.mitre.oval:tst:2645"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:430" version="2" class="vulnerability">
      <metadata>
        <title>Multilingual File Viewer .lv File Sneak Attack Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>lv</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0188" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0188"/>
        <description>lv reads a .lv file from the current working directory, which allows local users to execute arbitrary commands as other lv users by placing malicious .lv files into other directories.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-08-19T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-03-25T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:48.886-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:52:30.316-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
        <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
        <criterion comment="lv version is less than 4.49.4-9.9.1" negate="false" test_ref="oval:org.mitre.oval:tst:2639"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:434" version="2" class="vulnerability">
      <metadata>
        <title>Mutt BO Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>Mutt</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0140" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0140"/>
        <description>Buffer overflow in Mutt 1.4.0 and possibly earlier versions, 1.5.x up to 1.5.3, and other programs that use Mutt code such as Balsa before 2.0.10, allows a remote malicious IMAP server to cause a denial of service (crash) and possibly execute arbitrary code via a crafted folder.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-08-18T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-03-25T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-05-05T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:53.121-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:52:30.758-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criterion comment="mutt version is less than 1.4.1-1" negate="false" test_ref="oval:org.mitre.oval:tst:2638"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="/usr/bin/mutt is executable">
            <criterion comment="/usr/bin/mutt is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2637"/>
            <criterion comment="/usr/bin/mutt is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2636"/>
            <criterion comment="/usr/bin/mutt is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2635"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:436" version="2" class="vulnerability">
      <metadata>
        <title>MYSQLd Double-free Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>MySQL</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0073" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0073"/>
        <description>Double-free vulnerability in mysqld for MySQL before 3.23.55 allows attackers with MySQL access to cause a denial of service (crash) via mysql_change_user.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-08-18T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-03-25T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:42:05.441-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:52:31.006-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criterion comment="mysql-server version is less than 3.23.56-1.9" negate="false" test_ref="oval:org.mitre.oval:tst:2634"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="mysqld is listening to the network" negate="false" test_ref="oval:org.mitre.oval:tst:2633"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:442" version="2" class="vulnerability">
      <metadata>
        <title>MYSQL Privilege Escalation Vulnerability via INFO OUTFILE Select</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>MySQL</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0150" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0150"/>
        <description>MySQL 3.23.55 and earlier creates world-writeable files and allows mysql users to gain root privileges by using the "SELECT * INFO OUTFILE" operator to overwrite a configuration file and cause mysql to run as root upon restart, as demonstrated by modifying my.cnf.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-08-18T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-03-25T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:41.728-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:52:31.202-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criterion comment="mysql-server version is less than 3.23.56-1.9" negate="false" test_ref="oval:org.mitre.oval:tst:2634"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="mysqld is listening to the network" negate="false" test_ref="oval:org.mitre.oval:tst:2633"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:443" version="2" class="vulnerability">
      <metadata>
        <title>mountd xlog Function Off-by-One Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>nfs-utils</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0252" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0252"/>
        <description>Off-by-one error in the xlog function of mountd in the Linux NFS utils package (nfs-utils) before 1.0.4 allows remote attackers to cause a denial of service and possibly execute arbitrary code via certain RPC requests to mountd that do not contain newlines.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-09-02T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-03-25T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:56.121-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:52:31.401-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criterion comment="nfs-utils version is less than 1.0.1-3.9" negate="false" test_ref="oval:org.mitre.oval:tst:2631"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="rpc.mountd listens on the network" negate="false" test_ref="oval:org.mitre.oval:tst:2630"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:445" version="2" class="vulnerability">
      <metadata>
        <title>OpenSSH Indirect User Disclosure Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>OpenSSH</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0190" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0190"/>
        <description>OpenSSH-portable (OpenSSH) 3.6.1p1 and earlier with PAM support enabled immediately sends an error message when a user does not exist, which allows remote attackers to determine valid usernames via a timing attack.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-08-29T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-03-25T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:48.710-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:52:31.675-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criterion comment="openssh-server version is less than 3.5p1-6.9" negate="false" test_ref="oval:org.mitre.oval:tst:2629"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="sshd listens on the network" negate="false" test_ref="oval:org.mitre.oval:tst:2628"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:446" version="2" class="vulnerability">
      <metadata>
        <title>Memory Bugs in OpenSSH</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>OpenSSH</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0682" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0682"/>
        <description>"Memory bugs" in OpenSSH 3.7.1 and earlier, with unknown impact, a different set of vulnerabilities than CVE-2003-0693 and CVE-2003-0695.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-09-21T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-03-25T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:35.446-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:52:31.864-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criterion comment="openssh-server version is less than 3.5p1-11" negate="false" test_ref="oval:org.mitre.oval:tst:2627"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="sshd listens on the network" negate="false" test_ref="oval:org.mitre.oval:tst:2628"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:447" version="2" class="vulnerability">
      <metadata>
        <title>Mutliple Buffer Management Errors in OpenSSH II</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>OpenSSH</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0693" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0693"/>
        <description>A "buffer management error" in buffer_append_space of buffer.c for OpenSSH before 3.7 may allow remote attackers to execute arbitrary code by causing an incorrect amount of memory to be freed and corrupting the heap, a different vulnerability than CVE-2003-0695.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-09-21T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-03-25T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:26.157-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:52:32.039-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criterion comment="openssh-server version is less than 3.5p1-11" negate="false" test_ref="oval:org.mitre.oval:tst:2627"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="sshd listens on the network" negate="false" test_ref="oval:org.mitre.oval:tst:2628"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:452" version="2" class="vulnerability">
      <metadata>
        <title>Mutliple Buffer Management Errors in OpenSSH</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>OpenSSH</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0695" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0695"/>
        <description>Multiple "buffer management errors" in OpenSSH before 3.7.1 may allow attackers to cause a denial of service or execute arbitrary code using (1) buffer_init in buffer.c, (2) buffer_free in buffer.c, or (3) a separate function in channels.c, a different vulnerability than CVE-2003-0693.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-09-21T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-03-25T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:57.014-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:52:32.218-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criterion comment="openssh-server version is less than 3.5p1-11" negate="false" test_ref="oval:org.mitre.oval:tst:2627"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="sshd listens on the network" negate="false" test_ref="oval:org.mitre.oval:tst:2628"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:461" version="2" class="vulnerability">
      <metadata>
        <title>Klima-Pokorny-Rosa Attack Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>OpenSSL</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0131" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0131"/>
        <description>The SSL and TLS components for OpenSSL 0.9.6i and earlier, 0.9.7, and 0.9.7a allow remote attackers to perform an unauthorized RSA private key operation via a modified Bleichenbacher attack that uses a large number of SSL or TLS connections using PKCS #1 v1.5 padding that cause OpenSSL to leak information regarding the relationship between ciphertext and the associated plaintext, aka the "Klima-Pokorny-Rosa attack."</description>
        <oval_repository>
          <dates>
            <submitted date="2003-08-11T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-03-25T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </modified>
            <modified date="2004-05-11T12:00:00.000-04:00" comment="Added cmp-914 which uses an or to combine the 5 version tests. Previously the tests had been combined with an and.">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:51.829-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:52:32.405-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
        <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
        <criteria operator="OR" comment="affected version of SSL and TLS components for OpenSSL">
          <criterion comment="openssl version is less than 0.9.7a-5" negate="false" test_ref="oval:org.mitre.oval:tst:2618"/>
          <criterion comment="openssl-devel version is less than 0.9.7a-5" negate="false" test_ref="oval:org.mitre.oval:tst:2617"/>
          <criterion comment="openssl-perl version is less than 0.9.7a-5" negate="false" test_ref="oval:org.mitre.oval:tst:2616"/>
          <criterion comment="openssl096 version is less than 0.9.6-17" negate="false" test_ref="oval:org.mitre.oval:tst:2615"/>
          <criterion comment="openssl096b version is less than 0.9.6b-6" negate="false" test_ref="oval:org.mitre.oval:tst:2614"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:466" version="2" class="vulnerability">
      <metadata>
        <title>OpenSSL No RSA Blinding Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>OpenSSL</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0147" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0147"/>
        <description>OpenSSL does not use RSA blinding by default, which allows local and remote attackers to obtain the server's private key by determining factors using timing differences on (1) the number of extra reductions during Montgomery reduction, and (2) the use of different integer multiplication algorithms ("Karatsuba" and normal).</description>
        <oval_repository>
          <dates>
            <submitted date="2003-08-11T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-03-25T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </modified>
            <modified date="2004-05-11T12:00:00.000-04:00" comment="Added cmp-914 which uses an or to combine the 5 version tests. Previously the tests had been combined with an and.">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:37.910-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:52:32.667-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
        <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
        <criteria operator="OR" comment="affected version of SSL and TLS components for OpenSSL">
          <criterion comment="openssl version is less than 0.9.7a-5" negate="false" test_ref="oval:org.mitre.oval:tst:2618"/>
          <criterion comment="openssl-devel version is less than 0.9.7a-5" negate="false" test_ref="oval:org.mitre.oval:tst:2617"/>
          <criterion comment="openssl-perl version is less than 0.9.7a-5" negate="false" test_ref="oval:org.mitre.oval:tst:2616"/>
          <criterion comment="openssl096 version is less than 0.9.6-17" negate="false" test_ref="oval:org.mitre.oval:tst:2615"/>
          <criterion comment="openssl096b version is less than 0.9.6b-6" negate="false" test_ref="oval:org.mitre.oval:tst:2614"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:469" version="2" class="vulnerability">
      <metadata>
        <title>Buffer Overflow in PAM SMB Module</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>pam_smb</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0686" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0686"/>
        <description>Buffer overflow in PAM SMB module (pam_smb) 1.1.6 and earlier, when authenticating to a remote service, allows remote attackers to execute arbitrary code.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-09-05T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-03-25T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:38.611-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:52:32.853-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
        <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
        <criterion comment="pam_smb version is less than 1.1.6-9.9" negate="false" test_ref="oval:org.mitre.oval:tst:2608"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:470" version="2" class="vulnerability">
      <metadata>
        <title>CGI.pm Cross-site Scripting Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>CGI.pm</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0615" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0615"/>
        <description>Cross-site scripting (XSS) vulnerability in start_form() of CGI.pm allows remote attackers to insert web script via a URL that is fed into the form's action parameter.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-09-25T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-03-25T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-05-05T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:54.481-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:52:33.013-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
        <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
        <criterion comment="perl-CGI version is less than 2.81-88.3" negate="false" test_ref="oval:org.mitre.oval:tst:2607"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:485" version="2" class="vulnerability">
      <metadata>
        <title>PH Cross-site Scripting Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>php</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0442" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0442"/>
        <description>Cross-site scripting (XSS) vulnerability in the transparent SID support capability for PHP before 4.3.2 (session.use_trans_sid) allows remote attackers to insert arbitrary script via the PHPSESSID parameter.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-08-29T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-03-25T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:58.679-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:52:33.229-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
        <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
        <criterion comment="php version is less than 4.2.2-17.2" negate="false" test_ref="oval:org.mitre.oval:tst:2592"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:499" version="2" class="vulnerability">
      <metadata>
        <title>PINE Buffer Overflow</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>pine</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0720" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0720"/>
        <description>Buffer overflow in PINE before 4.58 allows remote attackers to execute arbitrary code via a malformed message/external-body MIME type.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-09-12T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-03-25T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:39.919-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:52:33.417-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criterion comment="pine version is less than 4.44-19.90.0" negate="false" test_ref="oval:org.mitre.oval:tst:2587"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="/usr/bin/pine is executable">
            <criterion comment="/usr/bin/pine is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2586"/>
            <criterion comment="/usr/bin/pine is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2585"/>
            <criterion comment="/usr/bin/pine is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2584"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:503" version="2" class="vulnerability">
      <metadata>
        <title>Integer Signedness Error in PINE</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>pine</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0721" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0721"/>
        <description>Integer signedness error in rfc2231_get_param from strings.c in PINE before 4.58 allows remote attackers to execute arbitrary code via an email that causes an out-of-bounds array access using a negative number.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-09-12T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-03-25T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:47.076-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:52:33.657-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criterion comment="pine version is less than 4.44-19.90.0" negate="false" test_ref="oval:org.mitre.oval:tst:2587"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="/usr/bin/pine is executable">
            <criterion comment="/usr/bin/pine is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2586"/>
            <criterion comment="/usr/bin/pine is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2585"/>
            <criterion comment="/usr/bin/pine is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2584"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:52" version="2" class="vulnerability">
      <metadata>
        <title>Red Hat Eye of GNOME (EOG) Packages Fix Format String Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>EOG</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0165" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0165"/>
        <description>Format string vulnerability in Eye Of Gnome (EOG) allows attackers to execute arbitrary code via format string specifiers in a command line argument for the file to display.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-08-14T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-03-25T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:49.492-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:52:33.934-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criterion comment="eog version is less than 2.2.0-2" negate="false" test_ref="oval:org.mitre.oval:tst:3011"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="eog is executable">
            <criterion comment="eog is world-executable" negate="false" test_ref="oval:org.mitre.oval:tst:3010"/>
            <criterion comment="eog is group-executable" negate="false" test_ref="oval:org.mitre.oval:tst:3009"/>
            <criterion comment="eog is owner-executable" negate="false" test_ref="oval:org.mitre.oval:tst:3008"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:522" version="2" class="vulnerability">
      <metadata>
        <title>Postfix Bounce Scans Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>Postfix</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0468" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0468"/>
        <description>Postfix 1.1.11 and earlier allows remote attackers to use Postfix to conduct "bounce scans" or DDos attacks of other hosts via an email address to the local host containing the target IP address and service name followed by a "!" string, which causes Postfix to attempt to use SMTP to communicate with the target on the associated port.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-09-02T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-03-25T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-05-05T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:22.986-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:52:34.153-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criterion comment="postfix version is less than 1.1.12-1" negate="false" test_ref="oval:org.mitre.oval:tst:2578"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="smtpd listens on the network" negate="false" test_ref="oval:org.mitre.oval:tst:2577"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:54" version="2" class="vulnerability">
      <metadata>
        <title>Ethereal SOCKS String Format Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>Ethereal</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0081" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0081"/>
        <description>Format string vulnerability in packet-socks.c of the SOCKS dissector for Ethereal 0.8.7 through 0.9.9 allows remote attackers to execute arbitrary code via SOCKS packets containing format string specifiers.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-08-17T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-03-25T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:34.832-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:52:34.325-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
        <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
        <criterion comment="ethereal version is less than 0.9.11-0.90.1" negate="false" test_ref="oval:org.mitre.oval:tst:3007"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:544" version="2" class="vulnerability">
      <metadata>
        <title>Denial of Service Vulnerability in Postfix Parser Code</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>Postfix</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0540" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0540"/>
        <description>The address parser code in Postfix 1.1.12 and earlier allows remote attackers to cause a denial of service (lock) via (1) a malformed envelope address to a local host that would generate a bounce and contains the ".!" string in the MAIL FROM or Errors-To headers, which causes nqmgr to lock up, or (2) via a valid MAIL FROM with a RCPT TO containing a ".!" string, which causes an instance of the SMTP listener to lock up.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-09-02T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-03-25T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-05-05T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:56.860-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:52:34.582-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criterion comment="postfix version is less than 1.1.12-1" negate="false" test_ref="oval:org.mitre.oval:tst:2578"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="smtpd listens on the network" negate="false" test_ref="oval:org.mitre.oval:tst:2577"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:55" version="2" class="vulnerability">
      <metadata>
        <title>Ethereal NTLMSSP Buffer Overflow</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>Ethereal</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0159" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0159"/>
        <description>Heap-based buffer overflow in the NTLMSSP code for Ethereal 0.9.9 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-08-17T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-03-25T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:45.490-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:52:34.756-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
        <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
        <criterion comment="ethereal version is less than 0.9.11-0.90.1" negate="false" test_ref="oval:org.mitre.oval:tst:3007"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:552" version="2" class="vulnerability">
      <metadata>
        <title>SMB/CIFS Packet Fragment Re-assembly BO</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>smbd</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0085" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0085"/>
        <description>Buffer overflow in the SMB/CIFS packet fragment re-assembly code for SMB daemon (smbd) in Samba before 2.2.8, and Samba-TNG before 0.3.1, allows remote attackers to execute arbitrary code.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-08-11T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-03-25T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:55.164-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:52:35.011-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criterion comment="samba version is less than 2.2.7a-7.9.0" negate="false" test_ref="oval:org.mitre.oval:tst:2566"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="smbd listens on the network" negate="false" test_ref="oval:org.mitre.oval:tst:2565"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:554" version="2" class="vulnerability">
      <metadata>
        <title>Samba Arbitrary File Overwrite Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>Samba</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0086" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0086"/>
        <description>The code for writing reg files in Samba before 2.2.8 allows local users to overwrite arbitrary files via a race condition involving chown.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-08-11T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-03-25T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:48.134-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:52:35.344-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
        <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
        <criterion comment="samba version is less than 2.2.7a-7.9.0" negate="false" test_ref="oval:org.mitre.oval:tst:2566"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:564" version="2" class="vulnerability">
      <metadata>
        <title>Multiple Buffer Overflows in Samba</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>Samba</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0196" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0196"/>
        <description>Multiple buffer overflows in Samba before 2.2.8a may allow remote attackers to execute arbitrary code or cause a denial of service, as discovered by the Samba team and a different vulnerability than CVE-2003-0201.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-08-17T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-03-25T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:53.310-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:52:35.547-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criterion comment="samba version is less than 2.2.7a-8.9.0" negate="false" test_ref="oval:org.mitre.oval:tst:2559"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="smbd is listening on the network" negate="false" test_ref="oval:org.mitre.oval:tst:2558"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:567" version="2" class="vulnerability">
      <metadata>
        <title>BO in Samba call_trans2open Function</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>Samba, Samba-TNG</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0201" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0201"/>
        <description>Buffer overflow in the call_trans2open function in trans2.c for Samba 2.2.x before 2.2.8a, 2.0.10 and earlier 2.0.x versions, and Samba-TNG before 0.3.2, allows remote attackers to execute arbitrary code.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-08-17T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-03-25T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:49.693-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:52:35.765-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criterion comment="samba version is less than 2.2.7a-8.9.0" negate="false" test_ref="oval:org.mitre.oval:tst:2559"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="smbd is listening on the network" negate="false" test_ref="oval:org.mitre.oval:tst:2558"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:569" version="2" class="vulnerability">
      <metadata>
        <title>Symlink Attack Vulnerability in semi/wemi MIME Libraries</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>semi MIME library</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0440" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0440"/>
        <description>The (1) semi MIME library 1.14.5 and earlier, and (2) wemi 1.14.0 and possibly other versions, allows local users to overwrite arbitrary files via a symlink attack on temporary files.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-08-29T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-03-25T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:21.573-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:52:35.987-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criteria operator="OR" comment="Vulnerable Config">
            <criterion comment="wl version is less than 2.10.1-1.1" negate="false" test_ref="oval:org.mitre.oval:tst:2557"/>
            <criterion comment="wl-xemacs version is less than 2.10.1-1.1" negate="false" test_ref="oval:org.mitre.oval:tst:2556"/>
          </criteria>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="Vulnerable Config">
            <criteria operator="OR" comment="/usr/bin/emacs is executable">
              <criterion comment="/usr/bin/emacs is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2555"/>
              <criterion comment="/usr/bin/emacs is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2554"/>
              <criterion comment="/usr/bin/emacs is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2553"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/xemacs is executable">
              <criterion comment="/usr/bin/xemacs is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2552"/>
              <criterion comment="/usr/bin/xemacs is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2551"/>
              <criterion comment="/usr/bin/xemacs is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2550"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:572" version="2" class="vulnerability">
      <metadata>
        <title>Sendmail BO in Prescan Function</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>Sendmail</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0694" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0694"/>
        <description>The prescan function in Sendmail 8.12.9 allows remote attackers to execute arbitrary code via buffer overflow attacks, as demonstrated using the parseaddr function in parseaddr.c.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-08-11T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-03-25T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:38.145-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:52:36.305-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criterion comment="sendmail version is less than 8.12.8-5.90" negate="false" test_ref="oval:org.mitre.oval:tst:2549"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="Vulnerable Config">
            <criteria operator="AND" comment="sendmail is Set-UID">
              <criterion comment="sendmail is Set-UID" negate="false" test_ref="oval:org.mitre.oval:tst:2548"/>
              <criteria operator="OR" comment="sendmail is Set-UID">
                <criterion comment="sendmail is Set-UID" negate="false" test_ref="oval:org.mitre.oval:tst:2547"/>
                <criterion comment="sendmail is Set-UID" negate="false" test_ref="oval:org.mitre.oval:tst:2546"/>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="sendmail is Set-GID">
              <criterion comment="sendmail is Set-GID" negate="false" test_ref="oval:org.mitre.oval:tst:2545"/>
              <criterion comment="sendmail is Set-UID" negate="false" test_ref="oval:org.mitre.oval:tst:2546"/>
            </criteria>
            <criterion comment="sendmail listening" negate="false" test_ref="oval:org.mitre.oval:tst:2544"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:595" version="2" class="vulnerability">
      <metadata>
        <title>Potential BO in Ruleset Parsing for Sendmail</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>Sendmail</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0681" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0681"/>
        <description>A "potential buffer overflow in ruleset parsing" for Sendmail 8.12.9, when using the nonstandard rulesets (1) recipient (2), final, or (3) mailer-specific envelope recipients, has unknown consequences.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-09-21T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-03-25T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:50.782-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:52:36.569-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criterion comment="sendmail version is less than 8.12.8-9.90" negate="false" test_ref="oval:org.mitre.oval:tst:2518"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="Vulnerable Config">
            <criteria operator="AND" comment="sendmail is Set-UID">
              <criterion comment="sendmail is Set-UID" negate="false" test_ref="oval:org.mitre.oval:tst:2548"/>
              <criteria operator="OR" comment="sendmail is Set-UID">
                <criterion comment="sendmail is Set-UID" negate="false" test_ref="oval:org.mitre.oval:tst:2547"/>
                <criterion comment="sendmail is Set-UID" negate="false" test_ref="oval:org.mitre.oval:tst:2546"/>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="sendmail is Set-GID">
              <criterion comment="sendmail is Set-GID" negate="false" test_ref="oval:org.mitre.oval:tst:2545"/>
              <criterion comment="sendmail is Set-UID" negate="false" test_ref="oval:org.mitre.oval:tst:2546"/>
            </criteria>
            <criterion comment="sendmail listening" negate="false" test_ref="oval:org.mitre.oval:tst:2544"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:597" version="2" class="vulnerability">
      <metadata>
        <title>Denial of Service in Sendmail via the enhdnsbl Feature</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>Sendmail</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0688" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0688"/>
        <description>The DNS map code in Sendmail 8.12.8 and earlier, when using the "enhdnsbl" feature, does not properly initialize certain data structures, which allows remote attackers to cause a denial of service (process crash) via an invalid DNS response that causes Sendmail to free incorrect data.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-09-05T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-03-25T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:49.069-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:52:36.804-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criterion comment="sendmail version is less than 8.12.8-6.90" negate="false" test_ref="oval:org.mitre.oval:tst:2517"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="sendmail is listening to the network" negate="false" test_ref="oval:org.mitre.oval:tst:2516"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6" version="2" class="vulnerability">
      <metadata>
        <title>Common Unix Printing System Partial Print DOS</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>Common Unix Printing System</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0195" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0195"/>
        <description>CUPS before 1.1.19 allows remote attackers to cause a denial of service via a partial printing request to the IPP port (631), which does not time out.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-08-19T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-03-25T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:56.350-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:52:37.018-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criterion comment="cups version is less than 1.1.17-13.3" negate="false" test_ref="oval:org.mitre.oval:tst:3147"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="cupsd listens on the network" negate="false" test_ref="oval:org.mitre.oval:tst:3146"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:603" version="2" class="vulnerability">
      <metadata>
        <title>Sendmail BO in prescan Function</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>Sendmail</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0694" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0694"/>
        <description>The prescan function in Sendmail 8.12.9 allows remote attackers to execute arbitrary code via buffer overflow attacks, as demonstrated using the parseaddr function in parseaddr.c.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-09-21T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-03-25T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:24.124-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:52:37.318-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criterion comment="sendmail version is less than 8.12.8-9.90" negate="false" test_ref="oval:org.mitre.oval:tst:2518"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="Vulnerable Config">
            <criteria operator="AND" comment="sendmail is Set-UID">
              <criterion comment="sendmail is Set-UID" negate="false" test_ref="oval:org.mitre.oval:tst:2548"/>
              <criteria operator="OR" comment="sendmail is Set-UID">
                <criterion comment="sendmail is Set-UID" negate="false" test_ref="oval:org.mitre.oval:tst:2547"/>
                <criterion comment="sendmail is Set-UID" negate="false" test_ref="oval:org.mitre.oval:tst:2546"/>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="sendmail is Set-GID">
              <criterion comment="sendmail is Set-GID" negate="false" test_ref="oval:org.mitre.oval:tst:2545"/>
              <criterion comment="sendmail is Set-UID" negate="false" test_ref="oval:org.mitre.oval:tst:2546"/>
            </criteria>
            <criterion comment="sendmail listening" negate="false" test_ref="oval:org.mitre.oval:tst:2544"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:614" version="2" class="vulnerability">
      <metadata>
        <title>SqirrelMail Cross-site Scripting Vulnerabilities</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>SquirrelMail</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0160" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0160"/>
        <description>Multiple cross-site scripting (XSS) vulnerabilities in SquirrelMail before 1.2.11 allow remote attackers to inject arbitrary HTML code and steal information from a client's web browser.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-08-17T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-03-25T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:33.275-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:52:37.549-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
        <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
        <criterion comment="squirrelmail version is less than 1.2.11-1" negate="false" test_ref="oval:org.mitre.oval:tst:2499"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:619" version="2" class="vulnerability">
      <metadata>
        <title>UnZip 5.0 Directory Traversal Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>unzip</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0282" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0282"/>
        <description>Directory traversal vulnerability in UnZip 5.50 allows attackers to overwrite arbitrary files via invalid characters between two . (dot) characters, which are filtered and result in a ".." sequence.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-09-04T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-03-25T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:46.657-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:52:37.784-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criterion comment="unzip version is less than 5.50-33" negate="false" test_ref="oval:org.mitre.oval:tst:2498"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="/usr/bin/unzip is executable">
            <criterion comment="/usr/bin/unzip is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2497"/>
            <criterion comment="/usr/bin/unzip is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2496"/>
            <criterion comment="/usr/bin/unzip is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2495"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:631" version="2" class="vulnerability">
      <metadata>
        <title>up2date RPM GPG Signature Verification Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>up2date</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0546" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0546"/>
        <description>up2date 3.0.7 and 3.1.23 does not properly verify RPM GPG signatures, which could allow remote attackers to cause unsigned packages to be installed from the Red Hat Network, if that network is compromised.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-09-03T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-03-25T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:48.365-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:52:38.112-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criterion comment="up2date version is less than 3.1.23.1-5" negate="false" test_ref="oval:org.mitre.oval:tst:2489"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="rhnsd is running" negate="false" test_ref="oval:org.mitre.oval:tst:2488"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:634" version="2" class="vulnerability">
      <metadata>
        <title>vsftpd Fails to Integrate with TCP Wrappers</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>vsftpd</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0135" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0135"/>
        <description>vsftpd FTP daemon in Red Hat Linux 9 is not compiled against TCP wrappers (tcp_wrappers) but is installed as a standalone service, which inadvertently prevents vsftpd from restricting access as intended.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-08-11T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-03-25T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:23.164-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:52:38.322-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criterion comment="vsftpd version is less than 1.1.3-8" negate="false" test_ref="oval:org.mitre.oval:tst:2487"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="vsftpd is listening to the network" negate="false" test_ref="oval:org.mitre.oval:tst:2486"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:657" version="2" class="vulnerability">
      <metadata>
        <title>xinitd Memory Leak Invites Denial of Service Attack</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>xinetd</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0211" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0211"/>
        <description>Memory leak in xinetd 2.3.10 allows remote attackers to cause a denial of service (memory consumption) via a large number of rejected connections.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-08-18T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-03-25T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </modified>
            <modified date="2004-05-17T12:00:00.000-04:00" comment="Changed tested epoch in xinetd test rvt-253 to 2, based on testing.">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </modified>
            <status_change date="2004-06-16T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:40.150-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:52:38.517-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criterion comment="xinetd version is less than 2:2.3.11-1.9.0" negate="false" test_ref="oval:org.mitre.oval:tst:2467"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="xinetd is listening to the network" negate="false" test_ref="oval:org.mitre.oval:tst:2466"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:664" version="2" class="vulnerability">
      <metadata>
        <title>Code Execution Vulnerability in XPDF PDF Viewer</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>xpdf</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0434" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0434"/>
        <description>Various PDF viewers including (1) Adobe Acrobat 5.06 and (2) Xpdf 1.01 allow remote attackers to execute arbitrary commands via shell metacharacters in an embedded hyperlink.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-08-29T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-03-25T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-05-05T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:43.685-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:52:38.816-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criterion comment="xpdf version is less than 2.0.1-11" negate="false" test_ref="oval:org.mitre.oval:tst:2455"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="xpdf is executable">
            <criterion comment="xpdf is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2454"/>
            <criterion comment="xpdf is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2453"/>
            <criterion comment="xpdf is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2452"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:667" version="2" class="vulnerability">
      <metadata>
        <title>ypserv NIS Server Denial of Service</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>ypserv</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0251" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0251"/>
        <description>ypserv NIS server before 2.7 allows remote attackers to cause a denial of service via a TCP client request that does not respond to the server, which causes ypserv to block.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-08-29T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-03-25T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:43.920-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:52:39.014-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criterion comment="ypserv version is less than 2.8-0.9E" negate="false" test_ref="oval:org.mitre.oval:tst:2451"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="ypserv is listening on the network" negate="false" test_ref="oval:org.mitre.oval:tst:2450"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:69" version="2" class="vulnerability">
      <metadata>
        <title>Off-by-one Vulnerabilities in Ethereal 0.9.11</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>Ethereal</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0356" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0356"/>
        <description>Multiple off-by-one vulnerabilities in Ethereal 0.9.11 and earlier allow remote attackers to cause a denial of service and possibly execute arbitrary code via the (1) AIM, (2) GIOP Gryphon, (3) OSPF, (4) PPTP, (5) Quake, (6) Quake2, (7) Quake3, (8) Rsync, (9) SMB, (10) SMPP, and (11) TSP dissectors, which do not properly use the tvb_get_nstringz and tvb_get_nstringz0 functions.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-08-29T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-03-25T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:47.572-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:52:39.216-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
        <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
        <criteria operator="OR" comment="Vulnerable Config">
          <criterion comment="ethereal version is less than 0.9.13-1.90.1" negate="false" test_ref="oval:org.mitre.oval:tst:2985"/>
          <criterion comment="ethereal-gnome version is less than 0.9.13-1.90.1" negate="false" test_ref="oval:org.mitre.oval:tst:2984"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:73" version="2" class="vulnerability">
      <metadata>
        <title>Integer Overflow Vulnerabilities in Ethereal 0.9.11</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>Ethereal</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0357" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0357"/>
        <description>Multiple integer overflow vulnerabilities in Ethereal 0.9.11 and earlier allow remote attackers to cause a denial of service and possibly execute arbitrary code via the (1) Mount and (2) PPP dissectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-08-29T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-03-25T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:55.945-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:52:39.569-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
        <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
        <criteria operator="OR" comment="Vulnerable Config">
          <criterion comment="ethereal version is less than 0.9.13-1.90.1" negate="false" test_ref="oval:org.mitre.oval:tst:2985"/>
          <criterion comment="ethereal-gnome version is less than 0.9.13-1.90.1" negate="false" test_ref="oval:org.mitre.oval:tst:2984"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:75" version="2" class="vulnerability">
      <metadata>
        <title>Ethereal 0.9.12 Vulnerability in DCERPC Dissector</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>Ethereal</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0428" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0428"/>
        <description>Unknown vulnerability in the DCERPC (DCE/RPC) dissector in Ethereal 0.9.12 and earlier allows remote attackers to cause a denial of service (memory consumption) via a certain NDR string.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-08-29T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-03-25T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:25.279-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:52:39.950-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
        <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
        <criteria operator="OR" comment="Vulnerable Config">
          <criterion comment="ethereal version is less than 0.9.13-1.90.1" negate="false" test_ref="oval:org.mitre.oval:tst:2985"/>
          <criterion comment="ethereal-gnome version is less than 0.9.13-1.90.1" negate="false" test_ref="oval:org.mitre.oval:tst:2984"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:803" version="2" class="vulnerability">
      <metadata>
        <title>RedHat Code Execution and DoS Vulnerabilities in PWLib</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>PWLib</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0097" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0097"/>
        <description>Multiple vulnerabilities in PWLib before 1.6.0 allow remote attackers to cause a denial of service and possibly execute arbitrary code, as demonstrated by the NISCC/OUSPG PROTOS test suite for the H.225 protocol.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-03-20T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Added a program_name element to rlt-217">
              <contributor organization="The MITRE Corporation">Matt Busby</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:57.185-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:52:40.547-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criterion comment="pwlib version is less than 1.4.7-4.1" negate="false" test_ref="oval:org.mitre.oval:tst:2321"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="a program is listening on TCP or UDP port 1720" negate="false" test_ref="oval:org.mitre.oval:tst:2320"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:804" version="2" class="vulnerability">
      <metadata>
        <title>Red Hat netpbm File Overwrite Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>netpbm</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0924" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0924"/>
        <description>netpbm 9.25 and earlier does not properly create temporary files, which allows local users to overwrite arbitrary files.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-03-20T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="The MITRE Corporation">Matt Busby</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:42:00.100-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:52:42.229-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criteria operator="OR" comment="Vulnerable Config">
            <criterion comment="netpbm version is less than 9.24-10.90.1" negate="false" test_ref="oval:org.mitre.oval:tst:2319"/>
            <criterion comment="netpbm-devel version is less than 9.24-10.90.1" negate="false" test_ref="oval:org.mitre.oval:tst:2318"/>
            <criterion comment="netpbm-progs version is less than 9.24-10.90.1" negate="false" test_ref="oval:org.mitre.oval:tst:2317"/>
          </criteria>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="Vulnerable configuration">
            <criteria operator="OR" comment="/usr/bin/411toppm is executable">
              <criterion comment="/usr/bin/411toppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2316"/>
              <criterion comment="/usr/bin/411toppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2315"/>
              <criterion comment="/usr/bin/411toppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2314"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/asciitopgm is executable">
              <criterion comment="/usr/bin/asciitopgm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2313"/>
              <criterion comment="/usr/bin/asciitopgm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2312"/>
              <criterion comment="/usr/bin/asciitopgm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2311"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/atktopbm is executable">
              <criterion comment="/usr/bin/atktopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2310"/>
              <criterion comment="/usr/bin/atktopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2309"/>
              <criterion comment="/usr/bin/atktopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2308"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/bioradtopgm is executable">
              <criterion comment="/usr/bin/bioradtopgm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2307"/>
              <criterion comment="/usr/bin/bioradtopgm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2306"/>
              <criterion comment="/usr/bin/bioradtopgm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2305"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/bmptoppm is executable">
              <criterion comment="/usr/bin/bmptoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2304"/>
              <criterion comment="/usr/bin/bmptoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2303"/>
              <criterion comment="/usr/bin/bmptoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2302"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/brushtopbm is executable">
              <criterion comment="/usr/bin/brushtopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2301"/>
              <criterion comment="/usr/bin/brushtopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2300"/>
              <criterion comment="/usr/bin/brushtopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2299"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/cmuwmtopbm is executable">
              <criterion comment="/usr/bin/cmuwmtopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2298"/>
              <criterion comment="/usr/bin/cmuwmtopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2297"/>
              <criterion comment="/usr/bin/cmuwmtopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2296"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/eyuvtoppm is executable">
              <criterion comment="/usr/bin/eyuvtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2295"/>
              <criterion comment="/usr/bin/eyuvtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2294"/>
              <criterion comment="/usr/bin/eyuvtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2293"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/fiascotopnm is executable">
              <criterion comment="/usr/bin/fiascotopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2292"/>
              <criterion comment="/usr/bin/fiascotopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2291"/>
              <criterion comment="/usr/bin/fiascotopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2290"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/fitstopnm is executable">
              <criterion comment="/usr/bin/fitstopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2289"/>
              <criterion comment="/usr/bin/fitstopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2288"/>
              <criterion comment="/usr/bin/fitstopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2287"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/fstopgm is executable">
              <criterion comment="/usr/bin/fstopgm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2286"/>
              <criterion comment="/usr/bin/fstopgm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2285"/>
              <criterion comment="/usr/bin/fstopgm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2284"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/g3topbm is executable">
              <criterion comment="/usr/bin/g3topbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2283"/>
              <criterion comment="/usr/bin/g3topbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2282"/>
              <criterion comment="/usr/bin/g3topbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2281"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/gemtopbm is executable">
              <criterion comment="/usr/bin/gemtopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2280"/>
              <criterion comment="/usr/bin/gemtopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2279"/>
              <criterion comment="/usr/bin/gemtopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2278"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/gemtopnm is executable">
              <criterion comment="/usr/bin/gemtopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2277"/>
              <criterion comment="/usr/bin/gemtopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2276"/>
              <criterion comment="/usr/bin/gemtopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2275"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/giftopnm is executable">
              <criterion comment="/usr/bin/giftopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2274"/>
              <criterion comment="/usr/bin/giftopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2273"/>
              <criterion comment="/usr/bin/giftopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2272"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/gouldtoppm is executable">
              <criterion comment="/usr/bin/gouldtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2271"/>
              <criterion comment="/usr/bin/gouldtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2270"/>
              <criterion comment="/usr/bin/gouldtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2269"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/hipstopgm is executable">
              <criterion comment="/usr/bin/hipstopgm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2268"/>
              <criterion comment="/usr/bin/hipstopgm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2267"/>
              <criterion comment="/usr/bin/hipstopgm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2266"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/hpcdtoppm is executable">
              <criterion comment="/usr/bin/hpcdtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2265"/>
              <criterion comment="/usr/bin/hpcdtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2264"/>
              <criterion comment="/usr/bin/hpcdtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2263"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/icontopbm is executable">
              <criterion comment="/usr/bin/icontopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2262"/>
              <criterion comment="/usr/bin/icontopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2261"/>
              <criterion comment="/usr/bin/icontopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2260"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ilbmtoppm is executable">
              <criterion comment="/usr/bin/ilbmtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2259"/>
              <criterion comment="/usr/bin/ilbmtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2258"/>
              <criterion comment="/usr/bin/ilbmtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2257"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/imgtoppm is executable">
              <criterion comment="/usr/bin/imgtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2256"/>
              <criterion comment="/usr/bin/imgtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2255"/>
              <criterion comment="/usr/bin/imgtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2254"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/jpegtopnm is executable">
              <criterion comment="/usr/bin/jpegtopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2253"/>
              <criterion comment="/usr/bin/jpegtopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2252"/>
              <criterion comment="/usr/bin/jpegtopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2251"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/leaftoppm is executable">
              <criterion comment="/usr/bin/leaftoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2250"/>
              <criterion comment="/usr/bin/leaftoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2249"/>
              <criterion comment="/usr/bin/leaftoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2248"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/lispmtopgm is executable">
              <criterion comment="/usr/bin/lispmtopgm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2247"/>
              <criterion comment="/usr/bin/lispmtopgm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2246"/>
              <criterion comment="/usr/bin/lispmtopgm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2245"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/macptopbm is executable">
              <criterion comment="/usr/bin/macptopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2244"/>
              <criterion comment="/usr/bin/macptopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2243"/>
              <criterion comment="/usr/bin/macptopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2242"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/mdatopbm is executable">
              <criterion comment="/usr/bin/mdatopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2241"/>
              <criterion comment="/usr/bin/mdatopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2240"/>
              <criterion comment="/usr/bin/mdatopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2239"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/mgrtopbm is executable">
              <criterion comment="/usr/bin/mgrtopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2238"/>
              <criterion comment="/usr/bin/mgrtopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2237"/>
              <criterion comment="/usr/bin/mgrtopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2236"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/mtvtoppm is executable">
              <criterion comment="/usr/bin/mtvtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2235"/>
              <criterion comment="/usr/bin/mtvtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2234"/>
              <criterion comment="/usr/bin/mtvtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2233"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/neotoppm is executable">
              <criterion comment="/usr/bin/neotoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2232"/>
              <criterion comment="/usr/bin/neotoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2231"/>
              <criterion comment="/usr/bin/neotoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2230"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/palmtopnm is executable">
              <criterion comment="/usr/bin/palmtopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2229"/>
              <criterion comment="/usr/bin/palmtopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2228"/>
              <criterion comment="/usr/bin/palmtopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2227"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pamchannel is executable">
              <criterion comment="/usr/bin/pamchannel is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2226"/>
              <criterion comment="/usr/bin/pamchannel is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2225"/>
              <criterion comment="/usr/bin/pamchannel is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2224"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pamcut is executable">
              <criterion comment="/usr/bin/pamcut is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2223"/>
              <criterion comment="/usr/bin/pamcut is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2222"/>
              <criterion comment="/usr/bin/pamcut is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2221"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pamdeinterlace is executable">
              <criterion comment="/usr/bin/pamdeinterlace is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2220"/>
              <criterion comment="/usr/bin/pamdeinterlace is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2219"/>
              <criterion comment="/usr/bin/pamdeinterlace is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2218"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pamfile is executable">
              <criterion comment="/usr/bin/pamfile is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2217"/>
              <criterion comment="/usr/bin/pamfile is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2216"/>
              <criterion comment="/usr/bin/pamfile is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2215"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pamoil is executable">
              <criterion comment="/usr/bin/pamoil is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2214"/>
              <criterion comment="/usr/bin/pamoil is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2213"/>
              <criterion comment="/usr/bin/pamoil is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2212"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pamstretch is executable">
              <criterion comment="/usr/bin/pamstretch is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2211"/>
              <criterion comment="/usr/bin/pamstretch is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2210"/>
              <criterion comment="/usr/bin/pamstretch is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2209"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pamtopnm is executable">
              <criterion comment="/usr/bin/pamtopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2208"/>
              <criterion comment="/usr/bin/pamtopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2207"/>
              <criterion comment="/usr/bin/pamtopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2206"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pbmclean is executable">
              <criterion comment="/usr/bin/pbmclean is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2205"/>
              <criterion comment="/usr/bin/pbmclean is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2204"/>
              <criterion comment="/usr/bin/pbmclean is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2203"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pbmlife is executable">
              <criterion comment="/usr/bin/pbmlife is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2202"/>
              <criterion comment="/usr/bin/pbmlife is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2201"/>
              <criterion comment="/usr/bin/pbmlife is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2200"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pbmmake is executable">
              <criterion comment="/usr/bin/pbmmake is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2199"/>
              <criterion comment="/usr/bin/pbmmake is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2198"/>
              <criterion comment="/usr/bin/pbmmake is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2197"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pbmmask is executable">
              <criterion comment="/usr/bin/pbmmask is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2196"/>
              <criterion comment="/usr/bin/pbmmask is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2195"/>
              <criterion comment="/usr/bin/pbmmask is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2194"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pbmpage is executable">
              <criterion comment="/usr/bin/pbmpage is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2193"/>
              <criterion comment="/usr/bin/pbmpage is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2192"/>
              <criterion comment="/usr/bin/pbmpage is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2191"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pbmpscale is executable">
              <criterion comment="/usr/bin/pbmpscale is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2190"/>
              <criterion comment="/usr/bin/pbmpscale is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2189"/>
              <criterion comment="/usr/bin/pbmpscale is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2188"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pbmreduce is executable">
              <criterion comment="/usr/bin/pbmreduce is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2187"/>
              <criterion comment="/usr/bin/pbmreduce is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2186"/>
              <criterion comment="/usr/bin/pbmreduce is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2185"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pbmtext is executable">
              <criterion comment="/usr/bin/pbmtext is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2184"/>
              <criterion comment="/usr/bin/pbmtext is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2183"/>
              <criterion comment="/usr/bin/pbmtext is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2182"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pbmto10x is executable">
              <criterion comment="/usr/bin/pbmto10x is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2181"/>
              <criterion comment="/usr/bin/pbmto10x is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2180"/>
              <criterion comment="/usr/bin/pbmto10x is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2179"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pbmto4425 is executable">
              <criterion comment="/usr/bin/pbmto4425 is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2178"/>
              <criterion comment="/usr/bin/pbmto4425 is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2177"/>
              <criterion comment="/usr/bin/pbmto4425 is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2176"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pbmtoascii is executable">
              <criterion comment="/usr/bin/pbmtoascii is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2175"/>
              <criterion comment="/usr/bin/pbmtoascii is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2174"/>
              <criterion comment="/usr/bin/pbmtoascii is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2173"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pbmtoatk is executable">
              <criterion comment="/usr/bin/pbmtoatk is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2172"/>
              <criterion comment="/usr/bin/pbmtoatk is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2171"/>
              <criterion comment="/usr/bin/pbmtoatk is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2170"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pbmtobbnbg is executable">
              <criterion comment="/usr/bin/pbmtobbnbg is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2169"/>
              <criterion comment="/usr/bin/pbmtobbnbg is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2168"/>
              <criterion comment="/usr/bin/pbmtobbnbg is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2167"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pbmtocmuwm is executable">
              <criterion comment="/usr/bin/pbmtocmuwm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2166"/>
              <criterion comment="/usr/bin/pbmtocmuwm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2165"/>
              <criterion comment="/usr/bin/pbmtocmuwm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2164"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pbmtoepsi is executable">
              <criterion comment="/usr/bin/pbmtoepsi is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2163"/>
              <criterion comment="/usr/bin/pbmtoepsi is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2162"/>
              <criterion comment="/usr/bin/pbmtoepsi is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2161"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pbmtoepson is executable">
              <criterion comment="/usr/bin/pbmtoepson is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2160"/>
              <criterion comment="/usr/bin/pbmtoepson is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2159"/>
              <criterion comment="/usr/bin/pbmtoepson is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2158"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pbmtog3 is executable">
              <criterion comment="/usr/bin/pbmtog3 is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2157"/>
              <criterion comment="/usr/bin/pbmtog3 is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2156"/>
              <criterion comment="/usr/bin/pbmtog3 is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2155"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pbmtogem is executable">
              <criterion comment="/usr/bin/pbmtogem is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2154"/>
              <criterion comment="/usr/bin/pbmtogem is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2153"/>
              <criterion comment="/usr/bin/pbmtogem is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2152"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pbmtogo is executable">
              <criterion comment="/usr/bin/pbmtogo is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2151"/>
              <criterion comment="/usr/bin/pbmtogo is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2150"/>
              <criterion comment="/usr/bin/pbmtogo is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2149"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pbmtoicon is executable">
              <criterion comment="/usr/bin/pbmtoicon is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2148"/>
              <criterion comment="/usr/bin/pbmtoicon is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2147"/>
              <criterion comment="/usr/bin/pbmtoicon is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2146"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pbmtolj is executable">
              <criterion comment="/usr/bin/pbmtolj is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2145"/>
              <criterion comment="/usr/bin/pbmtolj is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2144"/>
              <criterion comment="/usr/bin/pbmtolj is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2143"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pbmtoln03 is executable">
              <criterion comment="/usr/bin/pbmtoln03 is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2142"/>
              <criterion comment="/usr/bin/pbmtoln03 is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2141"/>
              <criterion comment="/usr/bin/pbmtoln03 is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2140"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pbmtolps is executable">
              <criterion comment="/usr/bin/pbmtolps is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2139"/>
              <criterion comment="/usr/bin/pbmtolps is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2138"/>
              <criterion comment="/usr/bin/pbmtolps is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2137"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pbmtomacp is executable">
              <criterion comment="/usr/bin/pbmtomacp is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2136"/>
              <criterion comment="/usr/bin/pbmtomacp is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2135"/>
              <criterion comment="/usr/bin/pbmtomacp is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2134"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pbmtomda is executable">
              <criterion comment="/usr/bin/pbmtomda is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2133"/>
              <criterion comment="/usr/bin/pbmtomda is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2132"/>
              <criterion comment="/usr/bin/pbmtomda is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2131"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pbmtomgr is executable">
              <criterion comment="/usr/bin/pbmtomgr is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2130"/>
              <criterion comment="/usr/bin/pbmtomgr is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2129"/>
              <criterion comment="/usr/bin/pbmtomgr is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2128"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pbmtonokia is executable">
              <criterion comment="/usr/bin/pbmtonokia is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2127"/>
              <criterion comment="/usr/bin/pbmtonokia is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2126"/>
              <criterion comment="/usr/bin/pbmtonokia is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2125"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pbmtopgm is executable">
              <criterion comment="/usr/bin/pbmtopgm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2124"/>
              <criterion comment="/usr/bin/pbmtopgm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2123"/>
              <criterion comment="/usr/bin/pbmtopgm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2122"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pbmtopi3 is executable">
              <criterion comment="/usr/bin/pbmtopi3 is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2121"/>
              <criterion comment="/usr/bin/pbmtopi3 is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2120"/>
              <criterion comment="/usr/bin/pbmtopi3 is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2119"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pbmtopk is executable">
              <criterion comment="/usr/bin/pbmtopk is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2118"/>
              <criterion comment="/usr/bin/pbmtopk is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2117"/>
              <criterion comment="/usr/bin/pbmtopk is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2116"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pbmtoplot is executable">
              <criterion comment="/usr/bin/pbmtoplot is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2115"/>
              <criterion comment="/usr/bin/pbmtoplot is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2114"/>
              <criterion comment="/usr/bin/pbmtoplot is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2113"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pbmtoppa is executable">
              <criterion comment="/usr/bin/pbmtoppa is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2112"/>
              <criterion comment="/usr/bin/pbmtoppa is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2111"/>
              <criterion comment="/usr/bin/pbmtoppa is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2110"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pbmtopsg3 is executable">
              <criterion comment="/usr/bin/pbmtopsg3 is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2109"/>
              <criterion comment="/usr/bin/pbmtopsg3 is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2108"/>
              <criterion comment="/usr/bin/pbmtopsg3 is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2107"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pbmtoptx is executable">
              <criterion comment="/usr/bin/pbmtoptx is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2106"/>
              <criterion comment="/usr/bin/pbmtoptx is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2105"/>
              <criterion comment="/usr/bin/pbmtoptx is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2104"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pbmtowbmp is executable">
              <criterion comment="/usr/bin/pbmtowbmp is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2103"/>
              <criterion comment="/usr/bin/pbmtowbmp is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2102"/>
              <criterion comment="/usr/bin/pbmtowbmp is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2101"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pbmtox10bm is executable">
              <criterion comment="/usr/bin/pbmtox10bm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2100"/>
              <criterion comment="/usr/bin/pbmtox10bm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2099"/>
              <criterion comment="/usr/bin/pbmtox10bm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2098"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pbmtoxbm is executable">
              <criterion comment="/usr/bin/pbmtoxbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2097"/>
              <criterion comment="/usr/bin/pbmtoxbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2096"/>
              <criterion comment="/usr/bin/pbmtoxbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2095"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pbmtoybm is executable">
              <criterion comment="/usr/bin/pbmtoybm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2094"/>
              <criterion comment="/usr/bin/pbmtoybm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2093"/>
              <criterion comment="/usr/bin/pbmtoybm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2092"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pbmtozinc is executable">
              <criterion comment="/usr/bin/pbmtozinc is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2091"/>
              <criterion comment="/usr/bin/pbmtozinc is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2090"/>
              <criterion comment="/usr/bin/pbmtozinc is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2089"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pbmupc is executable">
              <criterion comment="/usr/bin/pbmupc is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2088"/>
              <criterion comment="/usr/bin/pbmupc is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2087"/>
              <criterion comment="/usr/bin/pbmupc is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2086"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pcxtoppm is executable">
              <criterion comment="/usr/bin/pcxtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2085"/>
              <criterion comment="/usr/bin/pcxtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2084"/>
              <criterion comment="/usr/bin/pcxtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2083"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pgmbentley is executable">
              <criterion comment="/usr/bin/pgmbentley is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2082"/>
              <criterion comment="/usr/bin/pgmbentley is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2081"/>
              <criterion comment="/usr/bin/pgmbentley is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2080"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pgmcrater is executable">
              <criterion comment="/usr/bin/pgmcrater is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2079"/>
              <criterion comment="/usr/bin/pgmcrater is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2078"/>
              <criterion comment="/usr/bin/pgmcrater is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2077"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pgmedge is executable">
              <criterion comment="/usr/bin/pgmedge is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2076"/>
              <criterion comment="/usr/bin/pgmedge is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2075"/>
              <criterion comment="/usr/bin/pgmedge is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2074"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pgmenhance is executable">
              <criterion comment="/usr/bin/pgmenhance is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2073"/>
              <criterion comment="/usr/bin/pgmenhance is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2072"/>
              <criterion comment="/usr/bin/pgmenhance is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2071"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pgmhist is executable">
              <criterion comment="/usr/bin/pgmhist is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2070"/>
              <criterion comment="/usr/bin/pgmhist is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2069"/>
              <criterion comment="/usr/bin/pgmhist is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2068"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pgmkernel is executable">
              <criterion comment="/usr/bin/pgmkernel is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2067"/>
              <criterion comment="/usr/bin/pgmkernel is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2066"/>
              <criterion comment="/usr/bin/pgmkernel is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2065"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pgmnoise is executable">
              <criterion comment="/usr/bin/pgmnoise is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2064"/>
              <criterion comment="/usr/bin/pgmnoise is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2063"/>
              <criterion comment="/usr/bin/pgmnoise is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2062"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pgmnorm is executable">
              <criterion comment="/usr/bin/pgmnorm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2061"/>
              <criterion comment="/usr/bin/pgmnorm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2060"/>
              <criterion comment="/usr/bin/pgmnorm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2059"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pgmoil is executable">
              <criterion comment="/usr/bin/pgmoil is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2058"/>
              <criterion comment="/usr/bin/pgmoil is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2057"/>
              <criterion comment="/usr/bin/pgmoil is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2056"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pgmramp is executable">
              <criterion comment="/usr/bin/pgmramp is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2055"/>
              <criterion comment="/usr/bin/pgmramp is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2054"/>
              <criterion comment="/usr/bin/pgmramp is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2053"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pgmslice is executable">
              <criterion comment="/usr/bin/pgmslice is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2052"/>
              <criterion comment="/usr/bin/pgmslice is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2051"/>
              <criterion comment="/usr/bin/pgmslice is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2050"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pgmtexture is executable">
              <criterion comment="/usr/bin/pgmtexture is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2049"/>
              <criterion comment="/usr/bin/pgmtexture is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2048"/>
              <criterion comment="/usr/bin/pgmtexture is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2047"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pgmtofs is executable">
              <criterion comment="/usr/bin/pgmtofs is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2046"/>
              <criterion comment="/usr/bin/pgmtofs is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2045"/>
              <criterion comment="/usr/bin/pgmtofs is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2044"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pgmtolispm is executable">
              <criterion comment="/usr/bin/pgmtolispm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2043"/>
              <criterion comment="/usr/bin/pgmtolispm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2042"/>
              <criterion comment="/usr/bin/pgmtolispm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2041"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pgmtopbm is executable">
              <criterion comment="/usr/bin/pgmtopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2040"/>
              <criterion comment="/usr/bin/pgmtopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2039"/>
              <criterion comment="/usr/bin/pgmtopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2038"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pgmtoppm is executable">
              <criterion comment="/usr/bin/pgmtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2037"/>
              <criterion comment="/usr/bin/pgmtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2036"/>
              <criterion comment="/usr/bin/pgmtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2035"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pi1toppm is executable">
              <criterion comment="/usr/bin/pi1toppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2034"/>
              <criterion comment="/usr/bin/pi1toppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2033"/>
              <criterion comment="/usr/bin/pi1toppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2032"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pi3topbm is executable">
              <criterion comment="/usr/bin/pi3topbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2031"/>
              <criterion comment="/usr/bin/pi3topbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2030"/>
              <criterion comment="/usr/bin/pi3topbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2029"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pjtoppm is executable">
              <criterion comment="/usr/bin/pjtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2028"/>
              <criterion comment="/usr/bin/pjtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2027"/>
              <criterion comment="/usr/bin/pjtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2026"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pktopbm is executable">
              <criterion comment="/usr/bin/pktopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2025"/>
              <criterion comment="/usr/bin/pktopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2024"/>
              <criterion comment="/usr/bin/pktopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2023"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pngtopnm is executable">
              <criterion comment="/usr/bin/pngtopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2022"/>
              <criterion comment="/usr/bin/pngtopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2021"/>
              <criterion comment="/usr/bin/pngtopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2020"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmalias is executable">
              <criterion comment="/usr/bin/pnmalias is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2019"/>
              <criterion comment="/usr/bin/pnmalias is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2018"/>
              <criterion comment="/usr/bin/pnmalias is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2017"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmarith is executable">
              <criterion comment="/usr/bin/pnmarith is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2016"/>
              <criterion comment="/usr/bin/pnmarith is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2015"/>
              <criterion comment="/usr/bin/pnmarith is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2014"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmcat is executable">
              <criterion comment="/usr/bin/pnmcat is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2013"/>
              <criterion comment="/usr/bin/pnmcat is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2012"/>
              <criterion comment="/usr/bin/pnmcat is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2011"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmcolormap is executable">
              <criterion comment="/usr/bin/pnmcolormap is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2010"/>
              <criterion comment="/usr/bin/pnmcolormap is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2009"/>
              <criterion comment="/usr/bin/pnmcolormap is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2008"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmcomp is executable">
              <criterion comment="/usr/bin/pnmcomp is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2007"/>
              <criterion comment="/usr/bin/pnmcomp is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2006"/>
              <criterion comment="/usr/bin/pnmcomp is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2005"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmconvol is executable">
              <criterion comment="/usr/bin/pnmconvol is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2004"/>
              <criterion comment="/usr/bin/pnmconvol is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2003"/>
              <criterion comment="/usr/bin/pnmconvol is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2002"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmcrop is executable">
              <criterion comment="/usr/bin/pnmcrop is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2001"/>
              <criterion comment="/usr/bin/pnmcrop is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2000"/>
              <criterion comment="/usr/bin/pnmcrop is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1999"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmcut is executable">
              <criterion comment="/usr/bin/pnmcut is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1998"/>
              <criterion comment="/usr/bin/pnmcut is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1997"/>
              <criterion comment="/usr/bin/pnmcut is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1996"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmdepth is executable">
              <criterion comment="/usr/bin/pnmdepth is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1995"/>
              <criterion comment="/usr/bin/pnmdepth is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1994"/>
              <criterion comment="/usr/bin/pnmdepth is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1993"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmenlarge is executable">
              <criterion comment="/usr/bin/pnmenlarge is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1992"/>
              <criterion comment="/usr/bin/pnmenlarge is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1991"/>
              <criterion comment="/usr/bin/pnmenlarge is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1990"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmfile is executable">
              <criterion comment="/usr/bin/pnmfile is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1989"/>
              <criterion comment="/usr/bin/pnmfile is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1988"/>
              <criterion comment="/usr/bin/pnmfile is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1987"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmflip is executable">
              <criterion comment="/usr/bin/pnmflip is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1986"/>
              <criterion comment="/usr/bin/pnmflip is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1985"/>
              <criterion comment="/usr/bin/pnmflip is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1984"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmgamma is executable">
              <criterion comment="/usr/bin/pnmgamma is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1983"/>
              <criterion comment="/usr/bin/pnmgamma is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1982"/>
              <criterion comment="/usr/bin/pnmgamma is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1981"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmhisteq is executable">
              <criterion comment="/usr/bin/pnmhisteq is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1980"/>
              <criterion comment="/usr/bin/pnmhisteq is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1979"/>
              <criterion comment="/usr/bin/pnmhisteq is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1978"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmhistmap is executable">
              <criterion comment="/usr/bin/pnmhistmap is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1977"/>
              <criterion comment="/usr/bin/pnmhistmap is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1976"/>
              <criterion comment="/usr/bin/pnmhistmap is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1975"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnminterp is executable">
              <criterion comment="/usr/bin/pnminterp is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1974"/>
              <criterion comment="/usr/bin/pnminterp is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1973"/>
              <criterion comment="/usr/bin/pnminterp is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1972"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnminvert is executable">
              <criterion comment="/usr/bin/pnminvert is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1971"/>
              <criterion comment="/usr/bin/pnminvert is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1970"/>
              <criterion comment="/usr/bin/pnminvert is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1969"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmmontage is executable">
              <criterion comment="/usr/bin/pnmmontage is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1968"/>
              <criterion comment="/usr/bin/pnmmontage is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1967"/>
              <criterion comment="/usr/bin/pnmmontage is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1966"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmnlfilt is executable">
              <criterion comment="/usr/bin/pnmnlfilt is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1965"/>
              <criterion comment="/usr/bin/pnmnlfilt is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1964"/>
              <criterion comment="/usr/bin/pnmnlfilt is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1963"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmnoraw is executable">
              <criterion comment="/usr/bin/pnmnoraw is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1962"/>
              <criterion comment="/usr/bin/pnmnoraw is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1961"/>
              <criterion comment="/usr/bin/pnmnoraw is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1960"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmpad is executable">
              <criterion comment="/usr/bin/pnmpad is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1959"/>
              <criterion comment="/usr/bin/pnmpad is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1958"/>
              <criterion comment="/usr/bin/pnmpad is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1957"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmpaste is executable">
              <criterion comment="/usr/bin/pnmpaste is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1956"/>
              <criterion comment="/usr/bin/pnmpaste is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1955"/>
              <criterion comment="/usr/bin/pnmpaste is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1954"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmpsnr is executable">
              <criterion comment="/usr/bin/pnmpsnr is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1953"/>
              <criterion comment="/usr/bin/pnmpsnr is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1952"/>
              <criterion comment="/usr/bin/pnmpsnr is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1951"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmremap is executable">
              <criterion comment="/usr/bin/pnmremap is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1950"/>
              <criterion comment="/usr/bin/pnmremap is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1949"/>
              <criterion comment="/usr/bin/pnmremap is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1948"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmrotate is executable">
              <criterion comment="/usr/bin/pnmrotate is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1947"/>
              <criterion comment="/usr/bin/pnmrotate is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1946"/>
              <criterion comment="/usr/bin/pnmrotate is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1945"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmscale is executable">
              <criterion comment="/usr/bin/pnmscale is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1944"/>
              <criterion comment="/usr/bin/pnmscale is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1943"/>
              <criterion comment="/usr/bin/pnmscale is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1942"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmtopict is executable">
              <criterion comment="/usr/bin/ppmtopict is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1941"/>
              <criterion comment="/usr/bin/ppmtopict is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1940"/>
              <criterion comment="/usr/bin/ppmtopict is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1939"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmtopj is executable">
              <criterion comment="/usr/bin/ppmtopj is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1938"/>
              <criterion comment="/usr/bin/ppmtopj is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1937"/>
              <criterion comment="/usr/bin/ppmtopj is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1936"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmtopjxl is executable">
              <criterion comment="/usr/bin/ppmtopjxl is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1935"/>
              <criterion comment="/usr/bin/ppmtopjxl is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1934"/>
              <criterion comment="/usr/bin/ppmtopjxl is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1933"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmtopuzz is executable">
              <criterion comment="/usr/bin/ppmtopuzz is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1932"/>
              <criterion comment="/usr/bin/ppmtopuzz is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1931"/>
              <criterion comment="/usr/bin/ppmtopuzz is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1930"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmtorgb3 is executable">
              <criterion comment="/usr/bin/ppmtorgb3 is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1929"/>
              <criterion comment="/usr/bin/ppmtorgb3 is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1928"/>
              <criterion comment="/usr/bin/ppmtorgb3 is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1927"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmtosixel is executable">
              <criterion comment="/usr/bin/ppmtosixel is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1926"/>
              <criterion comment="/usr/bin/ppmtosixel is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1925"/>
              <criterion comment="/usr/bin/ppmtosixel is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1924"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmtotga is executable">
              <criterion comment="/usr/bin/ppmtotga is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1923"/>
              <criterion comment="/usr/bin/ppmtotga is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1922"/>
              <criterion comment="/usr/bin/ppmtotga is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1921"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmtouil is executable">
              <criterion comment="/usr/bin/ppmtouil is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1920"/>
              <criterion comment="/usr/bin/ppmtouil is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1919"/>
              <criterion comment="/usr/bin/ppmtouil is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1918"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmtowinicon is executable">
              <criterion comment="/usr/bin/ppmtowinicon is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1917"/>
              <criterion comment="/usr/bin/ppmtowinicon is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1916"/>
              <criterion comment="/usr/bin/ppmtowinicon is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1915"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmtoxpm is executable">
              <criterion comment="/usr/bin/ppmtoxpm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1914"/>
              <criterion comment="/usr/bin/ppmtoxpm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1913"/>
              <criterion comment="/usr/bin/ppmtoxpm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1912"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmtoyuv is executable">
              <criterion comment="/usr/bin/ppmtoyuv is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1911"/>
              <criterion comment="/usr/bin/ppmtoyuv is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1910"/>
              <criterion comment="/usr/bin/ppmtoyuv is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1909"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmtoyuvsplit is executable">
              <criterion comment="/usr/bin/ppmtoyuvsplit is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1908"/>
              <criterion comment="/usr/bin/ppmtoyuvsplit is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1907"/>
              <criterion comment="/usr/bin/ppmtoyuvsplit is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1906"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmtv is executable">
              <criterion comment="/usr/bin/ppmtv is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1905"/>
              <criterion comment="/usr/bin/ppmtv is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1904"/>
              <criterion comment="/usr/bin/ppmtv is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1903"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/psidtopgm is executable">
              <criterion comment="/usr/bin/psidtopgm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1902"/>
              <criterion comment="/usr/bin/psidtopgm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1901"/>
              <criterion comment="/usr/bin/psidtopgm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1900"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pstopnm is executable">
              <criterion comment="/usr/bin/pstopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1899"/>
              <criterion comment="/usr/bin/pstopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1898"/>
              <criterion comment="/usr/bin/pstopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1897"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/qrttoppm is executable">
              <criterion comment="/usr/bin/qrttoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1896"/>
              <criterion comment="/usr/bin/qrttoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1895"/>
              <criterion comment="/usr/bin/qrttoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1894"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/rasttopnm is executable">
              <criterion comment="/usr/bin/rasttopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1893"/>
              <criterion comment="/usr/bin/rasttopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1892"/>
              <criterion comment="/usr/bin/rasttopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1891"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/rawtopgm is executable">
              <criterion comment="/usr/bin/rawtopgm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1890"/>
              <criterion comment="/usr/bin/rawtopgm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1889"/>
              <criterion comment="/usr/bin/rawtopgm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1888"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/rawtoppm is executable">
              <criterion comment="/usr/bin/rawtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1887"/>
              <criterion comment="/usr/bin/rawtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1886"/>
              <criterion comment="/usr/bin/rawtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1885"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/rgb3toppm is executable">
              <criterion comment="/usr/bin/rgb3toppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1884"/>
              <criterion comment="/usr/bin/rgb3toppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1883"/>
              <criterion comment="/usr/bin/rgb3toppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1882"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/rletopnm is executable">
              <criterion comment="/usr/bin/rletopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1881"/>
              <criterion comment="/usr/bin/rletopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1880"/>
              <criterion comment="/usr/bin/rletopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1879"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/sbigtopgm is executable">
              <criterion comment="/usr/bin/sbigtopgm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1878"/>
              <criterion comment="/usr/bin/sbigtopgm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1877"/>
              <criterion comment="/usr/bin/sbigtopgm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1876"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/sgitopnm is executable">
              <criterion comment="/usr/bin/sgitopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1875"/>
              <criterion comment="/usr/bin/sgitopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1874"/>
              <criterion comment="/usr/bin/sgitopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1873"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/sirtopnm is executable">
              <criterion comment="/usr/bin/sirtopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1872"/>
              <criterion comment="/usr/bin/sirtopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1871"/>
              <criterion comment="/usr/bin/sirtopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1870"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/sldtoppm is executable">
              <criterion comment="/usr/bin/sldtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1869"/>
              <criterion comment="/usr/bin/sldtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1868"/>
              <criterion comment="/usr/bin/sldtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1867"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/spctoppm is executable">
              <criterion comment="/usr/bin/spctoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1866"/>
              <criterion comment="/usr/bin/spctoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1865"/>
              <criterion comment="/usr/bin/spctoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1864"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/spottopgm is executable">
              <criterion comment="/usr/bin/spottopgm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1863"/>
              <criterion comment="/usr/bin/spottopgm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1862"/>
              <criterion comment="/usr/bin/spottopgm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1861"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/sputoppm is executable">
              <criterion comment="/usr/bin/sputoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1860"/>
              <criterion comment="/usr/bin/sputoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1859"/>
              <criterion comment="/usr/bin/sputoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1858"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/tgatoppm is executable">
              <criterion comment="/usr/bin/tgatoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1857"/>
              <criterion comment="/usr/bin/tgatoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1856"/>
              <criterion comment="/usr/bin/tgatoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1855"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/thinkjettopbm is executable">
              <criterion comment="/usr/bin/thinkjettopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1854"/>
              <criterion comment="/usr/bin/thinkjettopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1853"/>
              <criterion comment="/usr/bin/thinkjettopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1852"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/tifftopnm is executable">
              <criterion comment="/usr/bin/tifftopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1851"/>
              <criterion comment="/usr/bin/tifftopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1850"/>
              <criterion comment="/usr/bin/tifftopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1849"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/wbmptopbm is executable">
              <criterion comment="/usr/bin/wbmptopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1848"/>
              <criterion comment="/usr/bin/wbmptopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1847"/>
              <criterion comment="/usr/bin/wbmptopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1846"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/winicontoppm is executable">
              <criterion comment="/usr/bin/winicontoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1845"/>
              <criterion comment="/usr/bin/winicontoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1844"/>
              <criterion comment="/usr/bin/winicontoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1843"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/xbmtopbm is executable">
              <criterion comment="/usr/bin/xbmtopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1842"/>
              <criterion comment="/usr/bin/xbmtopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1841"/>
              <criterion comment="/usr/bin/xbmtopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1840"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ximtoppm is executable">
              <criterion comment="/usr/bin/ximtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1839"/>
              <criterion comment="/usr/bin/ximtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1838"/>
              <criterion comment="/usr/bin/ximtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1837"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/xpmtoppm is executable">
              <criterion comment="/usr/bin/xpmtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1836"/>
              <criterion comment="/usr/bin/xpmtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1835"/>
              <criterion comment="/usr/bin/xpmtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1834"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/xvminitoppm is executable">
              <criterion comment="/usr/bin/xvminitoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1833"/>
              <criterion comment="/usr/bin/xvminitoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1832"/>
              <criterion comment="/usr/bin/xvminitoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1831"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/xwdtopnm is executable">
              <criterion comment="/usr/bin/xwdtopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1830"/>
              <criterion comment="/usr/bin/xwdtopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1829"/>
              <criterion comment="/usr/bin/xwdtopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1828"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ybmtopbm is executable">
              <criterion comment="/usr/bin/ybmtopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1827"/>
              <criterion comment="/usr/bin/ybmtopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1826"/>
              <criterion comment="/usr/bin/ybmtopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1825"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/yuvsplittoppm is executable">
              <criterion comment="/usr/bin/yuvsplittoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1824"/>
              <criterion comment="/usr/bin/yuvsplittoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1823"/>
              <criterion comment="/usr/bin/yuvsplittoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1822"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/yuvtoppm is executable">
              <criterion comment="/usr/bin/yuvtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1821"/>
              <criterion comment="/usr/bin/yuvtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1820"/>
              <criterion comment="/usr/bin/yuvtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1819"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/zeisstopnm is executable">
              <criterion comment="/usr/bin/zeisstopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1818"/>
              <criterion comment="/usr/bin/zeisstopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1817"/>
              <criterion comment="/usr/bin/zeisstopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1816"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmscalefixed is executable">
              <criterion comment="/usr/bin/pnmscalefixed is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1815"/>
              <criterion comment="/usr/bin/pnmscalefixed is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1814"/>
              <criterion comment="/usr/bin/pnmscalefixed is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1813"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmshear is executable">
              <criterion comment="/usr/bin/pnmshear is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1812"/>
              <criterion comment="/usr/bin/pnmshear is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1811"/>
              <criterion comment="/usr/bin/pnmshear is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1810"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmsmooth is executable">
              <criterion comment="/usr/bin/pnmsmooth is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1809"/>
              <criterion comment="/usr/bin/pnmsmooth is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1808"/>
              <criterion comment="/usr/bin/pnmsmooth is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1807"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmsplit is executable">
              <criterion comment="/usr/bin/pnmsplit is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1806"/>
              <criterion comment="/usr/bin/pnmsplit is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1805"/>
              <criterion comment="/usr/bin/pnmsplit is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1804"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmtile is executable">
              <criterion comment="/usr/bin/pnmtile is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1803"/>
              <criterion comment="/usr/bin/pnmtile is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1802"/>
              <criterion comment="/usr/bin/pnmtile is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1801"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmtoddif is executable">
              <criterion comment="/usr/bin/pnmtoddif is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1800"/>
              <criterion comment="/usr/bin/pnmtoddif is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1799"/>
              <criterion comment="/usr/bin/pnmtoddif is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1798"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmtofiasco is executable">
              <criterion comment="/usr/bin/pnmtofiasco is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1797"/>
              <criterion comment="/usr/bin/pnmtofiasco is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1796"/>
              <criterion comment="/usr/bin/pnmtofiasco is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1795"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmtofits is executable">
              <criterion comment="/usr/bin/pnmtofits is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1794"/>
              <criterion comment="/usr/bin/pnmtofits is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1793"/>
              <criterion comment="/usr/bin/pnmtofits is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1792"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmtojpeg is executable">
              <criterion comment="/usr/bin/pnmtojpeg is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1791"/>
              <criterion comment="/usr/bin/pnmtojpeg is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1790"/>
              <criterion comment="/usr/bin/pnmtojpeg is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1789"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmtopalm is executable">
              <criterion comment="/usr/bin/pnmtopalm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1788"/>
              <criterion comment="/usr/bin/pnmtopalm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1787"/>
              <criterion comment="/usr/bin/pnmtopalm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1786"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmtoplainpnm is executable">
              <criterion comment="/usr/bin/pnmtoplainpnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1785"/>
              <criterion comment="/usr/bin/pnmtoplainpnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1784"/>
              <criterion comment="/usr/bin/pnmtoplainpnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1783"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmtopng is executable">
              <criterion comment="/usr/bin/pnmtopng is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1782"/>
              <criterion comment="/usr/bin/pnmtopng is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1781"/>
              <criterion comment="/usr/bin/pnmtopng is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1780"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmtops is executable">
              <criterion comment="/usr/bin/pnmtops is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1779"/>
              <criterion comment="/usr/bin/pnmtops is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1778"/>
              <criterion comment="/usr/bin/pnmtops is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1777"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmtorast is executable">
              <criterion comment="/usr/bin/pnmtorast is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1776"/>
              <criterion comment="/usr/bin/pnmtorast is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1775"/>
              <criterion comment="/usr/bin/pnmtorast is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1774"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmtorle is executable">
              <criterion comment="/usr/bin/pnmtorle is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1773"/>
              <criterion comment="/usr/bin/pnmtorle is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1772"/>
              <criterion comment="/usr/bin/pnmtorle is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1771"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmtosgi is executable">
              <criterion comment="/usr/bin/pnmtosgi is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1770"/>
              <criterion comment="/usr/bin/pnmtosgi is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1769"/>
              <criterion comment="/usr/bin/pnmtosgi is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1768"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmtosir is executable">
              <criterion comment="/usr/bin/pnmtosir is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1767"/>
              <criterion comment="/usr/bin/pnmtosir is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1766"/>
              <criterion comment="/usr/bin/pnmtosir is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1765"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmtotiff is executable">
              <criterion comment="/usr/bin/pnmtotiff is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1764"/>
              <criterion comment="/usr/bin/pnmtotiff is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1763"/>
              <criterion comment="/usr/bin/pnmtotiff is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1762"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmtotiffcmyk is executable">
              <criterion comment="/usr/bin/pnmtotiffcmyk is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1761"/>
              <criterion comment="/usr/bin/pnmtotiffcmyk is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1760"/>
              <criterion comment="/usr/bin/pnmtotiffcmyk is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1759"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmtoxwd is executable">
              <criterion comment="/usr/bin/pnmtoxwd is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1758"/>
              <criterion comment="/usr/bin/pnmtoxwd is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1757"/>
              <criterion comment="/usr/bin/pnmtoxwd is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1756"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppm3d is executable">
              <criterion comment="/usr/bin/ppm3d is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1755"/>
              <criterion comment="/usr/bin/ppm3d is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1754"/>
              <criterion comment="/usr/bin/ppm3d is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1753"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmbrighten is executable">
              <criterion comment="/usr/bin/ppmbrighten is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1752"/>
              <criterion comment="/usr/bin/ppmbrighten is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1751"/>
              <criterion comment="/usr/bin/ppmbrighten is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1750"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmchange is executable">
              <criterion comment="/usr/bin/ppmchange is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1749"/>
              <criterion comment="/usr/bin/ppmchange is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1748"/>
              <criterion comment="/usr/bin/ppmchange is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1747"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmcie is executable">
              <criterion comment="/usr/bin/ppmcie is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1746"/>
              <criterion comment="/usr/bin/ppmcie is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1745"/>
              <criterion comment="/usr/bin/ppmcie is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1744"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmcolormask is executable">
              <criterion comment="/usr/bin/ppmcolormask is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1743"/>
              <criterion comment="/usr/bin/ppmcolormask is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1742"/>
              <criterion comment="/usr/bin/ppmcolormask is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1741"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmcolors is executable">
              <criterion comment="/usr/bin/ppmcolors is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1740"/>
              <criterion comment="/usr/bin/ppmcolors is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1739"/>
              <criterion comment="/usr/bin/ppmcolors is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1738"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmdim is executable">
              <criterion comment="/usr/bin/ppmdim is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1737"/>
              <criterion comment="/usr/bin/ppmdim is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1736"/>
              <criterion comment="/usr/bin/ppmdim is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1735"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmdist is executable">
              <criterion comment="/usr/bin/ppmdist is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1734"/>
              <criterion comment="/usr/bin/ppmdist is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1733"/>
              <criterion comment="/usr/bin/ppmdist is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1732"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmdither is executable">
              <criterion comment="/usr/bin/ppmdither is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1731"/>
              <criterion comment="/usr/bin/ppmdither is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1730"/>
              <criterion comment="/usr/bin/ppmdither is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1729"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmflash is executable">
              <criterion comment="/usr/bin/ppmflash is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1728"/>
              <criterion comment="/usr/bin/ppmflash is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1727"/>
              <criterion comment="/usr/bin/ppmflash is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1726"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmforge is executable">
              <criterion comment="/usr/bin/ppmforge is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1725"/>
              <criterion comment="/usr/bin/ppmforge is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1724"/>
              <criterion comment="/usr/bin/ppmforge is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1723"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmhist is executable">
              <criterion comment="/usr/bin/ppmhist is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1722"/>
              <criterion comment="/usr/bin/ppmhist is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1721"/>
              <criterion comment="/usr/bin/ppmhist is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1720"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmlabel is executable">
              <criterion comment="/usr/bin/ppmlabel is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1719"/>
              <criterion comment="/usr/bin/ppmlabel is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1718"/>
              <criterion comment="/usr/bin/ppmlabel is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1717"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmmake is executable">
              <criterion comment="/usr/bin/ppmmake is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1716"/>
              <criterion comment="/usr/bin/ppmmake is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1715"/>
              <criterion comment="/usr/bin/ppmmake is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1714"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmmix is executable">
              <criterion comment="/usr/bin/ppmmix is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1713"/>
              <criterion comment="/usr/bin/ppmmix is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1712"/>
              <criterion comment="/usr/bin/ppmmix is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1711"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmnorm is executable">
              <criterion comment="/usr/bin/ppmnorm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1710"/>
              <criterion comment="/usr/bin/ppmnorm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1709"/>
              <criterion comment="/usr/bin/ppmnorm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1708"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmntsc is executable">
              <criterion comment="/usr/bin/ppmntsc is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1707"/>
              <criterion comment="/usr/bin/ppmntsc is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1706"/>
              <criterion comment="/usr/bin/ppmntsc is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1705"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmpat is executable">
              <criterion comment="/usr/bin/ppmpat is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1704"/>
              <criterion comment="/usr/bin/ppmpat is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1703"/>
              <criterion comment="/usr/bin/ppmpat is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1702"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmquant is executable">
              <criterion comment="/usr/bin/ppmquant is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1701"/>
              <criterion comment="/usr/bin/ppmquant is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1700"/>
              <criterion comment="/usr/bin/ppmquant is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1699"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmqvga is executable">
              <criterion comment="/usr/bin/ppmqvga is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1698"/>
              <criterion comment="/usr/bin/ppmqvga is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1697"/>
              <criterion comment="/usr/bin/ppmqvga is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1696"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmrelief is executable">
              <criterion comment="/usr/bin/ppmrelief is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1695"/>
              <criterion comment="/usr/bin/ppmrelief is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1694"/>
              <criterion comment="/usr/bin/ppmrelief is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1693"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmshift is executable">
              <criterion comment="/usr/bin/ppmshift is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1692"/>
              <criterion comment="/usr/bin/ppmshift is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1691"/>
              <criterion comment="/usr/bin/ppmshift is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1690"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmspread is executable">
              <criterion comment="/usr/bin/ppmspread is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1689"/>
              <criterion comment="/usr/bin/ppmspread is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1688"/>
              <criterion comment="/usr/bin/ppmspread is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1687"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmtoacad is executable">
              <criterion comment="/usr/bin/ppmtoacad is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1686"/>
              <criterion comment="/usr/bin/ppmtoacad is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1685"/>
              <criterion comment="/usr/bin/ppmtoacad is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1684"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmtobmp is executable">
              <criterion comment="/usr/bin/ppmtobmp is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1683"/>
              <criterion comment="/usr/bin/ppmtobmp is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1682"/>
              <criterion comment="/usr/bin/ppmtobmp is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1681"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmtoeyuv is executable">
              <criterion comment="/usr/bin/ppmtoeyuv is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1680"/>
              <criterion comment="/usr/bin/ppmtoeyuv is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1679"/>
              <criterion comment="/usr/bin/ppmtoeyuv is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1678"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmtogif is executable">
              <criterion comment="/usr/bin/ppmtogif is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1677"/>
              <criterion comment="/usr/bin/ppmtogif is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1676"/>
              <criterion comment="/usr/bin/ppmtogif is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1675"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmtoicr is executable">
              <criterion comment="/usr/bin/ppmtoicr is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1674"/>
              <criterion comment="/usr/bin/ppmtoicr is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1673"/>
              <criterion comment="/usr/bin/ppmtoicr is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1672"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmtoilbm is executable">
              <criterion comment="/usr/bin/ppmtoilbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1671"/>
              <criterion comment="/usr/bin/ppmtoilbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1670"/>
              <criterion comment="/usr/bin/ppmtoilbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1669"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmtojpeg is executable">
              <criterion comment="/usr/bin/ppmtojpeg is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1668"/>
              <criterion comment="/usr/bin/ppmtojpeg is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1667"/>
              <criterion comment="/usr/bin/ppmtojpeg is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1666"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmtoleaf is executable">
              <criterion comment="/usr/bin/ppmtoleaf is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1665"/>
              <criterion comment="/usr/bin/ppmtoleaf is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1664"/>
              <criterion comment="/usr/bin/ppmtoleaf is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1663"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmtolj is executable">
              <criterion comment="/usr/bin/ppmtolj is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1662"/>
              <criterion comment="/usr/bin/ppmtolj is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1661"/>
              <criterion comment="/usr/bin/ppmtolj is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1660"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmtomitsu is executable">
              <criterion comment="/usr/bin/ppmtomitsu is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1659"/>
              <criterion comment="/usr/bin/ppmtomitsu is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1658"/>
              <criterion comment="/usr/bin/ppmtomitsu is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1657"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmtompeg is executable">
              <criterion comment="/usr/bin/ppmtompeg is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1656"/>
              <criterion comment="/usr/bin/ppmtompeg is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1655"/>
              <criterion comment="/usr/bin/ppmtompeg is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1654"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmtoneo is executable">
              <criterion comment="/usr/bin/ppmtoneo is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1653"/>
              <criterion comment="/usr/bin/ppmtoneo is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1652"/>
              <criterion comment="/usr/bin/ppmtoneo is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1651"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmtopcx is executable">
              <criterion comment="/usr/bin/ppmtopcx is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1650"/>
              <criterion comment="/usr/bin/ppmtopcx is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1649"/>
              <criterion comment="/usr/bin/ppmtopcx is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1648"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmtopgm is executable">
              <criterion comment="/usr/bin/ppmtopgm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1647"/>
              <criterion comment="/usr/bin/ppmtopgm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1646"/>
              <criterion comment="/usr/bin/ppmtopgm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1645"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmtopi1 is executable">
              <criterion comment="/usr/bin/ppmtopi1 is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1644"/>
              <criterion comment="/usr/bin/ppmtopi1 is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1643"/>
              <criterion comment="/usr/bin/ppmtopi1 is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1642"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:806" version="2" class="vulnerability">
      <metadata>
        <title>Red Hat XFree86 Buffer Overflow in ReadFontAlias</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>XFree86</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0083" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0083"/>
        <description>Buffer overflow in ReadFontAlias from dirfile.c of XFree86 4.1.0 through 4.3.0 allows local users and remote attackers to execute arbitrary code via a font alias file (font.alias) with a long token, a different vulnerability than CVE-2004-0084 and CVE-2004-0106.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-03-20T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="The MITRE Corporation">Matt Busby</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:23.593-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:52:47.083-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criterion comment="XFree86 version is less than 4.3.0-2.90.55" negate="false" test_ref="oval:org.mitre.oval:tst:1641"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="AND" comment="/usr/X11R6/bin/XFree86 is SUID and executable">
            <criterion comment="/usr/X11R6/bin/XFree86 is SUID and executable" negate="false" test_ref="oval:org.mitre.oval:tst:1640"/>
            <criteria operator="OR" comment="/usr/X11R6/bin/XFree86 is SUID and executable">
              <criterion comment="/usr/X11R6/bin/XFree86 is SUID and executable" negate="false" test_ref="oval:org.mitre.oval:tst:1639"/>
              <criterion comment="/usr/X11R6/bin/XFree86 is SUID and executable" negate="false" test_ref="oval:org.mitre.oval:tst:1638"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:807" version="2" class="vulnerability">
      <metadata>
        <title>Red Hat XFree86 Buffer Overflow in ReadFontAlias II</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>XFree86</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0084" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0084"/>
        <description>Buffer overflow in the ReadFontAlias function in XFree86 4.1.0 to 4.3.0, when using the CopyISOLatin1Lowered function, allows local or remote authenticated users to execute arbitrary code via a malformed entry in the font alias (font.alias) file, a different vulnerability than CVE-2004-0083 and CVE-2004-0106.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-03-20T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="The MITRE Corporation">Matt Busby</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:43.326-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:52:47.331-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criterion comment="XFree86 version is less than 4.3.0-2.90.55" negate="false" test_ref="oval:org.mitre.oval:tst:1641"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="AND" comment="/usr/X11R6/bin/XFree86 is SUID and executable">
            <criterion comment="/usr/X11R6/bin/XFree86 is SUID and executable" negate="false" test_ref="oval:org.mitre.oval:tst:1640"/>
            <criteria operator="OR" comment="/usr/X11R6/bin/XFree86 is SUID and executable">
              <criterion comment="/usr/X11R6/bin/XFree86 is SUID and executable" negate="false" test_ref="oval:org.mitre.oval:tst:1639"/>
              <criterion comment="/usr/X11R6/bin/XFree86 is SUID and executable" negate="false" test_ref="oval:org.mitre.oval:tst:1638"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:809" version="2" class="vulnerability">
      <metadata>
        <title>XFree86 Font File Handling Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>XFree86</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0106" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0106"/>
        <description>Multiple unknown vulnerabilities in XFree86 4.1.0 to 4.3.0, related to improper handling of font files, a different set of vulnerabilities than CVE-2004-0083 and CVE-2004-0084.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-03-20T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="The MITRE Corporation">Matt Busby</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:21.877-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:52:47.539-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criterion comment="XFree86 version is less than 4.3.0-2.90.55" negate="false" test_ref="oval:org.mitre.oval:tst:1641"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="AND" comment="/usr/X11R6/bin/XFree86 is SUID and executable">
            <criterion comment="/usr/X11R6/bin/XFree86 is SUID and executable" negate="false" test_ref="oval:org.mitre.oval:tst:1640"/>
            <criteria operator="OR" comment="/usr/X11R6/bin/XFree86 is SUID and executable">
              <criterion comment="/usr/X11R6/bin/XFree86 is SUID and executable" negate="false" test_ref="oval:org.mitre.oval:tst:1639"/>
              <criterion comment="/usr/X11R6/bin/XFree86 is SUID and executable" negate="false" test_ref="oval:org.mitre.oval:tst:1638"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:811" version="2" class="vulnerability">
      <metadata>
        <title>Red Hat Mutt BO in Index Menu</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>Mutt</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0078" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0078"/>
        <description>Buffer overflow in the index menu code (menu_pad_string of menu.c) for Mutt 1.4.1 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via certain mail messages.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-03-20T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-05-05T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:31.712-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:52:54.867-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criterion comment="mutt version is less than 1.4.1-3.3" negate="false" test_ref="oval:org.mitre.oval:tst:1634"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="/usr/bin/mutt is executable">
            <criterion comment="/usr/bin/mutt is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2637"/>
            <criterion comment="/usr/bin/mutt is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2636"/>
            <criterion comment="/usr/bin/mutt is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2635"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:813" version="2" class="vulnerability">
      <metadata>
        <title>Mailman Cross-site Scripting Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>Mailman</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0965" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0965"/>
        <description>Cross-site scripting (XSS) vulnerability in the admin CGI script for Mailman before 2.1.4 allows remote attackers to steal session cookies and conduct unauthorized activities.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-03-20T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-05-05T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:32.431-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:52:55.077-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criterion comment="mailman version is less than 2.1.1-5" negate="false" test_ref="oval:org.mitre.oval:tst:1631"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="httpd is listening on the network" negate="false" test_ref="oval:org.mitre.oval:tst:1630"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:815" version="2" class="vulnerability">
      <metadata>
        <title>Mailman Cross-site Scripting Vulnerability II</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>Mailman</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0992" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0992"/>
        <description>Cross-site scripting (XSS) vulnerability in the create CGI script for Mailman before 2.1.3 allows remote attackers to steal cookies of other users.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-03-20T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-05-05T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:56.512-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:52:55.374-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criterion comment="mailman version is less than 2.1.1-5" negate="false" test_ref="oval:org.mitre.oval:tst:1631"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="httpd is listening on the network" negate="false" test_ref="oval:org.mitre.oval:tst:1630"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:818" version="2" class="vulnerability">
      <metadata>
        <title>Gaim / Ultramagnetic BO Vulnerabilities</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>Gaim</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0006" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0006"/>
        <description>Multiple buffer overflows in Gaim 0.75 and earlier, and Ultramagnetic before 0.81, allow remote attackers to cause a denial of service and possibly execute arbitrary code via (1) cookies in a Yahoo web connection, (2) a long name parameter in the Yahoo login web page, (3) a long value parameter in the Yahoo login page, (4) a YMSG packet, (5) the URL parser, and (6) HTTP proxy connect.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-03-20T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-05-05T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:36.164-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:52:55.558-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criterion comment="gaim version is less than 0.75-0.9.0" negate="false" test_ref="oval:org.mitre.oval:tst:1629"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="/usr/bin/gaim is executable">
            <criterion comment="/usr/bin/gaim is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1628"/>
            <criterion comment="/usr/bin/gaim is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1627"/>
            <criterion comment="/usr/bin/gaim is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1626"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:819" version="2" class="vulnerability">
      <metadata>
        <title>Gaim / Ultramagnetic Extract Info Field Function BO</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>Gaim</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0007" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0007"/>
        <description>Buffer overflow in the Extract Info Field Function for (1) MSN and (2) YMSG protocol handlers in Gaim 0.74 and earlier, and Ultramagnetic before 0.81, allows remote attackers to cause a denial of service and possibly execute arbitrary code.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-03-20T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-05-05T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:39.253-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:52:55.739-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criterion comment="gaim version is less than 0.75-0.9.0" negate="false" test_ref="oval:org.mitre.oval:tst:1629"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="/usr/bin/gaim is executable">
            <criterion comment="/usr/bin/gaim is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1628"/>
            <criterion comment="/usr/bin/gaim is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1627"/>
            <criterion comment="/usr/bin/gaim is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1626"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:820" version="2" class="vulnerability">
      <metadata>
        <title>Gaim / Ultramagnetic directIM Packet Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>Gaim</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0008" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0008"/>
        <description>Integer overflow in Gaim 0.74 and earlier, and Ultramagnetic before 0.81, allows remote attackers to cause a denial of service and possibly execute arbitrary code via a directIM packet that triggers a heap-based buffer overflow.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-03-20T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-05-05T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:51.269-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:52:55.989-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criterion comment="gaim version is less than 0.75-0.9.0" negate="false" test_ref="oval:org.mitre.oval:tst:1629"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="/usr/bin/gaim is executable">
            <criterion comment="/usr/bin/gaim is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1628"/>
            <criterion comment="/usr/bin/gaim is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1627"/>
            <criterion comment="/usr/bin/gaim is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1626"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:821" version="2" class="vulnerability">
      <metadata>
        <title>slocate Privilege Escalation Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>slocate</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0848" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0848"/>
        <description>Heap-based buffer overflow in main.c of slocate 2.6, and possibly other versions, may allow local users to gain privileges via a modified slocate database that causes a negative "pathlen" value to be used.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-03-20T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="The MITRE Corporation">Matt Busby</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:39.635-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:52:56.173-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criterion comment="slocate version is less than 2.7-2" negate="false" test_ref="oval:org.mitre.oval:tst:1625"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="AND" comment="/usr/bin/slocate is setgid">
            <criterion comment="/usr/bin/slocate is setgid" negate="false" test_ref="oval:org.mitre.oval:tst:1624"/>
            <criterion comment="/usr/bin/slocate is setgid" negate="false" test_ref="oval:org.mitre.oval:tst:1623"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:822" version="2" class="vulnerability">
      <metadata>
        <title>Midnight Commander vfs_s_resolve_symlink BO</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>Midnight Commander</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-1023" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-1023"/>
        <description>Stack-based buffer overflow in vfs_s_resolve_symlink of vfs/direntry.c for Midnight Commander (mc) 4.6.0 and earlier, and possibly later versions, allows remote attackers to execute arbitrary code during symlink conversion.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-03-21T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="The MITRE Corporation">Matt Busby</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:43.070-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:52:56.376-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criterion comment="mc version is less than 4.6.0-7.9" negate="false" test_ref="oval:org.mitre.oval:tst:1622"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="/usr/bin/mc is executable">
            <criterion comment="/usr/bin/mc is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1621"/>
            <criterion comment="/usr/bin/mc is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1620"/>
            <criterion comment="/usr/bin/mc is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1619"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:823" version="2" class="vulnerability">
      <metadata>
        <title>Konqueror Cookie Access Restrictions Bypass Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>KDE</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0592" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0592"/>
        <description>Konqueror in KDE 3.1.3 and earlier (kdelibs) allows remote attackers to bypass intended cookie access restrictions on a web application via "%2e%2e" (encoded dot dot) directory traversal sequences in a URL, which causes Konqueror to send the cookie outside the specified URL subsets, e.g. to a vulnerable application that runs on the same server as the target application.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-03-20T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-05-05T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:45.940-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:52:56.638-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criterion comment="kdelibs version is less than 3.1-13" negate="false" test_ref="oval:org.mitre.oval:tst:1618"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="/usr/bin/konqueror is executable">
            <criterion comment="/usr/bin/konqueror is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2655"/>
            <criterion comment="/usr/bin/konqueror is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2654"/>
            <criterion comment="/usr/bin/konqueror is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2653"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:828" version="2" class="vulnerability">
      <metadata>
        <title>mod_python Web Server Denial of Service</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>mod_python</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0973" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0973"/>
        <description>Unknown vulnerability in mod_python 3.0.x before 3.0.4, and 2.7.x before 2.7.9, allows remote attackers to cause a denial of service (httpd crash) via a certain query string.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-03-20T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="The MITRE Corporation">Matt Busby</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:57.737-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:52:57.394-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criterion comment="mod_python version is less than 3.0.1-4" negate="false" test_ref="oval:org.mitre.oval:tst:1612"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="httpd is listening to the network" negate="false" test_ref="oval:org.mitre.oval:tst:1611"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:834" version="2" class="vulnerability">
      <metadata>
        <title>Red Hat Kernel R128 DRI Limits Checking Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>Linux kernel</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0003" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0003"/>
        <description>Unknown vulnerability in Linux kernel before 2.4.22 allows local users to gain privileges, related to "R128 DRI limits checking."</description>
        <oval_repository>
          <dates>
            <submitted date="2004-03-20T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="The MITRE Corporation">Matt Busby</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:58.073-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:52:58.430-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
        <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
        <criteria operator="OR" comment="Vulnerable Configuration">
          <criterion comment="kernel version is less than 2.4.20-30.9" negate="false" test_ref="oval:org.mitre.oval:tst:1606"/>
          <criterion comment="kernel-smp version is less than 2.4.20-30.9" negate="false" test_ref="oval:org.mitre.oval:tst:1605"/>
          <criterion comment="kernel-bigmem version is less than 2.4.20-30.9" negate="false" test_ref="oval:org.mitre.oval:tst:1604"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:835" version="2" class="vulnerability">
      <metadata>
        <title>Red Hat Kernel ncp_lookup Function BO</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>Linux kernel</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0010" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0010"/>
        <description>Stack-based buffer overflow in the ncp_lookup function for ncpfs in Linux kernel 2.4.x allows local users to gain privileges.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-03-20T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="The MITRE Corporation">Matt Busby</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:46.479-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:52:58.625-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
        <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
        <criteria operator="OR" comment="Vulnerable Configuration">
          <criterion comment="kernel version is less than 2.4.20-30.9" negate="false" test_ref="oval:org.mitre.oval:tst:1606"/>
          <criterion comment="kernel-smp version is less than 2.4.20-30.9" negate="false" test_ref="oval:org.mitre.oval:tst:1605"/>
          <criterion comment="kernel-bigmem version is less than 2.4.20-30.9" negate="false" test_ref="oval:org.mitre.oval:tst:1604"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:836" version="2" class="vulnerability">
      <metadata>
        <title>Vicam USB Driver Data Copy Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>Vicam USB driver</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0075" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0075"/>
        <description>The Vicam USB driver in Linux before 2.4.25 does not use the copy_from_user function when copying data from userspace to kernel space, which crosses security boundaries and allows local users to cause a denial of service.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-03-20T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="The MITRE Corporation">Matt Busby</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:52.053-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:52:58.802-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
        <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
        <criteria operator="OR" comment="Vulnerable Configuration">
          <criterion comment="kernel version is less than 2.4.20-30.9" negate="false" test_ref="oval:org.mitre.oval:tst:1606"/>
          <criterion comment="kernel-smp version is less than 2.4.20-30.9" negate="false" test_ref="oval:org.mitre.oval:tst:1605"/>
          <criterion comment="kernel-bigmem version is less than 2.4.20-30.9" negate="false" test_ref="oval:org.mitre.oval:tst:1604"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:837" version="2" class="vulnerability">
      <metadata>
        <title>Red Hat Linux Kernel do_mremap Privilege Escalation Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>mremap</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0077" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0077"/>
        <description>The do_mremap function for the mremap system call in Linux 2.2 to 2.2.25, 2.4 to 2.4.24, and 2.6 to 2.6.2, does not properly check the return value from the do_munmap function when the maximum number of VMA descriptors is exceeded, which allows local users to gain root privileges, a different vulnerability than CAN-2003-0985.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-03-20T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="The MITRE Corporation">Matt Busby</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:54.124-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:52:59.044-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
        <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
        <criteria operator="OR" comment="Vulnerable Configuration">
          <criterion comment="kernel version is less than 2.4.20-30.9" negate="false" test_ref="oval:org.mitre.oval:tst:1606"/>
          <criterion comment="kernel-smp version is less than 2.4.20-30.9" negate="false" test_ref="oval:org.mitre.oval:tst:1605"/>
          <criterion comment="kernel-bigmem version is less than 2.4.20-30.9" negate="false" test_ref="oval:org.mitre.oval:tst:1604"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:84" version="2" class="vulnerability">
      <metadata>
        <title>Ethereal 0.9.12 Vulnerability in OSI Dissector</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>Ethereal</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0429" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0429"/>
        <description>The OSI dissector in Ethereal 0.9.12 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code via invalid IPv4 or IPv6 prefix lengths, possibly triggering a buffer overflow.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-08-29T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-03-25T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:22.040-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:52:59.592-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
        <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
        <criteria operator="OR" comment="Vulnerable Config">
          <criterion comment="ethereal version is less than 0.9.13-1.90.1" negate="false" test_ref="oval:org.mitre.oval:tst:2985"/>
          <criterion comment="ethereal-gnome version is less than 0.9.13-1.90.1" negate="false" test_ref="oval:org.mitre.oval:tst:2984"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:846" version="2" class="vulnerability">
      <metadata>
        <title>Red Hat gdk-pixbuf Denial of Service</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>gdk-pixbuf</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0111" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0111"/>
        <description>gdk-pixbuf before 0.20 allows attackers to cause a denial of service (crash) via a malformed bitmap (BMP) file.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-03-20T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-05-05T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2004-05-11T12:00:00.000-04:00" comment="Corrected pattern used in rrt-206">
              <contributor organization="The MITRE Corporation">Matt Busby</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:25.497-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:52:59.959-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
        <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
        <criteria operator="OR" comment="Vulnerable configuration">
          <criterion comment="gdk-pixbuf version is less than 0.22.0-6.1.0" negate="false" test_ref="oval:org.mitre.oval:tst:1586"/>
          <criterion comment="gdk-pixbuf-devel version is less than 0.22.0-6.1.0" negate="false" test_ref="oval:org.mitre.oval:tst:1585"/>
          <criterion comment="gdk-pixbuf-gnome version is less than 0.22.0-6.1.0" negate="false" test_ref="oval:org.mitre.oval:tst:1584"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:847" version="2" class="vulnerability">
      <metadata>
        <title>Red Hat tcpdump Denial of Service via ISAKMP Packets</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>tcpdump</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0989" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0989"/>
        <description>tcpdump before 3.8.1 allows remote attackers to cause a denial of service (infinite loop) via certain ISAKMP packets, a different vulnerability than CVE-2004-0057.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-03-20T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-05-05T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:51.672-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:53:00.169-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criterion comment="tcpdump version is less than 3.7.2-7.9.1" negate="false" test_ref="oval:org.mitre.oval:tst:1583"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="/usr/sbin/tcpdump is executable">
            <criterion comment="/usr/sbin/tcpdump is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1582"/>
            <criterion comment="/usr/sbin/tcpdump is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1581"/>
            <criterion comment="/usr/sbin/tcpdump is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1580"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:849" version="2" class="vulnerability">
      <metadata>
        <title>Red Hat sysstat port and trigger Scripts symlink Attack Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>sysstat</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0107" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0107"/>
        <description>The (1) post and (2) trigger scripts in sysstat 4.0.7 and earlier allow local users to overwrite arbitrary files via symlink attacks on temporary files, a different vulnerability than CVE-2004-0108.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-03-20T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="The MITRE Corporation">Matt Busby</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-06-16T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:50.135-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:53:00.342-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
        <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
        <criterion comment="sysstat version is less than 4.0.7-4.rhl9.1" negate="false" test_ref="oval:org.mitre.oval:tst:1579"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:850" version="2" class="vulnerability">
      <metadata>
        <title>Red Hat tcpdump Denial of Service via print_attr_string Function</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>tcpdump</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0055" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0055"/>
        <description>The print_attr_string function in print-radius.c for tcpdump 3.8.1 and earlier allows remote attackers to cause a denial of service (segmentation fault) via a RADIUS attribute with a large length value.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-03-20T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-05-05T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:36.651-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:53:00.525-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criterion comment="tcpdump version is less than 3.7.2-7.9.1" negate="false" test_ref="oval:org.mitre.oval:tst:1583"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="/usr/sbin/tcpdump is executable">
            <criterion comment="/usr/sbin/tcpdump is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1582"/>
            <criterion comment="/usr/sbin/tcpdump is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1581"/>
            <criterion comment="/usr/sbin/tcpdump is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1580"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:851" version="2" class="vulnerability">
      <metadata>
        <title>Red Hat tcpdump Denial of Service via ISAKMP Packets II</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>tcpdump</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0057" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0057"/>
        <description>The rawprint function in the ISAKMP decoding routines (print-isakmp.c) for tcpdump 3.8.1 and earlier allows remote attackers to cause a denial of service (segmentation fault) via malformed ISAKMP packets that cause invalid "len" or "loc" values to be used in a loop, a different vulnerability than CVE-2003-0989.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-03-20T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-05-05T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:40.838-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:53:00.715-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criterion comment="tcpdump version is less than 3.7.2-7.9.1" negate="false" test_ref="oval:org.mitre.oval:tst:1583"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="/usr/sbin/tcpdump is executable">
            <criterion comment="/usr/sbin/tcpdump is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1582"/>
            <criterion comment="/usr/sbin/tcpdump is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1581"/>
            <criterion comment="/usr/sbin/tcpdump is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1580"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:855" version="2" class="vulnerability">
      <metadata>
        <title>Red Hat CVS Server root Directory Access Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>CVS server</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0977" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0977"/>
        <description>CVS server before 1.11.10 may allow attackers to cause the CVS server to create directories and files in the file system root directory via malformed module requests.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-03-20T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="The MITRE Corporation">Matt Busby</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:22.699-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:53:01.591-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criterion comment="cvs version is less than 1.11.2-13" negate="false" test_ref="oval:org.mitre.oval:tst:1577"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="/ is world-writable" negate="false" test_ref="oval:org.mitre.oval:tst:1576"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:856" version="2" class="vulnerability">
      <metadata>
        <title>Ethereal Malformed SMB Packet Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>Ethereal</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-1012" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-1012"/>
        <description>The SMB dissector in Ethereal before 0.10.0 allows remote attackers to cause a denial of service via a malformed SMB packet that triggers a segmentation fault during processing of Selected packets.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-03-20T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="The MITRE Corporation">Matt Busby</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:49.899-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:53:01.900-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criteria operator="OR" comment="Vulnerable Config">
            <criterion comment="ethereal version is less than 0.10.0a-0.90.1" negate="false" test_ref="oval:org.mitre.oval:tst:1575"/>
            <criterion comment="ethereal-gnome version is less than 0.10.0a-0.90.1" negate="false" test_ref="oval:org.mitre.oval:tst:1574"/>
          </criteria>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="Vulnerable Config">
            <criteria operator="OR" comment="/usr/bin/ethereal is executable">
              <criterion comment="/usr/bin/ethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1573"/>
              <criterion comment="/usr/bin/ethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1572"/>
              <criterion comment="/usr/bin/ethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1571"/>
            </criteria>
            <criteria operator="OR" comment="/usr/sbin/ethereal is executable">
              <criterion comment="/usr/sbin/ethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1570"/>
              <criterion comment="/usr/sbin/ethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1569"/>
              <criterion comment="/usr/sbin/ethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1568"/>
            </criteria>
            <criteria operator="OR" comment="/usr/sbin/tethereal is executable">
              <criterion comment="/usr/sbin/tethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1567"/>
              <criterion comment="/usr/sbin/tethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1566"/>
              <criterion comment="/usr/sbin/tethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1565"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:857" version="2" class="vulnerability">
      <metadata>
        <title>Ethereal Malformed Q.931 Packet Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>Tethereal</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-1013" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-1013"/>
        <description>The Q.931 dissector in Ethereal before 0.10.0, and Tethereal, allows remote attackers to cause a denial of service (crash) via a malformed Q.931, which triggers a null dereference.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-03-20T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="The MITRE Corporation">Matt Busby</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:55.490-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:53:02.172-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criteria operator="OR" comment="Vulnerable Config">
            <criterion comment="ethereal version is less than 0.10.0a-0.90.1" negate="false" test_ref="oval:org.mitre.oval:tst:1575"/>
            <criterion comment="ethereal-gnome version is less than 0.10.0a-0.90.1" negate="false" test_ref="oval:org.mitre.oval:tst:1574"/>
          </criteria>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="Vulnerable Config">
            <criteria operator="OR" comment="/usr/bin/ethereal is executable">
              <criterion comment="/usr/bin/ethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1573"/>
              <criterion comment="/usr/bin/ethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1572"/>
              <criterion comment="/usr/bin/ethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1571"/>
            </criteria>
            <criteria operator="OR" comment="/usr/sbin/ethereal is executable">
              <criterion comment="/usr/sbin/ethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1570"/>
              <criterion comment="/usr/sbin/ethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1569"/>
              <criterion comment="/usr/sbin/ethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1568"/>
            </criteria>
            <criteria operator="OR" comment="/usr/sbin/tethereal is executable">
              <criterion comment="/usr/sbin/tethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1567"/>
              <criterion comment="/usr/sbin/tethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1566"/>
              <criterion comment="/usr/sbin/tethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1565"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:858" version="2" class="vulnerability">
      <metadata>
        <title>Red Hat kdepim VCF File Information Reader BO</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>KDE Personal Information Management (kdepim)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0988" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0988"/>
        <description>Buffer overflow in the VCF file information reader for KDE Personal Information Management (kdepim) suite in KDE 3.1.0 through 3.1.4 allows attackers to execute arbitrary code via a VCF file.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-03-20T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-05-05T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:42:04.520-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:53:02.420-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criterion comment="kdepim version is less than 3.1-6" negate="false" test_ref="oval:org.mitre.oval:tst:1564"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="/usr/share/services/kfile_vcf.desktop is readable">
            <criterion comment="/usr/share/services/kfile_vcf.desktop is readable" negate="false" test_ref="oval:org.mitre.oval:tst:1563"/>
            <criterion comment="/usr/share/services/kfile_vcf.desktop is readable" negate="false" test_ref="oval:org.mitre.oval:tst:1562"/>
            <criterion comment="/usr/share/services/kfile_vcf.desktop is readable" negate="false" test_ref="oval:org.mitre.oval:tst:1561"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:859" version="2" class="vulnerability">
      <metadata>
        <title>Red Hat Kernel Real Time Clock Data Leakage</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>Linux kernel</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0984" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0984"/>
        <description>Real time clock (RTC) routines in Linux kernel 2.4.23 and earlier do not properly initialize their structures, which could leak kernel data to user space.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-03-20T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="The MITRE Corporation">Matt Busby</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:42:04.989-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:53:02.615-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
        <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
        <criteria operator="OR" comment="Vulnerable Configuration">
          <criterion comment="kernel version is less than 2.4.20-28.9" negate="false" test_ref="oval:org.mitre.oval:tst:1560"/>
          <criterion comment="kernel-smp version is less than 2.4.20-28.9" negate="false" test_ref="oval:org.mitre.oval:tst:1559"/>
          <criterion comment="kernel-bigmem version is less than 2.4.20-28.9" negate="false" test_ref="oval:org.mitre.oval:tst:1558"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:860" version="2" class="vulnerability">
      <metadata>
        <title>Red Hat Linux Kernel do_mremap Denial of Service Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>Linux kernel</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0985" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0985"/>
        <description>The mremap system call (do_mremap) in Linux kernel 2.4.x before 2.4.21, and possibly other versions before 2.4.24, does not properly perform bounds checks, which allows local users to cause a denial of service and possibly gain privileges by causing a remapping of a virtual memory area (VMA) to create a zero length VMA, a different vulnerability than CAN-2004-0077.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-03-20T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="The MITRE Corporation">Matt Busby</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:42.419-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:53:02.810-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
        <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
        <criteria operator="OR" comment="Vulnerable Configuration">
          <criterion comment="kernel version is less than 2.4.20-28.9" negate="false" test_ref="oval:org.mitre.oval:tst:1560"/>
          <criterion comment="kernel-smp version is less than 2.4.20-28.9" negate="false" test_ref="oval:org.mitre.oval:tst:1559"/>
          <criterion comment="kernel-bigmem version is less than 2.4.20-28.9" negate="false" test_ref="oval:org.mitre.oval:tst:1558"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:863" version="2" class="vulnerability">
      <metadata>
        <title>Red Hat Multiple stack-based BO Vulnerabilities in Apache</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>httpd</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0542" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0542"/>
        <description>Multiple stack-based buffer overflows in (1) mod_alias and (2) mod_rewrite for Apache before 1.3.29 allow attackers to create configuration files to cause a denial of service (crash) or execute arbitrary code via a regular expression with more than 9 captures.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-03-17T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="The MITRE Corporation">Matt Busby</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-06-16T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:37.702-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:53:03.502-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criterion comment="httpd version is less than 2.0.40-21.9" negate="false" test_ref="oval:org.mitre.oval:tst:1554"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="httpd.worker is listening on the network" negate="false" test_ref="oval:org.mitre.oval:tst:2851"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:872" version="2" class="vulnerability">
      <metadata>
        <title>Red Hat S/MIME Protocol Denial of Service Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>mozilla</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0564" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0564"/>
        <description>Multiple vulnerabilities in multiple vendor implementations of the Secure/Multipurpose Internet Mail Extensions (S/MIME) protocol allow remote attackers to cause a denial of service and possibly execute arbitrary code via an S/MIME email message containing certain unexpected ASN.1 constructs, as demonstrated using the NISSC test suite.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-03-18T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-05-05T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:39.006-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:53:05.158-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
        <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
        <criterion comment="mozilla-nss version is less than 1.4.2-0.9.0" negate="false" test_ref="oval:org.mitre.oval:tst:1539"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:873" version="2" class="vulnerability">
      <metadata>
        <title>Red Hat Mozilla Bypass Cookie Access Restrictions Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>mozilla</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0594" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0594"/>
        <description>Mozilla allows remote attackers to bypass intended cookie access restrictions on a web application via "%2e%2e" (encoded dot dot) directory traversal sequences in a URL, which causes Mozilla to send the cookie outside the specified URL subsets, e.g. to a vulnerable application that runs on the same server as the target application.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-03-18T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-05-05T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:24.788-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:53:05.449-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criterion comment="mozilla version is less than 1.4.2-0.9.0" negate="false" test_ref="oval:org.mitre.oval:tst:1538"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="/usr/bin/mozilla is executable">
            <criterion comment="/usr/bin/mozilla is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1537"/>
            <criterion comment="/usr/bin/mozilla is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1536"/>
            <criterion comment="/usr/bin/mozilla is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1535"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:874" version="2" class="vulnerability">
      <metadata>
        <title>Red Hat Mozilla Zombie Document Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>mozilla</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0191" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0191"/>
        <description>Mozilla before 1.4.2 executes Javascript events in the context of a new page while it is being loaded, allowing it to interact with the previous page (zombie document) and enable cross-domain and cross-site scripting (XSS) attacks, as demonstrated using onmousemove events.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-03-18T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-05-05T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:50.329-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:53:05.638-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criterion comment="mozilla version is less than 1.4.2-0.9.0" negate="false" test_ref="oval:org.mitre.oval:tst:1538"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="/usr/bin/mozilla is executable">
            <criterion comment="/usr/bin/mozilla is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1537"/>
            <criterion comment="/usr/bin/mozilla is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1536"/>
            <criterion comment="/usr/bin/mozilla is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1535"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:877" version="2" class="vulnerability">
      <metadata>
        <title>Red Hat Squid ACL Bypass Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0189" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0189"/>
        <description>The "%xx" URL decoding function in Squid 2.5STABLE4 and earlier allows remote attackers to bypass url_regex ACLs via a URL with a NULL ("%00") characterm, which causes Squid to use only a portion of the requested URL when comparing it against the access control lists.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-04-07T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-05-05T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:22.363-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:53:06.268-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criterion comment="squid version is less than 2.5STABLE1-3.9" negate="false" test_ref="oval:org.mitre.oval:tst:1533"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="squid is listening on the network" negate="false" test_ref="oval:org.mitre.oval:tst:1532"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:878" version="2" class="vulnerability">
      <metadata>
        <title>Multiple BO Vulnerabilities in Red Hat Ethereal</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0176" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0176"/>
        <description>Multiple buffer overflows in Ethereal 0.8.13 to 0.10.2 allow remote attackers to cause a denial of service and possibly execute arbitrary code via the (1) NetFlow, (2) IGAP, (3) EIGRP, (4) PGM, (5) IrDA, (6) BGP, (7) ISUP, or (8) TCAP dissectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-04-07T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-06-16T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:37.429-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:53:06.459-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criteria operator="OR" comment="Vulnerable Config">
            <criterion comment="ethereal version is less than 0.10.3-0.90.1" negate="false" test_ref="oval:org.mitre.oval:tst:1531"/>
            <criterion comment="ethereal-gnome version is less than 0.10.3-0.90.1" negate="false" test_ref="oval:org.mitre.oval:tst:1530"/>
          </criteria>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="Vulnerable Config">
            <criteria operator="OR" comment="/usr/bin/ethereal is executable">
              <criterion comment="/usr/bin/ethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1529"/>
              <criterion comment="/usr/bin/ethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1528"/>
              <criterion comment="/usr/bin/ethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1527"/>
            </criteria>
            <criteria operator="OR" comment="/usr/sbin/ethereal is executable">
              <criterion comment="/usr/sbin/ethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1526"/>
              <criterion comment="/usr/sbin/ethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1525"/>
              <criterion comment="/usr/sbin/ethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1524"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/tethereal is executable">
              <criterion comment="/usr/bin/tethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1523"/>
              <criterion comment="/usr/bin/tethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1522"/>
              <criterion comment="/usr/bin/tethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1521"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:879" version="2" class="vulnerability">
      <metadata>
        <title>Red Hat Ethereal Denial of Service via Malformed RADIUS Packet</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0365" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0365"/>
        <description>The dissect_attribute_value_pairs function in packet-radius.c for Ethereal 0.8.13 to 0.10.2 allows remote attackers to cause a denial of service (crash) via a malformed RADIUS packet that triggers a null dereference.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-04-07T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-06-16T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:45.657-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:53:06.701-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criteria operator="OR" comment="Vulnerable Config">
            <criterion comment="ethereal version is less than 0.10.3-0.90.1" negate="false" test_ref="oval:org.mitre.oval:tst:1531"/>
            <criterion comment="ethereal-gnome version is less than 0.10.3-0.90.1" negate="false" test_ref="oval:org.mitre.oval:tst:1530"/>
          </criteria>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="Vulnerable Config">
            <criteria operator="OR" comment="/usr/bin/ethereal is executable">
              <criterion comment="/usr/bin/ethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1529"/>
              <criterion comment="/usr/bin/ethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1528"/>
              <criterion comment="/usr/bin/ethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1527"/>
            </criteria>
            <criteria operator="OR" comment="/usr/sbin/ethereal is executable">
              <criterion comment="/usr/sbin/ethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1526"/>
              <criterion comment="/usr/sbin/ethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1525"/>
              <criterion comment="/usr/sbin/ethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1524"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/tethereal is executable">
              <criterion comment="/usr/bin/tethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1523"/>
              <criterion comment="/usr/bin/tethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1522"/>
              <criterion comment="/usr/bin/tethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1521"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:88" version="2" class="vulnerability">
      <metadata>
        <title>Ethereal SPNEGO Dissoector Denial of Service Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>Ethereal</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0430" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0430"/>
        <description>The SPNEGO dissector in Ethereal 0.9.12 and earlier allows remote attackers to cause a denial of service (crash) via an invalid ASN.1 value.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-08-29T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-03-25T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:35.658-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:53:06.986-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
        <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
        <criteria operator="OR" comment="Vulnerable Config">
          <criterion comment="ethereal version is less than 0.9.13-1.90.1" negate="false" test_ref="oval:org.mitre.oval:tst:2985"/>
          <criterion comment="ethereal-gnome version is less than 0.9.13-1.90.1" negate="false" test_ref="oval:org.mitre.oval:tst:2984"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:880" version="2" class="vulnerability">
      <metadata>
        <title>Red Hat Ethereal Denial of Service via 0-Length Presentation Protocol Selector</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0367" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0367"/>
        <description>Ethereal 0.10.1 to 0.10.2 allows remote attackers to cause a denial of service (crash) via a zero-length Presentation protocol selector.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-04-07T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-06-16T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:24.508-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:53:07.190-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criteria operator="OR" comment="Vulnerable Config">
            <criterion comment="ethereal version is less than 0.10.3-0.90.1" negate="false" test_ref="oval:org.mitre.oval:tst:1531"/>
            <criterion comment="ethereal-gnome version is less than 0.10.3-0.90.1" negate="false" test_ref="oval:org.mitre.oval:tst:1530"/>
          </criteria>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="Vulnerable Config">
            <criteria operator="OR" comment="/usr/bin/ethereal is executable">
              <criterion comment="/usr/bin/ethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1529"/>
              <criterion comment="/usr/bin/ethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1528"/>
              <criterion comment="/usr/bin/ethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1527"/>
            </criteria>
            <criteria operator="OR" comment="/usr/sbin/ethereal is executable">
              <criterion comment="/usr/sbin/ethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1526"/>
              <criterion comment="/usr/sbin/ethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1525"/>
              <criterion comment="/usr/sbin/ethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1524"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/tethereal is executable">
              <criterion comment="/usr/bin/tethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1523"/>
              <criterion comment="/usr/bin/tethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1522"/>
              <criterion comment="/usr/bin/tethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1521"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:902" version="2" class="vulnerability">
      <metadata>
        <title>Red Hat OpenSSL Improper Unknown Message Handling Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>OpenSSL</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0081" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0081"/>
        <description>OpenSSL 0.9.6 before 0.9.6d does not properly handle unknown message types, which allows remote attackers to cause a denial of service (infinite loop), as demonstrated using the Codenomicon TLS Test Tool.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-03-20T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Matt Busby</contributor>
            </submitted>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="The MITRE Corporation">Matt Busby</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-06-16T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:35.007-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:53:08.302-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
        <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
        <criterion comment="openssl version is less than 0.9.7a-20" negate="false" test_ref="oval:org.mitre.oval:tst:1484"/>
        <criterion comment="openssl-devel version is less than 0.9.7a-20" negate="false" test_ref="oval:org.mitre.oval:tst:1483"/>
        <criterion comment="openssl-perl version is less than 0.9.7a-20" negate="false" test_ref="oval:org.mitre.oval:tst:1482"/>
        <criterion comment="openssl096 version is less than 0.9.6-25.9" negate="false" test_ref="oval:org.mitre.oval:tst:1481"/>
        <criterion comment="openssl096b version is less than 0.9.6b-15" negate="false" test_ref="oval:org.mitre.oval:tst:1480"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:975" version="2" class="vulnerability">
      <metadata>
        <title>Red Hat OpenSSL do_change_cipher_spec Function Denial of Service</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>OpenSSL</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0079" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0079"/>
        <description>The do_change_cipher_spec function in OpenSSL 0.9.6c to 0.9.6k, and 0.9.7a to 0.9.7c, allows remote attackers to cause a denial of service (crash) via a crafted SSL/TLS handshake that triggers a null dereference.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-03-20T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Matt Busby</contributor>
            </submitted>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="The MITRE Corporation">Matt Busby</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-06-16T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:24.326-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:53:11.788-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
        <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
        <criterion comment="openssl version is less than 0.9.7a-20" negate="false" test_ref="oval:org.mitre.oval:tst:1484"/>
        <criterion comment="openssl-devel version is less than 0.9.7a-20" negate="false" test_ref="oval:org.mitre.oval:tst:1483"/>
        <criterion comment="openssl-perl version is less than 0.9.7a-20" negate="false" test_ref="oval:org.mitre.oval:tst:1482"/>
        <criterion comment="openssl096 version is less than 0.9.6-25.9" negate="false" test_ref="oval:org.mitre.oval:tst:1481"/>
        <criterion comment="openssl096b version is less than 0.9.6b-15" negate="false" test_ref="oval:org.mitre.oval:tst:1480"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:839" version="2" deprecated="true" class="vulnerability">
      <metadata>
        <title>mod_python Web Server Denial of Service</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>mod_python</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0973" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0973"/>
        <description>Unknown vulnerability in mod_python 3.0.x before 3.0.4, and 2.7.x before 2.7.9, allows remote attackers to cause a denial of service (httpd crash) via a certain query string.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-03-20T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="The MITRE Corporation">Matt Busby</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex to match only reasonable values for machine class. Implemented by Jon Baker of the MITRE Corporation." date="2007-04-10T15:39:00.888-04:00">
              <contributor organization="Maitreya Security">Thomas R. Jones</contributor>
            </modified>
            <status_change date="2007-04-10T15:41:59.304-04:00">INTERIM</status_change>
            <status_change date="2007-04-25T19:52:59.430-04:00">ACCEPTED</status_change>
            <modified date="2007-05-08T07:29:32.570-04:00" comment="Deprecated becased this definition is a duplicate of oval:org.mitre.oval:def:828">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2007-05-08T07:29:32.570-04:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criterion comment="mod_python version is less than 3.0.1-4" negate="false" test_ref="oval:org.mitre.oval:tst:1612"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="httpd is listening to the network" negate="false" test_ref="oval:org.mitre.oval:tst:1611"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1689" version="3" class="vulnerability">
      <metadata>
        <title>Sendmail setjmp longjmp bo (Red Hat Internal)</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <product>Sendmail</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-0058" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0058"/>
        <description>Signal handler race condition in Sendmail 8.13.x before 8.13.6 allows remote attackers to execute arbitrary code by triggering timeouts in a way that causes the setjmp and longjmp function calls to be interrupted and modify unexpected memory locations.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-03-27T09:51:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-04-06T06:30:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-05-03T10:06:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-05-31T09:45:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected regex in ste:694. Implemented by Jon Baker of The MITRE Corporation." date="2007-05-01T15:07:00.947-04:00">
              <contributor organization="DSCI Contractor">Vladimir Giszpenc</contributor>
            </modified>
            <status_change date="2007-05-01T15:08:55.075-04:00">INTERIM</status_change>
            <status_change date="2007-05-23T15:05:31.387-04:00">ACCEPTED</status_change>
            <modified comment="Corrected vulnerability information for Redhat 3 and Redhat 4" date="2008-01-15T11:57:00-04:00">
              <contributor organization="Secure Elements, Inc.">Sudhir Gandhe</contributor>
            </modified>
            <status_change date="2008-01-17T12:05:31.387-04:00">INTERIM</status_change>
            <status_change date="2008-02-04T04:00:06.233-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software section">
        <criteria operator="AND" comment="Sendmail on Redhat 4">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 4 for x86" definition_ref="oval:org.mitre.oval:def:1734"/>
          <criterion comment="sendmail version is less than 8.13.1-3" test_ref="oval:org.mitre.oval:tst:7716"/>
        </criteria>
        <criteria operator="AND" comment="Sendmail on Redhat 3">
          <extend_definition comment="The operating system installed on the system is Red Hat Enterprise Linux 3 for x86" definition_ref="oval:org.mitre.oval:def:5537"/>
          <criterion comment="sendmail version is less than 8.12.11-4" test_ref="oval:org.mitre.oval:tst:7751"/>
        </criteria>
        <criteria operator="AND" comment="Sendmail on other flavors of redhat">
          <extend_definition negate="true" comment="The operating system installed on the system is Red Hat Enterprise Linux 3 for x86" definition_ref="oval:org.mitre.oval:def:5537"/>
          <extend_definition negate="true" comment="The operating system installed on the system is Red Hat Enterprise Linux 4 for x86" definition_ref="oval:org.mitre.oval:def:1734"/>
          <criteria operator="OR" comment="vulnerable version of sendmail">
            <criterion comment="sendmail before 8.12.x is installed" test_ref="oval:org.mitre.oval:tst:774"/>
            <criterion comment="sendmail 8.12.x before 8.12.11 is installed" test_ref="oval:org.mitre.oval:tst:773"/>
            <criterion comment="sendmail 8.13.x before 8.13.6 is installed" test_ref="oval:org.mitre.oval:tst:772"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5537" version="1" class="inventory">
      <metadata>
        <title>The operating system installed on the system is Red Hat Enterprise Linux 3 for x86</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/o:redhat:enterprise_linux:3::ix86"/>
        <description>The operating system installed on the system is Red Hat Enterprise Linux 4 for x86.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-01-12T14:07:00">
              <contributor organization="Secure Elements, Inc.">Sudhir Gandhe</contributor>
            </submitted>
            <status_change date="2008-01-17T13:56:57.725-05:00">DRAFT</status_change>
            <status_change date="2008-02-04T04:00:08.231-05:00">INTERIM</status_change>
            <status_change date="2008-02-25T04:00:11.758-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="Red Hat Enterprise 3 is installed" test_ref="oval:org.mitre.oval:tst:7836"/>
        <criterion comment="ix86 architecture" test_ref="oval:org.mitre.oval:tst:3912"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1734" version="1" class="inventory">
      <metadata>
        <title>The operating system installed on the system is Red Hat Enterprise Linux 4 for x86</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/o:redhat:enterprise_linux:4::ix86"/>
        <description>The operating system installed on the system is Red Hat Enterprise Linux 4 for x86.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-07-27T12:00:00.000-06:00">
              <contributor organization="McAfee, Inc.">Mark Villanova</contributor>
            </submitted>
            <status_change date="2007-08-14T21:26:14.122-04:00">DRAFT</status_change>
            <status_change date="2007-09-06T09:13:28.105-04:00">INTERIM</status_change>
            <status_change date="2007-09-27T08:57:41.206-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="Red Hat Enterprise 4 is installed" test_ref="oval:org.mitre.oval:tst:2652"/>
        <criterion comment="ix86 architecture" test_ref="oval:org.mitre.oval:tst:3912"/>
      </criteria>
    </definition>
  </definitions>
  <tests>
    <rpminfo_test id="oval:org.mitre.oval:tst:2939" version="1" check="at least one" comment="evolution version is less than 1.2.2-5" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:1680"/>
      <state state_ref="oval:org.mitre.oval:ste:2754"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:2936" version="1" check="at least one" comment="gdm version is less than 2.4.1.3-5.1" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:1677"/>
      <state state_ref="oval:org.mitre.oval:ste:2751"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:2911" version="1" check="at least one" comment="ghostscript version is less than 7.05-32.1" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:1668"/>
      <state state_ref="oval:org.mitre.oval:ste:2727"/>
    </rpminfo_test>
    <file_test id="oval:org.mitre.oval:tst:2910" version="1" check="at least one" comment="/usr/bin/gs is executable" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1667"/>
      <state state_ref="oval:org.mitre.oval:ste:2726"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2909" version="1" check="at least one" comment="/usr/bin/gs is executable" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1667"/>
      <state state_ref="oval:org.mitre.oval:ste:2725"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2908" version="1" check="at least one" comment="/usr/bin/gs is executable" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1667"/>
      <state state_ref="oval:org.mitre.oval:ste:2724"/>
    </file_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:2901" version="1" check="at least one" comment="gnupg version is less than 1.2.1-4" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:1665"/>
      <state state_ref="oval:org.mitre.oval:ste:2717"/>
    </rpminfo_test>
    <file_test id="oval:org.mitre.oval:tst:2900" version="1" check="at least one" comment="/usr/bin/gnupg is executable" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1664"/>
      <state state_ref="oval:org.mitre.oval:ste:2716"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2899" version="1" check="at least one" comment="/usr/bin/gnupg is executable" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1664"/>
      <state state_ref="oval:org.mitre.oval:ste:2715"/>
    </file_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:2897" version="1" check="at least one" comment="gtkhtml version is less than 1.1.9-0.9" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:1663"/>
      <state state_ref="oval:org.mitre.oval:ste:2713"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:2877" version="1" check="at least one" comment="gtkhtml version is less than 1.1.9-0.9.1" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:1650"/>
      <state state_ref="oval:org.mitre.oval:ste:2693"/>
    </rpminfo_test>
    <file_test id="oval:org.mitre.oval:tst:2876" version="1" check="at least one" comment="/usr/bin/evolution is executable" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1649"/>
      <state state_ref="oval:org.mitre.oval:ste:2692"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2875" version="1" check="at least one" comment="/usr/bin/evolution is executable" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1649"/>
      <state state_ref="oval:org.mitre.oval:ste:2691"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2874" version="1" check="at least one" comment="/usr/bin/evolution is executable" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1649"/>
      <state state_ref="oval:org.mitre.oval:ste:2690"/>
    </file_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:2866" version="1" check="at least one" comment="httpd version is less than 2.0.40-21.1" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:1644"/>
      <state state_ref="oval:org.mitre.oval:ste:2684"/>
    </rpminfo_test>
    <inetlisteningservers_test id="oval:org.mitre.oval:tst:2865" version="1" check="at least one" comment="httpd listening on the network" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:1643"/>
      <state state_ref="oval:org.mitre.oval:ste:2683"/>
    </inetlisteningservers_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:2852" version="1" check="at least one" comment="httpd version is less than 2.0.40-21.5" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:1634"/>
      <state state_ref="oval:org.mitre.oval:ste:2670"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:3151" version="1" check="at least one" comment="balsa version is less than 2.0.6-2" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:1791"/>
      <state state_ref="oval:org.mitre.oval:ste:2947"/>
    </rpminfo_test>
    <file_test id="oval:org.mitre.oval:tst:3150" version="1" check="at least one" comment="/usr/bin/balsa is executable" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1790"/>
      <state state_ref="oval:org.mitre.oval:ste:2946"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:3149" version="1" check="at least one" comment="/usr/bin/balsa is executable" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1790"/>
      <state state_ref="oval:org.mitre.oval:ste:2945"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:3148" version="1" check="at least one" comment="/usr/bin/balsa is executable" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1790"/>
      <state state_ref="oval:org.mitre.oval:ste:2944"/>
    </file_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:2826" version="1" check="at least one" comment="kdebase version is less than 3.1-15" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:1619"/>
      <state state_ref="oval:org.mitre.oval:ste:2646"/>
    </rpminfo_test>
    <file_test id="oval:org.mitre.oval:tst:2825" version="1" check="at least one" comment="/usr/bin/kdm is executable" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1618"/>
      <state state_ref="oval:org.mitre.oval:ste:2645"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2824" version="1" check="at least one" comment="/usr/bin/kdm is executable" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1618"/>
      <state state_ref="oval:org.mitre.oval:ste:2644"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2823" version="1" check="at least one" comment="/usr/bin/kdm is executable" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1618"/>
      <state state_ref="oval:org.mitre.oval:ste:2643"/>
    </file_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:2785" version="1" check="at least one" comment="krb5-server version is less than 1.2.7-14" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:1597"/>
      <state state_ref="oval:org.mitre.oval:ste:2606"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:2756" version="1" check="at least one" comment="krb5-libs version is less than 1.2.7-14" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:1582"/>
      <state state_ref="oval:org.mitre.oval:ste:2577"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:2755" version="1" check="at least one" comment="krb5-workstation version is less than 1.2.7-14" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:1581"/>
      <state state_ref="oval:org.mitre.oval:ste:2576"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:2753" version="1" check="at least one" comment="kernel version = 2.4.20-6" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:1579"/>
      <state state_ref="oval:org.mitre.oval:ste:2574"/>
    </rpminfo_test>
    <uname_test id="oval:org.mitre.oval:tst:2752" version="1" check="at least one" comment="kernel 2.4.20-6 or earlier is running" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:679"/>
      <state state_ref="oval:org.mitre.oval:ste:2573"/>
    </uname_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:3061" version="1" check="at least one" comment="ddskk version is less than 11.6.0-11.90" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:1751"/>
      <state state_ref="oval:org.mitre.oval:ste:2866"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:3060" version="1" check="at least one" comment="ddskk-xemacs version is less than 11.6.0-11.90" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:1750"/>
      <state state_ref="oval:org.mitre.oval:ste:2865"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:2721" version="1" check="at least one" comment="kernel version is less than 2.4.20-18.9" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:1565"/>
      <state state_ref="oval:org.mitre.oval:ste:2542"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:2742" version="1" check="at least one" comment="kernel version is less than 2.4.20-13.9" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:1574"/>
      <state state_ref="oval:org.mitre.oval:ste:2563"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:2709" version="1" check="at least one" comment="kernel version is less than 2.4.20-19.9" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:1556"/>
      <state state_ref="oval:org.mitre.oval:ste:2530"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:2656" version="1" check="at least one" comment="kdelibs version is less than 3.1-12" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:1521"/>
      <state state_ref="oval:org.mitre.oval:ste:2481"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:2647" version="1" check="at least one" comment="lprng version is less than 3.8.19-3.1" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:1516"/>
      <state state_ref="oval:org.mitre.oval:ste:2473"/>
    </rpminfo_test>
    <file_test id="oval:org.mitre.oval:tst:2646" version="1" check="at least one" comment="psbanner is world-executable" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1515"/>
      <state state_ref="oval:org.mitre.oval:ste:2472"/>
    </file_test>
    <inetlisteningservers_test id="oval:org.mitre.oval:tst:2645" version="1" check="at least one" comment="lpd listening on the network" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:1514"/>
      <state state_ref="oval:org.mitre.oval:ste:2471"/>
    </inetlisteningservers_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:2639" version="1" check="at least one" comment="lv version is less than 4.49.4-9.9.1" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:1507"/>
      <state state_ref="oval:org.mitre.oval:ste:2466"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:2638" version="1" check="at least one" comment="mutt version is less than 1.4.1-1" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:1506"/>
      <state state_ref="oval:org.mitre.oval:ste:2465"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:2634" version="1" check="at least one" comment="mysql-server version is less than 3.23.56-1.9" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:1504"/>
      <state state_ref="oval:org.mitre.oval:ste:2461"/>
    </rpminfo_test>
    <inetlisteningservers_test id="oval:org.mitre.oval:tst:2633" version="1" check="at least one" comment="mysqld is listening to the network" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:1503"/>
      <state state_ref="oval:org.mitre.oval:ste:2460"/>
    </inetlisteningservers_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:2631" version="1" check="at least one" comment="nfs-utils version is less than 1.0.1-3.9" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:1502"/>
      <state state_ref="oval:org.mitre.oval:ste:2458"/>
    </rpminfo_test>
    <inetlisteningservers_test id="oval:org.mitre.oval:tst:2630" version="1" check="at least one" comment="rpc.mountd listens on the network" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:1501"/>
      <state state_ref="oval:org.mitre.oval:ste:2457"/>
    </inetlisteningservers_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:2629" version="1" check="at least one" comment="openssh-server version is less than 3.5p1-6.9" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:1500"/>
      <state state_ref="oval:org.mitre.oval:ste:2456"/>
    </rpminfo_test>
    <inetlisteningservers_test id="oval:org.mitre.oval:tst:2628" version="1" check="at least one" comment="sshd listens on the network" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:1499"/>
      <state state_ref="oval:org.mitre.oval:ste:2455"/>
    </inetlisteningservers_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:2627" version="1" check="at least one" comment="openssh-server version is less than 3.5p1-11" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:1498"/>
      <state state_ref="oval:org.mitre.oval:ste:2454"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:2618" version="1" check="at least one" comment="openssl version is less than 0.9.7a-5" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:1492"/>
      <state state_ref="oval:org.mitre.oval:ste:2447"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:2617" version="1" check="at least one" comment="openssl-devel version is less than 0.9.7a-5" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:1491"/>
      <state state_ref="oval:org.mitre.oval:ste:2446"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:2616" version="1" check="at least one" comment="openssl-perl version is less than 0.9.7a-5" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:1490"/>
      <state state_ref="oval:org.mitre.oval:ste:2445"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:2615" version="1" check="at least one" comment="openssl096 version is less than 0.9.6-17" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:1489"/>
      <state state_ref="oval:org.mitre.oval:ste:2444"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:2614" version="1" check="at least one" comment="openssl096b version is less than 0.9.6b-6" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:1488"/>
      <state state_ref="oval:org.mitre.oval:ste:2443"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:2608" version="1" check="at least one" comment="pam_smb version is less than 1.1.6-9.9" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:1483"/>
      <state state_ref="oval:org.mitre.oval:ste:2437"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:2607" version="1" check="at least one" comment="perl-CGI version is less than 2.81-88.3" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:1482"/>
      <state state_ref="oval:org.mitre.oval:ste:2436"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:2592" version="1" check="at least one" comment="php version is less than 4.2.2-17.2" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:1471"/>
      <state state_ref="oval:org.mitre.oval:ste:2425"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:2587" version="1" check="at least one" comment="pine version is less than 4.44-19.90.0" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:1468"/>
      <state state_ref="oval:org.mitre.oval:ste:2420"/>
    </rpminfo_test>
    <file_test id="oval:org.mitre.oval:tst:2586" version="1" check="at least one" comment="/usr/bin/pine is executable" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1467"/>
      <state state_ref="oval:org.mitre.oval:ste:2419"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2585" version="1" check="at least one" comment="/usr/bin/pine is executable" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1467"/>
      <state state_ref="oval:org.mitre.oval:ste:2418"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2584" version="1" check="at least one" comment="/usr/bin/pine is executable" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1467"/>
      <state state_ref="oval:org.mitre.oval:ste:2417"/>
    </file_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:3011" version="1" check="at least one" comment="eog version is less than 2.2.0-2" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:1724"/>
      <state state_ref="oval:org.mitre.oval:ste:2820"/>
    </rpminfo_test>
    <file_test id="oval:org.mitre.oval:tst:3010" version="1" check="at least one" comment="eog is world-executable" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1723"/>
      <state state_ref="oval:org.mitre.oval:ste:2819"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:3009" version="1" check="at least one" comment="eog is group-executable" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1723"/>
      <state state_ref="oval:org.mitre.oval:ste:2818"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:3008" version="1" check="at least one" comment="eog is owner-executable" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1723"/>
      <state state_ref="oval:org.mitre.oval:ste:2817"/>
    </file_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:2578" version="1" check="at least one" comment="postfix version is less than 1.1.12-1" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:1466"/>
      <state state_ref="oval:org.mitre.oval:ste:2411"/>
    </rpminfo_test>
    <inetlisteningservers_test id="oval:org.mitre.oval:tst:2577" version="1" check="at least one" comment="smtpd listens on the network" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:1465"/>
      <state state_ref="oval:org.mitre.oval:ste:2410"/>
    </inetlisteningservers_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:3007" version="1" check="at least one" comment="ethereal version is less than 0.9.11-0.90.1" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:1722"/>
      <state state_ref="oval:org.mitre.oval:ste:2816"/>
    </rpminfo_test>
    <inetlisteningservers_test id="oval:org.mitre.oval:tst:2565" version="1" check="at least one" comment="smbd listens on the network" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:1461"/>
      <state state_ref="oval:org.mitre.oval:ste:2398"/>
    </inetlisteningservers_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:2566" version="1" check="at least one" comment="samba version is less than 2.2.7a-7.9.0" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:1462"/>
      <state state_ref="oval:org.mitre.oval:ste:2399"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:2559" version="1" check="at least one" comment="samba version is less than 2.2.7a-8.9.0" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:1458"/>
      <state state_ref="oval:org.mitre.oval:ste:2393"/>
    </rpminfo_test>
    <inetlisteningservers_test id="oval:org.mitre.oval:tst:2558" version="1" check="at least one" comment="smbd is listening on the network" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:1457"/>
      <state state_ref="oval:org.mitre.oval:ste:2392"/>
    </inetlisteningservers_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:2557" version="1" check="at least one" comment="wl version is less than 2.10.1-1.1" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:1456"/>
      <state state_ref="oval:org.mitre.oval:ste:2391"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:2556" version="1" check="at least one" comment="wl-xemacs version is less than 2.10.1-1.1" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:1455"/>
      <state state_ref="oval:org.mitre.oval:ste:2390"/>
    </rpminfo_test>
    <file_test id="oval:org.mitre.oval:tst:2555" version="1" check="at least one" comment="/usr/bin/emacs is executable" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1454"/>
      <state state_ref="oval:org.mitre.oval:ste:2389"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2554" version="1" check="at least one" comment="/usr/bin/emacs is executable" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1454"/>
      <state state_ref="oval:org.mitre.oval:ste:2388"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2553" version="1" check="at least one" comment="/usr/bin/emacs is executable" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1454"/>
      <state state_ref="oval:org.mitre.oval:ste:2387"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2552" version="1" check="at least one" comment="/usr/bin/xemacs is executable" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1453"/>
      <state state_ref="oval:org.mitre.oval:ste:2386"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2551" version="1" check="at least one" comment="/usr/bin/xemacs is executable" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1453"/>
      <state state_ref="oval:org.mitre.oval:ste:2385"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2550" version="1" check="at least one" comment="/usr/bin/xemacs is executable" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1453"/>
      <state state_ref="oval:org.mitre.oval:ste:2384"/>
    </file_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:2549" version="1" check="at least one" comment="sendmail version is less than 8.12.8-5.90" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:1452"/>
      <state state_ref="oval:org.mitre.oval:ste:2383"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:2517" version="1" check="at least one" comment="sendmail version is less than 8.12.8-6.90" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:1433"/>
      <state state_ref="oval:org.mitre.oval:ste:2357"/>
    </rpminfo_test>
    <inetlisteningservers_test id="oval:org.mitre.oval:tst:2516" version="1" check="at least one" comment="sendmail is listening to the network" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:1432"/>
      <state state_ref="oval:org.mitre.oval:ste:2356"/>
    </inetlisteningservers_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:3147" version="1" check="at least one" comment="cups version is less than 1.1.17-13.3" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:1789"/>
      <state state_ref="oval:org.mitre.oval:ste:2943"/>
    </rpminfo_test>
    <inetlisteningservers_test id="oval:org.mitre.oval:tst:3146" version="1" check="at least one" comment="cupsd listens on the network" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:1788"/>
      <state state_ref="oval:org.mitre.oval:ste:2942"/>
    </inetlisteningservers_test>
    <file_test id="oval:org.mitre.oval:tst:2548" version="1" check="at least one" comment="sendmail is Set-UID" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1451"/>
      <state state_ref="oval:org.mitre.oval:ste:2382"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2547" version="1" check="at least one" comment="sendmail is Set-UID" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1451"/>
      <state state_ref="oval:org.mitre.oval:ste:2381"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2546" version="1" check="at least one" comment="sendmail is Set-UID" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1451"/>
      <state state_ref="oval:org.mitre.oval:ste:2380"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2545" version="1" check="at least one" comment="sendmail is Set-GID" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1451"/>
      <state state_ref="oval:org.mitre.oval:ste:2379"/>
    </file_test>
    <inetlisteningservers_test id="oval:org.mitre.oval:tst:2544" version="1" check="at least one" comment="sendmail listening" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:1450"/>
      <state state_ref="oval:org.mitre.oval:ste:2378"/>
    </inetlisteningservers_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:2518" version="1" check="at least one" comment="sendmail version is less than 8.12.8-9.90" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:1434"/>
      <state state_ref="oval:org.mitre.oval:ste:2358"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:2499" version="1" check="at least one" comment="squirrelmail version is less than 1.2.11-1" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:1424"/>
      <state state_ref="oval:org.mitre.oval:ste:2340"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:2498" version="1" check="at least one" comment="unzip version is less than 5.50-33" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:1423"/>
      <state state_ref="oval:org.mitre.oval:ste:2339"/>
    </rpminfo_test>
    <file_test id="oval:org.mitre.oval:tst:2497" version="1" check="at least one" comment="/usr/bin/unzip is executable" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1422"/>
      <state state_ref="oval:org.mitre.oval:ste:2338"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2496" version="1" check="at least one" comment="/usr/bin/unzip is executable" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1422"/>
      <state state_ref="oval:org.mitre.oval:ste:2337"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2495" version="1" check="at least one" comment="/usr/bin/unzip is executable" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1422"/>
      <state state_ref="oval:org.mitre.oval:ste:2336"/>
    </file_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:2489" version="1" check="at least one" comment="up2date version is less than 3.1.23.1-5" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:1419"/>
      <state state_ref="oval:org.mitre.oval:ste:2331"/>
    </rpminfo_test>
    <process_test id="oval:org.mitre.oval:tst:2488" version="1" check="at least one" comment="rhnsd is running" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1418"/>
    </process_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:2487" version="1" check="at least one" comment="vsftpd version is less than 1.1.3-8" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:1417"/>
      <state state_ref="oval:org.mitre.oval:ste:2330"/>
    </rpminfo_test>
    <inetlisteningservers_test id="oval:org.mitre.oval:tst:2486" version="1" check="at least one" comment="vsftpd is listening to the network" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:1416"/>
      <state state_ref="oval:org.mitre.oval:ste:2329"/>
    </inetlisteningservers_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:2467" version="1" check="at least one" comment="xinetd version is less than 2:2.3.11-1.9.0" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:1400"/>
      <state state_ref="oval:org.mitre.oval:ste:2311"/>
    </rpminfo_test>
    <inetlisteningservers_test id="oval:org.mitre.oval:tst:2466" version="1" check="at least one" comment="xinetd is listening to the network" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:1399"/>
      <state state_ref="oval:org.mitre.oval:ste:2310"/>
    </inetlisteningservers_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:2455" version="1" check="at least one" comment="xpdf version is less than 2.0.1-11" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:1393"/>
      <state state_ref="oval:org.mitre.oval:ste:2300"/>
    </rpminfo_test>
    <file_test id="oval:org.mitre.oval:tst:2454" version="1" check="at least one" comment="xpdf is executable" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1392"/>
      <state state_ref="oval:org.mitre.oval:ste:2299"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2453" version="1" check="at least one" comment="xpdf is executable" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1392"/>
      <state state_ref="oval:org.mitre.oval:ste:2298"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2452" version="1" check="at least one" comment="xpdf is executable" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1392"/>
      <state state_ref="oval:org.mitre.oval:ste:2297"/>
    </file_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:2451" version="1" check="at least one" comment="ypserv version is less than 2.8-0.9E" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:1391"/>
      <state state_ref="oval:org.mitre.oval:ste:2296"/>
    </rpminfo_test>
    <inetlisteningservers_test id="oval:org.mitre.oval:tst:2450" version="1" check="at least one" comment="ypserv is listening on the network" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:1390"/>
      <state state_ref="oval:org.mitre.oval:ste:2295"/>
    </inetlisteningservers_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:2321" version="1" check="at least one" comment="pwlib version is less than 1.4.7-4.1" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:1338"/>
      <state state_ref="oval:org.mitre.oval:ste:2173"/>
    </rpminfo_test>
    <inetlisteningservers_test id="oval:org.mitre.oval:tst:2320" version="1" check="at least one" comment="a program is listening on TCP or UDP port 1720" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:1337"/>
      <state state_ref="oval:org.mitre.oval:ste:2172"/>
    </inetlisteningservers_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:2319" version="1" check="at least one" comment="netpbm version is less than 9.24-10.90.1" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:1336"/>
      <state state_ref="oval:org.mitre.oval:ste:2171"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:2318" version="1" check="at least one" comment="netpbm-devel version is less than 9.24-10.90.1" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:1335"/>
      <state state_ref="oval:org.mitre.oval:ste:2170"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:2317" version="1" check="at least one" comment="netpbm-progs version is less than 9.24-10.90.1" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:1334"/>
      <state state_ref="oval:org.mitre.oval:ste:2169"/>
    </rpminfo_test>
    <file_test id="oval:org.mitre.oval:tst:2316" version="1" check="at least one" comment="/usr/bin/411toppm is executable" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1333"/>
      <state state_ref="oval:org.mitre.oval:ste:2168"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2315" version="1" check="at least one" comment="/usr/bin/411toppm is executable" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1333"/>
      <state state_ref="oval:org.mitre.oval:ste:2167"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2314" version="1" check="at least one" comment="/usr/bin/411toppm is executable" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1333"/>
      <state state_ref="oval:org.mitre.oval:ste:2166"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2313" version="1" check="at least one" comment="/usr/bin/asciitopgm is executable" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1332"/>
      <state state_ref="oval:org.mitre.oval:ste:2165"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2312" version="1" check="at least one" comment="/usr/bin/asciitopgm is executable" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1332"/>
      <state state_ref="oval:org.mitre.oval:ste:2164"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2311" version="1" check="at least one" comment="/usr/bin/asciitopgm is executable" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1332"/>
      <state state_ref="oval:org.mitre.oval:ste:2163"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2310" version="1" check="at least one" comment="/usr/bin/atktopbm is executable" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1331"/>
      <state state_ref="oval:org.mitre.oval:ste:2162"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2309" version="1" check="at least one" comment="/usr/bin/atktopbm is executable" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1331"/>
      <state state_ref="oval:org.mitre.oval:ste:2161"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2308" version="1" check="at least one" comment="/usr/bin/atktopbm is executable" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1331"/>
      <state state_ref="oval:org.mitre.oval:ste:2160"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2307" version="1" check="at least one" comment="/usr/bin/bioradtopgm is executable" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1330"/>
      <state state_ref="oval:org.mitre.oval:ste:2159"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2306" version="1" check="at least one" comment="/usr/bin/bioradtopgm is executable" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1330"/>
      <state state_ref="oval:org.mitre.oval:ste:2158"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2305" version="1" check="at least one" comment="/usr/bin/bioradtopgm is executable" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1330"/>
      <state state_ref="oval:org.mitre.oval:ste:2157"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2304" version="1" check="at least one" comment="/usr/bin/bmptoppm is executable" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1329"/>
      <state state_ref="oval:org.mitre.oval:ste:2156"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2303" version="1" check="at least one" comment="/usr/bin/bmptoppm is executable" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1329"/>
      <state state_ref="oval:org.mitre.oval:ste:2155"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2302" version="1" check="at least one" comment="/usr/bin/bmptoppm is executable" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1329"/>
      <state state_ref="oval:org.mitre.oval:ste:2154"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2301" version="1" check="at least one" comment="/usr/bin/brushtopbm is executable" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1328"/>
      <state state_ref="oval:org.mitre.oval:ste:2153"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2300" version="1" check="at least one" comment="/usr/bin/brushtopbm is executable" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1328"/>
      <state state_ref="oval:org.mitre.oval:ste:2152"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2299" version="1" check="at least one" comment="/usr/bin/brushtopbm is executable" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1328"/>
      <state state_ref="oval:org.mitre.oval:ste:2151"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2298" version="1" check="at least one" comment="/usr/bin/cmuwmtopbm is executable" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1327"/>
      <state state_ref="oval:org.mitre.oval:ste:2150"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2297" version="1" check="at least one" comment="/usr/bin/cmuwmtopbm is executable" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1327"/>
      <state state_ref="oval:org.mitre.oval:ste:2149"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2296" version="1" check="at least one" comment="/usr/bin/cmuwmtopbm is executable" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1327"/>
      <state state_ref="oval:org.mitre.oval:ste:2148"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2295" version="1" check="at least one" comment="/usr/bin/eyuvtoppm is executable" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1326"/>
      <state state_ref="oval:org.mitre.oval:ste:2147"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2294" version="1" check="at least one" comment="/usr/bin/eyuvtoppm is executable" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1326"/>
      <state state_ref="oval:org.mitre.oval:ste:2146"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2293" version="1" check="at least one" comment="/usr/bin/eyuvtoppm is executable" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1326"/>
      <state state_ref="oval:org.mitre.oval:ste:2145"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2292" version="1" check="at least one" comment="/usr/bin/fiascotopnm is executable" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1325"/>
      <state state_ref="oval:org.mitre.oval:ste:2144"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2291" version="1" check="at least one" comment="/usr/bin/fiascotopnm is executable" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1325"/>
      <state state_ref="oval:org.mitre.oval:ste:2143"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2290" version="1" check="at least one" comment="/usr/bin/fiascotopnm is executable" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1325"/>
      <state state_ref="oval:org.mitre.oval:ste:2142"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2289" version="1" check="at least one" comment="/usr/bin/fitstopnm is executable" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1324"/>
      <state state_ref="oval:org.mitre.oval:ste:2141"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2288" version="1" check="at least one" comment="/usr/bin/fitstopnm is executable" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1324"/>
      <state state_ref="oval:org.mitre.oval:ste:2140"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2287" version="1" check="at least one" comment="/usr/bin/fitstopnm is executable" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1324"/>
      <state state_ref="oval:org.mitre.oval:ste:2139"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2286" version="1" check="at least one" comment="/usr/bin/fstopgm is executable" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1323"/>
      <state state_ref="oval:org.mitre.oval:ste:2138"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2285" version="1" check="at least one" comment="/usr/bin/fstopgm is executable" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1323"/>
      <state state_ref="oval:org.mitre.oval:ste:2137"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2284" version="1" check="at least one" comment="/usr/bin/fstopgm is executable" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1323"/>
      <state state_ref="oval:org.mitre.oval:ste:2136"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2283" version="1" check="at least one" comment="/usr/bin/g3topbm is executable" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1322"/>
      <state state_ref="oval:org.mitre.oval:ste:2135"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2282" version="1" check="at least one" comment="/usr/bin/g3topbm is executable" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1322"/>
      <state state_ref="oval:org.mitre.oval:ste:2134"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2281" version="1" check="at least one" comment="/usr/bin/g3topbm is executable" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1322"/>
      <state state_ref="oval:org.mitre.oval:ste:2133"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2280" version="1" check="at least one" comment="/usr/bin/gemtopbm is executable" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1321"/>
      <state state_ref="oval:org.mitre.oval:ste:2132"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2279" version="1" check="at least one" comment="/usr/bin/gemtopbm is executable" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1321"/>
      <state state_ref="oval:org.mitre.oval:ste:2131"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2278" version="1" check="at least one" comment="/usr/bin/gemtopbm is executable" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1321"/>
      <state state_ref="oval:org.mitre.oval:ste:2130"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2277" version="1" check="at least one" comment="/usr/bin/gemtopnm is executable" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1320"/>
      <state state_ref="oval:org.mitre.oval:ste:2129"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2276" version="1" check="at least one" comment="/usr/bin/gemtopnm is executable" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1320"/>
      <state state_ref="oval:org.mitre.oval:ste:2128"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2275" version="1" check="at least one" comment="/usr/bin/gemtopnm is executable" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1320"/>
      <state state_ref="oval:org.mitre.oval:ste:2127"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2274" version="1" check="at least one" comment="/usr/bin/giftopnm is executable" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1319"/>
      <state state_ref="oval:org.mitre.oval:ste:2126"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2273" version="1" check="at least one" comment="/usr/bin/giftopnm is executable" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1319"/>
      <state state_ref="oval:org.mitre.oval:ste:2125"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2272" version="1" check="at least one" comment="/usr/bin/giftopnm is executable" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1319"/>
      <state state_ref="oval:org.mitre.oval:ste:2124"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2271" version="1" check="at least one" comment="/usr/bin/gouldtoppm is executable" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1318"/>
      <state state_ref="oval:org.mitre.oval:ste:2123"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2270" version="1" check="at least one" comment="/usr/bin/gouldtoppm is executable" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1318"/>
      <state state_ref="oval:org.mitre.oval:ste:2122"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2269" version="1" check="at least one" comment="/usr/bin/gouldtoppm is executable" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1318"/>
      <state state_ref="oval:org.mitre.oval:ste:2121"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2268" version="1" check="at least one" comment="/usr/bin/hipstopgm is executable" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1317"/>
      <state state_ref="oval:org.mitre.oval:ste:2120"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2267" version="1" check="at least one" comment="/usr/bin/hipstopgm is executable" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1317"/>
      <state state_ref="oval:org.mitre.oval:ste:2119"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2266" version="1" check="at least one" comment="/usr/bin/hipstopgm is executable" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1317"/>
      <state state_ref="oval:org.mitre.oval:ste:2118"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2265" version="1" check="at least one" comment="/usr/bin/hpcdtoppm is executable" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1316"/>
      <state state_ref="oval:org.mitre.oval:ste:2117"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2264" version="1" check="at least one" comment="/usr/bin/hpcdtoppm is executable" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1316"/>
      <state state_ref="oval:org.mitre.oval:ste:2116"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2263" version="1" check="at least one" comment="/usr/bin/hpcdtoppm is executable" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1316"/>
      <state state_ref="oval:org.mitre.oval:ste:2115"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2262" version="1" check="at least one" comment="/usr/bin/icontopbm is executable" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1315"/>
      <state state_ref="oval:org.mitre.oval:ste:2114"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2261" version="1" check="at least one" comment="/usr/bin/icontopbm is executable" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1315"/>
      <state state_ref="oval:org.mitre.oval:ste:2113"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2260" version="1" check="at least one" comment="/usr/bin/icontopbm is executable" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1315"/>
      <state state_ref="oval:org.mitre.oval:ste:2112"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2259" version="1" check="at least one" comment="/usr/bin/ilbmtoppm is executable" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1314"/>
      <state state_ref="oval:org.mitre.oval:ste:2111"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2258" version="1" check="at least one" comment="/usr/bin/ilbmtoppm is executable" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1314"/>
      <state state_ref="oval:org.mitre.oval:ste:2110"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2257" version="1" check="at least one" comment="/usr/bin/ilbmtoppm is executable" check_existence="at_least_one_exists"