<?xml version="1.0" encoding="UTF-8"?>
<oval_definitions xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-definitions-5 oval-definitions-schema.xsd http://oval.mitre.org/XMLSchema/oval-definitions-5#independent independent-definitions-schema.xsd http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris solaris-definitions-schema.xsd http://oval.mitre.org/XMLSchema/oval-common-5 oval-common-schema.xsd http://oval.mitre.org/XMLSchema/oval-definitions-5#unix unix-definitions-schema.xsd" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:oval="http://oval.mitre.org/XMLSchema/oval-common-5" xmlns:oval-def="http://oval.mitre.org/XMLSchema/oval-definitions-5">
  <generator>
    <oval:product_name>The OVAL Repository</oval:product_name>
    <oval:schema_version>5.9</oval:schema_version>
    <oval:timestamp>2012-01-27T05:11:14.756-05:00</oval:timestamp>
  </generator>
  <definitions>
    <definition id="oval:org.mitre.oval:def:998" version="1" class="vulnerability">
      <metadata>
        <title>Solaris Xorg Privilege Escalation via Pixmaps Vulnerability</title>
        <affected family="unix">
          <platform>Sun Solaris 9</platform>
          <platform>Sun Solaris 10</platform>
          <product>X</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2495" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2495"/>
        <description>Multiple integer overflows in XFree86 before 4.3.0 allow user-assisted attackers to execute arbitrary code via a crafted pixmap image.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-02-12T01:16:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-03-09T12:19:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-04-06T06:30:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-05-03T10:06:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="OR">
          <criteria operator="AND" comment="Solaris 9 (x86,Xorg) meets Sun Alert ID 101926 criteria.">
            <criterion comment="Solaris 9 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3051"/>
            <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:2463"/>
            <criterion comment="Patch 118908-02 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:1337"/>
            <criterion comment="File Xorg exists" negate="false" test_ref="oval:org.mitre.oval:tst:1336"/>
          </criteria>
          <criteria operator="AND" comment="Solaris 10 (x86,Xorg) meets Sun Alert ID 101926 criteria.">
            <criterion comment="Solaris 10 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:2459"/>
            <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:2463"/>
            <criterion comment="Patch 118966-09 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:1335"/>
            <criterion comment="File Xorg exists" negate="false" test_ref="oval:org.mitre.oval:tst:1336"/>
          </criteria>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="The Xorg X server is running" negate="false" test_ref="oval:org.mitre.oval:tst:1334"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:943" version="2" class="vulnerability">
      <metadata>
        <title>Solaris Xsun and Xprt Unspecified Local Privilege Escalation</title>
        <affected family="unix">
          <platform>Sun Solaris 7</platform>
          <platform>Sun Solaris 8</platform>
          <platform>Sun Solaris 9</platform>
          <platform>Sun Solaris 10</platform>
          <product>Xsun</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-3099" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-3099"/>
        <description>Unspecified vulnerability in the (1) Xsun and (2) Xprt commands in Solaris 7, 8, 9, and 10 allows local users to execute arbitrary code.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-09-22T05:52:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-09-22T20:15:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-07T09:15:54.666-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:16:01.243-04:00">ACCEPTED</status_change>
            <modified comment="Corrected CVE reference and title. Implemented by Jon Baker of The MITRE Corporation." date="2007-02-13T14:00:00.106-05:00">
              <contributor organization="Security-Database">Nabil Ouchn</contributor>
            </modified>
            <status_change date="2007-02-13T14:01:36.132-05:00">INTERIM</status_change>
            <status_change date="2007-03-21T16:17:28.569-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="OR">
          <criterion comment="Solaris 7 is installed." negate="false" test_ref="oval:org.mitre.oval:tst:3576"/>
          <criteria operator="AND" comment="Solaris 8 (SPARC) meets Sun Alert ID 101800 criteria." negate="false">
            <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3437"/>
            <criterion comment="sparc architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3237"/>
            <criterion comment="Patch 108652-93 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:3400"/>
          </criteria>
          <criteria operator="AND" comment="Solaris 8 (x86) meets Sun Alert ID 101800 criteria." negate="false">
            <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3437"/>
            <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3912"/>
            <criterion comment="Patch 108653-82 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:3355"/>
          </criteria>
          <criteria operator="AND" comment="Solaris 9 (SPARC) meets Sun Alert ID 101800 criteria." negate="false">
            <criterion comment="Solaris 9 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3172"/>
            <criterion comment="sparc architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3237"/>
            <criterion comment="Patch 112785-50 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:4130"/>
          </criteria>
          <criteria operator="AND" comment="Solaris 9 (x86) meets Sun Alert ID 101800 criteria." negate="false">
            <criterion comment="Solaris 9 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3172"/>
            <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3912"/>
            <criterion comment="Patch 112786-39 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:3404"/>
          </criteria>
          <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert ID 101800 criteria." negate="false">
            <criterion comment="Solaris 10 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3680"/>
            <criterion comment="sparc architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3237"/>
            <criterion comment="Patch 119059-05 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:3997"/>
          </criteria>
          <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert ID 101800 criteria." negate="false">
            <criterion comment="Solaris 10 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3680"/>
            <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3912"/>
            <criterion comment="Patch 119060-05 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:3529"/>
          </criteria>
        </criteria>
        <criteria comment="Configuration section" operator="OR">
          <criteria operator="AND" comment="File Xsun is SUID|SGID AND Executable" negate="false">
            <criteria operator="OR" comment="File Xsun SUID|SGID" negate="false">
              <criterion comment="File Xsun SUID" negate="false" test_ref="oval:org.mitre.oval:tst:3963"/>
              <criterion comment="File Xprt SUID" negate="false" test_ref="oval:org.mitre.oval:tst:3558"/>
            </criteria>
            <criterion comment="File Xsun SGID and executable" negate="false" test_ref="oval:org.mitre.oval:tst:3178"/>
          </criteria>
          <criteria operator="AND" comment="File Xprt is SUID|SGID AND Executable" negate="false">
            <criteria operator="OR" comment="File Xprt SUID|SGID" negate="false">
              <criterion comment="File Xsun SUID" negate="false" test_ref="oval:org.mitre.oval:tst:3963"/>
              <criterion comment="File Xprt SUID" negate="false" test_ref="oval:org.mitre.oval:tst:3558"/>
            </criteria>
            <criterion comment="File Xsun SGID and executable" negate="false" test_ref="oval:org.mitre.oval:tst:3178"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9165" version="1" class="vulnerability">
      <metadata>
        <title>Security Vulnerabilities in the KSSL Kernel Module May Lead to a System Panic</title>
        <affected family="unix">
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-3470" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3470"/>
        <description>Multiple unspecified vulnerabilities in the KSSL kernel module in Sun Solaris 10, when configured with the KSSL proxy, allow remote attackers to cause a denial of service (kernel panic) via unspecified vectors related to "memory buffers" of Secure Socket Layer (SSL) records.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-08-03T10:36:57.000-04:00">
              <contributor organization="Opsware, Inc.">Todd Dolinsky</contributor>
            </submitted>
            <status_change date="2007-08-03T16:51:06.630-04:00">DRAFT</status_change>
            <status_change date="2007-08-20T08:04:46.053-04:00">INTERIM</status_change>
            <status_change date="2007-09-06T09:13:39.334-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="Software Section">
          <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 102918" negate="false">
            <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
            <criterion comment="Patch 125100-10 or later installed" test_ref="oval:org.mitre.oval:tst:4665" negate="true"/>
            <criterion comment="Patch 121474-01 or later installed" test_ref="oval:org.mitre.oval:tst:4207" negate="false"/>
          </criteria>
          <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 102918" negate="false">
            <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
            <criterion comment="Patch 125101-10 or later installed" test_ref="oval:org.mitre.oval:tst:4966" negate="true"/>
            <criterion comment="Patch 121475-01 or later installed" test_ref="oval:org.mitre.oval:tst:4240" negate="false"/>
          </criteria>
        </criteria>
        <criterion comment="kssl running" negate="false" test_ref="oval:org.mitre.oval:tst:4861"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9039" version="1" class="vulnerability">
      <metadata>
        <title>Solaris 10 Systems May Panic or Hang When Running Certain DTrace D Programs</title>
        <affected family="unix">
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-4126" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4126"/>
        <description>Unspecified vulnerability in the dynamic tracing framework (DTrace) on Sun Solaris 10 before 20070730 allows local users with PRIV_DTRACE_USER privileges to cause a denial of service (panic or hang) via unspecified use of certain DTrace programs.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-08-02T11:47:26.000-04:00">
              <contributor organization="Opsware, Inc.">Todd Dolinsky</contributor>
            </submitted>
            <status_change date="2007-08-03T16:50:57.753-04:00">DRAFT</status_change>
            <status_change date="2007-08-20T08:04:45.800-04:00">INTERIM</status_change>
            <status_change date="2007-09-06T09:13:39.047-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 103021" negate="false">
          <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
          <criterion comment="Patch 125100-10 or later installed" test_ref="oval:org.mitre.oval:tst:4221" negate="true"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 103021" negate="false">
          <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
          <criterion comment="Patch 125101-10 or later installed" test_ref="oval:org.mitre.oval:tst:4704" negate="true"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:881" version="2" class="vulnerability">
      <metadata>
        <title>Bourne Shell Local-DoS Vulnerability</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <platform>Sun Solaris 9</platform>
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-1780" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1780"/>
        <description>The Bourne shell (sh) in Solaris 8, 9, and 10 allows local users to cause a denial of service (sh crash) via an unspecified attack vector that causes sh processes to crash during creation of temporary files.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-04-14T06:41:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-04-19T10:08:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-05-10T08:33:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-05-31T09:45:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Changed criterion to check for the patch or later being installed instead of simply checking if the patch is installed." date="2009-07-17T11:04:00.601-04:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </modified>
            <status_change date="2009-07-17T11:07:21.610-04:00">INTERIM</status_change>
            <status_change date="2009-08-03T04:00:04.542-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Solaris 8 (SPARC) meets Sun Alert ID 102282 criteria.">
          <criterion comment="Solaris 8 Installed" test_ref="oval:org.mitre.oval:tst:3145"/>
          <criterion comment="sparc architecture" test_ref="oval:org.mitre.oval:tst:2465"/>
          <criterion comment="Patch 109324-09 or later is installed" negate="true" test_ref="oval:org.mitre.oval:tst:1520"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (SPARC) meets Sun Alert ID 102282 criteria.">
          <criterion comment="Solaris 9 Installed" test_ref="oval:org.mitre.oval:tst:3051"/>
          <criterion comment="sparc architecture" test_ref="oval:org.mitre.oval:tst:2465"/>
          <criterion comment="Patch 118535-03 or later is installed" negate="true" test_ref="oval:org.mitre.oval:tst:1519"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert ID 102282 criteria.">
          <criterion comment="Solaris 10 Installed" test_ref="oval:org.mitre.oval:tst:2459"/>
          <criterion comment="sparc architecture" test_ref="oval:org.mitre.oval:tst:2465"/>
          <criterion comment="Patch 121004-01 or later is installed" negate="true" test_ref="oval:org.mitre.oval:tst:1518"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 8 (x86) meets Sun Alert ID 102282 criteria.">
          <criterion comment="Solaris 8 Installed" test_ref="oval:org.mitre.oval:tst:3145"/>
          <criterion comment="ix86 architecture" test_ref="oval:org.mitre.oval:tst:2463"/>
          <criterion comment="Patch 109325-09 or later is installed" negate="true" test_ref="oval:org.mitre.oval:tst:1517"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (x86) meets Sun Alert ID 102282 criteria.">
          <criterion comment="Solaris 9 Installed" test_ref="oval:org.mitre.oval:tst:3051"/>
          <criterion comment="ix86 architecture" test_ref="oval:org.mitre.oval:tst:2463"/>
          <criterion comment="Patch 118536-03 or later is installed" negate="true" test_ref="oval:org.mitre.oval:tst:1516"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert ID 102282 criteria.">
          <criterion comment="Solaris 10 Installed" test_ref="oval:org.mitre.oval:tst:2459"/>
          <criterion comment="ix86 architecture" test_ref="oval:org.mitre.oval:tst:2463"/>
          <criterion comment="Patch 121005-01 or later is installed" negate="true" test_ref="oval:org.mitre.oval:tst:1515"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8686" version="2" class="vulnerability">
      <metadata>
        <title>Multiple Security Vulnerabilities in the Adobe Flash Player for Solaris May Lead to a Denial of Service (DoS) or Arbitrary Code Execution (Adobe Security Bulletin APSB09-19)</title>
        <affected family="unix">
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-3794" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3794"/>
        <description>Heap-based buffer overflow in Adobe Flash Player before 10.0.42.34 and Adobe AIR before 1.5.3 allows remote attackers to execute arbitrary code via crafted dimensions of JPEG data in an SWF file.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-03-22T14:26:56.000-04:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2010-03-23T19:12:41.581-04:00">DRAFT</status_change>
            <status_change date="2010-05-17T04:01:50.163-04:00">INTERIM</status_change>
            <status_change date="2010-06-07T04:01:33.485-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 274250">
          <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
          <criterion negate="true" comment="Patch 125332-08 or later installed" test_ref="oval:org.mitre.oval:tst:21076"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 274250">
          <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
          <criterion negate="true" comment="Patch 125333-08 or later installed" test_ref="oval:org.mitre.oval:tst:21162"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8653" version="1" class="vulnerability">
      <metadata>
        <title>A Security Vulnerability in the TCP Loopback/Fusion Code May Lead to a System Hang Resulting in a Denial of Service (DoS)</title>
        <affected family="unix">
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-3469" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3469"/>
        <description>Unspecified vulnerability in the TCP Loopback/Fusion implementation in Sun Solaris 10 allows local users to cause a denial of service (resource exhaustion and service hang) via unspecified vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-08-03T10:36:57.000-04:00">
              <contributor organization="Opsware, Inc.">Todd Dolinsky</contributor>
            </submitted>
            <status_change date="2007-08-03T16:51:06.782-04:00">DRAFT</status_change>
            <status_change date="2007-08-20T08:04:43.600-04:00">INTERIM</status_change>
            <status_change date="2007-09-06T09:13:36.390-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 102963" negate="false">
          <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
          <criterion comment="Patch 125100-10 or later installed" test_ref="oval:org.mitre.oval:tst:4665" negate="true"/>
          <criterion comment="Patch 118833-17 or later installed" test_ref="oval:org.mitre.oval:tst:4625" negate="false"/>
          <criterion comment="Patch 118833-36 or earlier installed" test_ref="oval:org.mitre.oval:tst:4778" negate="false"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 102963" negate="false">
          <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
          <criterion comment="Patch 125101-10 or later installed" test_ref="oval:org.mitre.oval:tst:4966" negate="true"/>
          <criterion comment="Patch 118855-15 or later installed" test_ref="oval:org.mitre.oval:tst:4714" negate="false"/>
          <criterion comment="Patch 118855-36 or earlier installed" test_ref="oval:org.mitre.oval:tst:4725" negate="false"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8613" version="2" class="vulnerability">
      <metadata>
        <title>Multiple Security Vulnerabilities in the Adobe Flash Player for Solaris May Lead to a Denial of Service (DoS) or Arbitrary Code Execution (Adobe Security Bulletin APSB09-19)</title>
        <affected family="unix">
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-3800" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3800"/>
        <description>Multiple unspecified vulnerabilities in Adobe Flash Player before 10.0.42.34 and Adobe AIR before 1.5.3 allow attackers to cause a denial of service (application crash) or possibly execute arbitrary code via unknown vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-03-22T14:26:56.000-04:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2010-03-23T19:12:42.352-04:00">DRAFT</status_change>
            <status_change date="2010-05-17T04:01:45.633-04:00">INTERIM</status_change>
            <status_change date="2010-06-07T04:01:29.709-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 274250">
          <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
          <criterion negate="true" comment="Patch 125332-08 or later installed" test_ref="oval:org.mitre.oval:tst:21076"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 274250">
          <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
          <criterion negate="true" comment="Patch 125333-08 or later installed" test_ref="oval:org.mitre.oval:tst:21162"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8599" version="2" class="vulnerability">
      <metadata>
        <title>Security Vulnerabilities in GNU tar (see gtar(1)) May Lead to Files Being Overwritten, Execution of Arbitrary Code, or a Denial of Service (DoS)</title>
        <affected family="unix">
          <platform>Sun Solaris 9</platform>
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-4476" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4476"/>
        <description>Buffer overflow in the safer_name_suffix function in GNU tar has unspecified attack vectors and impact, resulting in a "crashing stack."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-03-26T14:24:08.000-04:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2010-03-26T14:56:04.724-04:00">DRAFT</status_change>
            <status_change date="2010-05-17T04:01:42.064-04:00">INTERIM</status_change>
            <status_change date="2010-06-07T04:01:26.445-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND" comment="Solaris 9 (SPARC) meets Sun Alert 273551">
          <extend_definition comment="Solaris 9 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1457"/>
          <criterion negate="true" comment="Patch 118191-04 or later installed" test_ref="oval:org.mitre.oval:tst:21169"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 273551">
          <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
          <criterion negate="true" comment="Patch 139099-03 or later installed" test_ref="oval:org.mitre.oval:tst:20999"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (x86) meets Sun Alert 273551">
          <extend_definition comment="Solaris 9 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1683"/>
          <criterion negate="true" comment="Patch 118192-04 or later installed" test_ref="oval:org.mitre.oval:tst:21124"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 273551">
          <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
          <criterion negate="true" comment="Patch 139100-03 or later installed" test_ref="oval:org.mitre.oval:tst:21085"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8496" version="1" class="vulnerability">
      <metadata>
        <title>Multiple Buffer and Integer Overflow Vulnerabilities in Python (python(1)) May Lead to a Denial of Service (DoS) or Allow Execution of Arbitrary Code</title>
        <affected family="unix">
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-4965" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4965"/>
        <description>Multiple integer overflows in the imageop module in Python 2.5.1 and earlier allow context-dependent attackers to cause a denial of service (application crash) and possibly obtain sensitive information (memory contents) via crafted arguments to (1) the tovideo method, and unspecified other vectors related to (2) imageop.c, (3) rbgimgmodule.c, and other files, which trigger heap-based buffer overflows.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-01-19T17:52:34.000-05:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2010-01-21T10:09:09.112-05:00">DRAFT</status_change>
            <status_change date="2010-02-08T04:04:17.823-05:00">INTERIM</status_change>
            <status_change date="2010-03-01T04:00:29.099-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 273570">
          <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
          <criterion negate="true" comment="Patch 143506-01 or later installed" test_ref="oval:org.mitre.oval:tst:20998"/>
          <criterion comment="SUNWPython is installed" test_ref="oval:org.mitre.oval:tst:20430"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 273570">
          <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
          <criterion negate="true" comment="Patch 143507-01 or later installed" test_ref="oval:org.mitre.oval:tst:20927"/>
          <criterion comment="SUNWPython is installed" test_ref="oval:org.mitre.oval:tst:20430"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8488" version="2" class="vulnerability">
      <metadata>
        <title>Security Vulnerabilities in the Apache 2 "mod_perl2" Module Components "Status.pm" May Lead to Denial of Service (DoS) or Unauthorized Access to Data</title>
        <affected family="unix">
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-0796" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0796"/>
        <description>Cross-site scripting (XSS) vulnerability in Status.pm in Apache::Status and Apache2::Status in mod_perl1 and mod_perl2 for the Apache HTTP Server, when /perl-status is accessible, allows remote attackers to inject arbitrary web script or HTML via the URI.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-03-16T15:16:58.000-04:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2010-03-17T22:26:12.371-04:00">DRAFT</status_change>
            <status_change date="2010-05-17T04:01:31.276-04:00">INTERIM</status_change>
            <status_change date="2010-06-07T04:01:16.198-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Software Section">
          <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 272230">
            <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
            <criterion negate="true" comment="Patch 120543-15 or later installed" test_ref="oval:org.mitre.oval:tst:20986"/>
          </criteria>
          <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 272230">
            <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
            <criterion negate="true" comment="Patch 120544-15 or later installed" test_ref="oval:org.mitre.oval:tst:21020"/>
          </criteria>
        </criteria>
        <criteria comment="Configuration Section">
          <criterion comment="Solaris 10 bundled Apache 2.0 web server service is enable" test_ref="oval:org.mitre.oval:tst:21122"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8445" version="1" class="vulnerability">
      <metadata>
        <title>Multiple Buffer and Integer Overflow Vulnerabilities in Python (python(1)) May Lead to a Denial of Service (DoS) or Allow Execution of Arbitrary Code</title>
        <affected family="unix">
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-2315" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-2315"/>
        <description>Multiple integer overflows in Python 2.5.2 and earlier allow context-dependent attackers to have an unknown impact via vectors related to the (1) stringobject, (2) unicodeobject, (3) bufferobject, (4) longobject, (5) tupleobject, (6) stropmodule, (7) gcmodule, and (8) mmapmodule modules.  NOTE: The expandtabs integer overflows in stringobject and unicodeobject in 2.5.2 are covered by CVE-2008-5031.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-01-19T17:52:34.000-05:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2010-01-21T10:09:10.453-05:00">DRAFT</status_change>
            <status_change date="2010-02-08T04:04:16.977-05:00">INTERIM</status_change>
            <status_change date="2010-03-01T04:00:26.143-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 273570">
          <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
          <criterion negate="true" comment="Patch 143506-01 or later installed" test_ref="oval:org.mitre.oval:tst:20998"/>
          <criterion comment="SUNWPython is installed" test_ref="oval:org.mitre.oval:tst:20430"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 273570">
          <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
          <criterion negate="true" comment="Patch 143507-01 or later installed" test_ref="oval:org.mitre.oval:tst:20927"/>
          <criterion comment="SUNWPython is installed" test_ref="oval:org.mitre.oval:tst:20430"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8444" version="1" class="vulnerability">
      <metadata>
        <title>A Security Vulnerability in Solaris Trusted Extensions due to Missing Libraries may Allow Privilege Escalation</title>
        <affected family="unix">
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0310" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0310"/>
        <description>Trusted Extensions in Sun Solaris 10 allows local users to gain privileges via vectors related to omission of unspecified libraries from software updates.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-01-19T17:52:34.000-05:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2010-01-21T10:09:09.783-05:00">DRAFT</status_change>
            <status_change date="2010-02-08T04:04:16.767-05:00">INTERIM</status_change>
            <status_change date="2010-03-01T04:00:25.851-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Software Section">
          <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 275410">
            <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
            <criterion negate="true" comment="Patch 143502-01 or later installed" test_ref="oval:org.mitre.oval:tst:20864"/>
          </criteria>
          <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 275410">
            <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
            <criterion negate="true" comment="Patch 143503-01 or later installed" test_ref="oval:org.mitre.oval:tst:20393"/>
          </criteria>
        </criteria>
        <criterion comment="System is configured to use Solaris Trusted Extensions (labeld service is online)" test_ref="oval:org.mitre.oval:tst:11134"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8350" version="2" class="vulnerability">
      <metadata>
        <title>Multiple Security Vulnerabilities in the Adobe Flash Player for Solaris May Lead to a Denial of Service (DoS) or Arbitrary Code Execution (Adobe Security Bulletin APSB09-19)</title>
        <affected family="unix">
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-3797" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3797"/>
        <description>Adobe Flash Player 10.x before 10.0.42.34 and Adobe AIR before 1.5.3 might allow attackers to execute arbitrary code via unspecified vectors that trigger memory corruption.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-03-22T14:26:56.000-04:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2010-03-23T19:12:41.887-04:00">DRAFT</status_change>
            <status_change date="2010-05-17T04:01:19.145-04:00">INTERIM</status_change>
            <status_change date="2010-06-07T04:01:05.699-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 274250">
          <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
          <criterion negate="true" comment="Patch 125332-08 or later installed" test_ref="oval:org.mitre.oval:tst:21076"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 274250">
          <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
          <criterion negate="true" comment="Patch 125333-08 or later installed" test_ref="oval:org.mitre.oval:tst:21162"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8349" version="2" class="vulnerability">
      <metadata>
        <title>Security Vulnerabilities in the Apache 2 "mod_perl2" Module Components "PerlRun.pm" May Lead to Denial of Service (DoS) or Unauthorized Access to Data</title>
        <affected family="unix">
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-1349" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1349"/>
        <description>PerlRun.pm in Apache mod_perl before 1.30, and RegistryCooker.pm in mod_perl 2.x, does not properly escape PATH_INFO before use in a regular expression, which allows remote attackers to cause a denial of service (resource consumption) via a crafted URI.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-03-16T15:16:58.000-04:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2010-03-17T22:26:12.189-04:00">DRAFT</status_change>
            <status_change date="2010-05-17T04:01:18.858-04:00">INTERIM</status_change>
            <status_change date="2010-06-07T04:01:05.430-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Software Section">
          <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 272230">
            <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
            <criterion negate="true" comment="Patch 120543-15 or later installed" test_ref="oval:org.mitre.oval:tst:20986"/>
          </criteria>
          <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 272230">
            <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
            <criterion negate="true" comment="Patch 120544-15 or later installed" test_ref="oval:org.mitre.oval:tst:21020"/>
          </criteria>
        </criteria>
        <criteria comment="Configuration Section">
          <criterion comment="Solaris 10 bundled Apache 2.0 web server service is enable" test_ref="oval:org.mitre.oval:tst:21122"/>
          <criterion comment="PerlRun.pm component is used" test_ref="oval:org.mitre.oval:tst:21159"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8334" version="1" class="vulnerability">
      <metadata>
        <title>A Security Vulnerability in lbxproxy(1) may Allow Unauthorized Read Access to Files</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <platform>Sun Solaris 9</platform>
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-4070" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4070"/>
        <description>Unspecified vulnerability in Low Bandwidth X proxy (lbxproxy) on Sun Solaris 8 through 10 before 20070725 allows local users to read arbitrary files with root group ownership via unknown vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-08-01T13:14:10.000-04:00">
              <contributor organization="Opsware, Inc.">Todd Dolinsky</contributor>
            </submitted>
            <status_change date="2007-08-01T22:21:39.310-04:00">DRAFT</status_change>
            <status_change date="2007-08-20T08:04:42.437-04:00">INTERIM</status_change>
            <status_change date="2007-09-06T09:13:34.971-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND" comment="Solaris 8 (SPARC) meets Sun Alert 102948" negate="false">
          <extend_definition comment="Solaris 8 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1539"/>
          <criterion comment="Patch 119067-08 or later installed" test_ref="oval:org.mitre.oval:tst:5089" negate="true"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (SPARC) meets Sun Alert 102948" negate="false">
          <extend_definition comment="Solaris 9 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1457"/>
          <criterion comment="Patch 112785-62 or later installed" test_ref="oval:org.mitre.oval:tst:4378" negate="true"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 102948" negate="false">
          <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
          <criterion comment="Patch 119059-28 or later installed" test_ref="oval:org.mitre.oval:tst:4559" negate="true"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 8 (x86) meets Sun Alert 102948" negate="false">
          <extend_definition comment="Solaris 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:2059"/>
          <criterion comment="Patch 119068-08 or later installed" test_ref="oval:org.mitre.oval:tst:4495" negate="true"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (x86) meets Sun Alert 102948" negate="false">
          <extend_definition comment="Solaris 9 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1683"/>
          <criterion comment="Patch 112786-51 or later installed" test_ref="oval:org.mitre.oval:tst:4915" negate="true"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 102948" negate="false">
          <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
          <criterion comment="Patch 119060-27 or later installed" test_ref="oval:org.mitre.oval:tst:5067" negate="true"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8290" version="1" class="vulnerability">
      <metadata>
        <title>An Integer Overflow Vulnerability in GIMP(1) May Lead to Denial of Service (DoS) or Execution of Arbitrary Code</title>
        <affected family="unix">
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-1570" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1570"/>
        <description>Integer overflow in the ReadImage function in plug-ins/file-bmp/bmp-read.c in GIMP 2.6.7 might allow remote attackers to execute arbitrary code via a BMP file with crafted width and height values that trigger a heap-based buffer overflow.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-01-19T17:52:34.000-05:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2010-01-21T10:09:09.387-05:00">DRAFT</status_change>
            <status_change date="2010-02-08T04:04:03.556-05:00">INTERIM</status_change>
            <status_change date="2010-03-01T04:00:17.105-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 274390">
          <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
          <criterion negate="true" comment="Patch 143510-01 or later installed" test_ref="oval:org.mitre.oval:tst:20765"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 274390">
          <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
          <criterion negate="true" comment="Patch 143511-01 or later installed" test_ref="oval:org.mitre.oval:tst:20779"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8272" version="1" class="vulnerability">
      <metadata>
        <title>Security Vulnerability in rm(1) may Lead to Unauthorized Deletion of Files or Directories</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <platform>Sun Solaris 9</platform>
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-0895" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0895"/>
        <description>Race condition in recursive directory deletion with the (1) -r or (2) -R option in rm in Solaris 8 through 10 before 20070208 allows local users to delete files and directories as the user running rm by moving a low-level directory to a higher level as it is being deleted, which causes rm to chdir to a ".." directory that is higher than expected, possibly up to the root file system, a related issue to CVE-2002-0435.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-08-06T11:50:11.000-04:00">
              <contributor organization="Opsware, Inc.">Todd Dolinsky</contributor>
            </submitted>
            <status_change date="2007-08-08T21:33:23.977-04:00">DRAFT</status_change>
            <status_change date="2007-08-23T14:55:19.959-04:00">INTERIM</status_change>
            <status_change date="2007-09-10T14:45:27.362-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND" comment="Solaris 8 (SPARC) meets Sun Alert 102782" negate="false">
          <extend_definition comment="Solaris 8 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1539"/>
          <criterion comment="Patch 124969-01 or later installed" test_ref="oval:org.mitre.oval:tst:4414" negate="true"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (SPARC) meets Sun Alert 102782" negate="false">
          <extend_definition comment="Solaris 9 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1457"/>
          <criterion comment="Patch 123372-02 or later installed" test_ref="oval:org.mitre.oval:tst:4946" negate="true"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 102782" negate="false">
          <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
          <criterion comment="Patch 124244-01 or later installed" test_ref="oval:org.mitre.oval:tst:4215" negate="true"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 8 (x86) meets Sun Alert 102782" negate="false">
          <extend_definition comment="Solaris 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:2059"/>
          <criterion comment="Patch 124970-01 or later installed" test_ref="oval:org.mitre.oval:tst:4906" negate="true"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (x86) meets Sun Alert 102782" negate="false">
          <extend_definition comment="Solaris 9 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1683"/>
          <criterion comment="Patch 123373-02 or later installed" test_ref="oval:org.mitre.oval:tst:5133" negate="true"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 102782" negate="false">
          <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
          <criterion comment="Patch 124245-01 or later installed" test_ref="oval:org.mitre.oval:tst:4576" negate="true"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8249" version="1" class="vulnerability">
      <metadata>
        <title>Multiple Buffer and Integer Overflow Vulnerabilities in Python (python(1)) May Lead to a Denial of Service (DoS) or Allow Execution of Arbitrary Code</title>
        <affected family="unix">
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-1721" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1721"/>
        <description>Integer signedness error in the zlib extension module in Python 2.5.2 and earlier allows remote attackers to execute arbitrary code via a negative signed integer, which triggers insufficient memory allocation and a buffer overflow.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-01-19T17:52:34.000-05:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2010-01-21T10:09:10.283-05:00">DRAFT</status_change>
            <status_change date="2010-02-08T04:03:56.147-05:00">INTERIM</status_change>
            <status_change date="2010-03-01T04:00:16.164-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 273570">
          <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
          <criterion negate="true" comment="Patch 143506-01 or later installed" test_ref="oval:org.mitre.oval:tst:20998"/>
          <criterion comment="SUNWPython is installed" test_ref="oval:org.mitre.oval:tst:20430"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 273570">
          <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
          <criterion negate="true" comment="Patch 143507-01 or later installed" test_ref="oval:org.mitre.oval:tst:20927"/>
          <criterion comment="SUNWPython is installed" test_ref="oval:org.mitre.oval:tst:20430"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8208" version="2" class="vulnerability">
      <metadata>
        <title>Multiple Security Vulnerabilities in the Adobe Flash Player for Solaris May Lead to a Denial of Service (DoS) or Arbitrary Code Execution (Adobe Security Bulletin APSB09-19)</title>
        <affected family="unix">
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-3799" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3799"/>
        <description>Integer overflow in the Verifier::parseExceptionHandlers function in Adobe Flash Player before 10.0.42.34 and Adobe AIR before 1.5.3 allows remote attackers to execute arbitrary code via an SWF file with a large exception_count value that triggers memory corruption, related to "generation of ActionScript exception handlers."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-03-22T14:26:56.000-04:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2010-03-23T19:12:42.221-04:00">DRAFT</status_change>
            <status_change date="2010-05-17T04:01:14.495-04:00">INTERIM</status_change>
            <status_change date="2010-06-07T04:01:00.780-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 274250">
          <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
          <criterion negate="true" comment="Patch 125332-08 or later installed" test_ref="oval:org.mitre.oval:tst:21076"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 274250">
          <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
          <criterion negate="true" comment="Patch 125333-08 or later installed" test_ref="oval:org.mitre.oval:tst:21162"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8192" version="2" class="vulnerability">
      <metadata>
        <title>Integer Overflow Security Vulnerability in AES and RC4 Decryption in the Solaris Kerberos Crypto Library May Lead to Execution of Arbitrary Code or a Denial of Service (DoS)</title>
        <affected family="unix">
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-4212" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4212"/>
        <description>Multiple integer underflows in the (1) AES and (2) RC4 decryption functionality in the crypto library in MIT Kerberos 5 (aka krb5) 1.3 through 1.6.3, and 1.7 before 1.7.1, allow remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code by providing ciphertext with a length that is too short to be valid.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-03-22T14:26:56.000-04:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2010-03-23T19:12:42.674-04:00">DRAFT</status_change>
            <status_change date="2010-05-17T04:01:14.268-04:00">INTERIM</status_change>
            <status_change date="2010-06-07T04:01:00.525-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Software Section">
          <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 275530">
            <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
            <criterion negate="true" comment="Patch 141500-06 or later installed" test_ref="oval:org.mitre.oval:tst:20614"/>
          </criteria>
          <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 275530">
            <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
            <criterion negate="true" comment="Patch 141501-07 or later installed" test_ref="oval:org.mitre.oval:tst:20894"/>
          </criteria>
        </criteria>
        <criterion comment="/etc/krb5/krb5.conf is configured with a kerberos domain" test_ref="oval:org.mitre.oval:tst:1153"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8134" version="2" class="vulnerability">
      <metadata>
        <title>Multiple Security Vulnerabilities in the Solaris GNOME PDF Rendering Libraries May Lead to a Denial of Service (DoS) or Execution of Arbitrary Code</title>
        <affected family="unix">
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-3609" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3609"/>
        <description>Integer overflow in the ImageStream::ImageStream function in Stream.cc in Xpdf before 3.02pl4 and Poppler before 0.12.1, as used in GPdf, kdegraphics KPDF, and CUPS pdftops, allows remote attackers to cause a denial of service (application crash) via a crafted PDF document that triggers a NULL pointer dereference or buffer over-read.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-03-22T14:26:56.000-04:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2010-03-23T19:12:41.327-04:00">DRAFT</status_change>
            <status_change date="2010-05-17T04:01:13.805-04:00">INTERIM</status_change>
            <status_change date="2010-06-07T04:01:00.084-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 274030">
          <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
          <criterion negate="true" comment="Patch 120739-06 or later installed" test_ref="oval:org.mitre.oval:tst:21117"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 274030">
          <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
          <criterion negate="true" comment="Patch 120740-06 or later installed" test_ref="oval:org.mitre.oval:tst:20980"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7973" version="1" class="vulnerability">
      <metadata>
        <title>Security Vulnerability in the Transport Layer Security (TLS) and Secure Sockets Layer 3.0 (SSLv3) Protocols Involving Handshake Renegotiation Affects Applications Utilizing Network Security Services (NSS)</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <platform>Sun Solaris 9</platform>
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-3555" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3555"/>
        <description>The TLS protocol, and the SSL protocol 3.0 and possibly earlier, as used in Microsoft Internet Information Services (IIS) 7.0, mod_ssl in the Apache HTTP Server 2.2.14 and earlier, OpenSSL before 0.9.8l, GnuTLS 2.8.5 and earlier, Mozilla Network Security Services (NSS) 3.12.4 and earlier, multiple Cisco products, and other products, does not properly associate renegotiation handshakes with an existing connection, which allows man-in-the-middle attackers to insert data into HTTPS sessions, and possibly other types of sessions protected by TLS or SSL, by sending an unauthenticated request that is processed retroactively by a server in a post-renegotiation context, related to a "plaintext injection" attack, aka the "Project Mogul" issue.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-01-19T17:52:34.000-05:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2010-01-21T10:09:08.599-05:00">DRAFT</status_change>
            <status_change date="2010-02-08T04:02:19.988-05:00">INTERIM</status_change>
            <status_change date="2010-03-01T04:00:13.620-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND" comment="Solaris 8 (SPARC) meets Sun Alert 273350">
          <extend_definition comment="Solaris 8 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1539"/>
          <criterion negate="true" comment="Patch 119209-22 or later installed" test_ref="oval:org.mitre.oval:tst:20450"/>
          <criterion comment="SUNWtls is installed" test_ref="oval:org.mitre.oval:tst:20907"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (SPARC) meets Sun Alert 273350">
          <extend_definition comment="Solaris 9 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1457"/>
          <criterion negate="true" comment="Patch 119211-22 or later installed" test_ref="oval:org.mitre.oval:tst:21074"/>
          <criterion comment="SUNWtls is installed" test_ref="oval:org.mitre.oval:tst:20907"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 273350">
          <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
          <criterion negate="true" comment="Patch 119213-21 or later installed" test_ref="oval:org.mitre.oval:tst:20949"/>
          <criterion comment="SUNWtls is installed" test_ref="oval:org.mitre.oval:tst:20907"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (x86) meets Sun Alert 273350">
          <extend_definition comment="Solaris 9 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1683"/>
          <criterion negate="true" comment="Patch 119212-22 or later installed" test_ref="oval:org.mitre.oval:tst:21052"/>
          <criterion comment="SUNWtls is installed" test_ref="oval:org.mitre.oval:tst:20907"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 273350">
          <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
          <criterion negate="true" comment="Patch 119214-21 or later installed" test_ref="oval:org.mitre.oval:tst:20806"/>
          <criterion comment="SUNWtls is installed" test_ref="oval:org.mitre.oval:tst:20907"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7902" version="2" class="vulnerability">
      <metadata>
        <title>Multiple Security Vulnerabilities in the Adobe Flash Player for Solaris May Lead to a Denial of Service (DoS) or Arbitrary Code Execution (Adobe Security Bulletin APSB09-19)</title>
        <affected family="unix">
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-3798" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3798"/>
        <description>Adobe Flash Player before 10.0.42.34 and Adobe AIR before 1.5.3 might allow attackers to execute arbitrary code via unspecified vectors that trigger memory corruption.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-03-22T14:26:56.000-04:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2010-03-23T19:12:42.072-04:00">DRAFT</status_change>
            <status_change date="2010-05-17T04:01:07.557-04:00">INTERIM</status_change>
            <status_change date="2010-06-07T04:00:54.661-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 274250">
          <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
          <criterion negate="true" comment="Patch 125332-08 or later installed" test_ref="oval:org.mitre.oval:tst:21076"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 274250">
          <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
          <criterion negate="true" comment="Patch 125333-08 or later installed" test_ref="oval:org.mitre.oval:tst:21162"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7836" version="2" class="vulnerability">
      <metadata>
        <title>Multiple Security Vulnerabilities in the Solaris GNOME PDF Rendering Libraries May Lead to a Denial of Service (DoS) or Execution of Arbitrary Code</title>
        <affected family="unix">
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-3606" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3606"/>
        <description>Integer overflow in the PSOutputDev::doImageL1Sep function in Xpdf before 3.02pl4, and Poppler 0.x, as used in kdegraphics KPDF, might allow remote attackers to execute arbitrary code via a crafted PDF document that triggers a heap-based buffer overflow.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-03-22T14:26:56.000-04:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2010-03-23T19:12:41.158-04:00">DRAFT</status_change>
            <status_change date="2010-05-17T04:01:05.558-04:00">INTERIM</status_change>
            <status_change date="2010-06-07T04:00:52.575-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 274030">
          <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
          <criterion negate="true" comment="Patch 120739-06 or later installed" test_ref="oval:org.mitre.oval:tst:21117"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 274030">
          <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
          <criterion negate="true" comment="Patch 120740-06 or later installed" test_ref="oval:org.mitre.oval:tst:20980"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7800" version="1" class="vulnerability">
      <metadata>
        <title>Multiple Buffer and Integer Overflow Vulnerabilities in Python (python(1)) May Lead to a Denial of Service (DoS) or Allow Execution of Arbitrary Code</title>
        <affected family="unix">
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-1679" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1679"/>
        <description>Multiple integer overflows in imageop.c in Python before 2.5.3 allow context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via crafted images that trigger heap-based buffer overflows.  NOTE: this issue is due to an incomplete fix for CVE-2007-4965.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-01-19T17:52:34.000-05:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2010-01-21T10:09:09.965-05:00">DRAFT</status_change>
            <status_change date="2010-02-08T04:01:17.596-05:00">INTERIM</status_change>
            <status_change date="2010-03-01T04:00:13.347-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 273570">
          <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
          <criterion negate="true" comment="Patch 143506-01 or later installed" test_ref="oval:org.mitre.oval:tst:20998"/>
          <criterion comment="SUNWPython is installed" test_ref="oval:org.mitre.oval:tst:20430"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 273570">
          <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
          <criterion negate="true" comment="Patch 143507-01 or later installed" test_ref="oval:org.mitre.oval:tst:20927"/>
          <criterion comment="SUNWPython is installed" test_ref="oval:org.mitre.oval:tst:20430"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7779" version="2" class="vulnerability">
      <metadata>
        <title>Security Vulnerabilities in GNU tar (see gtar(1)) May Lead to Files Being Overwritten, Execution of Arbitrary Code, or a Denial of Service (DoS)</title>
        <affected family="unix">
          <platform>Sun Solaris 9</platform>
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-4131" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4131"/>
        <description>Directory traversal vulnerability in the contains_dot_dot function in src/names.c in GNU tar allows user-assisted remote attackers to overwrite arbitrary files via certain //.. (slash slash dot dot) sequences in directory symlinks in a TAR archive.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-03-26T14:24:08.000-04:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2010-03-26T14:56:04.503-04:00">DRAFT</status_change>
            <status_change date="2010-05-17T04:01:03.879-04:00">INTERIM</status_change>
            <status_change date="2010-06-07T04:00:50.880-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND" comment="Solaris 9 (SPARC) meets Sun Alert 273551">
          <extend_definition comment="Solaris 9 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1457"/>
          <criterion negate="true" comment="Patch 118191-04 or later installed" test_ref="oval:org.mitre.oval:tst:21169"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 273551">
          <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
          <criterion negate="true" comment="Patch 139099-03 or later installed" test_ref="oval:org.mitre.oval:tst:20999"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (x86) meets Sun Alert 273551">
          <extend_definition comment="Solaris 9 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1683"/>
          <criterion negate="true" comment="Patch 118192-04 or later installed" test_ref="oval:org.mitre.oval:tst:21124"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 273551">
          <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
          <criterion negate="true" comment="Patch 139100-03 or later installed" test_ref="oval:org.mitre.oval:tst:21085"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7763" version="2" class="vulnerability">
      <metadata>
        <title>Multiple Security Vulnerabilities in the Adobe Flash Player for Solaris May Lead to a Denial of Service (DoS) or Arbitrary Code Execution (Adobe Security Bulletin APSB09-19)</title>
        <affected family="unix">
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-3796" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3796"/>
        <description>Adobe Flash Player before 10.0.42.34 and Adobe AIR before 1.5.3 might allow attackers to execute arbitrary code via unspecified vectors, related to a "data injection vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-03-22T14:26:56.000-04:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2010-03-23T19:12:41.736-04:00">DRAFT</status_change>
            <status_change date="2010-05-17T04:01:02.603-04:00">INTERIM</status_change>
            <status_change date="2010-06-07T04:00:49.571-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 274250">
          <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
          <criterion negate="true" comment="Patch 125332-08 or later installed" test_ref="oval:org.mitre.oval:tst:21076"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 274250">
          <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
          <criterion negate="true" comment="Patch 125333-08 or later installed" test_ref="oval:org.mitre.oval:tst:21162"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7731" version="2" class="vulnerability">
      <metadata>
        <title>Multiple Security Vulnerabilities in the Solaris GNOME PDF Rendering Libraries May Lead to a Denial of Service (DoS) or Execution of Arbitrary Code</title>
        <affected family="unix">
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-3605" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3605"/>
        <description>Multiple integer overflows in Poppler 0.10.5 and earlier allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted PDF file, related to (1) glib/poppler-page.cc; (2) ArthurOutputDev.cc, (3) CairoOutputDev.cc, (4) GfxState.cc, (5) JBIG2Stream.cc, (6) PSOutputDev.cc, and (7) SplashOutputDev.cc in poppler/; and (8) SplashBitmap.cc, (9) Splash.cc, and (10) SplashFTFont.cc in splash/.  NOTE: this may overlap CVE-2009-0791.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-03-22T14:26:56.000-04:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2010-03-23T19:12:40.963-04:00">DRAFT</status_change>
            <status_change date="2010-05-17T04:01:01.071-04:00">INTERIM</status_change>
            <status_change date="2010-06-07T04:00:47.905-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 274030">
          <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
          <criterion negate="true" comment="Patch 120739-06 or later installed" test_ref="oval:org.mitre.oval:tst:21117"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 274030">
          <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
          <criterion negate="true" comment="Patch 120740-06 or later installed" test_ref="oval:org.mitre.oval:tst:20980"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:765" version="3" class="vulnerability">
      <metadata>
        <title>GNU GZip CHMod File Permission Modification Race ConditionWeakness</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <platform>Sun Solaris 9</platform>
          <platform>Sun Solaris 10</platform>
          <product>gzip</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0988" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0988"/>
        <description>Race condition in gzip 1.2.4, 1.3.3, and earlier, when decompressing a gzipped file, allows local users to modify permissions of arbitrary files via a hard link attack on a file while it is being decompressed, whose permissions are changed by gzip after the decompression is complete.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-09-22T05:52:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-09-22T20:15:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-07T09:15:53.441-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:16:00.590-04:00">ACCEPTED</status_change>
            <modified comment="Added title. Implemented by Jon Baker of The MITRE Corporation." date="2007-02-13T14:47:00.641-05:00">
              <contributor organization="Security-Database">Nabil Ouchn</contributor>
            </modified>
            <status_change date="2007-02-13T14:48:04.662-05:00">INTERIM</status_change>
            <status_change date="2007-03-21T16:17:27.180-04:00">ACCEPTED</status_change>
            <modified comment="Corrected sparc criterion that was intended to be x86." date="2009-07-17T11:09:00.290-04:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </modified>
            <status_change date="2009-07-17T11:19:33.298-04:00">INTERIM</status_change>
            <status_change date="2009-08-03T04:00:04.095-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Solaris 8 (SPARC) meets Sun Alert ID 101816 criteria.">
          <criterion comment="Solaris 8 Installed" test_ref="oval:org.mitre.oval:tst:3437"/>
          <criterion comment="sparc architecture" test_ref="oval:org.mitre.oval:tst:3237"/>
          <criterion comment="Patch 112668-03 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:4005"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 8 (x86) meets Sun Alert ID 101816 criteria.">
          <criterion comment="Solaris 8 Installed" test_ref="oval:org.mitre.oval:tst:3437"/>
          <criterion comment="ix86 architecture" test_ref="oval:org.mitre.oval:tst:3912"/>
          <criterion comment="Patch 112669-03 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:4070"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (SPARC) meets Sun Alert ID 101816 criteria.">
          <criterion comment="Solaris 9 Installed" test_ref="oval:org.mitre.oval:tst:3172"/>
          <criterion comment="sparc architecture" test_ref="oval:org.mitre.oval:tst:3237"/>
          <criterion comment="Patch 116340-04 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:3666"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (x86) meets Sun Alert ID 101816 criteria.">
          <criterion comment="Solaris 9 Installed" test_ref="oval:org.mitre.oval:tst:3172"/>
          <criterion comment="ix86 architecture" test_ref="oval:org.mitre.oval:tst:3912"/>
          <criterion comment="Patch 116341-04 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:3778"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert ID 101816 criteria.">
          <criterion comment="Solaris 10 Installed" test_ref="oval:org.mitre.oval:tst:3680"/>
          <criterion comment="sparc architecture" test_ref="oval:org.mitre.oval:tst:3237"/>
          <criterion comment="Patch 120719-01 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:3295"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert ID 101816 criteria.">
          <criterion comment="Solaris 10 Installed" test_ref="oval:org.mitre.oval:tst:3680"/>
          <criterion comment="ix86 architecture" test_ref="oval:org.mitre.oval:tst:3912"/>
          <criterion comment="Patch 120720-01 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:3621"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7594" version="3" class="vulnerability">
      <metadata>
        <title>Solaris and OpenSolaris products kernel component vulnerability</title>
        <affected family="unix">
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0890" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0890"/>
        <description>Unspecified vulnerability in the Solaris component in Oracle Sun Product Suite 10 and OpenSolaris snv_01 through snv_98 allows local users to affect availability via unknown vectors related to the Kernel.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-04-21T14:34:00.000-04:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2010-04-22T13:39:57.735-04:00">DRAFT</status_change>
            <status_change date="2010-05-17T04:00:57.654-04:00">INTERIM</status_change>
            <status_change date="2010-06-07T04:00:44.734-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 242386">
          <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
          <criterion negate="true" comment="Patch 138888-01 or later installed" test_ref="oval:org.mitre.oval:tst:11384"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 242386">
          <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
          <criterion negate="true" comment="Patch 138889-01 or later installed" test_ref="oval:org.mitre.oval:tst:11447"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:755" version="2" class="vulnerability">
      <metadata>
        <title>Sun Java System Access Manager Local Authentication Bypass Vulnerability</title>
        <affected family="unix">
          <platform>Sun Solaris 10</platform>
          <platform>Sun Solaris 9</platform>
          <product>Access Manager</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-0531" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0531"/>
        <description>Unspecified vulnerability in Sun Java System Access Manager 7.0 allows local users logged in as "root" to bypass authentication and gain top-level administrator privileges via the amadmin CLI tool.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-09-22T05:52:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-09-22T20:15:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-07T09:15:53.102-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:16:00.406-04:00">ACCEPTED</status_change>
            <modified comment="Added title. Implemented by Jon Baker of The MITRE Corporation." date="2007-02-13T14:52:00.016-05:00">
              <contributor organization="Security-Database">Nabil Ouchn</contributor>
            </modified>
            <status_change date="2007-02-13T14:53:06.046-05:00">INTERIM</status_change>
            <status_change date="2007-03-21T16:17:26.994-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="x86" negate="false" test_ref="oval:org.mitre.oval:tst:3912"/>
        <criterion comment="Sun Java System Access Manager 7 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3551"/>
        <criterion comment="Patch 120955-01 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:3363"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7459" version="3" class="vulnerability">
      <metadata>
        <title>Security Vulnerability in BIND DNS Software Shipped With Solaris May Allow DNS Cache Poisoning</title>
        <affected family="unix">
          <platform>Sun Solaris 9</platform>
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-4022" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4022"/>
        <description>Unspecified vulnerability in ISC BIND 9.0.x through 9.3.x, 9.4 before 9.4.3-P4, 9.5 before 9.5.2-P1, 9.6 before 9.6.1-P2, and 9.7 beta before 9.7.0b3, with DNSSEC validation enabled and checking disabled (CD), allows remote attackers to conduct DNS cache poisoning attacks by receiving a recursive client query and sending a response that contains an Additional section with crafted data, which is not properly handled when the response is processed "at the same time as requesting DNSSEC records (DO)," aka Bug 20438.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-05-03T13:51:32.000-04:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2010-05-05T11:43:54.594-04:00">DRAFT</status_change>
            <status_change date="2010-05-24T04:00:04.610-04:00">INTERIM</status_change>
            <status_change date="2010-06-14T04:00:54.759-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Software Section">
          <criteria operator="AND" comment="Solaris 9 (SPARC) meets Sun Alert 273169">
            <extend_definition comment="Solaris 9 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1457"/>
            <criterion negate="true" comment="Patch 112837-21 or later installed" test_ref="oval:org.mitre.oval:tst:10994"/>
          </criteria>
          <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 273169">
            <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
            <criterion negate="true" comment="Patch 119783-14 or later installed" test_ref="oval:org.mitre.oval:tst:11625"/>
          </criteria>
          <criteria operator="AND" comment="Solaris 9 (x86) meets Sun Alert 273169">
            <extend_definition comment="Solaris 9 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1683"/>
            <criterion negate="true" comment="Patch 114265-20 or later installed" test_ref="oval:org.mitre.oval:tst:11199"/>
          </criteria>
          <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 273169">
            <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
            <criterion negate="true" comment="Patch 119784-14 or later installed" test_ref="oval:org.mitre.oval:tst:11385"/>
          </criteria>
        </criteria>
        <criterion comment="in.named running" test_ref="oval:org.mitre.oval:tst:2624"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7430" version="3" class="vulnerability">
      <metadata>
        <title>A vulnerability in the way named(1M) handles recursive client queries may allow a remote unprivileged user to cause named(1M) to return NXDOMAIN (Non-Existent Domain) for Internet hosts thus causing a Denial of Service (DoS) for those hosts to end users</title>
        <affected family="unix">
          <platform>Sun Solaris 9</platform>
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0097" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0097"/>
        <description>ISC BIND 9.0.x through 9.3.x, 9.4 before 9.4.3-P5, 9.5 before 9.5.2-P2, 9.6 before 9.6.1-P3, and 9.7.0 beta does not properly validate DNSSEC (1) NSEC and (2) NSEC3 records, which allows remote attackers to add the Authenticated Data (AD) flag to a forged NXDOMAIN response for an existing domain.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-05-03T13:51:32.000-04:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2010-05-05T11:43:55.135-04:00">DRAFT</status_change>
            <status_change date="2010-05-24T04:00:04.262-04:00">INTERIM</status_change>
            <status_change date="2010-06-14T04:00:52.110-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Software Section">
          <criteria operator="AND" comment="Solaris 9 (SPARC) meets Sun Alert 275890">
            <extend_definition comment="Solaris 9 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1457"/>
            <criterion negate="true" comment="Patch 112837-21 or later installed" test_ref="oval:org.mitre.oval:tst:11747"/>
          </criteria>
          <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 275890">
            <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
            <criterion negate="true" comment="Patch 119783-15 or later installed" test_ref="oval:org.mitre.oval:tst:11052"/>
          </criteria>
          <criteria operator="AND" comment="Solaris 9 (x86) meets Sun Alert 275890">
            <extend_definition comment="Solaris 9 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1683"/>
            <criterion negate="true" comment="Patch 114265-20 or later installed" test_ref="oval:org.mitre.oval:tst:11705"/>
          </criteria>
          <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 275890">
            <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
            <criterion negate="true" comment="Patch 119784-15 or later installed" test_ref="oval:org.mitre.oval:tst:11409"/>
          </criteria>
        </criteria>
        <criteria comment="Configuration Section">
          <criterion comment="in.named running" test_ref="oval:org.mitre.oval:tst:2624"/>
          <criterion comment="Server is configured as DNSSEC-validating nameserver (trusted-keys is set in /etc/named.conf)" test_ref="oval:org.mitre.oval:tst:11254"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:736" version="2" class="vulnerability">
      <metadata>
        <title>MIT Kerberos 5 Key Distribution Center Remote Denial of Service Vulnerability</title>
        <affected family="unix">
          <platform>Sun Solaris 7</platform>
          <platform>Sun Solaris 8</platform>
          <platform>Sun Solaris 9</platform>
          <platform>Sun Solaris 10</platform>
          <product>Kerberos</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1175" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1175"/>
        <description>Heap-based buffer overflow in the Key Distribution Center (KDC) in MIT Kerberos 5 (krb5) 1.4.1 and earlier allows remote attackers to cause a denial of service (apllication crash) and possibly execute arbitrary code via a certain valid TCP or UDP request.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-09-22T05:52:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-09-22T20:15:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-07T09:15:52.863-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:16:00.079-04:00">ACCEPTED</status_change>
            <modified comment="Added title. Implemented by Jon Baker of The MITRE Corporation." date="2007-02-13T14:02:00.285-05:00">
              <contributor organization="Security-Database">Nabil Ouchn</contributor>
            </modified>
            <status_change date="2007-02-13T14:04:28.310-05:00">INTERIM</status_change>
            <status_change date="2007-03-21T16:17:25.886-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="OR">
        <criteria operator="AND" comment="Solaris 7 (SPARC) meets Sun Alert ID 101809 criteria." negate="false">
          <criterion comment="Solaris 7 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3576"/>
          <criterion comment="sparc architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3237"/>
          <criterion comment="Patch 112536-06 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:3209"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 7 (x86) meets Sun Alert ID 101809 criteria." negate="false">
          <criterion comment="Solaris 7 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3576"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3912"/>
          <criterion comment="Patch 112537-06 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:3424"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 8 (SPARC) meets Sun Alert ID 101809 criteria." negate="false">
          <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3437"/>
          <criterion comment="sparc architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3237"/>
          <criterion comment="Patch 112237-13 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:3567"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 8 (x86) meets Sun Alert ID 101809 criteria." negate="false">
          <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3437"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3912"/>
          <criterion comment="Patch 112238-12 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:3898"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 8 (SPARC) with Supplmental Encryption Packages meets Sun Alert ID 101809 criteria." negate="false">
          <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3437"/>
          <criterion comment="sparc architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3237"/>
          <criteria operator="OR" comment="Solaris Supplemental Encryption Packages are installed" negate="false">
            <criterion comment="Pkg SUNWcry (Supplemental Encryption) is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3198"/>
            <criterion comment="Pkg SUNWcryr (Supplemental Encryption) is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3694"/>
          </criteria>
          <criterion comment="Patch 112390-11 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:3640"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 8 (x86) with Supplmental Encryption Packages meets Sun Alert ID 101809 criteria." negate="false">
          <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3437"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3912"/>
          <criteria operator="OR" comment="Solaris Supplemental Encryption Packages are installed" negate="false">
            <criterion comment="Pkg SUNWcry (Supplemental Encryption) is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3198"/>
            <criterion comment="Pkg SUNWcryr (Supplemental Encryption) is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3694"/>
          </criteria>
          <criterion comment="Patch 112240-10 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:3497"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (SPARC) meets Sun Alert ID 101809 criteria." negate="false">
          <criterion comment="Solaris 9 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3172"/>
          <criterion comment="sparc architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3237"/>
          <criterion comment="Patch 112908-20 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:3389"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (x86) meets Sun Alert ID 101809 criteria." negate="false">
          <criterion comment="Solaris 9 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3172"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3912"/>
          <criterion comment="Patch 115168-08 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:3624"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert ID 101809 criteria." negate="false">
          <criterion comment="Solaris 10 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3680"/>
          <criterion comment="sparc architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3237"/>
          <criterion comment="Patch 120469-01 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:3561"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert ID 101809 criteria." negate="false">
          <criterion comment="Solaris 10 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3680"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3912"/>
          <criterion comment="Patch 120470-01 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:3418"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7233" version="3" class="vulnerability">
      <metadata>
        <title>Sun Management Center Product Vulnerability</title>
        <affected family="unix">
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0891" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0891"/>
        <description>Unspecified vulnerability in the Sun Management Center component in Oracle Sun Product Suite 3.6.1 and 4.0 allows remote attackers to affect confidentiality and integrity via unknown vectors related to Solaris Container Manager.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-04-21T14:34:00.000-04:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2010-04-22T13:39:59.376-04:00">DRAFT</status_change>
            <status_change date="2010-05-17T04:00:48.442-04:00">INTERIM</status_change>
            <status_change date="2010-06-07T04:00:34.239-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 248666">
          <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
          <criterion negate="true" comment="Patch 125833-05 or later installed" test_ref="oval:org.mitre.oval:tst:11416"/>
          <criterion comment="SUNWessrv 3.6.1 is installed" test_ref="oval:org.mitre.oval:tst:11331"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 248666">
          <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
          <criterion negate="true" comment="Patch 139613-01 or later installed" test_ref="oval:org.mitre.oval:tst:11194"/>
          <criterion comment="SUNWessrv 4.0 is installed" test_ref="oval:org.mitre.oval:tst:11341"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 248666">
          <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
          <criterion negate="true" comment="Patch 143314-02 or later installed" test_ref="oval:org.mitre.oval:tst:11027"/>
          <criterion comment="SUNWessrv 4.0 is installed" test_ref="oval:org.mitre.oval:tst:11341"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7023" version="3" class="vulnerability">
      <metadata>
        <title>Solaris and OpenSolaris products Trusted Extensions component vulnerability</title>
        <affected family="unix">
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0882" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0882"/>
        <description>Unspecified vulnerability in the Solaris component in Oracle Sun Product Suite 10 and OpenSolaris snv_134 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Trusted Extensions.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-04-21T14:34:00.000-04:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2010-04-22T13:39:58.737-04:00">DRAFT</status_change>
            <status_change date="2010-05-17T04:00:37.659-04:00">INTERIM</status_change>
            <status_change date="2010-06-07T04:00:22.799-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Software Section">
          <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 263689">
            <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
            <criteria operator="OR">
              <criterion negate="true" comment="Patch 119906-15 or later installed" test_ref="oval:org.mitre.oval:tst:11348"/>
              <criterion negate="true" comment="Patch 122212-36 or later installed" test_ref="oval:org.mitre.oval:tst:11584"/>
              <criterion negate="true" comment="Patch 120460-16 or later installed" test_ref="oval:org.mitre.oval:tst:11336"/>
              <criterion negate="true" comment="Patch 120094-25 or later installed" test_ref="oval:org.mitre.oval:tst:11607"/>
              <criterion negate="true" comment="Patch 122470-03 or later installed" test_ref="oval:org.mitre.oval:tst:11633"/>
              <criterion negate="true" comment="Patch 125533-15 or later installed" test_ref="oval:org.mitre.oval:tst:11661"/>
            </criteria>
          </criteria>
          <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 263689">
            <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
            <criteria>
              <criterion negate="true" comment="Patch 122471-03 or later installed" test_ref="oval:org.mitre.oval:tst:11394"/>
              <criterion negate="true" comment="Patch 125534-15 or later installed" test_ref="oval:org.mitre.oval:tst:10950"/>
              <criterion negate="true" comment="Patch 119907-15 or later installed" test_ref="oval:org.mitre.oval:tst:11613"/>
              <criterion negate="true" comment="Patch 122213-36 or later installed" test_ref="oval:org.mitre.oval:tst:11317"/>
              <criterion negate="true" comment="Patch 120461-16 or later installed" test_ref="oval:org.mitre.oval:tst:11724"/>
              <criterion negate="true" comment="Patch 120095-25 or later installed" test_ref="oval:org.mitre.oval:tst:11890"/>
            </criteria>
          </criteria>
        </criteria>
        <criterion comment="System is configured to use Solaris Trusted Extensions (labeld service is online)" test_ref="oval:org.mitre.oval:tst:11134"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:702" version="3" class="vulnerability">
      <metadata>
        <title>Solaris Privilege Escalation/DoS Vulnerability (6293270)</title>
        <affected family="unix">
          <platform>Sun Solaris 9</platform>
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-0190" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0190"/>
        <description>Unspecified vulnerability in Sun Solaris 9 and 10 for the x86 platform allows local users to gain privileges or cause a denial of service (panic) via unspecified vectors, possibly involving functions from the mm driver.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-01-12T11:25:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-01-25T07:30:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-02-22T08:27:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-03-09T12:19:00.000-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:702 - Various corrections to comments and products to align with Authoring Style Guide" date="2011-04-22T23:54:00.899-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-04-23T00:06:50.977-04:00">INTERIM</status_change>
            <status_change date="2011-05-09T04:01:43.069-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Solaris 9 (x86) meets Sun Alert ID 102066 criteria.">
          <criterion comment="Solaris 9 Installed" test_ref="oval:org.mitre.oval:tst:3051"/>
          <criterion comment="ix86 architecture" test_ref="oval:org.mitre.oval:tst:2463"/>
          <criteria operator="OR" comment="Contributing factors for Solaris 9, Sun Alert ID 102066 criteria.">
            <criterion comment="Patch 112234-11 is installed" test_ref="oval:org.mitre.oval:tst:2413"/>
            <criterion comment="Patch 112234-12 is installed" test_ref="oval:org.mitre.oval:tst:2412"/>
            <criterion comment="Patch 117172-16 or later installed" test_ref="oval:org.mitre.oval:tst:2411"/>
          </criteria>
          <criterion negate="true" comment="Patch 118559-19 or later installed" test_ref="oval:org.mitre.oval:tst:2410"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert ID 102066 and 102108 criteria.">
          <criterion comment="Solaris 10 Installed" test_ref="oval:org.mitre.oval:tst:2459"/>
          <criterion comment="ix86 architecture" test_ref="oval:org.mitre.oval:tst:2463"/>
          <criterion negate="true" comment="Patch 118844-24 or later installed" test_ref="oval:org.mitre.oval:tst:2409"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6959" version="3" class="vulnerability">
      <metadata>
        <title>Solaris and OpenSolaris Products /dev/ucode Component Vulnerability</title>
        <affected family="unix">
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0453" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0453"/>
        <description>The ucode_ioctl function in intel/io/ucode_drv.c in Sun Solaris 10 and OpenSolaris snv_69 through snv_133, when running on x86 architectures, allows local users to cause a denial of service (panic) via a request with a 0 size value to the UCODE_GET_VERSION IOCTL, which triggers a NULL pointer dereference in the ucode_get_rev function, related to retrieval of the microcode revision.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-04-21T14:34:00.000-04:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2010-04-22T13:39:57.116-04:00">DRAFT</status_change>
            <status_change date="2010-05-17T04:00:34.611-04:00">INTERIM</status_change>
            <status_change date="2010-06-07T04:00:19.634-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
        <criterion comment="Patch 127128-11 installed" test_ref="oval:org.mitre.oval:tst:11295"/>
        <criterion negate="true" comment="Patch 143913-01 or later installed" test_ref="oval:org.mitre.oval:tst:11675"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6845" version="1" class="vulnerability">
      <metadata>
        <title>Security Vulnerability in Solaris Trusted Extensions may Prevent XScreenSaver (xscreensaver(1)) From Running</title>
        <affected family="unix">
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-3851" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3851"/>
        <description>Trusted Extensions in Sun Solaris 10 interferes with the operation of the xscreensaver-demo command for the XScreenSaver application, which makes it easier for physically proximate attackers to access an unattended workstation for which the intended screen locking did not occur, related to the "restart daemon."</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-17T14:02:00.000-05:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2009-12-17T17:21:51.728-05:00">DRAFT</status_change>
            <status_change date="2010-01-04T04:01:55.593-05:00">INTERIM</status_change>
            <status_change date="2010-01-25T04:00:26.233-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="Software Section">
          <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 270809">
            <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
            <criterion comment="Patch 125533-14 or later installed" test_ref="oval:org.mitre.oval:tst:11265"/>
            <criterion negate="true" comment="Patch 120094-28 or later installed" test_ref="oval:org.mitre.oval:tst:11162"/>
          </criteria>
          <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 270809">
            <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
            <criterion comment="Patch 125534-14 or later installed" test_ref="oval:org.mitre.oval:tst:11107"/>
            <criterion negate="true" comment="Patch 120095-28 or later installed" test_ref="oval:org.mitre.oval:tst:10350"/>
          </criteria>
        </criteria>
        <criterion comment="System is configured to use Solaris Trusted Extensions (labeld service is online)" test_ref="oval:org.mitre.oval:tst:11134"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6644" version="1" class="vulnerability">
      <metadata>
        <title>A Regression in the Solaris 10 Gnome-XScreenSaver (see xscreensaver(1)) may Allow Pop-up Windows to Appear through XScreenSaver when the Accessibility Feature is On</title>
        <affected family="unix">
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-3746" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3746"/>
        <description>XScreenSaver in Sun Solaris 10, when the accessibility feature is enabled, allows physically proximate attackers to obtain sensitive information by reading popup windows, which are displayed even when the screen is locked, a different vulnerability than CVE-2009-1276 and CVE-2009-2711.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-17T14:02:00.000-05:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2009-12-17T17:21:50.768-05:00">DRAFT</status_change>
            <status_change date="2010-01-04T04:01:54.722-05:00">INTERIM</status_change>
            <status_change date="2010-01-25T04:00:25.444-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 268288">
          <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
          <criteria operator="OR">
            <criterion comment="Patch 120094-27 installed" test_ref="oval:org.mitre.oval:tst:11280"/>
            <criterion comment="Patch 120094-28 installed" test_ref="oval:org.mitre.oval:tst:11303"/>
          </criteria>
          <criterion negate="true" comment="Patch 120094-29 or later installed" test_ref="oval:org.mitre.oval:tst:11098"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 268288">
          <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
          <criteria operator="OR">
            <criterion comment="Patch 120095-27 installed" test_ref="oval:org.mitre.oval:tst:11187"/>
            <criterion comment="Patch 120095-28 installed" test_ref="oval:org.mitre.oval:tst:10782"/>
          </criteria>
          <criterion negate="true" comment="Patch 120095-29 or later installed" test_ref="oval:org.mitre.oval:tst:11260"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:662" version="4" class="vulnerability">
      <metadata>
        <title>lpsched Local System Corruption Vulnerability</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <platform>Sun Solaris 9</platform>
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-0227" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0227"/>
        <description>Multiple unspecified vulnerabilities in lpsched in Sun Solaris 8, 9, and 10 allow local users to delete arbitrary files or disable the LP print service via unknown attack vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-01-16T12:05:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-01-25T07:30:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-02-22T08:27:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-03-09T12:19:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Fixed obj:1394 to more correctly look for subdirectories under /etc/lp/printers." date="2007-01-22T16:00:00.391-05:00">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2007-01-22T16:01:01.488-05:00">INTERIM</status_change>
            <status_change date="2007-02-20T13:40:51.556-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:662 - Various corrections to comments and products to align with Authoring Style Guide" date="2011-04-22T23:54:00.899-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-04-23T00:05:54.814-04:00">INTERIM</status_change>
            <status_change date="2011-05-09T04:01:39.926-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Solaris 8 (SPARC) meets Sun Alert ID 102033 criteria.">
          <criterion comment="Solaris 8 Installed" test_ref="oval:org.mitre.oval:tst:3145"/>
          <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
          <criterion negate="true" comment="Patch 109320-17 or later installed" test_ref="oval:org.mitre.oval:tst:2464"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 8 (x86) meets Sun Alert ID 102033 criteria.">
          <criterion comment="Solaris 8 Installed" test_ref="oval:org.mitre.oval:tst:3145"/>
          <criterion comment="ix86 architecture" test_ref="oval:org.mitre.oval:tst:2463"/>
          <criterion negate="true" comment="Patch 109321-17 or later installed" test_ref="oval:org.mitre.oval:tst:2462"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (SPARC) meets Sun Alert ID 102033 criteria.">
          <criterion comment="Solaris 9 Installed" test_ref="oval:org.mitre.oval:tst:3051"/>
          <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
          <criterion negate="true" comment="Patch 113329-16 or later installed" test_ref="oval:org.mitre.oval:tst:2461"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (x86) meets Sun Alert ID 102033 criteria.">
          <criterion comment="Solaris 9 Installed" test_ref="oval:org.mitre.oval:tst:3051"/>
          <criterion comment="ix86 architecture" test_ref="oval:org.mitre.oval:tst:2463"/>
          <criterion negate="true" comment="Patch 114980-17 or later installed" test_ref="oval:org.mitre.oval:tst:2460"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (sparc) meets Sun Alert ID 102033 criteria.">
          <criterion comment="Solaris 10 Installed" test_ref="oval:org.mitre.oval:tst:2459"/>
          <criterion comment="Installed architecture is sparc" test_ref="oval:org.mitre.oval:tst:2465"/>
          <criterion negate="true" comment="Patch 120467-03 or later installed" test_ref="oval:org.mitre.oval:tst:2458"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert ID 102033 criteria.">
          <criterion comment="Solaris 10 Installed" test_ref="oval:org.mitre.oval:tst:2459"/>
          <criterion comment="ix86 architecture" test_ref="oval:org.mitre.oval:tst:2463"/>
          <criterion negate="true" comment="Patch 120468-03 or later installed" test_ref="oval:org.mitre.oval:tst:2457"/>
        </criteria>
        <criterion comment="Target is configured as a print server" test_ref="oval:org.mitre.oval:tst:2456"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6563" version="1" class="vulnerability">
      <metadata>
        <title>A security vulnerability in Solaris Sockets Direct Protocol (SDP) driver (sdp(7D)) may allow a local or remote unprivileged user to exhaust all kernel memory</title>
        <affected family="unix">
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-3899" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3899"/>
        <description>Memory leak in the Sockets Direct Protocol (SDP) driver in Sun Solaris 10, and OpenSolaris snv_57 through snv_94, allows remote attackers to cause a denial of service (memory consumption) via unspecified vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-17T14:02:00.000-05:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2009-12-17T17:21:51.272-05:00">DRAFT</status_change>
            <status_change date="2010-01-04T04:01:53.927-05:00">INTERIM</status_change>
            <status_change date="2010-01-25T04:00:25.197-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 264730">
          <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
          <criterion comment="Patch 127127-11 or later installed" test_ref="oval:org.mitre.oval:tst:11269"/>
          <criterion negate="true" comment="Patch 141444-09 or later installed" test_ref="oval:org.mitre.oval:tst:10510"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 264730">
          <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
          <criterion comment="Patch 127128-11 or later installed" test_ref="oval:org.mitre.oval:tst:11157"/>
          <criterion negate="true" comment="Patch 141445-09 or later installed" test_ref="oval:org.mitre.oval:tst:11189"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6480" version="1" class="vulnerability">
      <metadata>
        <title>A Security Weakness in Solaris Trusted Extensions May Facilitate Privilege Escalation</title>
        <affected family="unix">
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-3839" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3839"/>
        <description>Unspecified vulnerability in the Solaris Trusted Extensions Policy configuration in Sun Solaris 10, and OpenSolaris snv_37 through snv_125, might allow remote attackers to execute arbitrary code by leveraging access to the X server.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-17T14:02:00.000-05:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2009-12-17T17:21:52.077-05:00">DRAFT</status_change>
            <status_change date="2010-01-04T04:01:49.466-05:00">INTERIM</status_change>
            <status_change date="2010-01-25T04:00:19.287-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="Software Section">
          <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 270969">
            <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
            <criterion negate="true" comment="Patch 126363-08 or later installed" test_ref="oval:org.mitre.oval:tst:11099"/>
          </criteria>
          <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 270969">
            <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
            <criterion negate="true" comment="Patch 126364-08 or later installed" test_ref="oval:org.mitre.oval:tst:11324"/>
          </criteria>
        </criteria>
        <criterion comment="System is configured to use Solaris Trusted Extensions (labeld service is online)" test_ref="oval:org.mitre.oval:tst:11134"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6392" version="1" class="vulnerability">
      <metadata>
        <title>Security Vulnerability in Solaris pollwakeup(9F) May Allow an Unprivileged User to Panic the System</title>
        <affected family="unix">
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-2952" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2952"/>
        <description>Unspecified vulnerability in the pollwakeup function in Sun Solaris 10, and OpenSolaris before snv_51, allows local users to cause a denial of service (panic) via unknown vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-08-25T16:38:09.000-04:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2009-08-26T08:16:49.443-04:00">DRAFT</status_change>
            <status_change date="2009-09-14T04:00:11.965-04:00">INTERIM</status_change>
            <status_change date="2009-10-05T04:00:06.640-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 265248">
          <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
          <criterion negate="true" comment="Patch 141414-09 or later installed" test_ref="oval:org.mitre.oval:tst:10377"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 265248">
          <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
          <criterion negate="true" comment="Patch 141415-09 or later installed" test_ref="oval:org.mitre.oval:tst:10060"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6361" version="1" class="vulnerability">
      <metadata>
        <title>A Security Vulnerability in the Solaris IP Filter (ipf(5)) May Lead to a Denial of Service (DoS) Condition</title>
        <affected family="unix">
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-2487" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2487"/>
        <description>Use-after-free vulnerability in the frpr_icmp function in the ipfilter (aka IP Filter) subsystem in Sun Solaris 10, and OpenSolaris snv_45 through snv_110, allows remote attackers to cause a denial of service (panic) via unspecified vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-08-12T12:29:13.000-04:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2009-08-12T18:16:43.070-04:00">DRAFT</status_change>
            <status_change date="2009-08-31T04:00:14.479-04:00">INTERIM</status_change>
            <status_change date="2009-09-21T04:00:07.905-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Software Section">
          <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 260951">
            <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
            <criteria operator="OR">
              <criterion comment="Patch 125014-02 or later installed" test_ref="oval:org.mitre.oval:tst:10532"/>
              <criterion comment="Patch 120011-14 or later installed" test_ref="oval:org.mitre.oval:tst:10461"/>
            </criteria>
            <criterion negate="true" comment="Patch 141020-01 or later installed" test_ref="oval:org.mitre.oval:tst:10397"/>
          </criteria>
          <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 260951">
            <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
            <criteria>
              <criterion comment="Patch 125015-02 or later installed" test_ref="oval:org.mitre.oval:tst:10569"/>
              <criterion comment="Patch 120012-14 or later installed" test_ref="oval:org.mitre.oval:tst:10366"/>
            </criteria>
            <criterion negate="true" comment="Patch 141021-01 or later installed" test_ref="oval:org.mitre.oval:tst:10459"/>
          </criteria>
        </criteria>
        <criteria comment="Configuration Section">
          <criterion comment="ipfilter(5) is running" test_ref="oval:org.mitre.oval:tst:10149"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6353" version="1" class="vulnerability">
      <metadata>
        <title>Security Vulnerability in the SNMP daemon (snmpd(1M)) May Lead to a Denial of Service (DoS) Condition</title>
        <affected family="unix">
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-4309" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-4309"/>
        <description>Integer overflow in the netsnmp_create_subtree_cache function in agent/snmp_agent.c in net-snmp 5.4 before 5.4.2.1, 5.3 before 5.3.2.3, and 5.2 before 5.2.5.1 allows remote attackers to cause a denial of service (crash) via a crafted SNMP GETBULK request, which triggers a heap-based buffer overflow,  related to the number of responses or repeats.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-09-10T11:34:43.000-04:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2009-09-10T19:37:14.283-04:00">DRAFT</status_change>
            <status_change date="2009-09-28T04:00:25.685-04:00">INTERIM</status_change>
            <status_change date="2009-10-19T04:00:16.342-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="Software Section">
          <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 262908">
            <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
            <criterion negate="true" comment="Patch 120272-25 or later installed" test_ref="oval:org.mitre.oval:tst:10802"/>
          </criteria>
          <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 262908">
            <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
            <criterion negate="true" comment="Patch 120273-27 or later installed" test_ref="oval:org.mitre.oval:tst:10754"/>
          </criteria>
        </criteria>
        <criterion comment="SUNWsmagt is installed" test_ref="oval:org.mitre.oval:tst:10650"/>
        <criterion comment="sma service is enabled" test_ref="oval:org.mitre.oval:tst:10248"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6349" version="1" class="vulnerability">
      <metadata>
        <title>A Security Vulnerability in the Solaris SCTP Packet Processing may Lead to a System Panic Resulting in a Denial of Service (DoS)</title>
        <affected family="unix">
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-2486" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2486"/>
        <description>Unspecified vulnerability in the SCTP implementation in Sun Solaris 10, and OpenSolaris before snv_120, allows remote attackers to cause a denial of service (panic) via unspecified packets.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-08-12T12:29:13.000-04:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2009-08-12T18:16:42.390-04:00">DRAFT</status_change>
            <status_change date="2009-08-31T04:00:14.243-04:00">INTERIM</status_change>
            <status_change date="2009-09-21T04:00:07.660-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 253608">
          <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
          <criterion negate="true" comment="Patch 141414-01 or later installed" test_ref="oval:org.mitre.oval:tst:10476"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 253608">
          <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
          <criterion negate="true" comment="Patch 141415-01 or later installed" test_ref="oval:org.mitre.oval:tst:10522"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6331" version="1" class="vulnerability">
      <metadata>
        <title>A Security Vulnerability in the Solaris rpc.nisd(1M) Daemon may Cause a Denial of Service (DoS) Condition to a NIS+ Server</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <platform>Sun Solaris 9</platform>
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-2029" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2029"/>
        <description>Unspecified vulnerability in rpc.nisd in Sun Solaris 8 through 10, and OpenSolaris before snv_104, allows remote authenticated users to cause a denial of service (NIS+ daemon hang) via unspecified vectors related to NIS+ callbacks.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-06-23T12:21:57.000-04:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2009-06-30T10:48:13.719-04:00">DRAFT</status_change>
            <status_change date="2009-07-20T04:00:44.613-04:00">INTERIM</status_change>
            <status_change date="2009-08-10T04:00:08.560-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Solaris 8 and 9">
          <criteria operator="OR" comment="Solaris 8 and 9 software section">
            <criteria operator="AND" comment="Solaris 8 (SPARC) meets Sun Alert 256748">
              <extend_definition comment="Solaris 8 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1539"/>
              <criterion negate="true" comment="Patch 128624-09 or later installed" test_ref="oval:org.mitre.oval:tst:9596"/>
            </criteria>
            <criteria operator="AND" comment="Solaris 9 (SPARC) meets Sun Alert 256748">
              <extend_definition comment="Solaris 9 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1457"/>
              <criterion negate="true" comment="Patch 112960-65 or later installed" test_ref="oval:org.mitre.oval:tst:9856"/>
            </criteria>
            <criteria operator="AND" comment="Solaris 8 (x86) meets Sun Alert 256748">
              <extend_definition comment="Solaris 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:2059"/>
              <criterion negate="true" comment="Patch 128625-09 or later installed" test_ref="oval:org.mitre.oval:tst:10082"/>
            </criteria>
            <criteria operator="AND" comment="Solaris 9 (x86) meets Sun Alert 256748">
              <extend_definition comment="Solaris 9 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1683"/>
              <criterion negate="true" comment="Patch 114242-50 or later installed" test_ref="oval:org.mitre.oval:tst:9784"/>
            </criteria>
          </criteria>
          <criterion comment="rpc.nisd service is running" test_ref="oval:org.mitre.oval:tst:10097"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10">
          <criteria operator="OR" comment="Solaris 10 software section">
            <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 256748">
              <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
              <criterion negate="true" comment="Patch 140917-01 or later installed" test_ref="oval:org.mitre.oval:tst:10226"/>
            </criteria>
            <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 256748">
              <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
              <criterion negate="true" comment="Patch 140918-01 or later installed" test_ref="oval:org.mitre.oval:tst:10054"/>
            </criteria>
          </criteria>
          <criterion comment="rpc.nisd service is running" test_ref="oval:org.mitre.oval:tst:10027"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6252" version="1" class="vulnerability">
      <metadata>
        <title>Security Vulnerability in PostgreSQL Shipped with Solaris may Allow a Denial of Service (DoS)</title>
        <affected family="unix">
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-0922" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0922"/>
        <description>PostgreSQL before 8.3.7, 8.2.13, 8.1.17, 8.0.21, and 7.4.25 allows remote authenticated users to cause a denial of service (stack consumption and crash) by triggering a failure in the conversion of a localized error message to a client-specified encoding, as demonstrated using mismatched encoding conversion requests.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-07-28T11:46:34.000-04:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2009-07-30T17:45:07.723-04:00">DRAFT</status_change>
            <status_change date="2009-08-17T04:00:03.670-04:00">INTERIM</status_change>
            <status_change date="2009-09-07T04:00:13.826-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="Software Section">
          <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 258808">
            <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
            <criterion negate="true" comment="Patch 123590-10 or later installed" test_ref="oval:org.mitre.oval:tst:10235"/>
            <criterion comment="SUNWpostgr is installed" test_ref="oval:org.mitre.oval:tst:10073"/>
          </criteria>
          <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 258808">
            <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
            <criterion negate="true" comment="Patch 136998-06 or later installed" test_ref="oval:org.mitre.oval:tst:10133"/>
            <criterion comment="SUNWpostgr-82* is installed" test_ref="oval:org.mitre.oval:tst:10339"/>
          </criteria>
          <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 258808">
            <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
            <criterion negate="true" comment="Patch 138826-04 or later installed" test_ref="oval:org.mitre.oval:tst:10362"/>
            <criterion comment="SUNWpostgr-83* is installed" test_ref="oval:org.mitre.oval:tst:10361"/>
          </criteria>
          <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 258808">
            <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
            <criterion negate="true" comment="Patch 123591-10 or later installed" test_ref="oval:org.mitre.oval:tst:10129"/>
            <criterion comment="SUNWpostgr is installed" test_ref="oval:org.mitre.oval:tst:10073"/>
          </criteria>
          <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 258808">
            <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
            <criterion negate="true" comment="Patch 136999-06 or later installed" test_ref="oval:org.mitre.oval:tst:10164"/>
            <criterion comment="SUNWpostgr-82* is installed" test_ref="oval:org.mitre.oval:tst:10339"/>
          </criteria>
          <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 258808">
            <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
            <criterion negate="true" comment="Patch 138827-04 or later installed" test_ref="oval:org.mitre.oval:tst:10385"/>
            <criterion comment="SUNWpostgr-83* is installed" test_ref="oval:org.mitre.oval:tst:10361"/>
          </criteria>
        </criteria>
        <criterion comment="Patch 136999-06 or later installed" test_ref="oval:org.mitre.oval:tst:10409"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6234" version="1" class="vulnerability">
      <metadata>
        <title>Security Vulnerabilities in the libxml2 Library Routines xmlBufferResize() May Lead to Denial of Service (DoS)</title>
        <affected family="unix">
          <platform>Sun Solaris 9</platform>
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-4225" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-4225"/>
        <description>Integer overflow in the xmlBufferResize function in libxml2 2.7.2 allows context-dependent attackers to cause a denial of service (infinite loop) via a large XML document.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-02-13T15:56:00.000-05:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2009-02-13T17:01:31.147-05:00">DRAFT</status_change>
            <status_change date="2009-03-02T04:00:28.318-05:00">INTERIM</status_change>
            <status_change date="2009-03-23T04:00:21.781-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND" comment="Solaris 9 (SPARC) meets Sun Alert 240546">
          <extend_definition comment="Solaris 9 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1457"/>
          <criterion negate="true" comment="Patch 114014-22 or later installed" test_ref="oval:org.mitre.oval:tst:9654"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 240546">
          <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
          <criterion negate="true" comment="Patch 125731-04 or later installed" test_ref="oval:org.mitre.oval:tst:8710"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (x86) meets Sun Alert 240546">
          <extend_definition comment="Solaris 9 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1683"/>
          <criterion negate="true" comment="Patch 114015-22 or later installed" test_ref="oval:org.mitre.oval:tst:9487"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 240546">
          <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
          <criterion negate="true" comment="Patch 125732-04 or later installed" test_ref="oval:org.mitre.oval:tst:9600"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:622" version="6" class="vulnerability">
      <metadata>
        <title>Solaris 8, 9, 10 Blind Connection Reset Attack Vulnerability</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <platform>Sun Solaris 9</platform>
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0790" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0790"/>
        <description>Multiple TCP/IP and ICMP implementations allow remote attackers to cause a denial of service (reset TCP connections) via spoofed ICMP error messages, aka the "blind connection-reset attack."  NOTE: CVE-2004-0790, CVE-2004-0791, and CVE-2004-1060 have been SPLIT based on different attacks; CVE-2005-0065, CVE-2005-0066, CVE-2005-0067, and CVE-2005-0068 are related identifiers that are SPLIT based on the underlying vulnerability.  While CVE normally SPLITs based on vulnerability, the attack-based identifiers exist due to the variety and number of affected implementations and solutions that address the attacks instead of the underlying vulnerabilities.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-09-22T05:52:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-09-22T20:15:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-07T09:15:50.491-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:15:58.160-04:00">ACCEPTED</status_change>
            <modified comment="Added title. Implemented by Jon Baker of The MITRE Corporation." date="2007-02-13T14:46:00.662-05:00">
              <contributor organization="Security-Database">Nabil Ouchn</contributor>
            </modified>
            <status_change date="2007-02-13T14:47:31.744-05:00">INTERIM</status_change>
            <modified comment="Standardized title." date="2007-02-26T01:01:00.306-05:00">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2007-03-21T16:17:22.881-04:00">ACCEPTED</status_change>
            <modified comment="Added missing patch checks." date="2007-06-26T10:59:00.754-04:00">
              <contributor organization="Opsware, Inc.">Pai Peng</contributor>
            </modified>
            <status_change date="2007-06-26T11:00:29.787-04:00">INTERIM</status_change>
            <status_change date="2007-07-11T15:17:33.358-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:622 - Various corrections to comments and products to align with Authoring Style Guide" date="2011-04-22T23:54:00.899-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-04-23T00:06:42.080-04:00">INTERIM</status_change>
            <status_change date="2011-05-09T04:01:38.771-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Solaris 8 (SPARC) meets Sun Alert ID 101658 criteria.">
          <criterion comment="Solaris 8 Installed" test_ref="oval:org.mitre.oval:tst:3437"/>
          <criterion comment="sparc architecture" test_ref="oval:org.mitre.oval:tst:3237"/>
          <criterion negate="true" comment="Patch 116965-19 or later installed" test_ref="oval:org.mitre.oval:tst:4028"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 8 (x86) meets Sun Alert ID 101658 criteria.">
          <criterion comment="Solaris 8 Installed" test_ref="oval:org.mitre.oval:tst:3437"/>
          <criterion comment="ix86 architecture" test_ref="oval:org.mitre.oval:tst:3912"/>
          <criterion negate="true" comment="Patch 116966-18 or later installed" test_ref="oval:org.mitre.oval:tst:4069"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (SPARC) meets Sun Alert ID 101658 criteria.">
          <criterion comment="Solaris 9 Installed" test_ref="oval:org.mitre.oval:tst:3172"/>
          <criterion comment="sparc architecture" test_ref="oval:org.mitre.oval:tst:3237"/>
          <criterion negate="true" comment="Patch 118305-08 or later installed" test_ref="oval:org.mitre.oval:tst:3204"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (x86) meets Sun Alert ID 101658 criteria.">
          <criterion comment="Solaris 9 Installed" test_ref="oval:org.mitre.oval:tst:3172"/>
          <criterion comment="ix86 architecture" test_ref="oval:org.mitre.oval:tst:3912"/>
          <criterion negate="true" comment="Patch 117470-07 or later installed" test_ref="oval:org.mitre.oval:tst:4114"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert ID 101658 criteria.">
          <criterion comment="Solaris 10 Installed" test_ref="oval:org.mitre.oval:tst:3680"/>
          <criterion comment="sparc architecture" test_ref="oval:org.mitre.oval:tst:3237"/>
          <criterion negate="true" comment="Patch 118822-27 or later installed" test_ref="oval:org.mitre.oval:tst:3505"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert ID 101658 criteria.">
          <criterion comment="Solaris 10 Installed" test_ref="oval:org.mitre.oval:tst:3680"/>
          <criterion comment="ix86 architecture" test_ref="oval:org.mitre.oval:tst:3912"/>
          <criterion negate="true" comment="Patch 118844-28 or later installed" test_ref="oval:org.mitre.oval:tst:3302"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6219" version="1" class="vulnerability">
      <metadata>
        <title>Security Vulnerabilities in the libxml2 Library Routines xmlSAX2Characters() May Lead to Arbitrary Code Execution or Denial of Service (DoS)</title>
        <affected family="unix">
          <platform>Sun Solaris 9</platform>
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-4226" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-4226"/>
        <description>Integer overflow in the xmlSAX2Characters function in libxml2 2.7.2 allows context-dependent attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via a large XML document.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-02-13T15:56:00.000-05:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2009-02-13T17:01:31.658-05:00">DRAFT</status_change>
            <status_change date="2009-03-02T04:00:27.722-05:00">INTERIM</status_change>
            <status_change date="2009-03-23T04:00:21.430-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND" comment="Solaris 9 (SPARC) meets Sun Alert 240546">
          <extend_definition comment="Solaris 9 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1457"/>
          <criterion negate="true" comment="Patch 114014-22 or later installed" test_ref="oval:org.mitre.oval:tst:9654"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 240546">
          <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
          <criterion negate="true" comment="Patch 125731-04 or later installed" test_ref="oval:org.mitre.oval:tst:8710"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (x86) meets Sun Alert 240546">
          <extend_definition comment="Solaris 9 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1683"/>
          <criterion negate="true" comment="Patch 114015-22 or later installed" test_ref="oval:org.mitre.oval:tst:9487"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 240546">
          <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
          <criterion negate="true" comment="Patch 125732-04 or later installed" test_ref="oval:org.mitre.oval:tst:9600"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6203" version="1" class="vulnerability">
      <metadata>
        <title>Security Vulnerability in the Solaris keysock Kernel Module may Lead to a System Panic</title>
        <affected family="unix">
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-0913" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0913"/>
        <description>Unspecified vulnerability in the keysock kernel module in Solaris 10 and OpenSolaris builds snv_01 through snv_108 allows local users to cause a denial of service (system panic) via unknown vectors related to PF_KEY socket, probably related to setting socket options.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-04-02T11:13:52.000-04:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2009-04-08T14:20:04.712-04:00">DRAFT</status_change>
            <status_change date="2009-04-27T04:00:16.486-04:00">INTERIM</status_change>
            <status_change date="2009-05-18T04:00:27.304-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 253568">
          <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
          <criterion negate="true" comment="Patch 141008-01 or later installed" test_ref="oval:org.mitre.oval:tst:9765"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 253568">
          <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
          <criterion negate="true" comment="Patch 141009-01 or later installed" test_ref="oval:org.mitre.oval:tst:9425"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6183" version="1" class="vulnerability">
      <metadata>
        <title>A Security Vulnerability in the Solaris dircmp(1) Shell Script may Allow Overwriting of Arbitrary Files</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <platform>Sun Solaris 9</platform>
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-1207" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1207"/>
        <description>Race condition in the dircmp script in Sun Solaris 8 through 10, and OpenSolaris snv_01 through snv_111, allows local users to overwrite arbitrary files, probably involving a symlink attack on temporary files.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-04-02T11:13:52.000-04:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2009-04-08T14:20:08.844-04:00">DRAFT</status_change>
            <status_change date="2009-04-27T04:00:15.946-04:00">INTERIM</status_change>
            <status_change date="2009-05-18T04:00:26.719-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND" comment="Solaris 8 (SPARC) meets Sun Alert 253468">
          <extend_definition comment="Solaris 8 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1539"/>
          <criterion negate="true" comment="Patch 140837-01 or later installed" test_ref="oval:org.mitre.oval:tst:9742"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (SPARC) meets Sun Alert 253468">
          <extend_definition comment="Solaris 9 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1457"/>
          <criterion negate="true" comment="Patch 138896-01 or later installed" test_ref="oval:org.mitre.oval:tst:9760"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 253468">
          <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
          <criterion negate="true" comment="Patch 141014-01 or later installed" test_ref="oval:org.mitre.oval:tst:9632"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 8 (x86) meets Sun Alert 253468">
          <extend_definition comment="Solaris 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:2059"/>
          <criterion negate="true" comment="Patch 140838-01 or later installed" test_ref="oval:org.mitre.oval:tst:9652"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (x86) meets Sun Alert 253468">
          <extend_definition comment="Solaris 9 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1683"/>
          <criterion negate="true" comment="Patch 138897-01 or later installed" test_ref="oval:org.mitre.oval:tst:9731"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 253468">
          <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
          <criterion negate="true" comment="Patch 141015-01 or later installed" test_ref="oval:org.mitre.oval:tst:9537"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6175" version="1" class="vulnerability">
      <metadata>
        <title>Security Vulnerabilities in the Solaris lpadmin(1M) and ppdmgr(1M) Utilities May Lead to a Denial of Service (DoS) Condition</title>
        <affected family="unix">
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-0167" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0167"/>
        <description>Unspecified vulnerability in lpadmin in Sun Solaris 10 and OpenSolaris snv_61 through snv_106 allows local users to cause a denial of service via unspecified vectors, related to enumeration of "wrong printers," aka a "Temporary file vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2009-02-05T13:18:38.000-05:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2009-02-06T15:58:48.744-05:00">DRAFT</status_change>
            <status_change date="2009-02-23T04:00:23.607-05:00">INTERIM</status_change>
            <status_change date="2009-03-16T04:00:20.571-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 249306">
          <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
          <criterion comment="Patch 127127-11 installed" test_ref="oval:org.mitre.oval:tst:9551"/>
          <criterion negate="true" comment="Patch 139390-01 or later installed" test_ref="oval:org.mitre.oval:tst:9591"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 249306">
          <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
          <criterion comment="Patch 127128-11 installed" test_ref="oval:org.mitre.oval:tst:9422"/>
          <criterion negate="true" comment="Patch 139391-01 or later installed" test_ref="oval:org.mitre.oval:tst:8934"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6174" version="1" class="vulnerability">
      <metadata>
        <title>A Security Vulnerability in Kerberos Incremental Propagation May Lead to a Denial of Service (DoS) Against Slave KDC Systems</title>
        <affected family="unix">
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-0923" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0923"/>
        <description>Unspecified vulnerability in Kerberos Incremental Propagation in Solaris 10 and OpenSolaris snv_01 through snv_110 allows remote attackers to cause a denial of service (loss of incremental propagation requests to slave KDC servers) via unknown vectors related to the master Key Distribution Center (KDC) server.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-04-02T11:13:52.000-04:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2009-04-08T14:20:10.595-04:00">DRAFT</status_change>
            <status_change date="2009-04-27T04:00:15.389-04:00">INTERIM</status_change>
            <status_change date="2009-05-18T04:00:26.164-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="Software Section">
          <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 249926">
            <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
            <criterion negate="true" comment="Patch 138371-05 or later installed" test_ref="oval:org.mitre.oval:tst:9662"/>
          </criteria>
          <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 249926">
            <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
            <criterion negate="true" comment="Patch 138372-05 or later installed" test_ref="oval:org.mitre.oval:tst:9253"/>
          </criteria>
        </criteria>
        <criterion comment="System is configured as a slave KDC" test_ref="oval:org.mitre.oval:tst:9764"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6168" version="1" class="vulnerability">
      <metadata>
        <title>Race Condition Security Vulnerability in Solaris Auditing Related to Extended File Attributes May Allow Local Unprivileged Users to Panic the System</title>
        <affected family="unix">
          <platform>Sun Solaris 9</platform>
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-2644" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2644"/>
        <description>Race condition in the Solaris Auditing subsystem in Sun Solaris 9 and 10 and OpenSolaris before snv_121, when extended file attributes are used, allows local users to cause a denial of service (panic) via vectors related to "pathnames for invalid fds."</description>
        <oval_repository>
          <dates>
            <submitted date="2009-08-10T16:40:08.000-04:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2009-08-12T09:49:57.004-04:00">DRAFT</status_change>
            <status_change date="2009-08-31T04:00:08.660-04:00">INTERIM</status_change>
            <status_change date="2009-09-21T04:00:05.908-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="Software Section">
          <criteria operator="AND" comment="Solaris 9 (SPARC) meets Sun Alert 264429">
            <extend_definition comment="Solaris 9 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1457"/>
            <criterion negate="true" comment="Patch 122300-42 or later installed" test_ref="oval:org.mitre.oval:tst:10143"/>
          </criteria>
          <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 264429">
            <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
            <criterion negate="true" comment="Patch 140921-02 or later installed" test_ref="oval:org.mitre.oval:tst:10518"/>
          </criteria>
          <criteria operator="AND" comment="Solaris 9 (x86) meets Sun Alert 264429">
            <extend_definition comment="Solaris 9 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1683"/>
            <criterion negate="true" comment="Patch 122301-42 or later installed" test_ref="oval:org.mitre.oval:tst:10507"/>
          </criteria>
          <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 264429">
            <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
            <criterion negate="true" comment="Patch 140922-02 or later installed" test_ref="oval:org.mitre.oval:tst:9991"/>
          </criteria>
        </criteria>
        <criterion comment="Solaris Auditing is enabled" test_ref="oval:org.mitre.oval:tst:10368"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6152" version="1" class="vulnerability">
      <metadata>
        <title>Security Vulnerability in the Solaris Kernel Involving the Interaction of the Filesystem and Virtual Memory Subsystems</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <platform>Sun Solaris 9</platform>
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-2857" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2857"/>
        <description>The kernel in Sun Solaris 8, 9, and 10, and OpenSolaris before snv_103, does not properly handle interaction between the filesystem and virtual-memory implementations, which allows local users to cause a denial of service (deadlock and system halt) via vectors involving mmap and write operations on the same file.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-08-21T11:07:35.000-04:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2009-08-21T20:56:31.695-04:00">DRAFT</status_change>
            <status_change date="2009-09-07T04:00:11.548-04:00">INTERIM</status_change>
            <status_change date="2009-09-28T04:00:15.555-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND" comment="Solaris 8 (SPARC) meets Sun Alert 257848">
          <extend_definition comment="Solaris 8 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1539"/>
          <criterion negate="true" comment="Patch 127721-02 or later installed" test_ref="oval:org.mitre.oval:tst:10639"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (SPARC) meets Sun Alert 257848">
          <extend_definition comment="Solaris 9 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1457"/>
          <criterion negate="true" comment="Patch 122300-41 or later installed" test_ref="oval:org.mitre.oval:tst:10603"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 257848">
          <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
          <criterion negate="true" comment="Patch 139555-08 or later installed" test_ref="oval:org.mitre.oval:tst:9767"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 8 (x86) meets Sun Alert 257848">
          <extend_definition comment="Solaris 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:2059"/>
          <criterion negate="true" comment="Patch 127722-02 or later installed" test_ref="oval:org.mitre.oval:tst:10324"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (x86) meets Sun Alert 257848">
          <extend_definition comment="Solaris 9 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1683"/>
          <criterion negate="true" comment="Patch 122301-41 or later installed" test_ref="oval:org.mitre.oval:tst:10053"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 257848">
          <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
          <criterion negate="true" comment="Patch 139556-08 or later installed" test_ref="oval:org.mitre.oval:tst:10254"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6136" version="1" class="vulnerability">
      <metadata>
        <title>Security Vulnerability in the Simple Authentication and Security Layer (SASL) Library Bundled with the Java Enterprise System (JES) may Allow Unprivileged Users to Crash Applications Using the sasl_encode64 Function</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <platform>Sun Solaris 9</platform>
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-0688" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0688"/>
        <description>Multiple buffer overflows in the CMU Cyrus SASL library before 2.1.23 might allow remote attackers to execute arbitrary code or cause a denial of service (application crash) via strings that are used as input to the sasl_encode64 function in lib/saslutil.c.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-07-28T11:14:39.000-04:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2009-07-30T17:45:06.789-04:00">DRAFT</status_change>
            <status_change date="2009-08-17T04:00:03.181-04:00">INTERIM</status_change>
            <status_change date="2009-09-07T04:00:11.189-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="Software Section">
          <criteria operator="AND" comment="Solaris 8 (SPARC) meets Sun Alert 264248">
            <extend_definition comment="Solaris 8 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1539"/>
            <criterion negate="true" comment="Patch 115328-08 or later installed" test_ref="oval:org.mitre.oval:tst:10445"/>
          </criteria>
          <criteria operator="AND" comment="Solaris 9 (SPARC) meets Sun Alert 264248">
            <extend_definition comment="Solaris 9 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1457"/>
            <criterion negate="true" comment="Patch 115342-08 or later installed" test_ref="oval:org.mitre.oval:tst:10367"/>
          </criteria>
          <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 264248">
            <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
            <criterion negate="true" comment="Patch 119345-07 or later installed" test_ref="oval:org.mitre.oval:tst:10193"/>
          </criteria>
          <criteria operator="AND" comment="Solaris 9 (x86) meets Sun Alert 264248">
            <extend_definition comment="Solaris 9 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1683"/>
            <criterion negate="true" comment="Patch 115343-08 or later installed" test_ref="oval:org.mitre.oval:tst:10455"/>
          </criteria>
          <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 264248">
            <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
            <criterion negate="true" comment="Patch 119346-07 or later installed" test_ref="oval:org.mitre.oval:tst:9898"/>
          </criteria>
        </criteria>
        <criterion comment="SUNWsasl is installed" test_ref="oval:org.mitre.oval:tst:9482"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6116" version="1" class="vulnerability">
      <metadata>
        <title>Security Vulnerability with IKE Packet Handling in Solaris libike Library may Lead to a Crash of in.iked(1M)</title>
        <affected family="unix">
          <platform>Sun Solaris 9</platform>
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-0267" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0267"/>
        <description>libike in Sun Solaris 9 and 10, and OpenSolaris before snv_100, does not properly check packets, which allows remote attackers to cause a denial of service (in.iked daemon crash) via an unspecified IKE packet, a different vulnerability than CVE-2007-2989.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-01-28T11:08:21.000-05:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2009-01-30T18:16:31.359-05:00">DRAFT</status_change>
            <status_change date="2009-02-16T04:00:26.978-05:00">INTERIM</status_change>
            <status_change date="2009-03-09T04:00:11.155-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="Software Section">
          <criteria operator="AND" comment="Solaris 9 (SPARC) meets Sun Alert 247406">
            <extend_definition comment="Solaris 9 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1457"/>
            <criterion negate="true" comment="Patch 113451-15 or later installed" test_ref="oval:org.mitre.oval:tst:9566"/>
          </criteria>
          <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 247406">
            <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
            <criterion negate="true" comment="Patch 140196-01 or later installed" test_ref="oval:org.mitre.oval:tst:8940"/>
          </criteria>
          <criteria operator="AND" comment="Solaris 9 (x86) meets Sun Alert 247406">
            <extend_definition comment="Solaris 9 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1683"/>
            <criterion negate="true" comment="Patch 114435-14 or later installed" test_ref="oval:org.mitre.oval:tst:9611"/>
          </criteria>
          <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 247406">
            <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
            <criterion negate="true" comment="Patch 140414-01 or later installed" test_ref="oval:org.mitre.oval:tst:8709"/>
          </criteria>
        </criteria>
        <criterion comment="File /etc/inet/ike/config exists" test_ref="oval:org.mitre.oval:tst:9478"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6088" version="1" class="vulnerability">
      <metadata>
        <title>A Security Vulnerability in the Solaris ip(7P) Kernel Module's IP-in-IP Packet Processing May Lead to a Denial of Service (DoS)</title>
        <affected family="unix">
          <platform>Sun Solaris 9</platform>
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-0346" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0346"/>
        <description>The IP-in-IP packet processing implementation in the IPsec and IP stacks in the kernel in Sun Solaris 9 and 10, and OpenSolaris snv_01 though snv_85, allows local users to cause a denial of service (panic) via a self-encapsulated packet that lacks IPsec protection.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-02-05T13:18:38.000-05:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2009-02-06T15:58:53.969-05:00">DRAFT</status_change>
            <status_change date="2009-02-23T04:00:23.036-05:00">INTERIM</status_change>
            <status_change date="2009-03-16T04:00:16.923-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND" comment="Solaris 9 (SPARC) meets Sun Alert 240086">
          <extend_definition comment="Solaris 9 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1457"/>
          <criterion negate="true" comment="Patch 114344-38 or later installed" test_ref="oval:org.mitre.oval:tst:9675"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 240086">
          <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
          <criterion negate="true" comment="Patch 138888-03 or later installed" test_ref="oval:org.mitre.oval:tst:8820"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (x86) meets Sun Alert 240086">
          <extend_definition comment="Solaris 9 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1683"/>
          <criterion negate="true" comment="Patch 119435-26 or later installed" test_ref="oval:org.mitre.oval:tst:9614"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 240086">
          <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
          <criterion negate="true" comment="Patch 138889-03 or later installed" test_ref="oval:org.mitre.oval:tst:9254"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6085" version="1" class="vulnerability">
      <metadata>
        <title>Security Vulnerability in Solaris SSH May Allow Unauthorized Access to X11 Sessions</title>
        <affected family="unix">
          <platform>Sun Solaris 9</platform>
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-1483" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1483"/>
        <description>OpenSSH 4.3p2, and probably other versions, allows local users to hijack forwarded X connections by causing ssh to set DISPLAY to :10, even when another process is listening on the associated port, as demonstrated by opening TCP port 6010 (IPv4) and sniffing a cookie sent by Emacs.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-08-25T11:33:40.000-04:00">
              <contributor organization="Hewlett-Packard">Nicholas Hansen</contributor>
            </submitted>
            <status_change date="2008-08-28T14:12:27.939-04:00">DRAFT</status_change>
            <status_change date="2008-09-15T04:00:28.608-04:00">INTERIM</status_change>
            <status_change date="2008-10-06T04:00:20.232-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="Software Section">
          <criteria operator="AND" comment="Solaris 9 (SPARC) meets Sun Alert 237444">
            <extend_definition comment="Solaris 9 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1457"/>
            <criterion negate="true" comment="Patch 114356-14 or later installed" test_ref="oval:org.mitre.oval:tst:9096"/>
            <criterion comment="X11Forwarding is enabled" test_ref="oval:org.mitre.oval:tst:9067"/>
          </criteria>
          <criteria operator="AND" comment="Solaris 9 (x86) meets Sun Alert 237444">
            <extend_definition comment="Solaris 9 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1683"/>
            <criterion negate="true" comment="Patch 114357-13 or later installed" test_ref="oval:org.mitre.oval:tst:9157"/>
            <criterion comment="X11Forwarding is enabled" test_ref="oval:org.mitre.oval:tst:9067"/>
          </criteria>
          <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 237444">
            <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
            <criterion negate="true" comment="Patch 126133-03 or later installed" test_ref="oval:org.mitre.oval:tst:9197"/>
            <criterion negate="true" comment="X11Forwarding is not enabled" test_ref="oval:org.mitre.oval:tst:9165"/>
          </criteria>
          <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 237444">
            <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
            <criterion negate="true" comment="Patch 126134-03 or later installed" test_ref="oval:org.mitre.oval:tst:9048"/>
            <criterion negate="true" comment="X11Forwarding is not enabled" test_ref="oval:org.mitre.oval:tst:9165"/>
          </criteria>
        </criteria>
        <criteria comment="Configuration Section">
          <criterion comment="sshd running" test_ref="oval:org.mitre.oval:tst:484"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6061" version="1" class="vulnerability">
      <metadata>
        <title>Security Vulnerability in the Solaris Pseudo-terminal Driver (pty(7D)) may Cause a System Panic</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <platform>Sun Solaris 9</platform>
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-0268" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0268"/>
        <description>Race condition in the pseudo-terminal (aka pty) driver module in Sun Solaris 8 through 10, and OpenSolaris before snv_103, allows local users to cause a denial of service (panic) via unspecified vectors related to lack of "properly sequenced code" in ptc and ptsl.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-01-28T11:08:21.000-05:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2009-01-30T18:16:32.895-05:00">DRAFT</status_change>
            <status_change date="2009-02-16T04:00:26.165-05:00">INTERIM</status_change>
            <status_change date="2009-03-09T04:00:10.700-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND" comment="Solaris 8 (SPARC) meets Sun Alert 249586">
          <extend_definition comment="Solaris 8 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1539"/>
          <criterion negate="true" comment="Patch 113685-07 or later installed" test_ref="oval:org.mitre.oval:tst:9513"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (SPARC) meets Sun Alert 249586">
          <extend_definition comment="Solaris 9 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1457"/>
          <criterion negate="true" comment="Patch 140426-01 or later installed" test_ref="oval:org.mitre.oval:tst:9267"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 249586">
          <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
          <criterion negate="true" comment="Patch 140383-01 or later installed" test_ref="oval:org.mitre.oval:tst:9659"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 8 (x86) meets Sun Alert 249586">
          <extend_definition comment="Solaris 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:2059"/>
          <criterion negate="true" comment="Patch 113686-06 or later installed" test_ref="oval:org.mitre.oval:tst:9438"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (x86) meets Sun Alert 249586">
          <extend_definition comment="Solaris 9 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1683"/>
          <criterion negate="true" comment="Patch 140427-01 or later installed" test_ref="oval:org.mitre.oval:tst:9498"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 249586">
          <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
          <criterion negate="true" comment="Patch 140384-01 or later installed" test_ref="oval:org.mitre.oval:tst:9523"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6038" version="1" class="vulnerability">
      <metadata>
        <title>Security Vulnerability in the Solaris IP(7p) Implementation, Related to Minor Number Allocation, may Lead to a Denial of Service (DoS) Condition</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <platform>Sun Solaris 9</platform>
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-0480" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0480"/>
        <description>The IP implementation in Sun Solaris 8 through 10, and OpenSolaris before snv_82, uses an improper arena when allocating minor numbers for sockets, which allows local users to cause a denial of service (32-bit application failure and login outage) by opening a large number of sockets.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-02-10T11:19:01.000-05:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2009-02-13T17:01:54.282-05:00">DRAFT</status_change>
            <status_change date="2009-03-02T04:00:19.981-05:00">INTERIM</status_change>
            <status_change date="2009-03-23T04:00:16.596-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND" comment="Solaris 8 (SPARC) meets Sun Alert 248026">
          <extend_definition comment="Solaris 8 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1539"/>
          <criterion negate="true" comment="Patch 116965-34 or later installed" test_ref="oval:org.mitre.oval:tst:9631"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (SPARC) meets Sun Alert 248026">
          <extend_definition comment="Solaris 9 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1457"/>
          <criterion negate="true" comment="Patch 114344-37 or later installed" test_ref="oval:org.mitre.oval:tst:9582"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 248026">
          <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
          <criterion negate="true" comment="Patch 138888-01 or later installed" test_ref="oval:org.mitre.oval:tst:9474"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 8 (x86) meets Sun Alert 248026">
          <extend_definition comment="Solaris 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:2059"/>
          <criterion negate="true" comment="Patch 116966-33 or later installed" test_ref="oval:org.mitre.oval:tst:9681"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (x86) meets Sun Alert 248026">
          <extend_definition comment="Solaris 9 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1683"/>
          <criterion negate="true" comment="Patch 119435-25 or later installed" test_ref="oval:org.mitre.oval:tst:8868"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 248026">
          <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
          <criterion negate="true" comment="Patch 138889-01 or later installed" test_ref="oval:org.mitre.oval:tst:9661"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6009" version="1" class="vulnerability">
      <metadata>
        <title>Security vulnerability in the Virtual Host Manager in Tomcat 5.5 bundled with Solaris 9 and Solaris 10 may lead to Cross Site Scripting (XSS).</title>
        <affected family="unix">
          <platform>Sun Solaris 9</platform>
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-1947" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1947"/>
        <description>Cross-site scripting (XSS) vulnerability in Apache Tomcat 5.5.9 through 5.5.26 and 6.0.0 through 6.0.16 allows remote attackers to inject arbitrary web script or HTML via the name parameter (aka the hostname attribute) to host-manager/html/add.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-02-26T10:58:29.000-05:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2009-02-27T16:20:22.124-05:00">DRAFT</status_change>
            <status_change date="2009-03-16T04:00:16.528-04:00">INTERIM</status_change>
            <status_change date="2009-04-06T04:00:18.038-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND" comment="Software Section">
        <criteria operator="OR">
          <criteria operator="AND" comment="Solaris 9 (SPARC) meets Sun Alert 251986">
            <extend_definition comment="Solaris 9 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1457"/>
            <criterion negate="true" comment="Patch 114016-03 or later installed" test_ref="oval:org.mitre.oval:tst:9634"/>
          </criteria>
          <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 251986">
            <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
            <criterion negate="true" comment="Patch 122911-15 or later installed" test_ref="oval:org.mitre.oval:tst:9605"/>
          </criteria>
          <criteria operator="AND" comment="Solaris 9 (x86) meets Sun Alert 251986">
            <extend_definition comment="Solaris 9 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1683"/>
            <criterion negate="true" comment="Patch 114017-03 or later installed" test_ref="oval:org.mitre.oval:tst:9480"/>
          </criteria>
          <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 251986">
            <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
            <criterion negate="true" comment="Patch 122912-15 or later installed" test_ref="oval:org.mitre.oval:tst:9406"/>
          </criteria>
        </criteria>
        <criterion comment="SUNWtcatr is installed" test_ref="oval:org.mitre.oval:tst:9550"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6003" version="1" class="vulnerability">
      <metadata>
        <title>Security Vulnerability in the X Inter Client Exchange Library (libICE) Shipped With Solaris May Allow a Denial of Service (DoS)</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <platform>Sun Solaris 9</platform>
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-5684" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-5684"/>
        <description>Unspecified vulnerability in the X Inter Client Exchange library (aka libICE) in Sun Solaris 8 through 10 and OpenSolaris before snv_85 allows context-dependent attackers to cause a denial of service (application crash), as demonstrated by a port scan that triggers a segmentation violation in the Gnome session manager (aka gnome-session).</description>
        <oval_repository>
          <dates>
            <submitted date="2009-01-05T16:39:26.000-05:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2009-01-09T14:23:46.445-05:00">DRAFT</status_change>
            <status_change date="2009-01-26T04:00:20.280-05:00">INTERIM</status_change>
            <status_change date="2009-02-16T04:00:24.753-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND" comment="Solaris 8 (SPARC) meets Sun Alert 243566">
          <extend_definition comment="Solaris 8 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1539"/>
          <criterion negate="true" comment="Patch 119067-11 or later installed" test_ref="oval:org.mitre.oval:tst:9572"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (SPARC) meets Sun Alert 243566">
          <extend_definition comment="Solaris 9 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1457"/>
          <criterion negate="true" comment="Patch 112785-65 or later installed" test_ref="oval:org.mitre.oval:tst:9617"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 243566">
          <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
          <criterion negate="true" comment="Patch 119059-46 or later installed" test_ref="oval:org.mitre.oval:tst:9472"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 8 (x86) meets Sun Alert 243566">
          <extend_definition comment="Solaris 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:2059"/>
          <criterion negate="true" comment="Patch 119068-11 or later installed" test_ref="oval:org.mitre.oval:tst:9453"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (x86) meets Sun Alert 243566">
          <extend_definition comment="Solaris 9 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1683"/>
          <criterion negate="true" comment="Patch 112786-54 or later installed" test_ref="oval:org.mitre.oval:tst:9118"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 243566">
          <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
          <criterion negate="true" comment="Patch 119060-45 or later installed" test_ref="oval:org.mitre.oval:tst:9264"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5985" version="1" class="vulnerability">
      <metadata>
        <title>Security vulnerability in the HttpServletResponse.sendError method in Tomcat 5.5 bundled with Solaris 9 and Solaris 10 may lead to Cross Site Scripting (XSS).</title>
        <affected family="unix">
          <platform>Sun Solaris 9</platform>
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-1232" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1232"/>
        <description>Cross-site scripting (XSS) vulnerability in Apache Tomcat 4.1.0 through 4.1.37, 5.5.0 through 5.5.26, and 6.0.0 through 6.0.16 allows remote attackers to inject arbitrary web script or HTML via a crafted string that is used in the message argument to the HttpServletResponse.sendError method.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-02-26T10:58:29.000-05:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2009-02-27T16:20:22.464-05:00">DRAFT</status_change>
            <status_change date="2009-03-16T04:00:16.102-04:00">INTERIM</status_change>
            <status_change date="2009-04-06T04:00:17.059-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND" comment="Software Section">
        <criteria operator="OR">
          <criteria operator="AND" comment="Solaris 9 (SPARC) meets Sun Alert 251986">
            <extend_definition comment="Solaris 9 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1457"/>
            <criterion negate="true" comment="Patch 114016-03 or later installed" test_ref="oval:org.mitre.oval:tst:9634"/>
          </criteria>
          <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 251986">
            <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
            <criterion negate="true" comment="Patch 122911-15 or later installed" test_ref="oval:org.mitre.oval:tst:9605"/>
          </criteria>
          <criteria operator="AND" comment="Solaris 9 (x86) meets Sun Alert 251986">
            <extend_definition comment="Solaris 9 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1683"/>
            <criterion negate="true" comment="Patch 114017-03 or later installed" test_ref="oval:org.mitre.oval:tst:9480"/>
          </criteria>
          <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 251986">
            <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
            <criterion negate="true" comment="Patch 122912-15 or later installed" test_ref="oval:org.mitre.oval:tst:9406"/>
          </criteria>
        </criteria>
        <criterion comment="SUNWtcatr is installed" test_ref="oval:org.mitre.oval:tst:9550"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5978" version="1" class="vulnerability">
      <metadata>
        <title>Security Vulnerability in GNU tar May Lead to Arbitrary Code Execution or Denial of Service (DoS)</title>
        <affected family="unix">
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-0300" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0300"/>
        <description>Buffer overflow in tar 1.14 through 1.15.90 allows user-assisted attackers to cause a denial of service (application crash) and possibly execute code via unspecified vectors involving PAX extended headers.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-04-30T11:23:00.000-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2009-05-07T11:17:33.789-04:00">DRAFT</status_change>
            <status_change date="2009-05-25T04:01:51.856-04:00">INTERIM</status_change>
            <status_change date="2009-06-15T04:00:53.458-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 241646">
          <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
          <criterion negate="true" comment="Patch 139099-01 or later installed" test_ref="oval:org.mitre.oval:tst:9629"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5977" version="1" class="vulnerability">
      <metadata>
        <title>Security Vulnerability in the Solaris "autofs" Kernel Module may Allow a Local Unprivileged User to Execute Arbitrary Code</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <platform>Sun Solaris 9</platform>
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-0319" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0319"/>
        <description>Unspecified vulnerability in the autofs module in the kernel in Sun Solaris 8 through 10, and OpenSolaris before snv_108, allows local users to cause a denial of service (autofs mount outage) or possibly gain privileges via vectors related to "xdr processing problems."</description>
        <oval_repository>
          <dates>
            <submitted date="2009-02-05T13:18:38.000-05:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2009-02-06T15:58:55.814-05:00">DRAFT</status_change>
            <status_change date="2009-02-23T04:00:21.897-05:00">INTERIM</status_change>
            <status_change date="2009-03-16T04:00:15.050-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="Software Section">
          <criteria operator="AND" comment="Solaris 8 (SPARC) meets Sun Alert 249966">
            <extend_definition comment="Solaris 8 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1539"/>
            <criterion negate="true" comment="Patch 128624-09 or later installed" test_ref="oval:org.mitre.oval:tst:9674"/>
          </criteria>
          <criteria operator="AND" comment="Solaris 9 (SPARC) meets Sun Alert 249966">
            <extend_definition comment="Solaris 9 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1457"/>
            <criterion negate="true" comment="Patch 113318-34 or later installed" test_ref="oval:org.mitre.oval:tst:9559"/>
          </criteria>
          <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 249966">
            <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
            <criterion negate="true" comment="Patch 139560-01 or later installed" test_ref="oval:org.mitre.oval:tst:9658"/>
          </criteria>
          <criteria operator="AND" comment="Solaris 8 (x86) meets Sun Alert 249966">
            <extend_definition comment="Solaris 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:2059"/>
            <criterion negate="true" comment="Patch 128625-09 or later installed" test_ref="oval:org.mitre.oval:tst:9544"/>
          </criteria>
          <criteria operator="AND" comment="Solaris 9 (x86) meets Sun Alert 249966">
            <extend_definition comment="Solaris 9 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1683"/>
            <criterion negate="true" comment="Patch 116053-03 or later installed" test_ref="oval:org.mitre.oval:tst:9593"/>
          </criteria>
          <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 249966">
            <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
            <criterion negate="true" comment="Patch 139561-01 or later installed" test_ref="oval:org.mitre.oval:tst:8913"/>
          </criteria>
        </criteria>
        <criterion comment="autofs is enabled" test_ref="oval:org.mitre.oval:tst:9385"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5960" version="1" class="vulnerability">
      <metadata>
        <title>SUNRAS Plugin of Gimp Vulnerability</title>
        <affected family="unix">
          <platform>Sun Solaris 9</platform>
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-2356" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2356"/>
        <description>Stack-based buffer overflow in the set_color_table function in sunras.c in the SUNRAS plugin in Gimp 2.2.14 allows user-assisted remote attackers to execute arbitrary code via a crafted RAS file.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-09-11T11:37:41.000-04:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2008-09-12T12:49:06.257-04:00">DRAFT</status_change>
            <status_change date="2008-09-29T04:00:49.434-04:00">INTERIM</status_change>
            <status_change date="2008-10-20T04:00:28.436-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 201320">
          <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
          <criterion negate="true" comment="Patch 122212-22 or later installed" test_ref="oval:org.mitre.oval:tst:8701"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (x86) meets Sun Alert 201320">
          <extend_definition comment="Solaris 9 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1683"/>
          <criterion negate="true" comment="Patch 121775-01 or later installed" test_ref="oval:org.mitre.oval:tst:9219"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 201320">
          <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
          <criterion negate="true" comment="Patch 122213-22 or later installed" test_ref="oval:org.mitre.oval:tst:8353"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5949" version="1" class="vulnerability">
      <metadata>
        <title>Security Vulnerability in Solaris IP Tunnel Parameter Processing May Lead to a System Panic or Possible Execution of Arbitrary Code by Unprivileged Users</title>
        <affected family="unix">
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-5689" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-5689"/>
        <description>tun in IP Tunnel in Solaris 10 and OpenSolaris snv_01 through snv_76 allows local users to cause a denial of service (panic) and possibly execute arbitrary code via a crafted SIOCGTUNPARAM IOCTL request, which triggers a NULL pointer dereference.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-01-05T16:39:26.000-05:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2009-01-09T14:23:46.915-05:00">DRAFT</status_change>
            <status_change date="2009-01-26T04:00:18.461-05:00">INTERIM</status_change>
            <status_change date="2009-02-16T04:00:23.987-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 242266">
          <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
          <criterion negate="true" comment="Patch 138888-01 or later installed" test_ref="oval:org.mitre.oval:tst:9457"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 242266">
          <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
          <criterion negate="true" comment="Patch 138889-01 or later installed" test_ref="oval:org.mitre.oval:tst:9500"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5917" version="1" class="vulnerability">
      <metadata>
        <title>Security Vulnerability in the DNS Protocol May Lead to DNS Cache Poisoning</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <platform>Sun Solaris 9</platform>
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-1447" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1447"/>
        <description>The DNS protocol, as implemented in (1) BIND 8 and 9 before 9.5.0-P1, 9.4.2-P1, and 9.3.5-P1; (2) Microsoft DNS in Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP1 and SP2; and other implementations allow remote attackers to spoof DNS traffic via a birthday attack that uses in-bailiwick referrals to conduct cache poisoning against recursive resolvers, related to insufficient randomness of DNS transaction IDs and source ports, aka "DNS Insufficient Socket Entropy Vulnerability" or "the Kaminsky bug."</description>
        <oval_repository>
          <dates>
            <submitted date="2009-08-25T16:38:09.000-04:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2009-08-26T08:16:51.091-04:00">DRAFT</status_change>
            <status_change date="2009-09-14T04:00:06.253-04:00">INTERIM</status_change>
            <status_change date="2009-10-05T04:00:05.186-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Software Section">
          <criteria operator="AND" comment="Solaris 8 (SPARC) meets Sun Alert 239392">
            <extend_definition comment="Solaris 8 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1539"/>
            <criterion negate="true" comment="Patch 109326-23 or later installed" test_ref="oval:org.mitre.oval:tst:10663"/>
          </criteria>
          <criteria operator="AND" comment="Solaris 9 (SPARC) meets Sun Alert 239392">
            <extend_definition comment="Solaris 9 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1457"/>
            <criterion negate="true" comment="Patch 112837-15 or later installed" test_ref="oval:org.mitre.oval:tst:10777"/>
          </criteria>
          <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 239392">
            <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
            <criterion negate="true" comment="Patch 119783-06 or later installed" test_ref="oval:org.mitre.oval:tst:10241"/>
          </criteria>
          <criteria operator="AND" comment="Solaris 8 (x86) meets Sun Alert 239392">
            <extend_definition comment="Solaris 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:2059"/>
            <criterion negate="true" comment="Patch 109327-23 or later installed" test_ref="oval:org.mitre.oval:tst:10701"/>
          </criteria>
          <criteria operator="AND" comment="Solaris 9 (x86) meets Sun Alert 239392">
            <extend_definition comment="Solaris 9 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1683"/>
            <criterion negate="true" comment="Patch 114265-14 or later installed" test_ref="oval:org.mitre.oval:tst:9857"/>
          </criteria>
          <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 239392">
            <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
            <criterion negate="true" comment="Patch 119784-06 or later installed" test_ref="oval:org.mitre.oval:tst:10275"/>
          </criteria>
        </criteria>
        <criterion comment="in.named running" test_ref="oval:org.mitre.oval:tst:2624"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5914" version="1" class="vulnerability">
      <metadata>
        <title>A Security Vulnerability in the OpenSSL PKCS#11 Engine May Result in Denial of Service (DoS) Due to a Corrupted Session Cache</title>
        <affected family="unix">
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-5410" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-5410"/>
        <description>The PK11_SESSION cache in the OpenSSL PKCS#11 engine in Sun Solaris 10 does not maintain reference counts for operations with asymmetric keys, which allows context-dependent attackers to cause a denial of service (failed cryptographic operations) via unspecified vectors, related to the (1) RSA_sign and (2) RSA_verify functions.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-01-05T16:39:26.000-05:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2009-01-09T14:23:45.557-05:00">DRAFT</status_change>
            <status_change date="2009-01-26T04:00:17.033-05:00">INTERIM</status_change>
            <status_change date="2009-02-16T04:00:23.547-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 246846">
          <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
          <criterion negate="true" comment="Patch 139459-01 or later installed" test_ref="oval:org.mitre.oval:tst:9516"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 246846">
          <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
          <criterion negate="true" comment="Patch 138863-02 or later installed" test_ref="oval:org.mitre.oval:tst:9087"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5908" version="1" class="vulnerability">
      <metadata>
        <title>Security Vulnerability in GIMP(1) May Lead to Denial of Service (DoS) or Execution of Arbitrary Code</title>
        <affected family="unix">
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-3404" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-3404"/>
        <description>Buffer overflow in the xcf_load_vector function in app/xcf/xcf-load.c for gimp before 2.2.12 allows user-assisted attackers to cause a denial of service (crash) and possibly execute arbitrary code via an XCF file with a large num_axes value in the VECTORS property.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-09-09T10:55:30.000-04:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2008-09-09T11:57:57.533-04:00">DRAFT</status_change>
            <status_change date="2008-09-29T04:00:47.920-04:00">INTERIM</status_change>
            <status_change date="2008-10-20T04:00:25.426-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 200070">
          <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
          <criterion negate="true" comment="Patch 122212-18 or later installed" test_ref="oval:org.mitre.oval:tst:8318"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 200070">
          <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
          <criterion negate="true" comment="Patch 122213-18 or later installed" test_ref="oval:org.mitre.oval:tst:9239"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5906" version="1" class="vulnerability">
      <metadata>
        <title>Two Race Condition Vulnerabilities in the Solaris Event Port API May Allow Local Users to Panic the System, Causing a Denial of Service (DoS)</title>
        <affected family="unix">
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-2135" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2135"/>
        <description>Multiple race conditions in the Solaris Event Port API in Sun Solaris 10 and OpenSolaris before snv_107 allow local users to cause a denial of service (panic) via unspecified vectors related to a race between the port_dissociate and close functions.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-06-23T12:21:57.000-04:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2009-06-30T10:48:14.002-04:00">DRAFT</status_change>
            <status_change date="2009-07-20T04:00:39.553-04:00">INTERIM</status_change>
            <status_change date="2009-08-10T04:00:05.339-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 260449">
          <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
          <criterion negate="true" comment="Patch 141414-01 or later installed" test_ref="oval:org.mitre.oval:tst:9911"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 260449">
          <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
          <criterion negate="true" comment="Patch 141415-01 or later installed" test_ref="oval:org.mitre.oval:tst:9619"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5884" version="1" class="vulnerability">
      <metadata>
        <title>Manipulated Tag Files used with Solaris Text Editors May Lead to Execution of Arbitrary Code</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <platform>Sun Solaris 9</platform>
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-4131" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-4131"/>
        <description>Multiple unspecified vulnerabilities in Sun Solaris 8 through 10 allow local users to gain privileges via vectors related to handling of tags with (1) the -t option and (2) the :tag command in the (a) vi, (b) ex, (c) vedit, (d) view, and (e) edit programs.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-09-24T10:35:21.000-04:00">
              <contributor organization="Hewlett-Packard">Todd Dolinsky</contributor>
            </submitted>
            <status_change date="2008-09-29T13:59:05.488-04:00">DRAFT</status_change>
            <status_change date="2008-10-20T04:00:24.938-04:00">INTERIM</status_change>
            <status_change date="2008-11-10T04:00:06.583-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND" comment="Solaris 8 (SPARC) meets Sun Alert 237987">
          <extend_definition comment="Solaris 8 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1539"/>
          <criterion negate="true" comment="Patch 110903-08 or later installed" test_ref="oval:org.mitre.oval:tst:8986"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (SPARC) meets Sun Alert 237987">
          <extend_definition comment="Solaris 9 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1457"/>
          <criterion negate="true" comment="Patch 113031-04 or later installed" test_ref="oval:org.mitre.oval:tst:9138"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 237987">
          <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
          <criterion negate="true" comment="Patch 120830-06 or later installed" test_ref="oval:org.mitre.oval:tst:9109"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 8 (x86) meets Sun Alert 237987">
          <extend_definition comment="Solaris 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:2059"/>
          <criterion negate="true" comment="Patch 110904-08 or later installed" test_ref="oval:org.mitre.oval:tst:9009"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (x86) meets Sun Alert 237987">
          <extend_definition comment="Solaris 9 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1683"/>
          <criterion negate="true" comment="Patch 116479-02 or later installed" test_ref="oval:org.mitre.oval:tst:9291"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 237987">
          <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
          <criterion negate="true" comment="Patch 120831-06 or later installed" test_ref="oval:org.mitre.oval:tst:9137"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5876" version="1" class="vulnerability">
      <metadata>
        <title>Security vulnerability in the RequestDispatcher class in Tomcat 5.5 bundled with Solaris 9 and Solaris 10 may lead to Directory Traversal.</title>
        <affected family="unix">
          <platform>Sun Solaris 9</platform>
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-2370" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-2370"/>
        <description>Apache Tomcat 4.1.0 through 4.1.37, 5.5.0 through 5.5.26, and 6.0.0 through 6.0.16, when a RequestDispatcher is used, performs path normalization before removing the query string from the URI, which allows remote attackers to conduct directory traversal attacks and read arbitrary files via a .. (dot dot) in a request parameter.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-02-26T10:58:29.000-05:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2009-02-27T16:20:22.715-05:00">DRAFT</status_change>
            <status_change date="2009-03-16T04:00:13.906-04:00">INTERIM</status_change>
            <status_change date="2009-04-06T04:00:13.554-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND" comment="Software Section">
        <criteria operator="OR">
          <criteria operator="AND" comment="Solaris 9 (SPARC) meets Sun Alert 251986">
            <extend_definition comment="Solaris 9 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1457"/>
            <criterion negate="true" comment="Patch 114016-03 or later installed" test_ref="oval:org.mitre.oval:tst:9634"/>
          </criteria>
          <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 251986">
            <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
            <criterion negate="true" comment="Patch 122911-15 or later installed" test_ref="oval:org.mitre.oval:tst:9605"/>
          </criteria>
          <criteria operator="AND" comment="Solaris 9 (x86) meets Sun Alert 251986">
            <extend_definition comment="Solaris 9 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1683"/>
            <criterion negate="true" comment="Patch 114017-03 or later installed" test_ref="oval:org.mitre.oval:tst:9480"/>
          </criteria>
          <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 251986">
            <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
            <criterion negate="true" comment="Patch 122912-15 or later installed" test_ref="oval:org.mitre.oval:tst:9406"/>
          </criteria>
        </criteria>
        <criterion comment="SUNWtcatr is installed" test_ref="oval:org.mitre.oval:tst:9550"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5838" version="1" class="vulnerability">
      <metadata>
        <title>A Security Vulnerability May Allow Popup Windows to Appear Through the Solaris XScreenSaver Program on Xorg(1) Servers</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <platform>Sun Solaris 9</platform>
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-2711" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2711"/>
        <description>XScreenSaver in Sun Solaris 9 and 10, OpenSolaris before snv_120, and X11 6.4.1 for Solaris 8, when the Xorg or Xnewt server is used, allows physically proximate attackers to obtain sensitive information by reading popup windows, which are displayed even when the screen is locked, a different vulnerability than CVE-2009-1276.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-08-10T16:40:08.000-04:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2009-08-12T09:49:58.244-04:00">DRAFT</status_change>
            <status_change date="2009-08-31T04:00:06.335-04:00">INTERIM</status_change>
            <status_change date="2009-09-21T04:00:04.819-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="Software Section">
          <criteria operator="AND" comment="Solaris 8 (SPARC) meets Sun Alert 258928">
            <extend_definition comment="Solaris 8 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1539"/>
            <criterion negate="true" comment="Patch 115298-02 or later installed" test_ref="oval:org.mitre.oval:tst:10067"/>
          </criteria>
          <criteria operator="AND" comment="Solaris 9 (SPARC) meets Sun Alert 258928">
            <extend_definition comment="Solaris 9 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1457"/>
            <criterion negate="true" comment="Patch 115158-11 or later installed" test_ref="oval:org.mitre.oval:tst:10579"/>
          </criteria>
          <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 258928">
            <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
            <criterion negate="true" comment="Patch 120094-23 or later installed" test_ref="oval:org.mitre.oval:tst:10472"/>
          </criteria>
          <criteria operator="AND" comment="Solaris 8 (x86) meets Sun Alert 258928">
            <extend_definition comment="Solaris 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:2059"/>
            <criterion negate="true" comment="Patch 115299-02 or later installed" test_ref="oval:org.mitre.oval:tst:10441"/>
          </criteria>
          <criteria operator="AND" comment="Solaris 9 (x86) meets Sun Alert 258928">
            <extend_definition comment="Solaris 9 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1683"/>
            <criterion negate="true" comment="Patch 115159-11 or later installed" test_ref="oval:org.mitre.oval:tst:10429"/>
          </criteria>
          <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 258928">
            <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
            <criterion negate="true" comment="Patch 120095-23 or later installed" test_ref="oval:org.mitre.oval:tst:10567"/>
          </criteria>
        </criteria>
        <criterion comment="SUNWxwsvr is installed" test_ref="oval:org.mitre.oval:tst:10577"/>
        <criterion comment="The Xorg X server is running" test_ref="oval:org.mitre.oval:tst:1334"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5817" version="1" class="vulnerability">
      <metadata>
        <title>Security Vulnerabilities in DHCP Handling of DHCP Requests May Allow Remote Users to Execute Arbitrary Code or Cause a Denial of the DHCP Service</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <platform>Sun Solaris 9</platform>
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-5365" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5365"/>
        <description>Stack-based buffer overflow in the cons_options function in options.c in dhcpd in OpenBSD 4.0 through 4.2, and some other dhcpd implementations based on ISC dhcp-2, allows remote attackers to execute arbitrary code or cause a denial of service (daemon crash) via a DHCP request specifying a maximum message size smaller than the minimum IP MTU.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-01-05T16:39:26.000-05:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2009-01-09T14:23:44.885-05:00">DRAFT</status_change>
            <status_change date="2009-01-26T04:00:15.739-05:00">INTERIM</status_change>
            <status_change date="2009-02-16T04:00:22.825-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND" comment="Solaris 8 (SPARC) meets Sun Alert 243806">
          <extend_definition comment="Solaris 8 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1539"/>
          <criterion negate="true" comment="Patch 109077-21 or later installed" test_ref="oval:org.mitre.oval:tst:9562"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (SPARC) meets Sun Alert 243806">
          <extend_definition comment="Solaris 9 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1457"/>
          <criterion negate="true" comment="Patch 112837-16 or later installed" test_ref="oval:org.mitre.oval:tst:9503"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 243806">
          <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
          <criterion negate="true" comment="Patch 138876-01 or later installed" test_ref="oval:org.mitre.oval:tst:9282"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 8 (x86) meets Sun Alert 243806">
          <extend_definition comment="Solaris 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:2059"/>
          <criterion negate="true" comment="Patch 109078-21 or later installed" test_ref="oval:org.mitre.oval:tst:9497"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (x86) meets Sun Alert 243806">
          <extend_definition comment="Solaris 9 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1683"/>
          <criterion negate="true" comment="Patch 114265-15 or later installed" test_ref="oval:org.mitre.oval:tst:9355"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 243806">
          <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
          <criterion negate="true" comment="Patch 138877-01 or later installed" test_ref="oval:org.mitre.oval:tst:8742"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5802" version="1" class="vulnerability">
      <metadata>
        <title>PCX Plugin of Gimp Vulnerability</title>
        <affected family="unix">
          <platform>Sun Solaris 9</platform>
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1046" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1046"/>
        <description>Buffer overflow in the kimgio library for KDE 3.4.0 allows remote attackers to execute arbitrary code via a crafted PCX image file.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-09-11T11:37:41.000-04:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2008-09-12T12:49:06.892-04:00">DRAFT</status_change>
            <status_change date="2008-09-29T04:00:44.977-04:00">INTERIM</status_change>
            <status_change date="2008-10-20T04:00:22.743-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 201320">
          <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
          <criterion negate="true" comment="Patch 122212-22 or later installed" test_ref="oval:org.mitre.oval:tst:8701"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (x86) meets Sun Alert 201320">
          <extend_definition comment="Solaris 9 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1683"/>
          <criterion negate="true" comment="Patch 121775-01 or later installed" test_ref="oval:org.mitre.oval:tst:9219"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 201320">
          <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
          <criterion negate="true" comment="Patch 122213-22 or later installed" test_ref="oval:org.mitre.oval:tst:8353"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5792" version="1" class="vulnerability">
      <metadata>
        <title>A Security Vulnerability in the Management of Solaris Kerberos (see kerberos(5)) may Lead to a User Denial of Service (DoS) Attack</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <platform>Sun Solaris 9</platform>
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-5690" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-5690"/>
        <description>The Kerberos credential renewal feature in Sun Solaris 8, 9, and 10, and OpenSolaris build snv_01 through snv_104, allows local users to cause a denial of service (authentication failure) via unspecified vectors related to incorrect cache file permissions, and lack of credential storage by the store_cred function in pam_krb5.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-01-05T16:39:26.000-05:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2009-01-09T14:23:47.824-05:00">DRAFT</status_change>
            <status_change date="2009-01-26T04:00:13.978-05:00">INTERIM</status_change>
            <status_change date="2009-02-16T04:00:21.959-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND" comment="Solaris 8 (SPARC) meets Sun Alert 244866">
          <extend_definition comment="Solaris 8 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1539"/>
          <criterion negate="true" comment="Patch 109805-19 or later installed" test_ref="oval:org.mitre.oval:tst:9258"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (SPARC) meets Sun Alert 244866">
          <extend_definition comment="Solaris 9 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1457"/>
          <criterion negate="true" comment="Patch 112908-33 or later installed" test_ref="oval:org.mitre.oval:tst:9565"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 244866">
          <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
          <criterion negate="true" comment="Patch 139478-01 or later installed" test_ref="oval:org.mitre.oval:tst:9246"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 8 (x86) meets Sun Alert 244866">
          <extend_definition comment="Solaris 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:2059"/>
          <criterion negate="true" comment="Patch 109806-19 or later installed" test_ref="oval:org.mitre.oval:tst:9364"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (x86) meets Sun Alert 244866">
          <extend_definition comment="Solaris 9 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1683"/>
          <criterion negate="true" comment="Patch 115168-18 or later installed" test_ref="oval:org.mitre.oval:tst:9595"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 244866">
          <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
          <criterion negate="true" comment="Patch 139479-01 or later installed" test_ref="oval:org.mitre.oval:tst:9348"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5772" version="1" class="vulnerability">
      <metadata>
        <title>PSD Plugin of Gimp vulnerability</title>
        <affected family="unix">
          <platform>Sun Solaris 9</platform>
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-2949" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2949"/>
        <description>Integer overflow in the seek_to_and_unpack_pixeldata function in the psd.c plugin in Gimp 2.2.15 allows remote attackers to execute arbitrary code via a crafted PSD file that contains a large (1) width or (2) height value.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-09-11T11:37:41.000-04:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2008-09-12T12:49:07.128-04:00">DRAFT</status_change>
            <status_change date="2008-09-29T04:00:44.579-04:00">INTERIM</status_change>
            <status_change date="2008-10-20T04:00:22.365-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 201320">
          <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
          <criterion negate="true" comment="Patch 122212-22 or later installed" test_ref="oval:org.mitre.oval:tst:8701"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (x86) meets Sun Alert 201320">
          <extend_definition comment="Solaris 9 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1683"/>
          <criterion negate="true" comment="Patch 121775-01 or later installed" test_ref="oval:org.mitre.oval:tst:9219"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 201320">
          <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
          <criterion negate="true" comment="Patch 122213-22 or later installed" test_ref="oval:org.mitre.oval:tst:8353"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5762" version="1" class="vulnerability">
      <metadata>
        <title>Vulnerability in the Solaris 10 Event Port Implementation May Lead to a System Panic, Resulting in a Denial of Service (DoS)</title>
        <affected family="unix">
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-2706" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-2706"/>
        <description>Unspecified vulnerability in the event port implementation in Sun Solaris 10 allows local users to cause a denial of service (panic) by submitting and retrieving user-defined events, probably related to a NULL dereference.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-06-17T14:54:16.000-04:00">
              <contributor organization="Hewlett-Packard">Todd Dolinsky</contributor>
            </submitted>
            <status_change date="2008-06-18T17:12:08.386-04:00">DRAFT</status_change>
            <status_change date="2008-07-07T04:00:36.344-04:00">INTERIM</status_change>
            <status_change date="2008-07-28T04:00:26.268-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 235122">
          <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
          <criterion negate="true" comment="Patch 137111-01 or later installed" test_ref="oval:org.mitre.oval:tst:7853"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 235122">
          <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
          <criterion negate="true" comment="Patch 137112-01 or later installed" test_ref="oval:org.mitre.oval:tst:8065"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5742" version="1" class="vulnerability">
      <metadata>
        <title>Security Vulnerability in Solaris snoop(1M) when Displaying SMB Traffic</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <platform>Sun Solaris 9</platform>
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-0965" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-0965"/>
        <description>Multiple format string vulnerabilities in snoop on Sun Solaris 8 through 10 and OpenSolaris before snv_96, when the -o option is omitted, allow remote attackers to execute arbitrary code via format string specifiers in an SMB packet.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-08-11T12:08:06.000-04:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2008-08-14T15:03:06.340-04:00">DRAFT</status_change>
            <status_change date="2008-09-01T04:01:05.820-04:00">INTERIM</status_change>
            <status_change date="2008-09-22T04:00:30.399-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 240101">
          <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
          <criterion negate="true" comment="Patch 138083-01 or later installed" test_ref="oval:org.mitre.oval:tst:9062"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (SPARC) meets Sun Alert 240101">
          <extend_definition comment="Solaris 9 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1457"/>
          <criterion negate="true" comment="Patch 112915-05 or later installed" test_ref="oval:org.mitre.oval:tst:9103"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 8 (SPARC) meets Sun Alert 240101">
          <extend_definition comment="Solaris 8 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1539"/>
          <criterion negate="true" comment="Patch 108964-11 or later installed" test_ref="oval:org.mitre.oval:tst:8936"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 240101">
          <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
          <criterion negate="true" comment="Patch 138084-01 or later installed" test_ref="oval:org.mitre.oval:tst:8152"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (x86) meets Sun Alert 240101">
          <extend_definition comment="Solaris 9 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1683"/>
          <criterion negate="true" comment="Patch 114262-04 or later installed" test_ref="oval:org.mitre.oval:tst:8854"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 8 (x86) meets Sun Alert 240101">
          <extend_definition comment="Solaris 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:2059"/>
          <criterion negate="true" comment="Patch 108965-11 or later installed" test_ref="oval:org.mitre.oval:tst:9126"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5732" version="1" class="vulnerability">
      <metadata>
        <title>A Security Vulnerability in the Solaris Kerberos PAM Module May Allow Use of a User Specified Kerberos Configuration File, Leading to Escalation of Privileges</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <platform>Sun Solaris 9</platform>
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-0360" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0360"/>
        <description>Russ Allbery pam-krb5 before 3.13, when linked against MIT Kerberos, does not properly initialize the Kerberos libraries for setuid use, which allows local users to gain privileges by pointing an environment variable to a modified Kerberos configuration file, and then launching a PAM-based setuid application.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-03-27T14:00:00.000-04:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2009-04-01T14:58:24.663-04:00">DRAFT</status_change>
            <status_change date="2009-04-20T04:00:18.263-04:00">INTERIM</status_change>
            <status_change date="2009-05-11T04:00:21.367-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND" comment="Solaris 8 (SPARC) meets Sun Alert 252767">
          <extend_definition comment="Solaris 8 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1539"/>
          <criterion negate="true" comment="Patch 112237-16 or later installed" test_ref="oval:org.mitre.oval:tst:9624"/>
          <criterion negate="true" comment="Patch 112390-14 or later installed" test_ref="oval:org.mitre.oval:tst:8797"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (SPARC) meets Sun Alert 252767">
          <extend_definition comment="Solaris 9 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1457"/>
          <criterion negate="true" comment="Patch 112908-34 or later installed" test_ref="oval:org.mitre.oval:tst:9570"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 252767">
          <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
          <criterion negate="true" comment="Patch 138371-06 or later installed" test_ref="oval:org.mitre.oval:tst:9655"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 8 (x86) meets Sun Alert 252767">
          <extend_definition comment="Solaris 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:2059"/>
          <criterion negate="true" comment="Patch 112238-15 or later installed" test_ref="oval:org.mitre.oval:tst:9370"/>
          <criterion negate="true" comment="Patch 112240-13 or later installed" test_ref="oval:org.mitre.oval:tst:9206"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (x86) meets Sun Alert 252767">
          <extend_definition comment="Solaris 9 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1683"/>
          <criterion negate="true" comment="Patch 115168-19 or later installed" test_ref="oval:org.mitre.oval:tst:9606"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 252767">
          <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
          <criterion negate="true" comment="Patch 138372-06 or later installed" test_ref="oval:org.mitre.oval:tst:9713"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5731" version="1" class="vulnerability">
      <metadata>
        <title>A Security Vulnerability in IP Multicast Filter processing of Sockets may lead to a system panic or possible execution of Arbitrary Code</title>
        <affected family="unix">
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-2710" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-2710"/>
        <description>Integer signedness error in the ip_set_srcfilter function in the IP Multicast Filter in uts/common/inet/ip/ip_multi.c in the kernel in Sun Solaris 10 and OpenSolaris before snv_92 allows local users to execute arbitrary code in other Solaris Zones via an SIOCSIPMSFILTER IOCTL request with a large value of the imsf->imsf_numsrc field, which triggers an out-of-bounds write of kernel memory.  NOTE: this was reported as an integer overflow, but the root cause involves the bypass of a signed comparison.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-06-17T14:54:16.000-04:00">
              <contributor organization="Hewlett-Packard">Todd Dolinsky</contributor>
            </submitted>
            <status_change date="2008-06-18T17:12:08.608-04:00">DRAFT</status_change>
            <status_change date="2008-07-07T04:00:34.971-04:00">INTERIM</status_change>
            <status_change date="2008-07-28T04:00:24.214-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 237965">
          <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
          <criterion negate="true" comment="Patch 137111-01 or later installed" test_ref="oval:org.mitre.oval:tst:7853"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 237965">
          <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
          <criterion negate="true" comment="Patch 137112-01 or later installed" test_ref="oval:org.mitre.oval:tst:8065"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5698" version="1" class="vulnerability">
      <metadata>
        <title>The Solaris rpc.metad(1M) Daemon is Vulnerable to a Denial of Service (DoS) Attack</title>
        <affected family="unix">
          <platform>Sun Solaris 9</platform>
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-1480" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1480"/>
        <description>rpc.metad in Sun Solaris 10 allows remote attackers to cause a denial of service (daemon crash) via a malformed RPC request.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-05-06T17:15:10.000-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2009-05-07T11:17:43.220-04:00">DRAFT</status_change>
            <status_change date="2009-05-25T04:01:43.025-04:00">INTERIM</status_change>
            <status_change date="2009-06-15T04:00:46.835-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND" comment="Solaris 9 (SPARC) meets Sun Alert 249146">
          <extend_definition comment="Solaris 9 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1457"/>
          <criterion negate="true" comment="Patch 116669-34 or later installed" test_ref="oval:org.mitre.oval:tst:9832"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 249146">
          <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
          <criterion negate="true" comment="Patch 138632-03 or later installed" test_ref="oval:org.mitre.oval:tst:9259"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (x86) meets Sun Alert 249146">
          <extend_definition comment="Solaris 9 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1683"/>
          <criterion negate="true" comment="Patch 138574-01 or later installed" test_ref="oval:org.mitre.oval:tst:9628"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 249146">
          <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
          <criterion negate="true" comment="Patch 138882-02 or later installed" test_ref="oval:org.mitre.oval:tst:9974"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5692" version="1" class="vulnerability">
      <metadata>
        <title>Security Vulnerability in the Solaris sendfile(3EXT) and sendfilev(3EXT) Extended Library Functions may Result in a Denial of Service (DoS) Condition due to a System Panic</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <platform>Sun Solaris 9</platform>
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-2912" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2912"/>
        <description>The (1) sendfile and (2) sendfilev functions in Sun Solaris 8 through 10, and OpenSolaris before snv_110, allow local users to cause a denial of service (panic) via vectors related to vnode function calls.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-08-21T11:07:35.000-04:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2009-08-21T20:56:32.365-04:00">DRAFT</status_change>
            <status_change date="2009-09-07T04:00:05.294-04:00">INTERIM</status_change>
            <status_change date="2009-09-28T04:00:07.402-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND" comment="Solaris 8 (SPARC) meets Sun Alert 258588">
          <extend_definition comment="Solaris 8 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1539"/>
          <criterion negate="true" comment="Patch 127721-02 or later installed" test_ref="oval:org.mitre.oval:tst:10485"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (SPARC) meets Sun Alert 258588">
          <extend_definition comment="Solaris 9 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1457"/>
          <criterion negate="true" comment="Patch 122300-42 or later installed" test_ref="oval:org.mitre.oval:tst:10637"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 258588">
          <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
          <criterion negate="true" comment="Patch 141414-05 or later installed" test_ref="oval:org.mitre.oval:tst:10676"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 8 (x86) meets Sun Alert 258588">
          <extend_definition comment="Solaris 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:2059"/>
          <criterion negate="true" comment="Patch 127722-02 or later installed" test_ref="oval:org.mitre.oval:tst:10535"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (x86) meets Sun Alert 258588">
          <extend_definition comment="Solaris 9 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1683"/>
          <criterion negate="true" comment="Patch 122301-42 or later installed" test_ref="oval:org.mitre.oval:tst:10364"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 258588">
          <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
          <criterion negate="true" comment="Patch 141415-05 or later installed" test_ref="oval:org.mitre.oval:tst:10432"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5668" version="1" class="vulnerability">
      <metadata>
        <title>Security Vulnerabilities in DHCP Handling of DHCP Requests May Allow Remote Users to Execute Arbitrary Code or Cause a Denial of the DHCP Service</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <platform>Sun Solaris 9</platform>
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-5010" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-5010"/>
        <description>in.dhcpd in the DHCP implementation in Sun Solaris 8 through 10, and OpenSolaris before snv_103, allows remote attackers to cause a denial of service (assertion failure and daemon exit) via unknown DHCP requests related to the "number of offers," aka Bug ID 6713805.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-11-12T10:55:27.000-05:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2008-11-17T16:33:20.811-05:00">DRAFT</status_change>
            <status_change date="2008-12-08T04:00:55.761-05:00">INTERIM</status_change>
            <status_change date="2008-12-29T04:00:19.867-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="Software Section">
          <criteria operator="AND" comment="Solaris 8 (SPARC) meets Sun Alert 243806">
            <extend_definition comment="Solaris 8 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1539"/>
            <criterion negate="true" comment="Patch 109077-21 or later installed" test_ref="oval:org.mitre.oval:tst:9421"/>
          </criteria>
          <criteria operator="AND" comment="Solaris 9 (SPARC) meets Sun Alert 243806">
            <extend_definition comment="Solaris 9 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1457"/>
            <criterion negate="true" comment="Patch 112837-16 or later installed" test_ref="oval:org.mitre.oval:tst:8553"/>
          </criteria>
          <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 243806">
            <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
            <criterion negate="true" comment="Patch 138876-01 or later installed" test_ref="oval:org.mitre.oval:tst:9473"/>
          </criteria>
          <criteria operator="AND" comment="Solaris 8 (x86) meets Sun Alert 243806">
            <extend_definition comment="Solaris 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:2059"/>
            <criterion negate="true" comment="Patch 109078-21 or later installed" test_ref="oval:org.mitre.oval:tst:9315"/>
          </criteria>
          <criteria operator="AND" comment="Solaris 9 (x86) meets Sun Alert 243806">
            <extend_definition comment="Solaris 9 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1683"/>
            <criterion negate="true" comment="Patch 114265-15 or later installed" test_ref="oval:org.mitre.oval:tst:9359"/>
          </criteria>
          <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 243806">
            <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
            <criterion negate="true" comment="Patch 138877-01 or later installed" test_ref="oval:org.mitre.oval:tst:9008"/>
          </criteria>
        </criteria>
        <criterion comment="System is configured as a DHCP server" test_ref="oval:org.mitre.oval:tst:8812"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5641" version="1" class="vulnerability">
      <metadata>
        <title>A Security Vulnerability With the Solaris Crypto Driver May Cause a System Panic</title>
        <affected family="unix">
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-0838" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0838"/>
        <description>The crypto pseudo device driver in Sun Solaris 10, and OpenSolaris snv_88 through snv_102, does not properly free memory, which allows local users to cause a denial of service (panic) via unspecified vectors, related to the vmem_hash_delete function.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-03-10T13:09:16.000-04:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2009-03-13T20:24:03.298-04:00">DRAFT</status_change>
            <status_change date="2009-03-30T04:00:18.937-04:00">INTERIM</status_change>
            <status_change date="2009-04-20T04:00:16.154-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 254088">
          <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
          <criterion negate="true" comment="Patch 139498-04 or later installed" test_ref="oval:org.mitre.oval:tst:9626"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 254088">
          <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
          <criterion negate="true" comment="Patch 139499-04 or later installed" test_ref="oval:org.mitre.oval:tst:9460"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5639" version="1" class="vulnerability">
      <metadata>
        <title>Security Vulnerability in the ACL (acl(2)) Implementation for UFS File Systems May Allow a Local User to Panic the System</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <platform>Sun Solaris 9</platform>
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-4160" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-4160"/>
        <description>Unspecified vulnerability in the UFS module in Sun Solaris 8 through 10 and OpenSolaris allows local users to cause a denial of service (NULL pointer dereference and kernel panic) via unknown vectors related to the Solaris Access Control List (ACL) implementation.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-08-19T11:48:53.000-04:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2009-08-19T14:58:28.865-04:00">DRAFT</status_change>
            <status_change date="2009-09-07T04:00:04.209-04:00">INTERIM</status_change>
            <status_change date="2009-09-28T04:00:06.168-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criteria operator="OR" comment="Software Section">
          <criteria operator="AND" comment="Solaris 8 (SPARC) meets Sun Alert 242267">
            <extend_definition comment="Solaris 8 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1539"/>
            <criterion negate="true" comment="Patch 117350-60 or later installed" test_ref="oval:org.mitre.oval:tst:10320"/>
          </criteria>
          <criteria operator="AND" comment="Solaris 9 (SPARC) meets Sun Alert 242267">
            <extend_definition comment="Solaris 9 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1457"/>
            <criterion negate="true" comment="Patch 122300-34 or later installed" test_ref="oval:org.mitre.oval:tst:10524"/>
          </criteria>
          <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 242267">
            <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
            <criterion negate="true" comment="Patch 139483-01 or later installed" test_ref="oval:org.mitre.oval:tst:10531"/>
          </criteria>
          <criteria operator="AND" comment="Solaris 8 (x86) meets Sun Alert 242267">
            <extend_definition comment="Solaris 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:2059"/>
            <criterion negate="true" comment="Patch 117351-60 or later installed" test_ref="oval:org.mitre.oval:tst:9984"/>
          </criteria>
          <criteria operator="AND" comment="Solaris 9 (x86) meets Sun Alert 242267">
            <extend_definition comment="Solaris 9 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1683"/>
            <criterion negate="true" comment="Patch 122301-34 or later installed" test_ref="oval:org.mitre.oval:tst:10020"/>
          </criteria>
          <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 242267">
            <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
            <criterion negate="true" comment="Patch 139484-01 or later installed" test_ref="oval:org.mitre.oval:tst:9621"/>
          </criteria>
        </criteria>
        <criterion comment="The system has UFS file systems mounted which are writable (read-write)" test_ref="oval:org.mitre.oval:tst:10049"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5609" version="1" class="vulnerability">
      <metadata>
        <title>A Security Vulnerability in the namefs Kernel module may result in Arbitrary Code Execution or a Denial of Service (DoS)</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <platform>Sun Solaris 9</platform>
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-3450" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-3450"/>
        <description>Unspecified vulnerability in the namefs kernel module in Sun Solaris 8 through 10 allows local users to gain privileges or cause a denial of service (panic) via unspecified vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-08-05T10:37:22.000-04:00">
              <contributor organization="Hewlett-Packard">Nicholas Hansen</contributor>
            </submitted>
            <status_change date="2008-08-11T11:11:36.400-04:00">DRAFT</status_change>
            <status_change date="2008-09-01T04:01:01.503-04:00">INTERIM</status_change>
            <status_change date="2008-09-22T04:00:26.767-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND" comment="Solaris 8 (SPARC) meets Sun Alert 237986">
          <extend_definition comment="Solaris 8 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1539"/>
          <criterion negate="true" comment="Patch 114984-02 or later installed" test_ref="oval:org.mitre.oval:tst:9052"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 8 (x86) meets Sun Alert 237986">
          <extend_definition comment="Solaris 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:2059"/>
          <criterion negate="true" comment="Patch 114985-02 or later installed" test_ref="oval:org.mitre.oval:tst:9021"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (SPARC) meets Sun Alert 237986">
          <extend_definition comment="Solaris 9 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1457"/>
          <criterion negate="true" comment="Patch 114971-03 or later installed" test_ref="oval:org.mitre.oval:tst:9022"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (x86) meets Sun Alert 237986">
          <extend_definition comment="Solaris 9 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1683"/>
          <criterion negate="true" comment="Patch 138570-01 or later installed" test_ref="oval:org.mitre.oval:tst:8942"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 237986">
          <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
          <criterion negate="true" comment="Patch 136716-01 or later installed" test_ref="oval:org.mitre.oval:tst:8779"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 237986">
          <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
          <criterion negate="true" comment="Patch 136717-01 or later installed" test_ref="oval:org.mitre.oval:tst:9079"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5586" version="1" class="vulnerability">
      <metadata>
        <title>Unspecified vulnerability in the NFSv4 module in the kernel in Sun Solaris 10."</title>
        <affected family="unix">
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-2488" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2488"/>
        <description>Unspecified vulnerability in the NFSv4 module in the kernel in Sun Solaris 10, and OpenSolaris snv_102 through snv_119, allows local users to cause a denial of service (client panic) via vectors involving "file operations."</description>
        <oval_repository>
          <dates>
            <submitted date="2009-08-09T17:59:08-04:00">
              <contributor organization="DTCC">Aharon Chernin</contributor>
            </submitted>
            <status_change date="2009-08-12T09:49:45.817-04:00">DRAFT</status_change>
            <status_change date="2009-08-31T04:00:04.652-04:00">INTERIM</status_change>
            <status_change date="2009-09-21T04:00:04.218-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND" comment="Solaris 10 (X86) meets Sun Alert ID 262788 criteria.">
          <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
          <criterion negate="true" comment="Patch 141734-03 or later installed" test_ref="oval:org.mitre.oval:tst:10132"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert ID 262788 criteria.">
          <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
          <criterion negate="true" comment="Patch 141733-03 or later installed" test_ref="oval:org.mitre.oval:tst:10550"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5545" version="1" class="vulnerability">
      <metadata>
        <title>Security Vulnerability in Simplified Chinese, Traditional Chinese, Korean, and Thai Language Input Methods</title>
        <affected family="unix">
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-0730" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-0730"/>
        <description>The (1) Simplified Chinese, (2) Traditional Chinese, (3) Korean, and (4) Thai language input methods in Sun Solaris 10 create files and directories with weak permissions under (a) .iiim/le and (b) .Xlocale in home directories, which might allow local users to write to, or read from, the home directories of other users.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-02-13T12:26:00.000-05:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2008-02-13T16:34:40.858-05:00">DRAFT</status_change>
            <status_change date="2008-03-03T04:00:18.561-05:00">INTERIM</status_change>
            <status_change date="2008-03-24T04:00:48.962-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="Software Section">
          <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 201315">
            <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
            <criteria operator="OR">
              <criterion negate="true" comment="Patch 120412-08 or later installed" test_ref="oval:org.mitre.oval:tst:7399"/>
              <criterion negate="true" comment="Patch 120414-20 or later installed" test_ref="oval:org.mitre.oval:tst:7700"/>
            </criteria>
          </criteria>
          <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 201315">
            <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
            <criteria operator="OR">
              <criterion negate="true" comment="Patch 120413-08 or later installed" test_ref="oval:org.mitre.oval:tst:7743"/>
              <criterion negate="true" comment="Patch 120415-20 or later installed" test_ref="oval:org.mitre.oval:tst:7675"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="OR" comment="Configuration Section">
          <criterion comment="Package SUNWcleu2 (Simplified Chinese) is installed" test_ref="oval:org.mitre.oval:tst:6860"/>
          <criterion comment="Package SUNWhleu2 (Traditional Chinese) is installed" test_ref="oval:org.mitre.oval:tst:7614"/>
          <criterion comment="PPackage SUNWhkleu (Traditional Chinese (Hong Kong)) is installed" test_ref="oval:org.mitre.oval:tst:7115"/>
          <criterion comment="Package SUNWkleu (Korean) is installed" test_ref="oval:org.mitre.oval:tst:7155"/>
          <criterion comment="Package SUNWtleu (Thai) is installed" test_ref="oval:org.mitre.oval:tst:7742"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5532" version="1" class="vulnerability">
      <metadata>
        <title>Security Vulnerability in FreeType 2 Font Engine May Allow Privilege Escalation Due to Heap Overflow</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <platform>Sun Solaris 9</platform>
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-2754" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2754"/>
        <description>Integer signedness error in truetype/ttgload.c in Freetype 2.3.4 and earlier might allow remote attackers to execute arbitrary code via a crafted TTF image with a negative n_points value, which leads to an integer overflow and heap-based buffer overflow.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-01-09T07:41:41.000-05:00">
              <contributor organization="Hewlett-Packard">Nicholas Hansen</contributor>
            </submitted>
            <status_change date="2008-01-09T14:14:49.552-05:00">DRAFT</status_change>
            <status_change date="2008-02-04T10:19:29.641-05:00">INTERIM</status_change>
            <status_change date="2008-02-25T04:00:11.261-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND" comment="Solaris 8 (SPARC) meets Sun Alert 103171">
          <extend_definition comment="Solaris 8 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1539"/>
          <criterion negate="true" comment="Patch 124420-03 or later installed" test_ref="oval:org.mitre.oval:tst:7777"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (SPARC) meets Sun Alert 103171">
          <extend_definition comment="Solaris 9 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1457"/>
          <criterion negate="true" comment="Patch 116105-08 or later installed" test_ref="oval:org.mitre.oval:tst:7445"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 103171">
          <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
          <criterion negate="true" comment="Patch 119812-05 or later installed" test_ref="oval:org.mitre.oval:tst:7736"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 8 (x86) meets Sun Alert 103171">
          <extend_definition comment="Solaris 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:2059"/>
          <criterion negate="true" comment="Patch 124421-03 or later installed" test_ref="oval:org.mitre.oval:tst:7493"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (x86) meets Sun Alert 103171">
          <extend_definition comment="Solaris 9 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1683"/>
          <criterion negate="true" comment="Patch 116106-07 or later installed" test_ref="oval:org.mitre.oval:tst:7547"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 103171">
          <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
          <criterion negate="true" comment="Patch 119813-07 or later installed" test_ref="oval:org.mitre.oval:tst:6931"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5511" version="1" class="vulnerability">
      <metadata>
        <title>Security Vulnerability May Allow Firewall Compromise or Creation of Denial of Service (DoS) Condition</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <platform>Sun Solaris 9</platform>
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-1095" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1095"/>
        <description>Unspecified vulnerability in the Internet Protocol (IP) implementation in Sun Solaris 8, 9, and 10 allows remote attackers to bypass intended firewall policies or cause a denial of service (panic) via unknown vectors, possibly related to ICMP packets and IP fragment reassembly.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-03-04T08:44:56.000-05:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2008-03-06T08:35:11.775-05:00">DRAFT</status_change>
            <status_change date="2008-03-24T04:00:48.629-04:00">INTERIM</status_change>
            <status_change date="2008-04-14T04:00:10.100-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND" comment="Solaris 8 (SPARC) meets Sun Alert 200183">
          <extend_definition comment="Solaris 8 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1539"/>
          <criterion negate="true" comment="Patch 116965-30 or later installed" test_ref="oval:org.mitre.oval:tst:7533"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (SPARC) meets Sun Alert 200183">
          <extend_definition comment="Solaris 9 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1457"/>
          <criterion negate="true" comment="Patch 114344-32 or later installed" test_ref="oval:org.mitre.oval:tst:7854"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 200183">
          <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
          <criterion negate="true" comment="Patch 118822-27 or later installed" test_ref="oval:org.mitre.oval:tst:7608"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 8 (x86) meets Sun Alert 200183">
          <extend_definition comment="Solaris 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:2059"/>
          <criterion negate="true" comment="Patch 116966-29 or later installed" test_ref="oval:org.mitre.oval:tst:7656"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (x86) meets Sun Alert 200183">
          <extend_definition comment="Solaris 9 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1683"/>
          <criterion negate="true" comment="Patch 119435-20 or later installed" test_ref="oval:org.mitre.oval:tst:6892"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 200183">
          <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
          <criterion negate="true" comment="Patch 118844-28 or later installed" test_ref="oval:org.mitre.oval:tst:7175"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5507" version="1" class="vulnerability">
      <metadata>
        <title>Multiple Security Vulnerabilities in ICU 3.2 Library Regular Expression Processing May Cause a Denial of Service (DoS)</title>
        <affected family="unix">
          <platform>Sun Solaris 9</platform>
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-4770" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4770"/>
        <description>libicu in International Components for Unicode (ICU) 3.8.1 and earlier attempts to process backreferences to the nonexistent capture group zero (aka \0), which might allow context-dependent attackers to read from, or write to, out-of-bounds memory locations, related to corruption of REStackFrames.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-03-11T10:54:47.000-04:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2008-03-12T09:38:11.814-04:00">DRAFT</status_change>
            <status_change date="2008-03-31T04:00:11.544-04:00">INTERIM</status_change>
            <status_change date="2008-04-21T04:00:22.668-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND" comment="Solaris 9 (SPARC) meets Sun Alert 233922">
          <extend_definition comment="Solaris 9 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1457"/>
          <criterion negate="true" comment="Patch 114677-15 or later installed" test_ref="oval:org.mitre.oval:tst:7086"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 233922">
          <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
          <criterion negate="true" comment="Patch 119810-05 or later installed" test_ref="oval:org.mitre.oval:tst:7683"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (x86) meets Sun Alert 233922">
          <extend_definition comment="Solaris 9 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1683"/>
          <criterion negate="true" comment="Patch 114678-15 or later installed" test_ref="oval:org.mitre.oval:tst:7869"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 233922">
          <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
          <criterion negate="true" comment="Patch 119811-05 or later installed" test_ref="oval:org.mitre.oval:tst:6971"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5503" version="1" class="vulnerability">
      <metadata>
        <title>Security Vulnerabilities in the Solaris lpadmin(1M) and ppdmgr(1M) Utilities May Lead to a Denial of Service (DoS) Condition</title>
        <affected family="unix">
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-0168" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0168"/>
        <description>Unspecified vulnerability in ppdmgr in Sun Solaris 10 and OpenSolaris snv_61 through snv_106 allows local users to cause a denial of service via unspecified vectors, related to a failure to "include all cache files," and improper handling of temporary files.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-02-05T13:18:38.000-05:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2009-02-06T15:58:58.298-05:00">DRAFT</status_change>
            <status_change date="2009-02-23T04:00:14.196-05:00">INTERIM</status_change>
            <status_change date="2009-03-16T04:00:10.751-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 249306">
          <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
          <criterion comment="Patch 127127-11 installed" test_ref="oval:org.mitre.oval:tst:9551"/>
          <criterion negate="true" comment="Patch 139390-01 or later installed" test_ref="oval:org.mitre.oval:tst:9591"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 249306">
          <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
          <criterion comment="Patch 127128-11 installed" test_ref="oval:org.mitre.oval:tst:9422"/>
          <criterion negate="true" comment="Patch 139391-01 or later installed" test_ref="oval:org.mitre.oval:tst:8934"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5476" version="1" class="vulnerability">
      <metadata>
        <title>Two Security Vulnerabilities Exist Within the cpc(3CPC) Sub-System of the Solaris Kernel</title>
        <affected family="unix">
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-0933" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-0933"/>
        <description>Multiple race conditions in the CPU Performance Counters (cpc) subsystem in the kernel in Sun Solaris 10 allow local users to cause a denial of service (panic) via unspecified vectors related to kcpc_unbind and kcpc_restore.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-02-27T15:10:44.000-05:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2008-02-28T09:30:27.469-05:00">DRAFT</status_change>
            <status_change date="2008-03-17T04:00:23.723-04:00">INTERIM</status_change>
            <status_change date="2008-04-07T04:00:10.576-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 231466">
          <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
          <criterion negate="true" comment="Patch 127111-08 or later installed" test_ref="oval:org.mitre.oval:tst:7708"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 231466">
          <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
          <criterion negate="true" comment="Patch 127112-08 or later installed" test_ref="oval:org.mitre.oval:tst:7275"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5474" version="3" class="vulnerability">
      <metadata>
        <title>A Security Vulnerability in the USB Mouse STREAMS Module May Lead to a System Panic</title>
        <affected family="unix">
          <platform>Sun Solaris 9</platform>
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-0718" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-0718"/>
        <description>Unspecified vulnerability in the USB Mouse STREAMS module (usbms) in Sun Solaris 9 and 10, when 64-bit mode is enabled, allows local users to cause a denial of service (panic) via unspecified vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-02-13T12:25:59.000-05:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2008-02-13T16:34:39.778-05:00">DRAFT</status_change>
            <status_change date="2008-03-03T04:00:18.196-05:00">INTERIM</status_change>
            <status_change date="2008-03-24T04:00:47.661-04:00">ACCEPTED</status_change>
            <modified comment="Added datatype to bits entity on an isainfo_state.  Datatype set to int." date="2010-09-02T21:09:00.853-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2010-09-02T21:11:44.185-04:00">INTERIM</status_change>
            <status_change date="2010-09-20T04:00:28.762-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="Software Section">
          <criteria operator="AND" comment="Solaris 9 (SPARC) meets Sun Alert 201316">
            <extend_definition comment="Solaris 9 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1457"/>
            <criterion negate="true" comment="Patch 115553-29 or later installed" test_ref="oval:org.mitre.oval:tst:7796"/>
          </criteria>
          <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 201316">
            <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
            <criterion negate="true" comment="Patch 123402-01 or later installed" test_ref="oval:org.mitre.oval:tst:7809"/>
          </criteria>
          <criteria operator="AND" comment="Solaris 9 (x86) meets Sun Alert 201316">
            <extend_definition comment="Solaris 9 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1683"/>
            <criterion negate="true" comment="Patch 115554-25 or later installed" test_ref="oval:org.mitre.oval:tst:6972"/>
          </criteria>
          <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 201316">
            <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
            <criterion negate="true" comment="Patch 123403-01 or later installed" test_ref="oval:org.mitre.oval:tst:7804"/>
          </criteria>
        </criteria>
        <criterion comment="system is running in 64-bit mode" test_ref="oval:org.mitre.oval:tst:3884"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5453" version="1" class="vulnerability">
      <metadata>
        <title>Covert Channel Security Vulnerability in the Solaris Kernel</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <platform>Sun Solaris 9</platform>
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-3875" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-3875"/>
        <description>The kernel in Sun Solaris 8 through 10 and OpenSolaris before snv_90 allows local users to bypass chroot, zones, and the Solaris Trusted Extensions multi-level security policy, and establish a covert communication channel, via unspecified vectors involving system calls.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-09-03T10:23:55.000-04:00">
              <contributor organization="Hewlett-Packard">Nicholas Hansen</contributor>
            </submitted>
            <status_change date="2008-09-09T10:51:57.209-04:00">DRAFT</status_change>
            <status_change date="2008-09-29T04:00:42.720-04:00">INTERIM</status_change>
            <status_change date="2008-10-20T04:00:19.491-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND" comment="Solaris 8 (SPARC) meets Sun Alert 240706">
          <extend_definition comment="Solaris 8 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1539"/>
          <criterion negate="true" comment="Patch 117350-56 or later installed" test_ref="oval:org.mitre.oval:tst:9150"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 8 (x86) meets Sun Alert 240706">
          <extend_definition comment="Solaris 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:2059"/>
          <criterion negate="true" comment="Patch 117351-56 or later installed" test_ref="oval:org.mitre.oval:tst:8843"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (SPARC) meets Sun Alert 240706">
          <extend_definition comment="Solaris 9 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1457"/>
          <criterion negate="true" comment="Patch 122300-30 or later installed" test_ref="oval:org.mitre.oval:tst:9046"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (x86) meets Sun Alert 240706">
          <extend_definition comment="Solaris 9 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1683"/>
          <criterion negate="true" comment="Patch 122301-30 or later installed" test_ref="oval:org.mitre.oval:tst:9227"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 240706">
          <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
          <criterion negate="true" comment="Patch 137111-05 or later installed" test_ref="oval:org.mitre.oval:tst:9075"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 240706">
          <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
          <criterion negate="true" comment="Patch 137112-05 or later installed" test_ref="oval:org.mitre.oval:tst:8905"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5451" version="1" class="vulnerability">
      <metadata>
        <title>Security Vulnerability in the Solaris 10 DTrace Dynamic Tracing Framework May Allow Unauthorized Kernel Level Tracing</title>
        <affected family="unix">
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-0938" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-0938"/>
        <description>Unspecified vulnerability in the dynamic tracing framework (DTrace) in Sun Solaris 10 allows local users with PRIV_DTRACE_USER or PRIV_DTRACE_PROC privileges to obtain sensitive kernel information via unspecified vectors, a different vulnerability than CVE-2007-4126.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-02-27T15:10:45.000-05:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2008-02-28T09:30:27.910-05:00">DRAFT</status_change>
            <status_change date="2008-03-17T04:00:23.061-04:00">INTERIM</status_change>
            <status_change date="2008-04-07T04:00:09.767-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 231803">
          <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
          <criterion negate="true" comment="Patch 120011-04 or later installed" test_ref="oval:org.mitre.oval:tst:7688"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 231803">
          <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
          <criterion negate="true" comment="Patch 120012-04 or later installed" test_ref="oval:org.mitre.oval:tst:7520"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5446" version="1" class="vulnerability">
      <metadata>
        <title>Security Vulnerabilities in the Solaris Priority Inherited pthread mutex API May Result in a Denial of Service (DoS) Condition</title>
        <affected family="unix">
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-3549" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-3549"/>
        <description>Unspecified vulnerability in the pthread_mutex_reltimedlock_np API in Sun Solaris 10 and OpenSolaris before snv_90 allows local users to cause a denial of service (system hang or panic) via unknown vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-08-11T17:42:55.000-04:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2008-08-14T15:03:12.846-04:00">DRAFT</status_change>
            <status_change date="2008-09-01T04:00:56.846-04:00">INTERIM</status_change>
            <status_change date="2008-09-22T04:00:23.912-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 239387">
          <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
          <criterion negate="true" comment="Patch 137111-04 or later installed" test_ref="oval:org.mitre.oval:tst:9095"/>
          <criterion comment="deadman feature is enabled (kernel variable 'snooping' has a value of one)" test_ref="oval:org.mitre.oval:tst:8414"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 239387">
          <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
          <criterion negate="true" comment="Patch 137112-04 or later installed" test_ref="oval:org.mitre.oval:tst:9125"/>
          <criterion comment="deadman feature is enabled (kernel variable 'snooping' has a value of one)" test_ref="oval:org.mitre.oval:tst:8414"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5431" version="1" class="vulnerability">
      <metadata>
        <title>Multiple Security Vulnerabilities in ICU 3.2 Library Regular Expression Processing May Cause a Denial of Service (DoS)</title>
        <affected family="unix">
          <platform>Sun Solaris 9</platform>
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-4771" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4771"/>
        <description>Heap-based buffer overflow in the doInterval function in regexcmp.cpp in libicu in International Components for Unicode (ICU) 3.8.1 and earlier allows context-dependent attackers to cause a denial of service (memory consumption) and possibly have unspecified other impact via a regular expression that writes a large amount of data to the backtracking stack.  NOTE: some of these details are obtained from third party information.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-03-11T10:54:48.000-04:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2008-03-12T09:38:12.118-04:00">DRAFT</status_change>
            <status_change date="2008-03-31T04:00:09.181-04:00">INTERIM</status_change>
            <status_change date="2008-04-21T04:00:22.018-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND" comment="Solaris 9 (SPARC) meets Sun Alert 233922">
          <extend_definition comment="Solaris 9 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1457"/>
          <criterion negate="true" comment="Patch 114677-15 or later installed" test_ref="oval:org.mitre.oval:tst:7086"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 233922">
          <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
          <criterion negate="true" comment="Patch 119810-05 or later installed" test_ref="oval:org.mitre.oval:tst:7683"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (x86) meets Sun Alert 233922">
          <extend_definition comment="Solaris 9 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1683"/>
          <criterion negate="true" comment="Patch 114678-15 or later installed" test_ref="oval:org.mitre.oval:tst:7869"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 233922">
          <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
          <criterion negate="true" comment="Patch 119811-05 or later installed" test_ref="oval:org.mitre.oval:tst:6971"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5403" version="1" class="vulnerability">
      <metadata>
        <title>A Security Vulnerability in the Solaris Kerberos PAM Module May Allow Use of a User Specified Kerberos Configuration File, Leading to Escalation of Privileges</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <platform>Sun Solaris 9</platform>
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-0361" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0361"/>
        <description>Russ Allbery pam-krb5 before 3.13, as used by libpam-heimdal, su in Solaris 10, and other software, does not properly handle calls to pam_setcred when running setuid, which allows local users to overwrite and change the ownership of arbitrary files by setting the KRB5CCNAME environment variable, and then launching a setuid application that performs certain pam_setcred operations.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-03-27T14:00:00.000-04:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2009-04-01T14:58:25.195-04:00">DRAFT</status_change>
            <status_change date="2009-04-20T04:00:10.359-04:00">INTERIM</status_change>
            <status_change date="2009-05-11T04:00:19.532-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND" comment="Solaris 8 (SPARC) meets Sun Alert 252767">
          <extend_definition comment="Solaris 8 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1539"/>
          <criterion negate="true" comment="Patch 112237-16 or later installed" test_ref="oval:org.mitre.oval:tst:9624"/>
          <criterion negate="true" comment="Patch 112390-14 or later installed" test_ref="oval:org.mitre.oval:tst:8797"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (SPARC) meets Sun Alert 252767">
          <extend_definition comment="Solaris 9 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1457"/>
          <criterion negate="true" comment="Patch 112908-34 or later installed" test_ref="oval:org.mitre.oval:tst:9570"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 252767">
          <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
          <criterion negate="true" comment="Patch 138371-06 or later installed" test_ref="oval:org.mitre.oval:tst:9655"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 8 (x86) meets Sun Alert 252767">
          <extend_definition comment="Solaris 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:2059"/>
          <criterion negate="true" comment="Patch 112238-15 or later installed" test_ref="oval:org.mitre.oval:tst:9370"/>
          <criterion negate="true" comment="Patch 112240-13 or later installed" test_ref="oval:org.mitre.oval:tst:9206"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (x86) meets Sun Alert 252767">
          <extend_definition comment="Solaris 9 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1683"/>
          <criterion negate="true" comment="Patch 115168-19 or later installed" test_ref="oval:org.mitre.oval:tst:9606"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 252767">
          <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
          <criterion negate="true" comment="Patch 138372-06 or later installed" test_ref="oval:org.mitre.oval:tst:9713"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5400" version="1" class="vulnerability">
      <metadata>
        <title>Security Vulnerability in Solaris 10 Related to the dotoprocs() Routine</title>
        <affected family="unix">
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-0269" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-0269"/>
        <description>Unspecified vulnerability in the dotoprocs function in Sun Solaris 10 allows local users to cause a denial of service (panic) via unspecified vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-01-16T09:18:15.000-05:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2008-01-17T09:53:53.580-05:00">DRAFT</status_change>
            <status_change date="2008-02-04T10:19:21.179-05:00">INTERIM</status_change>
            <status_change date="2008-02-25T04:00:10.927-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 103188">
          <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
          <criterion negate="true" comment="Patch 127111-06 or later installed" test_ref="oval:org.mitre.oval:tst:7472"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 103188">
          <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
          <criterion negate="true" comment="Patch 127112-06 or later installed" test_ref="oval:org.mitre.oval:tst:7670"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5393" version="1" class="vulnerability">
      <metadata>
        <title>Security Vulnerability in the Solaris X Server May Lead to Unauthorized Disclosure of Information on Access Restricted Files and Directories</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <platform>Sun Solaris 9</platform>
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-5958" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5958"/>
        <description>X.Org Xserver before 1.4.1 allows local users to determine the existence of arbitrary files via a filename argument in the -sp option to the X program, which produces different error messages depending on whether the filename exists.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-02-12T08:48:34.000-05:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2008-02-13T09:26:36.813-05:00">DRAFT</status_change>
            <status_change date="2008-03-03T04:00:16.207-05:00">INTERIM</status_change>
            <status_change date="2008-03-24T04:00:46.668-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND" comment="Solaris 8 (SPARC) meets Sun Alert 230901">
          <extend_definition comment="Solaris 8 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1539"/>
          <criterion negate="true" comment="Patch 119067-09 or later installed" test_ref="oval:org.mitre.oval:tst:7606"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (SPARC) meets Sun Alert 230901">
          <extend_definition comment="Solaris 9 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1457"/>
          <criterion negate="true" comment="Patch 112785-63 or later installed" test_ref="oval:org.mitre.oval:tst:7770"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
          <criteria operator="OR">
            <criteria operator="AND">
              <criterion comment="File Xsun exists" test_ref="oval:org.mitre.oval:tst:3109"/>
              <criterion negate="true" comment="Patch 119059-38 or later installed" test_ref="oval:org.mitre.oval:tst:7694"/>
            </criteria>
            <criteria operator="AND">
              <criterion comment="File Xorg exists" test_ref="oval:org.mitre.oval:tst:1336"/>
              <criterion negate="true" comment="Patch 125719-07 or later installed" test_ref="oval:org.mitre.oval:tst:7744"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Solaris 8 (x86) meets Sun Alert 230901">
          <extend_definition comment="Solaris 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:2059"/>
          <criterion negate="true" comment="Patch 119068-09 or later installed" test_ref="oval:org.mitre.oval:tst:7681"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="Solaris 9 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1683"/>
          <criteria operator="OR">
            <criteria operator="AND">
              <criterion comment="File Xsun exists" test_ref="oval:org.mitre.oval:tst:3109"/>
              <criterion negate="true" comment="Patch 112786-52 or later installed" test_ref="oval:org.mitre.oval:tst:7415"/>
            </criteria>
            <criteria operator="AND">
              <criterion comment="File Xorg exists" test_ref="oval:org.mitre.oval:tst:1336"/>
              <criterion negate="true" comment="Patch 118908-04 or later installed" test_ref="oval:org.mitre.oval:tst:7428"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
          <criteria operator="OR">
            <criteria operator="AND">
              <criterion comment="File Xsun exists" test_ref="oval:org.mitre.oval:tst:3109"/>
              <criterion negate="true" comment="Patch 119060-37 or later installed" test_ref="oval:org.mitre.oval:tst:7764"/>
            </criteria>
            <criteria operator="AND">
              <criterion comment="File Xorg exists" test_ref="oval:org.mitre.oval:tst:1336"/>
              <criterion negate="true" comment="Patch 125720-17 or later installed" test_ref="oval:org.mitre.oval:tst:7423"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5369" version="1" class="vulnerability">
      <metadata>
        <title>Security Vulnerability in inetd(1M) Daemon When Debug Logging is Enabled</title>
        <affected family="unix">
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-1684" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1684"/>
        <description>inetd on Sun Solaris 10, when debug logging is enabled, allows local users to write to arbitrary files via a symlink attack on the /var/tmp/inetd.log temporary file.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-04-08T07:20:30.000-04:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2008-04-09T13:51:36.728-04:00">DRAFT</status_change>
            <status_change date="2008-04-28T04:00:15.519-04:00">INTERIM</status_change>
            <status_change date="2008-05-19T04:00:13.301-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="Software Section">
          <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 233284">
            <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
            <criterion negate="true" comment="Patch 127718-05 or later installed" test_ref="oval:org.mitre.oval:tst:7859"/>
          </criteria>
          <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 233284">
            <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
            <criterion negate="true" comment="Patch 127719-05 or later installed" test_ref="oval:org.mitre.oval:tst:7909"/>
          </criteria>
        </criteria>
        <criterion comment="File /var/tmp/inetd.log exists" test_ref="oval:org.mitre.oval:tst:7756"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5346" version="1" class="vulnerability">
      <metadata>
        <title>Security Vulnerability in the Solaris 10 STREAMS Administrative Driver ("sad") May Allow a Denial of Service (System panic)</title>
        <affected family="unix">
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-2418" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-2418"/>
        <description>Race condition in the STREAMS Administrative Driver (sad) in Sun Solaris 10 allows local users to cause a denial of service (panic) via unknown vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-05-29T14:40:41.000-04:00">
              <contributor organization="Hewlett-Packard">Nicholas Hansen</contributor>
            </submitted>
            <status_change date="2008-06-02T10:54:28.218-04:00">DRAFT</status_change>
            <status_change date="2008-06-23T04:00:13.629-04:00">INTERIM</status_change>
            <status_change date="2008-07-14T04:00:20.599-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 237584">
          <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
          <criterion negate="true" comment="Patch 127743-01 or later installed" test_ref="oval:org.mitre.oval:tst:7719"/>
          <criterion comment="Patch 120011-06 or later installed" test_ref="oval:org.mitre.oval:tst:7858"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 237584">
          <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
          <criterion negate="true" comment="Patch 127744-01 or later installed" test_ref="oval:org.mitre.oval:tst:8071"/>
          <criterion comment="Patch 120012-06 or later installed" test_ref="oval:org.mitre.oval:tst:8036"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5337" version="1" class="vulnerability">
      <metadata>
        <title>Security Vulnerability in Solaris 10 OpenSSL SSL_get_shared_ciphers() Function</title>
        <affected family="unix">
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-5135" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5135"/>
        <description>Off-by-one error in the SSL_get_shared_ciphers function in OpenSSL 0.9.7 up to 0.9.7l, and 0.9.8 up to 0.9.8f, might allow remote attackers to execute arbitrary code via a crafted packet that triggers a one-byte buffer underflow.  NOTE: this issue was introduced as a result of a fix for CVE-2006-3738.  As of 20071012, it is unknown whether code execution is possible.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-02-14T08:25:18.000-05:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2008-02-14T15:57:58.357-05:00">DRAFT</status_change>
            <status_change date="2008-03-03T04:00:13.537-05:00">INTERIM</status_change>
            <status_change date="2008-03-24T04:00:43.411-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 200858">
          <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
          <criterion negate="true" comment="Patch 127111-08 or later installed" test_ref="oval:org.mitre.oval:tst:7721"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 200858">
          <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
          <criterion negate="true" comment="Patch 127112-08 or later installed" test_ref="oval:org.mitre.oval:tst:7761"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5318" version="1" class="vulnerability">
      <metadata>
        <title>Security Vulnerability in Solaris snoop(1M) when Displaying SMB Traffic</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <platform>Sun Solaris 9</platform>
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-0964" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-0964"/>
        <description>Multiple stack-based buffer overflows in snoop on Sun Solaris 8 through 10 and OpenSolaris before snv_96, when the -o option is omitted, allow remote attackers to execute arbitrary code via a crafted SMB packet.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-08-11T12:08:06.000-04:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2008-08-14T15:03:14.279-04:00">DRAFT</status_change>
            <status_change date="2008-09-01T04:00:54.664-04:00">INTERIM</status_change>
            <status_change date="2008-09-22T04:00:22.547-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 240101">
          <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
          <criterion negate="true" comment="Patch 138083-01 or later installed" test_ref="oval:org.mitre.oval:tst:9062"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (SPARC) meets Sun Alert 240101">
          <extend_definition comment="Solaris 9 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1457"/>
          <criterion negate="true" comment="Patch 112915-05 or later installed" test_ref="oval:org.mitre.oval:tst:9103"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 8 (SPARC) meets Sun Alert 240101">
          <extend_definition comment="Solaris 8 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1539"/>
          <criterion negate="true" comment="Patch 108964-11 or later installed" test_ref="oval:org.mitre.oval:tst:8936"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 240101">
          <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
          <criterion negate="true" comment="Patch 138084-01 or later installed" test_ref="oval:org.mitre.oval:tst:8152"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (x86) meets Sun Alert 240101">
          <extend_definition comment="Solaris 9 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1683"/>
          <criterion negate="true" comment="Patch 114262-04 or later installed" test_ref="oval:org.mitre.oval:tst:8854"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 8 (x86) meets Sun Alert 240101">
          <extend_definition comment="Solaris 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:2059"/>
          <criterion negate="true" comment="Patch 108965-11 or later installed" test_ref="oval:org.mitre.oval:tst:9126"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5269" version="1" class="vulnerability">
      <metadata>
        <title>Security Vulnerabilities in Solaris Print Service May Lead to Denial of Service (DoS) or Execution of Arbitrary Code</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <platform>Sun Solaris 9</platform>
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-2144" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-2144"/>
        <description>Multiple unspecified vulnerabilities in Solaris print service for Sun Solaris 8, 9, and 10 allow remote attackers to cause a denial of service or execute arbitrary code via unknown vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-05-14T13:20:42.000-04:00">
              <contributor organization="Hewlett-Packard">Nicholas Hansen</contributor>
            </submitted>
            <status_change date="2008-05-15T14:47:17.480-04:00">DRAFT</status_change>
            <status_change date="2008-06-02T04:00:08.809-04:00">INTERIM</status_change>
            <status_change date="2008-06-23T04:00:12.580-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND" comment="Solaris 8 (SPARC) meets Sun Alert 236884">
          <extend_definition comment="Solaris 8 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1539"/>
          <criterion negate="true" comment="Patch 109320-20 or later installed" test_ref="oval:org.mitre.oval:tst:7494"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 8 (x86) meets Sun Alert 236884">
          <extend_definition comment="Solaris 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:2059"/>
          <criterion negate="true" comment="Patch 109321-20 or later installed" test_ref="oval:org.mitre.oval:tst:7873"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (SPARC) meets Sun Alert 236884">
          <extend_definition comment="Solaris 9 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1457"/>
          <criterion negate="true" comment="Patch 113329-19 or later installed" test_ref="oval:org.mitre.oval:tst:7921"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (x86) meets Sun Alert 236884">
          <extend_definition comment="Solaris 9 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1683"/>
          <criterion negate="true" comment="Patch 114980-20 or later installed" test_ref="oval:org.mitre.oval:tst:7759"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 236884">
          <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
          <criterion negate="true" comment="Patch 127127-11 or later installed" test_ref="oval:org.mitre.oval:tst:7382"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 236884">
          <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
          <criterion negate="true" comment="Patch 127128-11 or later installed" test_ref="oval:org.mitre.oval:tst:7793"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5258" version="1" class="vulnerability">
      <metadata>
        <title>Security Vulnerability in Solaris 10 Involving the SCTP Protocol May Result in a Denial of Network Services Due to Network Flooding</title>
        <affected family="unix">
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-2090" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-2090"/>
        <description>Unspecified vulnerability in the SCTP protocol implementation in Sun Solaris 10 allows remote attackers to cause a denial of service (CPU consumption and network traffic amplification) via a crafted SCTP packet.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-05-05T13:33:55.000-04:00">
              <contributor organization="Hewlett-Packard">Nicholas Hansen</contributor>
            </submitted>
            <status_change date="2008-05-08T13:36:09.054-04:00">DRAFT</status_change>
            <status_change date="2008-05-26T04:00:20.600-04:00">INTERIM</status_change>
            <status_change date="2008-06-16T04:00:07.192-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 236521">
          <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
          <criterion negate="true" comment="Patch 127127-08 or later installed" test_ref="oval:org.mitre.oval:tst:7996"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 236521">
          <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
          <criterion negate="true" comment="Patch 127128-08 or later installed" test_ref="oval:org.mitre.oval:tst:7373"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5252" version="1" class="vulnerability">
      <metadata>
        <title>Security Vulnerability in GNU tar May Lead to Arbitrary Code Execution or Denial of Service (DoS)</title>
        <affected family="unix">
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-0300" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0300"/>
        <description>Buffer overflow in tar 1.14 through 1.15.90 allows user-assisted attackers to cause a denial of service (application crash) and possibly execute code via unspecified vectors involving PAX extended headers.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-04-30T11:23:00.000-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2009-05-07T11:17:46.363-04:00">DRAFT</status_change>
            <status_change date="2009-05-25T04:01:32.862-04:00">INTERIM</status_change>
            <status_change date="2009-06-15T04:00:39.412-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 241646">
          <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
          <criterion negate="true" comment="Patch 139100-01 or later installed" test_ref="oval:org.mitre.oval:tst:9899"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5216" version="1" class="vulnerability">
      <metadata>
        <title>Security Vulnerability in the libxml2 Library May Lead to a Denial of Service (DoS)</title>
        <affected family="unix">
          <platform>Sun Solaris 9</platform>
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-6284" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6284"/>
        <description>The xmlCurrentChar function in libxml2 before 2.6.31 allows context-dependent attackers to cause a denial of service (infinite loop) via XML containing invalid UTF-8 sequences.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-02-12T08:48:33.000-05:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2008-02-13T09:26:34.461-05:00">DRAFT</status_change>
            <status_change date="2008-03-03T04:00:10.886-05:00">INTERIM</status_change>
            <status_change date="2008-03-24T04:00:40.950-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND" comment="Solaris 9 (SPARC) meets Sun Alert 201514">
          <extend_definition comment="Solaris 9 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1457"/>
          <criterion negate="true" comment="Patch 114014-18 or later installed" test_ref="oval:org.mitre.oval:tst:7816"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 201514">
          <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
          <criterion negate="true" comment="Patch 125731-02 or later installed" test_ref="oval:org.mitre.oval:tst:7732"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (x86) meets Sun Alert 201514">
          <extend_definition comment="Solaris 9 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1683"/>
          <criterion negate="true" comment="Patch 114015-18 or later installed" test_ref="oval:org.mitre.oval:tst:7223"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 201514">
          <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
          <criterion negate="true" comment="Patch 125732-02 or later installed" test_ref="oval:org.mitre.oval:tst:7419"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5211" version="1" class="vulnerability">
      <metadata>
        <title>A Security Vulnerability in libdevinfo(3LIB) May Allow Unauthorized Access to Files on the System</title>
        <affected family="unix">
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-0242" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-0242"/>
        <description>Unspecified vulnerability in libdevinfo in Sun Solaris 10 allows local users to access files and gain privileges via unknown vectors, related to login device permissions.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-01-15T11:52:30.000-05:00">
              <contributor organization="Hewlett-Packard">Yuzheng Zhou</contributor>
            </submitted>
            <status_change date="2008-01-17T09:54:51.531-05:00">DRAFT</status_change>
            <status_change date="2008-02-04T10:19:00.101-05:00">INTERIM</status_change>
            <status_change date="2008-02-25T04:00:10.261-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 103165">
          <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
          <criterion negate="true" comment="Patch 125251-02 installed" test_ref="oval:org.mitre.oval:tst:7347"/>
          <criterion comment="Patch 118833-04 or later installed" test_ref="oval:org.mitre.oval:tst:7841"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 103165">
          <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
          <criterion negate="true" comment="Patch 125252-02 installed" test_ref="oval:org.mitre.oval:tst:7106"/>
          <criterion comment="Patch 118855-03 or later installed" test_ref="oval:org.mitre.oval:tst:7786"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5165" version="1" class="vulnerability">
      <metadata>
        <title>Security Vulnerability in Solaris 10 Involving the SCTP Protocol May Result in a Panic and Denial of Service (DoS)</title>
        <affected family="unix">
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-2089" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-2089"/>
        <description>Unspecified vulnerability in the SCTP protocol implementation in Sun Solaris 10 allows remote attackers to cause a denial of service (panic) via a crafted SCTP packet.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-05-05T13:33:55.000-04:00">
              <contributor organization="Hewlett-Packard">Nicholas Hansen</contributor>
            </submitted>
            <status_change date="2008-05-08T13:36:09.338-04:00">DRAFT</status_change>
            <status_change date="2008-05-26T04:00:19.762-04:00">INTERIM</status_change>
            <status_change date="2008-06-16T04:00:06.194-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 236321">
          <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
          <criterion negate="true" comment="Patch 127127-08 or later installed" test_ref="oval:org.mitre.oval:tst:7996"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 236321">
          <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
          <criterion negate="true" comment="Patch 127128-08 or later installed" test_ref="oval:org.mitre.oval:tst:7373"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5128" version="1" class="vulnerability">
      <metadata>
        <title>A Security Vulnerability in Solaris 10 involving the sendfilev() system call could result in Denial of Service (DoS) due to System Panic</title>
        <affected family="unix">
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-3666" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-3666"/>
        <description>Unspecified vulnerability in Sun Solaris 10 and OpenSolaris before snv_96 allows (1) context-dependent attackers to cause a denial of service (panic) via vectors involving creation of a crafted file and use of the sendfilev system call, as demonstrated by a file served by an Apache 2.2.x web server with EnableSendFile configured; and (2) local users to cause a denial of service (panic) via a call to the sendfile system call, as reachable through the sendfilev library.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-08-14T11:25:43.000-04:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2008-08-14T15:03:16.477-04:00">DRAFT</status_change>
            <status_change date="2008-09-01T04:00:51.409-04:00">INTERIM</status_change>
            <status_change date="2008-09-22T04:00:21.027-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 239186">
          <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
          <criterion negate="true" comment="Patch 137111-04 or later installed" test_ref="oval:org.mitre.oval:tst:9073"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 239186">
          <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
          <criterion negate="true" comment="Patch 137112-04 or later installed" test_ref="oval:org.mitre.oval:tst:8753"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:4950" version="1" class="vulnerability">
      <metadata>
        <title>A Security Vulnerability in Floating Point Context Switch Implementation May Result in a Denial of Service (DoS) or Data Integrity Issues</title>
        <affected family="unix">
          <platform>Sun Solaris 9</platform>
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-1778" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1778"/>
        <description>Unspecified vulnerability in the floating point context switch implementation in Sun Solaris 9 and 10 on x86 platforms might allow local users to cause a denial of service (application exit), corrupt data, or trigger incorrect calculations via unknown vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-04-15T07:48:47.000-04:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2008-04-15T12:06:15.409-04:00">DRAFT</status_change>
            <status_change date="2008-05-05T04:00:22.388-04:00">INTERIM</status_change>
            <status_change date="2008-05-26T04:00:19.375-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND" comment="Solaris 9 (x86) meets Sun Alert 233921">
          <extend_definition comment="Solaris 9 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1683"/>
          <criterion negate="true" comment="Patch 122301-23 or later installed" test_ref="oval:org.mitre.oval:tst:7682"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 233921">
          <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
          <criterion negate="true" comment="Patch 127112-10 or later installed" test_ref="oval:org.mitre.oval:tst:7749"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:4848" version="1" class="vulnerability">
      <metadata>
        <title>A Security Vulnerability in the Handling of Self Encapsulated IP Packets may Lead to a Denial of Service (DOS) Condition.</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <platform>Sun Solaris 9</platform>
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-1779" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1779"/>
        <description>Sun Solaris 8, 9, and 10 allows "remote privileged" users to cause a denial of service (panic) via unknown vectors related to self encapsulated IP packets.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-04-15T07:48:47.000-04:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2008-04-15T12:06:17.868-04:00">DRAFT</status_change>
            <status_change date="2008-05-05T04:00:21.938-04:00">INTERIM</status_change>
            <status_change date="2008-05-26T04:00:15.482-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND" comment="Solaris 8 (SPARC) meets Sun Alert 235901">
          <extend_definition comment="Solaris 8 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1539"/>
          <criterion negate="true" comment="Patch 116965-32 or later installed" test_ref="oval:org.mitre.oval:tst:7947"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (SPARC) meets Sun Alert 235901">
          <extend_definition comment="Solaris 9 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1457"/>
          <criterion negate="true" comment="Patch 114344-34 or later installed" test_ref="oval:org.mitre.oval:tst:7482"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 235901">
          <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
          <criterion negate="true" comment="Patch 127111-11 or later installed" test_ref="oval:org.mitre.oval:tst:7975"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 8 (x86) meets Sun Alert 235901">
          <extend_definition comment="Solaris 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:2059"/>
          <criterion negate="true" comment="Patch 116966-31 or later installed" test_ref="oval:org.mitre.oval:tst:7668"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (x86) meets Sun Alert 235901">
          <extend_definition comment="Solaris 9 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1683"/>
          <criterion negate="true" comment="Patch 119435-22 or later installed" test_ref="oval:org.mitre.oval:tst:7881"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 235901">
          <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
          <criterion negate="true" comment="Patch 127112-11 or later installed" test_ref="oval:org.mitre.oval:tst:7822"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:4814" version="1" class="vulnerability">
      <metadata>
        <title>A Security Vulnerability in Solaris 10 libexif May Allow Code Execution or a Denial of Service (DoS) Condition</title>
        <affected family="unix">
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-6352" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6352"/>
        <description>Integer overflow in libexif 0.6.16 and earlier allows context-dependent attackers to execute arbitrary code via an image with crafted EXIF tags, possibly involving the exif_data_load_data_thumbnail function in exif-data.c.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-03-25T13:04:49.000-04:00">
              <contributor organization="Hewlett-Packard">Nicholas Hansen</contributor>
            </submitted>
            <status_change date="2008-03-26T16:26:15.177-04:00">DRAFT</status_change>
            <status_change date="2008-04-14T04:00:08.823-04:00">INTERIM</status_change>
            <status_change date="2008-05-05T04:00:21.678-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 234701">
          <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
          <criterion negate="true" comment="Patch 121095-02 or later installed" test_ref="oval:org.mitre.oval:tst:7952"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 234701">
          <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
          <criterion negate="true" comment="Patch 121096-02 or later installed" test_ref="oval:org.mitre.oval:tst:7912"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:4725" version="1" class="vulnerability">
      <metadata>
        <title>Security Vulnerability in the Solaris crontab(1) utility may allow execution of Arbitrary Code</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <platform>Sun Solaris 9</platform>
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-2538" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-2538"/>
        <description>Unspecified vulnerability in crontab on Sun Solaris 8 through 10, and OpenSolaris before snv_93, allows local users to insert cron jobs into the crontab files of arbitrary users via unspecified vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-06-05T11:19:56.000-04:00">
              <contributor organization="Hewlett-Packard">Nicholas Hansen</contributor>
            </submitted>
            <status_change date="2008-06-05T14:00:22.164-04:00">DRAFT</status_change>
            <status_change date="2008-06-23T04:00:11.562-04:00">INTERIM</status_change>
            <modified comment="Fixed duplicate criteria for Solaris 9" date="2008-07-02T16:52:00.808-04:00">
              <contributor organization="Secure Elements, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2008-07-21T04:00:08.039-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND" comment="Solaris 8 (SPARC) meets Sun Alert 237864">
          <extend_definition comment="Solaris 8 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1539"/>
          <criterion negate="true" comment="Patch 109007-26 or later installed" test_ref="oval:org.mitre.oval:tst:7905"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (SPARC) meets Sun Alert 237864">
          <extend_definition comment="Solaris 9 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1457"/>
          <criterion negate="true" comment="Patch 122300-27 or later installed" test_ref="oval:org.mitre.oval:tst:7763"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 237864">
          <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
          <criterion negate="true" comment="Patch 137017-02 or later installed" test_ref="oval:org.mitre.oval:tst:8027"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 8 (x86) meets Sun Alert 237864">
          <extend_definition comment="Solaris 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:2059"/>
          <criterion negate="true" comment="Patch 109008-26 or later installed" test_ref="oval:org.mitre.oval:tst:7968"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (x86) meets Sun Alert 237864">
          <extend_definition comment="Solaris 9 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1683"/>
          <criterion negate="true" comment="Patch 122301-27 or later installed" test_ref="oval:org.mitre.oval:tst:7797"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 237864">
          <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
          <criterion negate="true" comment="Patch 137018-02 or later installed" test_ref="oval:org.mitre.oval:tst:8019"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:464" version="6" class="vulnerability">
      <metadata>
        <title>Solaris 8, 9, 10 ICMP Source Quench Attack Vulnerability</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <platform>Sun Solaris 9</platform>
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0791" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0791"/>
        <description>Multiple TCP/IP and ICMP implementations allow remote attackers to cause a denial of service (network throughput reduction for TCP connections) via a blind throughput-reduction attack using spoofed Source Quench packets, aka the "ICMP Source Quench attack."  NOTE: CVE-2004-0790, CVE-2004-0791, and CVE-2004-1060 have been SPLIT based on different attacks; CVE-2005-0065, CVE-2005-0066, CVE-2005-0067, and CVE-2005-0068 are related identifiers that are SPLIT based on the underlying vulnerability.  While CVE normally SPLITs based on vulnerability, the attack-based identifiers exist due to the variety and number of affected implementations and solutions that address the attacks instead of the underlying vulnerabilities.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-09-22T05:52:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-09-22T20:15:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-07T09:15:47.997-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:15:55.567-04:00">ACCEPTED</status_change>
            <modified comment="Added title. Implemented by Jon Baker of The MITRE Corporation." date="2007-02-13T14:45:00.680-05:00">
              <contributor organization="Security-Database">Nabil Ouchn</contributor>
            </modified>
            <status_change date="2007-02-13T14:46:46.709-05:00">INTERIM</status_change>
            <modified comment="Standardized title." date="2007-02-23T13:00:00.812-05:00">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2007-03-21T16:17:19.479-04:00">ACCEPTED</status_change>
            <modified comment="Added missing patch checks." date="2007-06-26T10:59:00.998-04:00">
              <contributor organization="Opsware, Inc.">Pai Peng</contributor>
            </modified>
            <status_change date="2007-06-26T11:01:33.028-04:00">INTERIM</status_change>
            <status_change date="2007-07-11T15:17:32.802-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:464 - Various corrections to comments and products to align with Authoring Style Guide" date="2011-04-22T23:54:00.899-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-04-23T00:05:38.269-04:00">INTERIM</status_change>
            <status_change date="2011-05-09T04:01:34.130-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Solaris 8 (SPARC) meets Sun Alert ID 101658 criteria.">
          <criterion comment="Solaris 8 Installed" test_ref="oval:org.mitre.oval:tst:3437"/>
          <criterion comment="sparc architecture" test_ref="oval:org.mitre.oval:tst:3237"/>
          <criterion negate="true" comment="Patch 116965-19 or later installed" test_ref="oval:org.mitre.oval:tst:4028"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 8 (x86) meets Sun Alert ID 101658 criteria.">
          <criterion comment="Solaris 8 Installed" test_ref="oval:org.mitre.oval:tst:3437"/>
          <criterion comment="ix86 architecture" test_ref="oval:org.mitre.oval:tst:3912"/>
          <criterion negate="true" comment="Patch 116966-18 or later installed" test_ref="oval:org.mitre.oval:tst:4069"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (SPARC) meets Sun Alert ID 101658 criteria.">
          <criterion comment="Solaris 9 Installed" test_ref="oval:org.mitre.oval:tst:3172"/>
          <criterion comment="sparc architecture" test_ref="oval:org.mitre.oval:tst:3237"/>
          <criterion negate="true" comment="Patch 118305-08 or later installed" test_ref="oval:org.mitre.oval:tst:3204"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (x86) meets Sun Alert ID 101658 criteria.">
          <criterion comment="Solaris 9 Installed" test_ref="oval:org.mitre.oval:tst:3172"/>
          <criterion comment="ix86 architecture" test_ref="oval:org.mitre.oval:tst:3912"/>
          <criterion negate="true" comment="Patch 117470-07 or later installed" test_ref="oval:org.mitre.oval:tst:4114"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert ID 101658 criteria.">
          <criterion comment="Solaris 10 Installed" test_ref="oval:org.mitre.oval:tst:3680"/>
          <criterion comment="sparc architecture" test_ref="oval:org.mitre.oval:tst:3237"/>
          <criterion negate="true" comment="Patch 118822-27 or later installed" test_ref="oval:org.mitre.oval:tst:3505"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert ID 101658 criteria.">
          <criterion comment="Solaris 10 Installed" test_ref="oval:org.mitre.oval:tst:3680"/>
          <criterion comment="ix86 architecture" test_ref="oval:org.mitre.oval:tst:3912"/>
          <criterion negate="true" comment="Patch 118844-28 or later installed" test_ref="oval:org.mitre.oval:tst:3302"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:4356" version="1" class="vulnerability">
      <metadata>
        <title>Security Vulnerabilities in OpenSSL May Lead to a Denial of Service (DoS) to Applications or Execution of Arbitrary Code With Elevated Privileges</title>
        <affected family="unix">
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-4343" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-4343"/>
        <description>The get_server_hello function in the SSLv2 client code in OpenSSL 0.9.7 before 0.9.7l, 0.9.8 before 0.9.8d, and earlier versions allows remote servers to cause a denial of service (client crash) via unknown vectors that trigger a null pointer dereference.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-12-04T09:53:52.000-05:00">
              <contributor organization="Hewlett-Packard">Todd Dolinsky</contributor>
            </submitted>
            <status_change date="2007-12-06T15:39:49.237-05:00">DRAFT</status_change>
            <status_change date="2007-12-24T04:06:29.015-05:00">INTERIM</status_change>
            <status_change date="2008-01-14T04:00:06.896-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 102711">
          <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
          <criteria operator="OR">
            <criterion negate="true" comment="Patch 121229-02 or later installed" test_ref="oval:org.mitre.oval:tst:6483"/>
            <criteria operator="AND">
              <criterion comment="Patch 121229-02 or later installed" test_ref="oval:org.mitre.oval:tst:6483"/>
              <criterion negate="true" comment="Patch 118562-13 or later installed" test_ref="oval:org.mitre.oval:tst:6849"/>
              <criterion comment="Pkg SUNWcry (Supplemental Encryption) is installed" test_ref="oval:org.mitre.oval:tst:3198"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 102711">
          <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
          <criteria operator="OR">
            <criterion negate="true" comment="Patch 121230-02 or later installed" test_ref="oval:org.mitre.oval:tst:6715"/>
            <criteria operator="AND">
              <criterion comment="Patch 121230-02 or later installed" test_ref="oval:org.mitre.oval:tst:6715"/>
              <criterion negate="true" comment="Patch 118563-13 or later installed" test_ref="oval:org.mitre.oval:tst:6121"/>
              <criterion comment="Pkg SUNWcry (Supplemental Encryption) is installed" test_ref="oval:org.mitre.oval:tst:3198"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:4256" version="1" class="vulnerability">
      <metadata>
        <title>Security Vulnerabilities in OpenSSL May Lead to a Denial of Service (DoS) to Applications or Execution of Arbitrary Code With Elevated Privileges</title>
        <affected family="unix">
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-3738" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-3738"/>
        <description>Buffer overflow in the SSL_get_shared_ciphers function in OpenSSL 0.9.7 before 0.9.7l, 0.9.8 before 0.9.8d, and earlier versions has unspecified impact and remote attack vectors involving a long list of ciphers.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-12-04T09:53:52.000-05:00">
              <contributor organization="Hewlett-Packard">Todd Dolinsky</contributor>
            </submitted>
            <status_change date="2007-12-06T15:39:48.901-05:00">DRAFT</status_change>
            <status_change date="2007-12-24T04:06:15.412-05:00">INTERIM</status_change>
            <status_change date="2008-01-14T04:00:05.944-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 102711">
          <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
          <criteria operator="OR">
            <criterion negate="true" comment="Patch 121229-02 or later installed" test_ref="oval:org.mitre.oval:tst:6483"/>
            <criteria operator="AND">
              <criterion comment="Patch 121229-02 or later installed" test_ref="oval:org.mitre.oval:tst:6483"/>
              <criterion negate="true" comment="Patch 118562-13 or later installed" test_ref="oval:org.mitre.oval:tst:6849"/>
              <criterion comment="Pkg SUNWcry (Supplemental Encryption) is installed" test_ref="oval:org.mitre.oval:tst:3198"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 102711">
          <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
          <criteria operator="OR">
            <criterion negate="true" comment="Patch 121230-02 or later installed" test_ref="oval:org.mitre.oval:tst:6715"/>
            <criteria operator="AND">
              <criterion comment="Patch 121230-02 or later installed" test_ref="oval:org.mitre.oval:tst:6715"/>
              <criterion negate="true" comment="Patch 118563-13 or later installed" test_ref="oval:org.mitre.oval:tst:6121"/>
              <criterion comment="Pkg SUNWcry (Supplemental Encryption) is installed" test_ref="oval:org.mitre.oval:tst:3198"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:4095" version="1" class="vulnerability">
      <metadata>
        <title>A Security Vulnerability in Solaris Volume Manager (SVM) May Allow a Denial of Service (DoS)</title>
        <affected family="unix">
          <platform>Sun Solaris 9</platform>
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-5921" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5921"/>
        <description>Unspecified vulnerability in the ioctl interface in the Solaris Volume Manager (SVM) in Sun Solaris 9 and 10 allows local users to cause a denial of service (panic) via unspecified vectors, a different vulnerability than CVE-2004-1346.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-11-14T13:46:57.000-05:00">
              <contributor organization="Hewlett-Packard">Nicholas Hansen</contributor>
            </submitted>
            <status_change date="2007-11-16T08:53:16.185-05:00">DRAFT</status_change>
            <status_change date="2007-12-03T04:05:58.160-05:00">INTERIM</status_change>
            <status_change date="2007-12-24T04:05:42.679-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 103143">
          <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
          <criterion negate="true" comment="Patch 124256-03 or later installed" test_ref="oval:org.mitre.oval:tst:6439"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 103143">
          <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
          <criterion negate="true" comment="Patch 126257-04 or later installed" test_ref="oval:org.mitre.oval:tst:6587"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (SPARC) meets Sun Alert 103143">
          <extend_definition comment="Solaris 9 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1457"/>
          <criterion negate="true" comment="Patch 116669-31 or later installed" test_ref="oval:org.mitre.oval:tst:5870"/>
          <criteria operator="OR" comment="Solaris 9 (SPARC) Sun Alert 103143 extra patches">
            <criterion comment="Patch 113026-03 or later installed" test_ref="oval:org.mitre.oval:tst:6795"/>
            <criterion comment="Patch 113073-11 or later installed" test_ref="oval:org.mitre.oval:tst:6844"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (x86) meets Sun Alert 103143">
          <extend_definition comment="Solaris 9 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1683"/>
          <criterion negate="true" comment="Patch 122371-07 or later installed" test_ref="oval:org.mitre.oval:tst:6632"/>
          <criteria operator="OR" comment="Solaris 9 (x86) Sun Alert 103143 extra patches">
            <criterion comment="Patch 113994-02 or later installed" test_ref="oval:org.mitre.oval:tst:6596"/>
            <criterion comment="Patch 118559-12 or later installed" test_ref="oval:org.mitre.oval:tst:6809"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:397" version="2" class="vulnerability">
      <metadata>
        <title>MIT Kerberos 5 Key Distribution Center Remote Denial of Service Vulnerability</title>
        <affected family="unix">
          <platform>Sun Solaris 7</platform>
          <platform>Sun Solaris 8</platform>
          <platform>Sun Solaris 9</platform>
          <platform>Sun Solaris 10</platform>
          <product>Kerberos</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1174" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1174"/>
        <description>MIT Kerberos 5 (krb5) 1.3 through 1.4.1 Key Distribution Center (KDC) allows remote attackers to cause a denial of service (application crash) via a certain valid TCP connection that causes a free of unallocated memory.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-09-22T05:52:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-09-22T20:15:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-07T09:15:46.201-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:15:53.901-04:00">ACCEPTED</status_change>
            <modified comment="Added title. Implemented by Jon Baker of The MITRE Corporation." date="2007-02-13T14:01:00.728-05:00">
              <contributor organization="Security-Database">Nabil Ouchn</contributor>
            </modified>
            <status_change date="2007-02-13T14:02:18.764-05:00">INTERIM</status_change>
            <status_change date="2007-03-21T16:17:18.240-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="OR">
        <criteria operator="AND" comment="Solaris 7 (SPARC) meets Sun Alert ID 101809 criteria." negate="false">
          <criterion comment="Solaris 7 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3576"/>
          <criterion comment="sparc architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3237"/>
          <criterion comment="Patch 112536-06 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:3209"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 7 (x86) meets Sun Alert ID 101809 criteria." negate="false">
          <criterion comment="Solaris 7 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3576"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3912"/>
          <criterion comment="Patch 112537-06 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:3424"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 8 (SPARC) meets Sun Alert ID 101809 criteria." negate="false">
          <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3437"/>
          <criterion comment="sparc architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3237"/>
          <criterion comment="Patch 112237-13 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:3567"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 8 (x86) meets Sun Alert ID 101809 criteria." negate="false">
          <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3437"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3912"/>
          <criterion comment="Patch 112238-12 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:3898"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 8 (SPARC) with Supplmental Encryption Packages meets Sun Alert ID 101809 criteria." negate="false">
          <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3437"/>
          <criterion comment="sparc architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3237"/>
          <criteria operator="OR" comment="Solaris Supplemental Encryption Packages are installed" negate="false">
            <criterion comment="Pkg SUNWcry (Supplemental Encryption) is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3198"/>
            <criterion comment="Pkg SUNWcryr (Supplemental Encryption) is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3694"/>
          </criteria>
          <criterion comment="Patch 112390-11 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:3640"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 8 (x86) with Supplmental Encryption Packages meets Sun Alert ID 101809 criteria." negate="false">
          <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3437"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3912"/>
          <criteria operator="OR" comment="Solaris Supplemental Encryption Packages are installed" negate="false">
            <criterion comment="Pkg SUNWcry (Supplemental Encryption) is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3198"/>
            <criterion comment="Pkg SUNWcryr (Supplemental Encryption) is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3694"/>
          </criteria>
          <criterion comment="Patch 112240-10 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:3497"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (SPARC) meets Sun Alert ID 101809 criteria." negate="false">
          <criterion comment="Solaris 9 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3172"/>
          <criterion comment="sparc architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3237"/>
          <criterion comment="Patch 112908-20 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:3389"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (x86) meets Sun Alert ID 101809 criteria." negate="false">
          <criterion comment="Solaris 9 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3172"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3912"/>
          <criterion comment="Patch 115168-08 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:3624"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert ID 101809 criteria." negate="false">
          <criterion comment="Solaris 10 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3680"/>
          <criterion comment="sparc architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3237"/>
          <criterion comment="Patch 120469-01 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:3561"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert ID 101809 criteria." negate="false">
          <criterion comment="Solaris 10 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3680"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3912"/>
          <criterion comment="Patch 120470-01 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:3418"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:360" version="2" class="vulnerability">
      <metadata>
        <title>Sun Java System Access Manager Local Authentication Bypass Vulnerability</title>
        <affected family="unix">
          <platform>Sun Solaris 10</platform>
          <platform>Sun Solaris 9</platform>
          <platform>Sun Solaris 8</platform>
          <product>Access Manager</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-0531" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0531"/>
        <description>Unspecified vulnerability in Sun Java System Access Manager 7.0 allows local users logged in as "root" to bypass authentication and gain top-level administrator privileges via the amadmin CLI tool.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-09-22T05:52:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-09-22T20:15:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-07T09:15:45.919-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:15:53.570-04:00">ACCEPTED</status_change>
            <modified comment="Added title. Implemented by Jon Baker of The MITRE Corporation." date="2007-02-13T14:50:00.385-05:00">
              <contributor organization="Security-Database">Nabil Ouchn</contributor>
            </modified>
            <status_change date="2007-02-13T14:52:25.407-05:00">INTERIM</status_change>
            <status_change date="2007-03-21T16:17:17.664-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="SPARC" negate="false" test_ref="oval:org.mitre.oval:tst:3237"/>
        <criterion comment="Sun Java System Access Manager 7 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3551"/>
        <criterion comment="Patch 120954-01 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:4067"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:3270" version="2" class="vulnerability">
      <metadata>
        <title>Security Vulnerability in the Solaris 10 Internet Protocol (ip(7P)) may Lead to a Denial of Service (DoS) Condition</title>
        <affected family="unix">
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-5716" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5716"/>
        <description>Unspecified vulnerability in the Internet Protocol (IP) functionality in Sun Solaris 10 allows local users to cause a denial of service (panic) via unspecified vectors, probably related to a UDP packet.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-11-05T11:19:05.000-05:00">
              <contributor organization="Opsware, Inc.">Pai Peng</contributor>
            </submitted>
            <status_change date="2007-11-06T13:03:43.139-05:00">DRAFT</status_change>
            <status_change date="2007-11-26T04:00:04.347-05:00">INTERIM</status_change>
            <status_change date="2007-12-17T04:00:05.181-05:00">ACCEPTED</status_change>
            <modified comment="Changed criterion to check for the patch or later being installed instead of simply checking if the patch is installed." date="2009-07-17T11:04:00.761-04:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </modified>
            <status_change date="2009-07-17T11:09:04.768-04:00">INTERIM</status_change>
            <status_change date="2009-08-03T04:00:03.743-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 103087">
          <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
          <criterion comment="Patch 118833-04 or later installed" test_ref="oval:org.mitre.oval:tst:5394"/>
          <criterion negate="true" comment="Patch 127111-02 or later installed" test_ref="oval:org.mitre.oval:tst:5429"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 103087">
          <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
          <criterion comment="Patch 118855-03 or later installed" test_ref="oval:org.mitre.oval:tst:5577"/>
          <criterion negate="true" comment="Patch 127112-02 or later installed" test_ref="oval:org.mitre.oval:tst:5048"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:3162" version="1" class="vulnerability">
      <metadata>
        <title>Security Vulnerability in RPCSEC_GSS (rpcsec_gss(3NSL)) Affects Kerberos Administration Daemon (kadmind(1M))</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <platform>Sun Solaris 9</platform>
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-3999" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3999"/>
        <description>Stack-based buffer overflow in the svcauth_gss_validate function in lib/rpc/svc_auth_gss.c in the RPCSEC_GSS RPC library (librpcsecgss) in MIT Kerberos 5 (krb5) 1.4 through 1.6.2, as used by the Kerberos administration daemon (kadmind) and some third-party applications that use krb5, allows remote attackers to cause a denial of service (daemon crash) and probably execute arbitrary code via a long string in an RPC message.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-10-31T12:34:51.000-04:00">
              <contributor organization="Opsware, Inc.">Nicholas Hansen</contributor>
            </submitted>
            <status_change date="2007-11-01T12:41:43.692-04:00">DRAFT</status_change>
            <status_change date="2007-11-16T08:14:50.135-05:00">INTERIM</status_change>
            <status_change date="2007-12-03T04:01:50.066-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND" comment="Solaris 8 (SPARC) meets Sun Alert 103060">
          <extend_definition comment="Solaris 8 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1539"/>
          <criterion negate="true" comment="Patch 126928-02 or later installed" test_ref="oval:org.mitre.oval:tst:5410"/>
          <criterion comment="Key Distribution Center (kadmind) process running" test_ref="oval:org.mitre.oval:tst:3331"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (SPARC) meets Sun Alert 103060">
          <extend_definition comment="Solaris 9 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1457"/>
          <criterion negate="true" comment="Patch 113318-32 or later installed" test_ref="oval:org.mitre.oval:tst:5371"/>
          <criterion comment="Key Distribution Center (kadmind) process running" test_ref="oval:org.mitre.oval:tst:3331"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 103060">
          <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
          <criterion negate="true" comment="Patch 126661-02 or later installed" test_ref="oval:org.mitre.oval:tst:5581"/>
          <criterion comment="Key Distribution Center (kadmind) process running" test_ref="oval:org.mitre.oval:tst:3331"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 8 (x86) meets Sun Alert 103060">
          <extend_definition comment="Solaris 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:2059"/>
          <criterion negate="true" comment="Patch 126929-02 or later installed" test_ref="oval:org.mitre.oval:tst:5434"/>
          <criterion comment="Key Distribution Center (kadmind) process running" test_ref="oval:org.mitre.oval:tst:3331"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (x86) meets Sun Alert 103060">
          <extend_definition comment="Solaris 9 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1683"/>
          <criterion negate="true" comment="Patch 117468-18 or later installed" test_ref="oval:org.mitre.oval:tst:5207"/>
          <criterion comment="Key Distribution Center (kadmind) process running" test_ref="oval:org.mitre.oval:tst:3331"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 103060">
          <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
          <criterion negate="true" comment="Patch 126662-02 or later installed" test_ref="oval:org.mitre.oval:tst:5538"/>
          <criterion comment="Key Distribution Center (kadmind) process running" test_ref="oval:org.mitre.oval:tst:3331"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:3027" version="1" class="vulnerability">
      <metadata>
        <title>Security Vulnerabilities in Solaris Kernel Statistics Retrieval Process May Allow a Denial of Service (DoS)</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <platform>Sun Solaris 9</platform>
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-5632" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5632"/>
        <description>Multiple unspecified vulnerabilities in the kernel in Sun Solaris 8 through 10 allow local users to cause a denial of service (panic), related to the support for retrieval of kernel statistics, and possibly related to the sfmmu_mlspl_enter or sfmmu_mlist_enter functions.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-10-24T12:32:39.000-04:00">
              <contributor organization="Opsware, Inc.">Nicholas Hansen</contributor>
            </submitted>
            <status_change date="2007-10-24T17:06:05.258-04:00">DRAFT</status_change>
            <status_change date="2007-11-13T12:01:11.224-05:00">INTERIM</status_change>
            <status_change date="2007-12-03T04:01:12.772-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND" comment="Solaris 8 (SPARC) meets Sun Alert 103064">
          <extend_definition comment="Solaris 8 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1539"/>
          <criterion negate="true" comment="Patch 117350-50 or later installed" test_ref="oval:org.mitre.oval:tst:5260"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (SPARC) meets Sun Alert 103064">
          <extend_definition comment="Solaris 9 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1457"/>
          <criterion negate="true" comment="Patch 122300-13 or later installed" test_ref="oval:org.mitre.oval:tst:4570"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 103064">
          <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
          <criterion negate="true" comment="Patch 127111-01 or later installed" test_ref="oval:org.mitre.oval:tst:5241"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 8 (x86) meets Sun Alert 103064">
          <extend_definition comment="Solaris 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:2059"/>
          <criterion negate="true" comment="Patch 117351-50 or later installed" test_ref="oval:org.mitre.oval:tst:5306"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (x86) meets Sun Alert 103064">
          <extend_definition comment="Solaris 9 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1683"/>
          <criterion negate="true" comment="Patch 122301-13 or later installed" test_ref="oval:org.mitre.oval:tst:5341"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 103064">
          <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
          <criterion negate="true" comment="Patch 127112-01 or later installed" test_ref="oval:org.mitre.oval:tst:5374"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:297" version="2" class="vulnerability">
      <metadata>
        <title>Solaris 10 patchadd T-patch Issue</title>
        <affected family="unix">
          <platform>Sun Solaris 10</platform>
          <product>patchadd</product>
        </affected>
        <reference source="MISC" ref_id="http://sunsolve9.sun.com/search/document.do?assetkey=1-26-101666-1&amp;searchclause="/>
        <description>The patchadd facility for Solaris 10 fails to install T-patches.  Sun sometimes releases a T-patch as a temporary version of a patch prior to the final release of that patch.  While this flaw does not directly represent a vulnerability, it does prevent the timely application of some (possibly critical) updates.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-09-22T05:52:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-09-22T20:15:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-07T09:15:45.131-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:15:52.633-04:00">ACCEPTED</status_change>
            <modified comment="Added title." date="2007-02-26T01:12:00.098-05:00">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2007-02-26T01:12:39.122-05:00">INTERIM</status_change>
            <status_change date="2007-03-21T16:17:15.226-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="OR">
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert ID 101666 criteria." negate="false">
          <criterion comment="Solaris 10 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3680"/>
          <criterion comment="sparc architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3237"/>
          <criterion comment="Patch 119254-03 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:3284"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert ID 101666 criteria." negate="false">
          <criterion comment="Solaris 10 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3680"/>
          <criterion comment="sparc architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3237"/>
          <criterion comment="Patch 119255-03 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:3698"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:2226" version="1" class="vulnerability">
      <metadata>
        <title>Security Vulnerability in Solaris 10 BIND: Susceptible to Cache Poisoning Attack</title>
        <affected family="unix">
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-2926" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2926"/>
        <description>ISC BIND 9 through 9.5.0a5 uses a weak random number generator during generation of DNS query ids when answering resolver questions or sending NOTIFY messages to slave name servers, which makes it easier for remote attackers to guess the next query id and perform DNS cache poisoning.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-08-23T13:32:59.000-04:00">
              <contributor organization="Opsware, Inc.">Nicholas Hansen</contributor>
            </submitted>
            <status_change date="2007-08-24T08:19:39.287-04:00">DRAFT</status_change>
            <status_change date="2007-09-10T14:45:26.976-04:00">INTERIM</status_change>
            <status_change date="2007-09-27T08:57:47.043-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 103018" negate="false">
          <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
          <criterion comment="BIND DNS Name server (SUNWbind) is installed" test_ref="oval:org.mitre.oval:tst:4225" negate="false"/>
          <criterion comment="Patch 119783-05 or later installed" test_ref="oval:org.mitre.oval:tst:3255" negate="true"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 103018" negate="false">
          <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
          <criterion comment="BIND DNS Name server (SUNWbind) installed" test_ref="oval:org.mitre.oval:tst:4225" negate="false"/>
          <criterion comment="Patch 119784-05 or later installed" test_ref="oval:org.mitre.oval:tst:3372" negate="true"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:2223" version="1" class="vulnerability">
      <metadata>
        <title>Local Users May be Able to Hang Systems That Have Loaded The Kernel Debugger kmdb(1)</title>
        <affected family="unix">
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-3782" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-3782"/>
        <description>Unspecified vulnerability in the kernel debugger (kmdb) in Sun Solaris 10, when running on x86, allows local users to cause a denial of service (system hang) via unspecified vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-08-10T12:25:26.000-04:00">
              <contributor organization="Opsware, Inc.">Pai Peng</contributor>
            </submitted>
            <status_change date="2007-08-13T13:57:14.041-04:00">DRAFT</status_change>
            <status_change date="2007-09-06T09:13:32.678-04:00">INTERIM</status_change>
            <status_change date="2007-09-27T08:57:46.961-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 102512" negate="false">
          <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
          <criterion comment="Patch 118855-15 or later installed" test_ref="oval:org.mitre.oval:tst:3399" negate="true"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:2214" version="1" class="vulnerability">
      <metadata>
        <title>A Security Vulnerability in the Handling of Thread Contexts in the Solaris Kernel May Allow a Denial of Service (DoS)</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <platform>Sun Solaris 9</platform>
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-5132" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5132"/>
        <description>Race condition in the kernel in Sun Solaris 8 through 10 allows local users to cause a denial of service (panic) via unspecified vectors related to "the handling of thread contexts."</description>
        <oval_repository>
          <dates>
            <submitted date="2007-09-28T13:02:59.000-04:00">
              <contributor organization="Opsware, Inc.">Nicholas Hansen</contributor>
            </submitted>
            <status_change date="2007-10-02T08:04:40.234-04:00">DRAFT</status_change>
            <status_change date="2007-10-18T21:59:20.303-04:00">INTERIM</status_change>
            <status_change date="2007-11-02T07:17:42.208-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND" comment="Solaris 8 (SPARC) meets Sun Alert 103084" negate="false">
          <extend_definition comment="Solaris 8 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1539"/>
          <criterion comment="Patch 117350-48 or later installed" test_ref="oval:org.mitre.oval:tst:4094" negate="true"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (SPARC) meets Sun Alert 103084" negate="false">
          <extend_definition comment="Solaris 9 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1457"/>
          <criterion comment="Patch 122300-10 or later installed" test_ref="oval:org.mitre.oval:tst:3262" negate="true"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 103084" negate="false">
          <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
          <criterion comment="Patch 125100-02 or later installed" test_ref="oval:org.mitre.oval:tst:3554" negate="true"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 8 (x86) meets Sun Alert 103084" negate="false">
          <extend_definition comment="Solaris 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:2059"/>
          <criterion comment="Patch 117351-48 or later installed" test_ref="oval:org.mitre.oval:tst:4106" negate="true"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (x86) meets Sun Alert 103084" negate="false">
          <extend_definition comment="Solaris 9 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1683"/>
          <criterion comment="Patch 122301-10 or later installed" test_ref="oval:org.mitre.oval:tst:4263" negate="true"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 103084" negate="false">
          <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
          <criterion comment="Patch 125101-02 or later installed" test_ref="oval:org.mitre.oval:tst:3275" negate="true"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:2205" version="1" class="vulnerability">
      <metadata>
        <title>Security Vulnerability in X Display Manager (xdm(1)) Xsession Script</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <platform>Sun Solaris 9</platform>
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-5215" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-5215"/>
        <description>The Xsession script, as used by X Display Manager (xdm) in NetBSD before 20060212, X.Org before 20060317, and Solaris 8 through 10 before 20061006, allows local users to overwrite arbitrary files, or read another user's Xsession errors file, via a symlink attack on a /tmp/xses-$USER file.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-08-10T12:25:23.000-04:00">
              <contributor organization="Opsware, Inc.">Pai Peng</contributor>
            </submitted>
            <status_change date="2007-08-13T13:57:13.067-04:00">DRAFT</status_change>
            <status_change date="2007-09-06T09:13:32.233-04:00">INTERIM</status_change>
            <status_change date="2007-09-27T08:57:46.256-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND" comment="Solaris 8 (SPARC) meets Sun Alert 102652" negate="false">
          <extend_definition comment="Solaris 8 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1539"/>
          <criterion comment="Patch 111844-04 or later installed" test_ref="oval:org.mitre.oval:tst:3324" negate="true"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (SPARC) meets Sun Alert 102652" negate="false">
          <extend_definition comment="Solaris 9 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1457"/>
          <criterion comment="Patch 124830-01 or later installed" test_ref="oval:org.mitre.oval:tst:3994" negate="true"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 102652" negate="false">
          <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
          <criterion comment="Patch 124457-01 or later installed" test_ref="oval:org.mitre.oval:tst:3954" negate="true"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 8 (x86) meets Sun Alert 102652" negate="false">
          <extend_definition comment="Solaris 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:2059"/>
          <criterion comment="Patch 111845-04 or later installed" test_ref="oval:org.mitre.oval:tst:4176" negate="true"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (x86) meets Sun Alert 102652" negate="false">
          <extend_definition comment="Solaris 9 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1683"/>
          <criterion comment="Patch 124831-01 or later installed" test_ref="oval:org.mitre.oval:tst:3585" negate="true"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 102652" negate="false">
          <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
          <criterion comment="Patch 124458-01 or later installed" test_ref="oval:org.mitre.oval:tst:3425" negate="true"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:2202" version="1" class="vulnerability">
      <metadata>
        <title>Security Vulnerability in the in.telnetd(1M) Daemon May Allow Unauthorized Remote Users to Gain Access to a Solaris Host</title>
        <affected family="unix">
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-0882" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0882"/>
        <description>Argument injection vulnerability in the telnet daemon (in.telnetd) in Solaris 10 and 11 (SunOS 5.10 and 5.11) misinterprets certain client "-f" sequences as valid requests for the login program to skip authentication, which allows remote attackers to log into certain accounts, as demonstrated by the bin account.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-08-10T12:25:19.000-04:00">
              <contributor organization="Opsware, Inc.">Pai Peng</contributor>
            </submitted>
            <status_change date="2007-08-13T13:57:11.422-04:00">DRAFT</status_change>
            <status_change date="2007-09-06T09:13:32.140-04:00">INTERIM</status_change>
            <status_change date="2007-09-27T08:57:46.156-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 102802" negate="false">
          <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
          <criterion comment="Patch 120068-02 or later installed" test_ref="oval:org.mitre.oval:tst:3727" negate="true"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 102802" negate="false">
          <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
          <criterion comment="Patch 120069-02 or later installed" test_ref="oval:org.mitre.oval:tst:3199" negate="true"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:2199" version="1" class="vulnerability">
      <metadata>
        <title>Security Vulnerability in the Solaris 10 TCP Fusion Code May Lead to a System Panic, Resulting in a Denial of Service (DoS)</title>
        <affected family="unix">
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-5396" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-5396"/>
        <description>The tcp_fuse_rcv_drain function in the Sun Solaris 10 kernel before 20061017, when TCP Fusion is enabled, allows local users to cause a denial of service (system crash) via a TCP loopback connection with both endpoints on the same system.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-08-10T12:25:23.000-04:00">
              <contributor organization="Opsware, Inc.">Pai Peng</contributor>
            </submitted>
            <status_change date="2007-08-13T13:57:12.927-04:00">DRAFT</status_change>
            <status_change date="2007-09-06T09:13:32.000-04:00">INTERIM</status_change>
            <status_change date="2007-09-27T08:57:45.983-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 102667" negate="false">
          <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
          <criterion comment="Patch 118833-23 or later installed" test_ref="oval:org.mitre.oval:tst:3263" negate="true"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 102667" negate="false">
          <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
          <criterion comment="Patch 118855-19 or later installed" test_ref="oval:org.mitre.oval:tst:3362" negate="true"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:219" version="6" class="vulnerability">
      <metadata>
        <title>Sun Solaris Unspecified x86 64 Bit Local Denial Of ServiceVulnerability</title>
        <affected family="unix">
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-0516" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0516"/>
        <description>Unspecified vulnerability in the kernel processing in Solaris 10 64 bit platform, when running in 64-bit mode, allows local users to cause a denial of service (system panic) via unknown attack vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-09-22T05:52:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-09-25T12:47:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-10T20:39:58.679-04:00">INTERIM</status_change>
            <status_change date="2006-10-31T19:35:30.871-05:00">ACCEPTED</status_change>
            <modified comment="Added title. Implemented by Jon Baker of The MITRE Corporation." date="2007-02-13T14:50:00.900-05:00">
              <contributor organization="Security-Database">Nabil Ouchn</contributor>
            </modified>
            <status_change date="2007-02-13T14:50:50.923-05:00">INTERIM</status_change>
            <status_change date="2007-03-21T16:17:12.403-04:00">ACCEPTED</status_change>
            <modified comment="Added datatype to bits entity on an isainfo_state.  Datatype set to int." date="2010-09-02T21:09:00.853-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2010-09-02T21:11:44.313-04:00">INTERIM</status_change>
            <status_change date="2010-09-20T04:00:19.873-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:219 - Various corrections to comments and products to align with Authoring Style Guide" date="2011-04-22T23:54:00.899-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-04-23T00:04:57.460-04:00">INTERIM</status_change>
            <status_change date="2011-05-09T04:01:27.252-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="AND" comment="Software section">
          <criterion comment="Solaris 10 Installed" test_ref="oval:org.mitre.oval:tst:3955"/>
          <criterion comment="ix86 architecture" test_ref="oval:org.mitre.oval:tst:3338"/>
          <criterion negate="true" comment="Patch 118844-14 or later installed" test_ref="oval:org.mitre.oval:tst:3195"/>
        </criteria>
        <criteria operator="AND" comment="Configuration section">
          <criterion comment="system is running in 64-bit mode" test_ref="oval:org.mitre.oval:tst:3884"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:2173" version="1" class="vulnerability">
      <metadata>
        <title>A Security Vulnerability With the Special File System (SPECFS) strfreectty() Function May Allow a Local Unprivileged User to Panic a System</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <platform>Sun Solaris 9</platform>
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-4732" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4732"/>
        <description>Unspecified vulnerability in the strfreectty function in the Special File System (SPECFS) in Sun Solaris 8 through 10 allows local users to cause a denial of service (system panic), related to passing a NULL pointer to the pgsignal function.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-09-10T09:34:14.000-04:00">
              <contributor organization="Opsware, Inc.">Todd Dolinsky</contributor>
            </submitted>
            <status_change date="2007-09-10T14:41:52.544-04:00">DRAFT</status_change>
            <status_change date="2007-09-27T08:57:45.669-04:00">INTERIM</status_change>
            <status_change date="2007-10-12T07:56:14.294-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND" comment="Solaris 8 (SPARC) meets Sun Alert 103009" negate="false">
          <extend_definition comment="Solaris 8 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1539"/>
          <criterion comment="Patch 109025-07 or later installed" test_ref="oval:org.mitre.oval:tst:4230" negate="true"/>
          <criterion comment="Patch 117350-49 or later installed" test_ref="oval:org.mitre.oval:tst:3903" negate="true"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (SPARC) meets Sun Alert 103009" negate="false">
          <extend_definition comment="Solaris 9 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1457"/>
          <criterion comment="Patch 122300-11 or later installed" test_ref="oval:org.mitre.oval:tst:3307" negate="true"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 103009" negate="false">
          <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
          <criterion comment="Patch 118822-24 or later installed" test_ref="oval:org.mitre.oval:tst:3780" negate="true"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 8 (x86) meets Sun Alert 103009" negate="false">
          <extend_definition comment="Solaris 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:2059"/>
          <criterion comment="Patch 109026-08 or later installed" test_ref="oval:org.mitre.oval:tst:3708" negate="true"/>
          <criterion comment="Patch 117351-49 or later installed" test_ref="oval:org.mitre.oval:tst:3841" negate="true"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (x86) meets Sun Alert 103009" negate="false">
          <extend_definition comment="Solaris 9 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1683"/>
          <criterion comment="Patch 122301-11 or later installed" test_ref="oval:org.mitre.oval:tst:3697" negate="true"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 103009" negate="false">
          <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
          <criterion comment="Patch 118844-24 or later installed" test_ref="oval:org.mitre.oval:tst:4200" negate="true"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:2170" version="1" class="vulnerability">
      <metadata>
        <title>Security Vulnerability in Solaris Named Pipes (pipe(2)) May Allow Unauthorized Data Access</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <platform>Sun Solaris 9</platform>
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-5225" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5225"/>
        <description>Integer signedness error in FIFO filesystems (named pipes) on Sun Solaris 8 through 10 allows local users to read the contents of unspecified memory locations via a negative maximum length value to the I_PEEK ioctl.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-10-10T07:52:08.000-04:00">
              <contributor organization="Opsware, Inc.">Nicholas Hansen</contributor>
            </submitted>
            <status_change date="2007-10-10T13:53:56.913-04:00">DRAFT</status_change>
            <status_change date="2007-10-25T13:04:40.663-04:00">INTERIM</status_change>
            <status_change date="2007-11-13T12:01:06.734-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND" comment="Solaris 8 (SPARC) meets Sun Alert 103061">
          <extend_definition comment="Solaris 8 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1539"/>
          <criterion negate="true" comment="Patch 109454-06 or later installed" test_ref="oval:org.mitre.oval:tst:4308"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (SPARC) meets Sun Alert 103061">
          <extend_definition comment="Solaris 9 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1457"/>
          <criterion negate="true" comment="Patch 117471-04 or later installed" test_ref="oval:org.mitre.oval:tst:3569"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 103061">
          <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
          <criterion negate="true" comment="Patch 127737-01 or later installed" test_ref="oval:org.mitre.oval:tst:4494"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 8 (x86) meets Sun Alert 103061">
          <extend_definition comment="Solaris 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:2059"/>
          <criterion negate="true" comment="Patch 109455-06 or later installed" test_ref="oval:org.mitre.oval:tst:4095"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (x86) meets Sun Alert 103061">
          <extend_definition comment="Solaris 9 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1683"/>
          <criterion negate="true" comment="Patch 117472-04 or later installed" test_ref="oval:org.mitre.oval:tst:4375"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 103061">
          <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
          <criterion negate="true" comment="Patch 127738-01 or later installed" test_ref="oval:org.mitre.oval:tst:4523"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:2164" version="1" class="vulnerability">
      <metadata>
        <title>Security Vulnerability Due to Buffer Overflow in The format(1M) Command May Allow Privilege Elevation For Certain RBAC Profiles</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <platform>Sun Solaris 9</platform>
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-4319" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-4319"/>
        <description>Buffer overflow in the format command in Solaris 8, 9, and 10 allows local users with access to format (such as the "File System Management" RBAC profile) to execute arbitrary code via unknown vectors, a different vulnerability than CVE-2006-4307.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-08-10T12:25:25.000-04:00">
              <contributor organization="Opsware, Inc.">Pai Peng</contributor>
            </submitted>
            <status_change date="2007-08-13T13:57:13.779-04:00">DRAFT</status_change>
            <status_change date="2007-09-06T09:13:31.628-04:00">INTERIM</status_change>
            <status_change date="2007-09-27T08:57:45.469-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND" comment="Solaris 8 (SPARC) meets Sun Alert 102519" negate="false">
          <extend_definition comment="Solaris 8 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1539"/>
          <criterion comment="Patch 108975-10 or later installed" test_ref="oval:org.mitre.oval:tst:3837" negate="true"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (SPARC) meets Sun Alert 102519" negate="false">
          <extend_definition comment="Solaris 9 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1457"/>
          <criterion comment="Patch 113072-08 or later installed" test_ref="oval:org.mitre.oval:tst:4119" negate="true"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 102519" negate="false">
          <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
          <criterion comment="Patch 118833-18 or later installed" test_ref="oval:org.mitre.oval:tst:3220" negate="true"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 8 (x86) meets Sun Alert 102519" negate="false">
          <extend_definition comment="Solaris 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:2059"/>
          <criterion comment="Patch 108976-10 or later installed" test_ref="oval:org.mitre.oval:tst:3332" negate="true"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (x86) meets Sun Alert 102519" negate="false">
          <extend_definition comment="Solaris 9 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1683"/>
          <criterion comment="Patch 114423-07 or later installed" test_ref="oval:org.mitre.oval:tst:3870" negate="true"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 102519" negate="false">
          <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
          <criterion comment="Patch 118997-09 or later installed" test_ref="oval:org.mitre.oval:tst:3445" negate="true"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:2143" version="1" class="vulnerability">
      <metadata>
        <title>Security Vulnerability in the Solaris libsldap Library May Allow a Denial of Service to nscd(1M)</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <platform>Sun Solaris 9</platform>
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-3458" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3458"/>
        <description>The libsldap library in Sun Solaris 8, 9, and 10 allows local users to cause a denial of service (Name Service Caching Daemon (nscd) crash) via unspecified vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-08-10T12:25:18.000-04:00">
              <contributor organization="Opsware, Inc.">Pai Peng</contributor>
            </submitted>
            <status_change date="2007-08-13T13:57:11.150-04:00">DRAFT</status_change>
            <status_change date="2007-09-06T09:13:31.197-04:00">INTERIM</status_change>
            <status_change date="2007-09-27T08:57:45.094-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND" comment="Solaris 8 (SPARC) meets Sun Alert 102926" negate="false">
          <extend_definition comment="Solaris 8 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1539"/>
          <criterion comment="Patch 126373-02 or later installed" test_ref="oval:org.mitre.oval:tst:3188" negate="true"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (SPARC) meets Sun Alert 102926" negate="false">
          <extend_definition comment="Solaris 9 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1457"/>
          <criterion comment="Patch 112960-40 or later installed" test_ref="oval:org.mitre.oval:tst:3433" negate="true"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 102926" negate="false">
          <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
          <criterion comment="Patch 120036-07 or later installed" test_ref="oval:org.mitre.oval:tst:3274" negate="true"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 8 (x86) meets Sun Alert 102926" negate="false">
          <extend_definition comment="Solaris 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:2059"/>
          <criterion comment="Patch 126374-02 or later installed" test_ref="oval:org.mitre.oval:tst:3728" negate="true"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (x86) meets Sun Alert 102926" negate="false">
          <extend_definition comment="Solaris 9 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1683"/>
          <criterion comment="Patch 114242-27 or later installed" test_ref="oval:org.mitre.oval:tst:3171" negate="true"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 102926" negate="false">
          <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
          <criterion comment="Patch 120037-07 or later installed" test_ref="oval:org.mitre.oval:tst:4079" negate="true"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:2121" version="1" class="vulnerability">
      <metadata>
        <title>Security Vulnerabilities in Solaris ld.so.1(1) may Lead to Execution of Arbitrary Code with Elevated Privileges</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <platform>Sun Solaris 9</platform>
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-6494" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-6494"/>
        <description>Directory traversal vulnerability in ld.so.1 in Sun Solaris 8, 9, and 10 allows local users to execute arbitrary code via a .. (dot dot) sequence in the LANG environment variable that points to a locale file containing attacker-controlled format string specifiers.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-08-10T12:25:21.000-04:00">
              <contributor organization="Opsware, Inc.">Pai Peng</contributor>
            </submitted>
            <status_change date="2007-08-13T13:57:12.395-04:00">DRAFT</status_change>
            <status_change date="2007-09-06T09:13:30.885-04:00">INTERIM</status_change>
            <status_change date="2007-09-27T08:57:44.757-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND" comment="Solaris 8 (SPARC) meets Sun Alert 102724" negate="false">
          <extend_definition comment="Solaris 8 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1539"/>
          <criterion comment="Patch 109147-42 or later installed" test_ref="oval:org.mitre.oval:tst:3395" negate="true"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (SPARC) meets Sun Alert 102724" negate="false">
          <extend_definition comment="Solaris 9 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1457"/>
          <criterion comment="Patch 112963-27 or later installed" test_ref="oval:org.mitre.oval:tst:3790" negate="true"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 102724" negate="false">
          <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
          <criterion comment="Patch 124922-01 or later installed" test_ref="oval:org.mitre.oval:tst:3922" negate="true"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 8 (x86) meets Sun Alert 102724" negate="false">
          <extend_definition comment="Solaris 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:2059"/>
          <criterion comment="Patch 109148-41 or later installed" test_ref="oval:org.mitre.oval:tst:3236" negate="true"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (x86) meets Sun Alert 102724" negate="false">
          <extend_definition comment="Solaris 9 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1683"/>
          <criterion comment="Patch 113986-22 or later installed" test_ref="oval:org.mitre.oval:tst:3819" negate="true"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 102724" negate="false">
          <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
          <criterion comment="Patch 124923-01 or later installed" test_ref="oval:org.mitre.oval:tst:3173" negate="true"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:2120" version="1" class="vulnerability">
      <metadata>
        <title>A Security Vulnerability in the TCP Implementation of Solaris 10 Systems May Result in a System Panic Under High TCP/IP Traffic</title>
        <affected family="unix">
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-0914" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0914"/>
        <description>Race condition in the TCP subsystem for Solaris 10 allows remote attackers to cause a denial of service (system panic) via unknown vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-06-28T09:00:00.000-04:00">
              <contributor organization="Opsware, Inc.">Gyesi Amaniampong</contributor>
            </submitted>
            <status_change date="2007-06-29T09:24:19.159-04:00">DRAFT</status_change>
            <status_change date="2007-07-16T09:55:14.965-04:00">INTERIM</status_change>
            <status_change date="2007-08-01T22:26:15.758-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="OR">
        <criteria operator="AND" comment="Solaris 10 (SPARC)" negate="false">
          <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
          <criterion comment="Patch 119998-01 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:3448"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86)" negate="false">
          <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
          <criterion comment="Patch 119999-01 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:3655"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:2099" version="1" class="vulnerability">
      <metadata>
        <title>Vulnerability With Solaris IPv6 May Allow a Remote User the Ability to Create a Denial of Service Condition</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <platform>Sun Solaris 9</platform>
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-5073" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-5073"/>
        <description>Unspecified vulnerability in Sun Solaris 8, 9 and 10 allows remote attackers to cause a denial of service (panic) via crafted IPv6 packets, a different vulnerability than CVE-2006-5013.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-08-10T12:25:24.000-04:00">
              <contributor organization="Opsware, Inc.">Pai Peng</contributor>
            </submitted>
            <status_change date="2007-08-13T13:57:13.314-04:00">DRAFT</status_change>
            <status_change date="2007-09-06T09:13:30.639-04:00">INTERIM</status_change>
            <status_change date="2007-09-27T08:57:44.301-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND" comment="Solaris 8 (SPARC) meets Sun Alert 102144" negate="false">
          <extend_definition comment="Solaris 8 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1539"/>
          <criterion comment="Patch 116965-22 or later installed" test_ref="oval:org.mitre.oval:tst:3455" negate="true"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (SPARC) meets Sun Alert 102144" negate="false">
          <extend_definition comment="Solaris 9 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1457"/>
          <criterion comment="Patch 114344-20 or later installed" test_ref="oval:org.mitre.oval:tst:4036" negate="true"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 102144" negate="false">
          <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
          <criterion comment="Patch 119075-13 or later installed" test_ref="oval:org.mitre.oval:tst:3800" negate="true"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 8 (x86) meets Sun Alert 102144" negate="false">
          <extend_definition comment="Solaris 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:2059"/>
          <criterion comment="Patch 116966-21 or later installed" test_ref="oval:org.mitre.oval:tst:4061" negate="true"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (x86) meets Sun Alert 102144" negate="false">
          <extend_definition comment="Solaris 9 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1683"/>
          <criterion comment="Patch 119435-10 or later installed" test_ref="oval:org.mitre.oval:tst:3968" negate="true"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 102144" negate="false">
          <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
          <criterion comment="Patch 119076-11 or later installed" test_ref="oval:org.mitre.oval:tst:3217" negate="true"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:2096" version="1" class="vulnerability">
      <metadata>
        <title>Security Vulnerability in the Solaris Auditing (BSM) Related to Network Auditing May Lead to Denial of Service (DoS)</title>
        <affected family="unix">
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-5422" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5422"/>
        <description>Unspecified vulnerability in "Solaris Auditing" in the Basic Security Module (BSM) in Sun Solaris 10, when configured for auditing of networking (nt) events, allows local users to cause a denial of service (panic) via unspecified vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-10-16T10:34:50.000-04:00">
              <contributor organization="Opsware, Inc.">Todd Dolinsky</contributor>
            </submitted>
            <status_change date="2007-10-16T14:50:57.377-04:00">DRAFT</status_change>
            <status_change date="2007-11-02T07:17:37.733-04:00">INTERIM</status_change>
            <status_change date="2007-11-19T04:00:56.246-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software and Configuration sections" operator="AND">
        <criteria operator="OR" comment="Software Section">
          <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 103096" negate="false">
            <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
            <criterion comment="Patch 127111-01 or later installed" test_ref="oval:org.mitre.oval:tst:3953" negate="true"/>
          </criteria>
          <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 103096" negate="false">
            <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
            <criterion comment="Patch 127112-01 or later installed" test_ref="oval:org.mitre.oval:tst:4336" negate="true"/>
          </criteria>
        </criteria>
        <criterion comment="Solaris auditing is enabled" negate="false" test_ref="oval:org.mitre.oval:tst:4548"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:2078" version="1" class="vulnerability">
      <metadata>
        <title>Security Vulnerabilities in The Solaris Event Port API May Result in a Denial of Service (DoS) Condition</title>
        <affected family="unix">
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-3781" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-3781"/>
        <description>Unspecified vulnerability in Sun Solaris 10 allows context-dependent attackers to cause a denial of service (panic) via unspecified vectors involving the event port API.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-08-10T12:25:26.000-04:00">
              <contributor organization="Opsware, Inc.">Pai Peng</contributor>
            </submitted>
            <status_change date="2007-08-13T13:57:14.069-04:00">DRAFT</status_change>
            <status_change date="2007-09-06T09:13:29.992-04:00">INTERIM</status_change>
            <status_change date="2007-09-27T08:57:43.586-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 102485" negate="false">
          <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
          <criterion comment="Patch 118833-12 or later installed" test_ref="oval:org.mitre.oval:tst:3185" negate="true"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 102485" negate="false">
          <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
          <criterion comment="Patch 118855-10 or later installed" test_ref="oval:org.mitre.oval:tst:4131" negate="true"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:2038" version="1" class="vulnerability">
      <metadata>
        <title>Security Vulnerabilities in the tip(1) Command May Allow Execution of Arbitrary Code With Elevated Privileges</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <platform>Sun Solaris 9</platform>
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-0470" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0470"/>
        <description>Multiple unspecified vulnerabilities in tip in Sun Solaris 8, 9, and 10 allow local users to gain uucp account privileges via unspecified vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-08-10T12:25:20.000-04:00">
              <contributor organization="Opsware, Inc.">Pai Peng</contributor>
            </submitted>
            <status_change date="2007-08-13T13:57:11.835-04:00">DRAFT</status_change>
            <status_change date="2007-09-06T09:13:29.716-04:00">INTERIM</status_change>
            <status_change date="2007-09-27T08:57:43.199-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND" comment="Solaris 8 (SPARC) meets Sun Alert 102773" negate="false">
          <extend_definition comment="Solaris 8 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1539"/>
          <criterion comment="Patch 111504-02 or later installed" test_ref="oval:org.mitre.oval:tst:3623" negate="true"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (SPARC) meets Sun Alert 102773" negate="false">
          <extend_definition comment="Solaris 9 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1457"/>
          <criterion comment="Patch 123368-01 or later installed" test_ref="oval:org.mitre.oval:tst:3805" negate="true"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 102773" negate="false">
          <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
          <criterion comment="Patch 124997-01 or later installed" test_ref="oval:org.mitre.oval:tst:3829" negate="true"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 8 (x86) meets Sun Alert 102773" negate="false">
          <extend_definition comment="Solaris 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:2059"/>
          <criterion comment="Patch 111505-02 or later installed" test_ref="oval:org.mitre.oval:tst:3755" negate="true"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (x86) meets Sun Alert 102773" negate="false">
          <extend_definition comment="Solaris 9 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1683"/>
          <criterion comment="Patch 123369-01 or later installed" test_ref="oval:org.mitre.oval:tst:3273" negate="true"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 102773" negate="false">
          <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
          <criterion comment="Patch 124998-01 or later installed" test_ref="oval:org.mitre.oval:tst:4023" negate="true"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:2032" version="3" class="vulnerability">
      <metadata>
        <title>A Security Vulnerability in the Solaris 10 inetd(1M) Service May Lead to a Denial of Service (DoS) Condition</title>
        <affected family="unix">
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-2990" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2990"/>
        <description>Unspecified vulnerability in inetd in Sun Solaris 10 before 20070529 allows local users to cause a denial of service (daemon termination) via unspecified manipulations of the /var/run/.inetd.uds Unix domain socket file.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-06-06T11:47:00.000-04:00">
              <contributor organization="Opsware, Inc.">Pai Peng</contributor>
            </submitted>
            <status_change date="2007-06-06T14:28:00.000-04:00">DRAFT</status_change>
            <status_change date="2007-06-22T08:57:42.624-04:00">INTERIM</status_change>
            <status_change date="2007-07-10T21:08:50.809-04:00">ACCEPTED</status_change>
            <modified comment="Fixed incorrect user_id element value in process_state.  Incorrect value was 'root', updated to value of '0'." date="2010-09-02T15:11:00.501-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2010-09-02T15:13:55.102-04:00">INTERIM</status_change>
            <status_change date="2010-09-20T04:00:19.273-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="OR">
          <criteria operator="AND" comment="Solaris 10 (SPARC)" negate="false">
            <criterion comment="Solaris 10 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3680"/>
            <criterion comment="sparc architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3237"/>
            <criterion comment="Patch 121288-03 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:3934"/>
          </criteria>
          <criteria operator="AND" comment="Solaris 10 (x86)" negate="false">
            <criterion comment="Solaris 10 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3680"/>
            <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3912"/>
            <criterion comment="Patch 121289-04 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:3679"/>
          </criteria>
        </criteria>
        <criterion comment="inetd running" negate="false" test_ref="oval:org.mitre.oval:tst:3135"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:2021" version="1" class="vulnerability">
      <metadata>
        <title>Security Vulnerability in the Human Interface Device (HID) Class Driver for Solaris</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <platform>Sun Solaris 9</platform>
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-5118" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5118"/>
        <description>Unspecified vulnerability in the HID (Human Interface Device) class driver in Sun Solaris 8, 9, and 10 before 20070925 allows local users to cause a denial of service (panic) via unspecified vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-09-28T13:03:00.000-04:00">
              <contributor organization="Opsware, Inc.">Nicholas Hansen</contributor>
            </submitted>
            <status_change date="2007-10-02T08:04:40.419-04:00">DRAFT</status_change>
            <status_change date="2007-10-18T21:59:19.829-04:00">INTERIM</status_change>
            <status_change date="2007-11-02T07:17:35.588-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND" comment="Solaris 8 (SPARC) meets Sun Alert 102883" negate="false">
          <extend_definition comment="Solaris 8 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1539"/>
          <criterion comment="Patch 109896-35 or later installed" test_ref="oval:org.mitre.oval:tst:3285" negate="true"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (SPARC) meets Sun Alert 102883" negate="false">
          <extend_definition comment="Solaris 9 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1457"/>
          <criterion comment="Patch 115553-28 or later installed" test_ref="oval:org.mitre.oval:tst:4284" negate="true"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 102883" negate="false">
          <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
          <criterion comment="Patch 125123-01 or later installed" test_ref="oval:org.mitre.oval:tst:3599" negate="true"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (x86) meets Sun Alert 102883" negate="false">
          <extend_definition comment="Solaris 9 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1683"/>
          <criterion comment="Patch 115554-24 or later installed" test_ref="oval:org.mitre.oval:tst:4255" negate="true"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 102883" negate="false">
          <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
          <criterion comment="Patch 125124-01 or later installed" test_ref="oval:org.mitre.oval:tst:4246" negate="true"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:2015" version="1" class="vulnerability">
      <metadata>
        <title>dtsession(1X) Contains a Buffer Overflow Vulnerability</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <platform>Sun Solaris 9</platform>
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-3471" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3471"/>
        <description>Buffer overflow in the dtsession Common Desktop Environment (CDE) Session Manager in Sun Solaris 8, 9, and 10 allows local users to execute arbitrary code via unspecified vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-07-03T09:00:00.000-04:00">
              <contributor organization="Opsware, Inc.">Yuzheng Zhou</contributor>
            </submitted>
            <status_change date="2007-07-03T21:46:26.557-04:00">DRAFT</status_change>
            <status_change date="2007-07-18T15:57:52.224-04:00">INTERIM</status_change>
            <status_change date="2007-08-02T14:47:15.305-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="OR">
        <criteria operator="AND" comment="Solaris 8 (SPARC)" negate="false">
          <extend_definition comment="Solaris 8 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1539"/>
          <criterion comment="Patch 109354-26 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:3656"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 8 (x86)" negate="false">
          <extend_definition comment="Solaris 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:2059"/>
          <criterion comment="Patch 109355-25 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:3474"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (SPARC)" negate="false">
          <extend_definition comment="Solaris 9 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1457"/>
          <criterion comment="Patch 113240-13 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:3196"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (x86)" negate="false">
          <extend_definition comment="Solaris 9 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1683"/>
          <criterion comment="Patch 113241-13 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:3818"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (SPARC)" negate="false">
          <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
          <criterion comment="Patch 125279-02 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:3803"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86)" negate="false">
          <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
          <criterion comment="Patch 125280-02 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:3725"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:2010" version="1" class="vulnerability">
      <metadata>
        <title>pkgadd(1M) May Set Incorrect Permissions if The pkgmap(4) File Contains a "?" in The "Mode" Field</title>
        <affected family="unix">
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-4439" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-4439"/>
        <description>pkgadd in Sun Solaris 10 before 20060825 installs files with insecure file and directory permissions (755 or 777) if the pkgmap file contains a "?" (question mark) in the mode field, which allows local users to modify arbitrary files or directories, a different vulnerability than CVE-2002-1871.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-08-10T12:25:25.000-04:00">
              <contributor organization="Opsware, Inc.">Pai Peng</contributor>
            </submitted>
            <status_change date="2007-08-13T13:57:13.656-04:00">DRAFT</status_change>
            <status_change date="2007-09-06T09:13:29.485-04:00">INTERIM</status_change>
            <status_change date="2007-09-27T08:57:42.976-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 102513" negate="false">
          <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
          <criterion comment="Patch 119254-26 or later installed" test_ref="oval:org.mitre.oval:tst:3525" negate="true"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 102513" negate="false">
          <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
          <criterion comment="Patch 119255-26 or later installed" test_ref="oval:org.mitre.oval:tst:3358" negate="true"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1989" version="1" class="vulnerability">
      <metadata>
        <title>Security Vulnerability in the vuidmice(7M) STREAMS Modules May Lead to a Denial of Service (DoS) Condition</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <platform>Sun Solaris 9</platform>
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-5319" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5319"/>
        <description>Unspecified vulnerability in the vuidmice STREAMS modules in Sun Solaris 8, 9, and 10 allows local users with console (/dev/console) access to cause a denial of service ("unusable" system console) via unspecified vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-10-10T07:52:08.000-04:00">
              <contributor organization="Opsware, Inc.">Nicholas Hansen</contributor>
            </submitted>
            <status_change date="2007-10-10T13:53:56.573-04:00">DRAFT</status_change>
            <status_change date="2007-10-25T13:04:40.350-04:00">INTERIM</status_change>
            <status_change date="2007-11-13T12:01:04.274-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND" comment="Solaris 8 (x86) meets Sun Alert 103065">
          <extend_definition comment="Solaris 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:2059"/>
          <criterion negate="true" comment="Patch 114154-02 or later installed" test_ref="oval:org.mitre.oval:tst:4419"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (x86) meets Sun Alert 103065">
          <extend_definition comment="Solaris 9 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1683"/>
          <criterion negate="true" comment="Patch 117419-03 or later installed" test_ref="oval:org.mitre.oval:tst:3534"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 103065">
          <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
          <criterion negate="true" comment="Patch 127751-01 or later installed" test_ref="oval:org.mitre.oval:tst:4460"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1980" version="1" class="vulnerability">
      <metadata>
        <title>Multiple vulnerabilities in libfreetype, Xsun(1) and Xorg(1)</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <platform>Sun Solaris 9</platform>
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-1003" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1003"/>
        <description>Integer overflow in ALLOCATE_LOCAL in the ProcXCMiscGetXIDList function in the XC-MISC extension in the X.Org X11 server (xserver) 7.1-1.1.0, and other versions before 20070403, allows remote authenticated users to execute arbitrary code via a large expression, which results in memory corruption.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-07-30T08:16:45.000-04:00">
              <contributor organization="Opsware, Inc.">Pai Peng</contributor>
            </submitted>
            <status_change date="2007-08-01T22:21:20.780-04:00">DRAFT</status_change>
            <status_change date="2007-08-20T08:04:39.670-04:00">INTERIM</status_change>
            <status_change date="2007-09-06T09:13:29.249-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND" comment="Solaris 8 (SPARC) meets Sun Alert 102886" negate="false">
          <extend_definition comment="Solaris 8 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1539"/>
          <criterion comment="Patch 119067-07 or later installed" test_ref="oval:org.mitre.oval:tst:3167" negate="true"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 102886" negate="false">
          <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
          <criterion comment="Patch 119060-24 or later installed" test_ref="oval:org.mitre.oval:tst:3231" negate="true"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 102886" negate="false">
          <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
          <criterion comment="Patch 125720-03 or later installed" test_ref="oval:org.mitre.oval:tst:4003" negate="true"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (SPARC) meets Sun Alert 102886" negate="false">
          <extend_definition comment="Solaris 9 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1457"/>
          <criterion comment="Patch 112785-61 or later installed" test_ref="oval:org.mitre.oval:tst:3874" negate="true"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 102886" negate="false">
          <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
          <criterion comment="Patch 119059-25 or later installed" test_ref="oval:org.mitre.oval:tst:3577" negate="true"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 8 (x86) meets Sun Alert 102886" negate="false">
          <extend_definition comment="Solaris 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:2059"/>
          <criterion comment="Patch 119068-07 or later installed" test_ref="oval:org.mitre.oval:tst:3216" negate="true"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (x86) meets Sun Alert 102886" negate="false">
          <extend_definition comment="Solaris 9 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1683"/>
          <criterion comment="Patch 112786-50 or later installed" test_ref="oval:org.mitre.oval:tst:3471" negate="true"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (x86) meets Sun Alert 102886" negate="false">
          <extend_definition comment="Solaris 9 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1683"/>
          <criterion comment="Patch 124833-02 or later installed" test_ref="oval:org.mitre.oval:tst:3278" negate="true"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1957" version="1" class="vulnerability">
      <metadata>
        <title>Security Vulnerability in NFS Client Module May Lead to a Denial of Service Condition</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <platform>Sun Solaris 9</platform>
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-2882" ref_url="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2007-2882"/>
        <description>Unspecified vulnerability in the NFS client module in Sun Solaris 8 through 10 before 20070524, when operating as an NFS server, allows remote attackers to cause a denial of service (crash) via certain Access Control List (acl) packets.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-06-15T09:00:00.000-04:00">
              <contributor organization="Opsware, Inc.">John Wregglesworth</contributor>
            </submitted>
            <status_change date="2007-06-15T11:20:00.000-04:00">DRAFT</status_change>
            <status_change date="2007-07-03T14:05:57.850-04:00">INTERIM</status_change>
            <status_change date="2007-07-18T15:57:51.521-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="OR">
        <criteria operator="AND" comment="Solaris 8 (SPARC)" negate="false">
          <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3437"/>
          <criterion comment="sparc architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3237"/>
          <criterion comment="Patch 116959-16 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:3570"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 8 (x86)" negate="false">
          <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3437"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3912"/>
          <criterion comment="Patch 116960-16 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:4073"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (SPARC)" negate="false">
          <criterion comment="Solaris 9 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3172"/>
          <criterion comment="sparc architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3237"/>
          <criterion comment="Patch 113318-29 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:3914"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (x86)" negate="false">
          <criterion comment="Solaris 9 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3172"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3912"/>
          <criterion comment="Patch 117468-15 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:3605"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (SPARC)" negate="false">
          <criterion comment="Solaris 10 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3680"/>
          <criterion comment="sparc architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3237"/>
          <criterion comment="Patch 124258-04 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:3213"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86)" negate="false">
          <criterion comment="Solaris 10 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3680"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3912"/>
          <criterion comment="Patch 124259-04 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:3414"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1933" version="1" class="vulnerability">
      <metadata>
        <title>Security Vulnerability in the Solaris 10 Virtual File System (VFS) may Lead to a Denial of Service (DoS) Condition</title>
        <affected family="unix">
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-5367" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5367"/>
        <description>Unspecified vulnerability in the Virtual File System (VFS) in Sun Solaris 10 allows local users to cause a denial of service (kernel memory consumption) via unspecified vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-10-12T07:38:45.000-04:00">
              <contributor organization="Opsware, Inc.">Pai Peng</contributor>
            </submitted>
            <status_change date="2007-10-15T18:16:19.589-04:00">DRAFT</status_change>
            <status_change date="2007-11-02T07:17:33.539-04:00">INTERIM</status_change>
            <status_change date="2007-11-19T04:00:45.447-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 103088" negate="false">
          <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
          <criterion comment="Patch 127111-01 or later installed" test_ref="oval:org.mitre.oval:tst:3557" negate="true"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 103088" negate="false">
          <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
          <criterion comment="Patch 127112-01 or later installed" test_ref="oval:org.mitre.oval:tst:4169" negate="true"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1921" version="1" class="vulnerability">
      <metadata>
        <title>Security Vulnerability With NIS server ypserv(1M) May Allow a Denial of Service (DoS) to Occur</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <platform>Sun Solaris 9</platform>
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-3664" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-3664"/>
        <description>Unspecified vulnerability in NIS server on Sun Solaris 8, 9, and 10 allows local and remote attackers to cause a denial of service (ypserv hang) via unknown vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-08-10T12:25:27.000-04:00">
              <contributor organization="Opsware, Inc.">Pai Peng</contributor>
            </submitted>
            <status_change date="2007-08-13T13:57:14.232-04:00">DRAFT</status_change>
            <status_change date="2007-09-06T09:13:29.026-04:00">INTERIM</status_change>
            <status_change date="2007-09-27T08:57:42.566-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND" comment="Solaris 8 (SPARC) meets Sun Alert 102462" negate="false">
          <extend_definition comment="Solaris 8 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1539"/>
          <criterion comment="Patch 109328-06 or later installed" test_ref="oval:org.mitre.oval:tst:3189" negate="true"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (SPARC) meets Sun Alert 102462" negate="false">
          <extend_definition comment="Solaris 9 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1457"/>
          <criterion comment="Patch 113579-09 or later installed" test_ref="oval:org.mitre.oval:tst:3489" negate="true"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 102462" negate="false">
          <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
          <criterion comment="Patch 123186-01 or later installed" test_ref="oval:org.mitre.oval:tst:3820" negate="true"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 8 (x86) meets Sun Alert 102462" negate="false">
          <extend_definition comment="Solaris 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:2059"/>
          <criterion comment="Patch 109329-06 or later installed" test_ref="oval:org.mitre.oval:tst:4121" negate="true"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (x86) meets Sun Alert 102462" negate="false">
          <extend_definition comment="Solaris 9 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1683"/>
          <criterion comment="Patch 114342-09 or later installed" test_ref="oval:org.mitre.oval:tst:3508" negate="true"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 102462" negate="false">
          <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
          <criterion comment="Patch 122078-02 or later installed" test_ref="oval:org.mitre.oval:tst:3928" negate="true"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1920" version="1" class="vulnerability">
      <metadata>
        <title>Security Vulnerability in Sun Remote Services (SRS) Net Connect Software</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <platform>Sun Solaris 9</platform>
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-2617" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2617"/>
        <description>srsexec in Sun Remote Services (SRS) Net Connect Software Proxy Core package in Sun Solaris 10 does not enforce file permissions when opening files, which allows local users to read the first line of arbitrary files via the -d and -v options.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-08-10T12:25:19.000-04:00">
              <contributor organization="Opsware, Inc.">Pai Peng</contributor>
            </submitted>
            <status_change date="2007-08-13T13:57:11.321-04:00">DRAFT</status_change>
            <status_change date="2007-09-06T09:13:28.914-04:00">INTERIM</status_change>
            <status_change date="2007-09-27T08:57:42.438-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND" comment="Solaris 8 (SPARC) meets Sun Alert 102891" negate="false">
          <extend_definition comment="Solaris 8 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1539"/>
          <criterion comment="Patch 125713-01 or later installed" test_ref="oval:org.mitre.oval:tst:3206" negate="true"/>
          <criterion comment="SRS Net Connect Software 3.2.3 is installed" test_ref="oval:org.mitre.oval:tst:4171"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (SPARC) meets Sun Alert 102891" negate="false">
          <extend_definition comment="Solaris 9 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1457"/>
          <criterion comment="Patch 125713-01 or later installed" test_ref="oval:org.mitre.oval:tst:3206" negate="true"/>
          <criterion comment="SRS Net Connect Software 3.2.3 is installed" test_ref="oval:org.mitre.oval:tst:4171"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 102891" negate="false">
          <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
          <criterion comment="Patch 125713-01 or later installed" test_ref="oval:org.mitre.oval:tst:3206" negate="true"/>
          <criterion comment="SRS Net Connect Software 3.2.3 is installed" test_ref="oval:org.mitre.oval:tst:4171"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 8 (x86) meets Sun Alert 102891" negate="false">
          <extend_definition comment="Solaris 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:2059"/>
          <criterion comment="Patch 123870-02 or later installed" test_ref="oval:org.mitre.oval:tst:4014" negate="true"/>
          <criterion comment="SRS Net Connect Software 3.2.4 is installed" test_ref="oval:org.mitre.oval:tst:3230"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (x86) meets Sun Alert 102891" negate="false">
          <extend_definition comment="Solaris 9 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1683"/>
          <criterion comment="Patch 123870-02 or later installed" test_ref="oval:org.mitre.oval:tst:4014" negate="true"/>
          <criterion comment="SRS Net Connect Software 3.2.4 is installed" test_ref="oval:org.mitre.oval:tst:3230"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 102891" negate="false">
          <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
          <criterion comment="Patch 123870-02 or later installed" test_ref="oval:org.mitre.oval:tst:4014" negate="true"/>
          <criterion comment="SRS Net Connect Software 3.2.4 is installed" test_ref="oval:org.mitre.oval:tst:3230"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1909" version="1" class="vulnerability">
      <metadata>
        <title>Security Vulnerabilities in Solaris ld.so.1(1) may Lead to Execution of Arbitrary Code with Elevated Privileges</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <platform>Sun Solaris 9</platform>
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-6495" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-6495"/>
        <description>Stack-based buffer overflow in ld.so.1 in Sun Solaris 8, 9, and 10 allows local users to execute arbitrary code via large precision padding values in a format string specifier in the format parameter of the doprf function.  NOTE: this issue normally does not cross privilege boundaries, except in cases of external introduction of malicious message files, or if it is leveraged with other vulnerabilities such as CVE-2006-6494.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-08-10T12:25:21.000-04:00">
              <contributor organization="Opsware, Inc.">Pai Peng</contributor>
            </submitted>
            <status_change date="2007-08-13T13:57:12.283-04:00">DRAFT</status_change>
            <status_change date="2007-09-06T09:13:28.806-04:00">INTERIM</status_change>
            <status_change date="2007-09-27T08:57:42.313-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND" comment="Solaris 8 (SPARC) meets Sun Alert 102724" negate="false">
          <extend_definition comment="Solaris 8 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1539"/>
          <criterion comment="Patch 109147-42 or later installed" test_ref="oval:org.mitre.oval:tst:3395" negate="true"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (SPARC) meets Sun Alert 102724" negate="false">
          <extend_definition comment="Solaris 9 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1457"/>
          <criterion comment="Patch 112963-27 or later installed" test_ref="oval:org.mitre.oval:tst:3790" negate="true"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 102724" negate="false">
          <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
          <criterion comment="Patch 124922-01 or later installed" test_ref="oval:org.mitre.oval:tst:3922" negate="true"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 8 (x86) meets Sun Alert 102724" negate="false">
          <extend_definition comment="Solaris 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:2059"/>
          <criterion comment="Patch 109148-41 or later installed" test_ref="oval:org.mitre.oval:tst:3236" negate="true"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (x86) meets Sun Alert 102724" negate="false">
          <extend_definition comment="Solaris 9 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1683"/>
          <criterion comment="Patch 113986-22 or later installed" test_ref="oval:org.mitre.oval:tst:3819" negate="true"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 102724" negate="false">
          <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
          <criterion comment="Patch 124923-01 or later installed" test_ref="oval:org.mitre.oval:tst:3173" negate="true"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1893" version="1" class="vulnerability">
      <metadata>
        <title>Security Vulnerability in Solaris 10 Link Aggregation may Allow Local Users Total Access to Network Packets</title>
        <affected family="unix">
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-5013" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-5013"/>
        <description>Sun Solaris 10 before patch 118855-16 (20060925), when run on x64 systems using IPv6, allows remote attackers to cause a denial of service (kernel panic) via crafted IPv6 packets.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-08-10T12:25:23.000-04:00">
              <contributor organization="Opsware, Inc.">Pai Peng</contributor>
            </submitted>
            <status_change date="2007-08-13T13:57:13.177-04:00">DRAFT</status_change>
            <status_change date="2007-09-06T09:13:28.723-04:00">INTERIM</status_change>
            <status_change date="2007-09-27T08:57:42.219-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 102606" negate="false">
          <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
          <criterion comment="Patch 118833-23 or later installed" test_ref="oval:org.mitre.oval:tst:3263" negate="true"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 102606" negate="false">
          <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
          <criterion comment="Patch 118855-19 or later installed" test_ref="oval:org.mitre.oval:tst:3362" negate="true"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1892" version="1" class="vulnerability">
      <metadata>
        <title>Security Vulnerabilities in the Solaris Trusted Extensions "labeld" Service May Lead to a Denial of Service (DoS) Condition</title>
        <affected family="unix">
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-5368" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5368"/>
        <description>Multiple unspecified vulnerabilities in labeld in Trusted Extensions in Sun Solaris 10 allow local users to cause a denial of service (multiple application hang) via unspecified vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-10-12T07:38:45.000-04:00">
              <contributor organization="Opsware, Inc.">Pai Peng</contributor>
            </submitted>
            <status_change date="2007-10-15T18:16:19.852-04:00">DRAFT</status_change>
            <status_change date="2007-11-02T07:17:32.943-04:00">INTERIM</status_change>
            <status_change date="2007-11-19T04:00:43.393-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 103109" negate="false">
          <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
          <criterion comment="Patch 126448-04 or later installed" test_ref="oval:org.mitre.oval:tst:4307" negate="true"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 103109" negate="false">
          <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
          <criterion comment="Patch 126449-04 or later installed" test_ref="oval:org.mitre.oval:tst:4545" negate="true"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1832" version="1" class="vulnerability">
      <metadata>
        <title>A Security Vulnerability in How xscreensaver(1) Interacts With GNOME Assistive Technology May Allow Arbitrary Command Execution</title>
        <affected family="unix">
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-3069" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3069"/>
        <description>xscreensaver in Sun Solaris 10 before 20070604, when a GNOME session with Assistive Technology support is running, allows attackers with physical access to take control of the session after entering an Alt-Tab sequence.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-06-07T14:01:00.000-04:00">
              <contributor organization="Opsware, Inc.">Pai Peng</contributor>
            </submitted>
            <status_change date="2007-06-07T14:28:00.000-04:00">DRAFT</status_change>
            <status_change date="2007-06-22T08:57:41.387-04:00">INTERIM</status_change>
            <status_change date="2007-07-10T21:08:50.203-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="OR">
        <criteria operator="AND" comment="Solaris 10 (SPARC)" negate="false">
          <criterion comment="Solaris 10 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3680"/>
          <criterion comment="sparc architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3237"/>
          <criterion comment="Patch 120094-11 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:3833"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86)" negate="false">
          <criterion comment="Solaris 10 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3680"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3912"/>
          <criterion comment="Patch 120095-11 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:4096"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1819" version="1" class="vulnerability">
      <metadata>
        <title>Security Vulnerability in the Netscape Portable Runtime (NSPR) API Affects Solaris</title>
        <affected family="unix">
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-4842" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-4842"/>
        <description>The Netscape Portable Runtime (NSPR) API 4.6.1 and 4.6.2, as used in Sun Solaris 10, trusts user-specified environment variables for specifying log files even when running from setuid programs, which allows local users to create or overwrite arbitrary files.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-08-10T12:25:24.000-04:00">
              <contributor organization="Opsware, Inc.">Pai Peng</contributor>
            </submitted>
            <status_change date="2007-08-13T13:57:13.389-04:00">DRAFT</status_change>
            <status_change date="2007-09-06T09:13:28.654-04:00">INTERIM</status_change>
            <status_change date="2007-09-27T08:57:42.133-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 102658" negate="false">
          <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
          <criterion comment="Patch 119213-10 or later installed" test_ref="oval:org.mitre.oval:tst:3926" negate="true"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 102658" negate="false">
          <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
          <criterion comment="Patch 119214-10 or later installed" test_ref="oval:org.mitre.oval:tst:3572" negate="true"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1810" version="1" class="vulnerability">
      <metadata>
        <title>Multiple vulnerabilities in libfreetype, Xsun(1) and Xorg(1)</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <platform>Sun Solaris 9</platform>
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-1351" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1351"/>
        <description>Integer overflow in the bdfReadCharacters function in bdfread.c in (1) X.Org libXfont before 20070403 and (2) freetype 2.3.2 and earlier allows remote authenticated users to execute arbitrary code via crafted BDF fonts, which result in a heap overflow.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-07-30T08:16:45.000-04:00">
              <contributor organization="Opsware, Inc.">Pai Peng</contributor>
            </submitted>
            <status_change date="2007-08-01T22:21:20.643-04:00">DRAFT</status_change>
            <status_change date="2007-08-20T08:04:38.899-04:00">INTERIM</status_change>
            <status_change date="2007-09-06T09:13:28.469-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND" comment="Solaris 8 (SPARC) meets Sun Alert 102886" negate="false">
          <extend_definition comment="Solaris 8 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1539"/>
          <criterion comment="Patch 119067-07 or later installed" test_ref="oval:org.mitre.oval:tst:3167" negate="true"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 8 (SPARC) meets Sun Alert 102886" negate="false">
          <extend_definition comment="Solaris 8 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1539"/>
          <criterion comment="Patch 124420-02 or later installed" test_ref="oval:org.mitre.oval:tst:3470" negate="true"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (x86) meets Sun Alert 102886" negate="false">
          <extend_definition comment="Solaris 9 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1683"/>
          <criterion comment="Patch 116106-06 or later installed" test_ref="oval:org.mitre.oval:tst:3765" negate="true"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 102886" negate="false">
          <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
          <criterion comment="Patch 119060-24 or later installed" test_ref="oval:org.mitre.oval:tst:3231" negate="true"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 102886" negate="false">
          <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
          <criterion comment="Patch 125720-03 or later installed" test_ref="oval:org.mitre.oval:tst:4003" negate="true"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 102886" negate="false">
          <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
          <criterion comment="Patch 119813-04 or later installed" test_ref="oval:org.mitre.oval:tst:3930" negate="true"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (SPARC) meets Sun Alert 102886" negate="false">
          <extend_definition comment="Solaris 9 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1457"/>
          <criterion comment="Patch 112785-61 or later installed" test_ref="oval:org.mitre.oval:tst:3874" negate="true"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (SPARC) meets Sun Alert 102886" negate="false">
          <extend_definition comment="Solaris 9 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1457"/>
          <criterion comment="Patch 116105-07 or later installed" test_ref="oval:org.mitre.oval:tst:3197" negate="true"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 102886" negate="false">
          <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
          <criterion comment="Patch 119059-25 or later installed" test_ref="oval:org.mitre.oval:tst:3577" negate="true"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 102886" negate="false">
          <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
          <criterion comment="Patch 119812-03 or later installed" test_ref="oval:org.mitre.oval:tst:3921" negate="true"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 8 (x86) meets Sun Alert 102886" negate="false">
          <extend_definition comment="Solaris 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:2059"/>
          <criterion comment="Patch 119068-07 or later installed" test_ref="oval:org.mitre.oval:tst:3216" negate="true"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 8 (x86) meets Sun Alert 102886" negate="false">
          <extend_definition comment="Solaris 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:2059"/>
          <criterion comment="Patch 124421-02 or later installed" test_ref="oval:org.mitre.oval:tst:3676" negate="true"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (x86) meets Sun Alert 102886" negate="false">
          <extend_definition comment="Solaris 9 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1683"/>
          <criterion comment="Patch 112786-50 or later installed" test_ref="oval:org.mitre.oval:tst:3471" negate="true"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (x86) meets Sun Alert 102886" negate="false">
          <extend_definition comment="Solaris 9 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1683"/>
          <criterion comment="Patch 124833-02 or later installed" test_ref="oval:org.mitre.oval:tst:3278" negate="true"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1798" version="1" class="vulnerability">
      <metadata>
        <title>Buffer Overflow Vulnerability in libX11</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <platform>Sun Solaris 9</platform>
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-4655" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-4655"/>
        <description>Buffer overflow in the Strcmp function in the XKEYBOARD extension in X Window System X11R6.4 and earlier, as used in SCO UnixWare 7.1.3 and Sun Solaris 8 through 10, allows local users to gain privileges via a long _XKB_CHARSET environment variable value.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-08-10T12:25:24.000-04:00">
              <contributor organization="Opsware, Inc.">Pai Peng</contributor>
            </submitted>
            <status_change date="2007-08-13T13:57:13.571-04:00">DRAFT</status_change>
            <status_change date="2007-09-06T09:13:28.351-04:00">INTERIM</status_change>
            <status_change date="2007-09-27T08:57:41.950-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND" comment="Solaris 8 (SPARC) meets Sun Alert 102570" negate="false">
          <extend_definition comment="Solaris 8 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1539"/>
          <criterion comment="Patch 119067-03 or later installed" test_ref="oval:org.mitre.oval:tst:3849" negate="true"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (SPARC) meets Sun Alert 102570" negate="false">
          <extend_definition comment="Solaris 9 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1457"/>
          <criterion comment="Patch 112785-56 or later installed" test_ref="oval:org.mitre.oval:tst:4065" negate="true"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 102570" negate="false">
          <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
          <criterion comment="Patch 119059-16 or later installed" test_ref="oval:org.mitre.oval:tst:3650" negate="true"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 8 (x86) meets Sun Alert 102570" negate="false">
          <extend_definition comment="Solaris 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:2059"/>
          <criterion comment="Patch 119068-03 or later installed" test_ref="oval:org.mitre.oval:tst:3615" negate="true"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (x86) meets Sun Alert 102570" negate="false">
          <extend_definition comment="Solaris 9 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1683"/>
          <criterion comment="Patch 112786-45 or later installed" test_ref="oval:org.mitre.oval:tst:4004" negate="true"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 102570" negate="false">
          <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
          <criterion comment="Patch 119060-15 or later installed" test_ref="oval:org.mitre.oval:tst:3329" negate="true"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1772" version="1" class="vulnerability">
      <metadata>
        <title>Security Vulnerability in the rcp(1) Command May Allow Execution of Unintended Commands</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <platform>Sun Solaris 9</platform>
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-3717" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3717"/>
        <description>rcp on Sun Solaris 8, 9, and 10 before 20070710 does not properly call certain helper applications, which allows local users to gain privileges by creating files with certain names, possibly containing shell metacharacters or spaces, a similar issue to CVE-2006-0225.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-07-12T12:19:52.000-04:00">
              <contributor organization="Opsware, Inc.">Pai Peng</contributor>
            </submitted>
            <status_change date="2007-07-16T08:59:43.133-04:00">DRAFT</status_change>
            <status_change date="2007-08-01T22:26:14.652-04:00">INTERIM</status_change>
            <status_change date="2007-08-20T08:04:38.771-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND" comment="Solaris 8 (SPARC) meets Sun Alert 102978" negate="false">
          <extend_definition comment="Solaris 8 Installed" definition_ref="oval:org.mitre.oval:def:1539"/>
          <criteria operator="AND" comment="Patch 110670-04 and 114669-04 or later installed" negate="true">
            <criterion comment="Patch 110670-04 or later installed" test_ref="oval:org.mitre.oval:tst:3292" negate="false"/>
            <criterion comment="Patch 114669-04 or later installed" test_ref="oval:org.mitre.oval:tst:3763" negate="false"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Solaris 8 (x86) meets Sun Alert 102978" negate="false">
          <extend_definition comment="Solaris 8 Installed" definition_ref="oval:org.mitre.oval:def:2059"/>
          <criteria operator="AND" comment="Patch 110671-04 and 114670-04 or later installed" negate="true">
            <criterion comment="Patch 110671-04 or later installed" test_ref="oval:org.mitre.oval:tst:3592" negate="false"/>
            <criterion comment="Patch 114670-04 or later installed" test_ref="oval:org.mitre.oval:tst:3608" negate="false"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (SPARC) meets Sun Alert 102978" negate="false">
          <extend_definition comment="Solaris 9 Installed" definition_ref="oval:org.mitre.oval:def:1457"/>
          <criterion comment="Patch 114716-05 or later installed" test_ref="oval:org.mitre.oval:tst:3667" negate="true"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (x86) meets Sun Alert 102978" negate="false">
          <extend_definition comment="Solaris 9 Installed" definition_ref="oval:org.mitre.oval:def:1683"/>
          <criterion comment="Patch 114717-05 or later installed" test_ref="oval:org.mitre.oval:tst:3799" negate="true"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 102978" negate="false">
          <extend_definition comment="Solaris 10 Installed" definition_ref="oval:org.mitre.oval:def:1440"/>
          <criterion comment="Patch 121132-03 or later installed" test_ref="oval:org.mitre.oval:tst:3927" negate="true"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 102978" negate="false">
          <extend_definition comment="Solaris 10 Installed" definition_ref="oval:org.mitre.oval:def:1926"/>
          <criterion comment="Patch 125794-02 or later installed" test_ref="oval:org.mitre.oval:tst:4051" negate="true"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1760" version="1" class="vulnerability">
      <metadata>
        <title>Security Vulnerability in X Display Manager (xdm(1)) Xsession Script</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <platform>Sun Solaris 9</platform>
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-5214" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-5214"/>
        <description>Race condition in the Xsession script, as used by X Display Manager (xdm) in NetBSD before 20060212, X.Org before 20060225, and Solaris 8 through 10 before 20061006, causes a user's Xsession errors file to have weak permissions before a chmod is performed, which allows local users to read Xsession errors files of other users.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-08-10T12:25:23.000-04:00">
              <contributor organization="Opsware, Inc.">Pai Peng</contributor>
            </submitted>
            <status_change date="2007-08-13T13:57:13.122-04:00">DRAFT</status_change>
            <status_change date="2007-09-06T09:13:28.241-04:00">INTERIM</status_change>
            <status_change date="2007-09-27T08:57:41.428-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND" comment="Solaris 8 (SPARC) meets Sun Alert 102652" negate="false">
          <extend_definition comment="Solaris 8 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1539"/>
          <criterion comment="Patch 111844-04 or later installed" test_ref="oval:org.mitre.oval:tst:3324" negate="true"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (SPARC) meets Sun Alert 102652" negate="false">
          <extend_definition comment="Solaris 9 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1457"/>
          <criterion comment="Patch 124830-01 or later installed" test_ref="oval:org.mitre.oval:tst:3994" negate="true"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 102652" negate="false">
          <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
          <criterion comment="Patch 124457-01 or later installed" test_ref="oval:org.mitre.oval:tst:3954" negate="true"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 8 (x86) meets Sun Alert 102652" negate="false">
          <extend_definition comment="Solaris 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:2059"/>
          <criterion comment="Patch 111845-04 or later installed" test_ref="oval:org.mitre.oval:tst:4176" negate="true"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (x86) meets Sun Alert 102652" negate="false">
          <extend_definition comment="Solaris 9 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1683"/>
          <criterion comment="Patch 124831-01 or later installed" test_ref="oval:org.mitre.oval:tst:3585" negate="true"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 102652" negate="false">
          <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
          <criterion comment="Patch 124458-01 or later installed" test_ref="oval:org.mitre.oval:tst:3425" negate="true"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1726" version="2" class="vulnerability">
      <metadata>
        <title>Security Vulnerability in the Kerberos Administration Daemon (kadmind(1M)) May Lead to Arbitrary Code Execution</title>
        <affected family="unix">
          <platform>Sun Solaris 9</platform>
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-2798" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2798"/>
        <description>Stack-based buffer overflow in the rename_principal_2_svc function in kadmind for MIT Kerberos 1.5.3, 1.6.1, and other versions allows remote authenticated users to execute arbitrary code via a crafted request to rename a principal.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-06-28T09:00:00.000-04:00">
              <contributor organization="Opsware, Inc.">Nicholas Hansen</contributor>
            </submitted>
            <status_change date="2007-06-29T09:24:18.908-04:00">DRAFT</status_change>
            <status_change date="2007-07-16T09:55:10.258-04:00">INTERIM</status_change>
            <status_change date="2007-08-01T22:26:14.499-04:00">ACCEPTED</status_change>
            <modified comment="The test references for all the criterion were inverted. This fix corrects the test_refs and updates the criteria comments to include the Sun Alert reference." date="2007-11-01T13:08:00.938-04:00">
              <contributor organization="Opsware, Inc.">Nicholas Hansen</contributor>
            </modified>
            <status_change date="2007-11-01T13:11:21.000-04:00">INTERIM</status_change>
            <status_change date="2007-11-16T08:14:19.297-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software section">
        <criteria operator="AND" comment="Solaris 8 (SPARC) meets Sun Alert 102985">
          <extend_definition comment="Solaris 8 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1539"/>
          <criterion comment="Sun Enterprise Authentication Mechanism (SEAM, SUNWkr5ma) installed" test_ref="oval:org.mitre.oval:tst:3971"/>
          <criterion comment="Key Distribution Center (kadmind) process running" test_ref="oval:org.mitre.oval:tst:3331"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 8 (x86) meets Sun Alert 102985">
          <extend_definition comment="Solaris 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:2059"/>
          <criterion comment="Sun Enterprise Authentication Mechanism (SEAM, SUNWkr5ma) installed" test_ref="oval:org.mitre.oval:tst:3971"/>
          <criterion comment="Key Distribution Center (kadmind) process running" test_ref="oval:org.mitre.oval:tst:3331"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (SPARC) meets Sun Alert 102985">
          <extend_definition comment="Solaris 9 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1457"/>
          <criterion comment="Sun Enterprise Authentication Mechanism (SEAM, SUNWkr5ma) installed" test_ref="oval:org.mitre.oval:tst:3971"/>
          <criterion comment="Key Distribution Center (kadmind) process running" test_ref="oval:org.mitre.oval:tst:3331"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (x86) meets Sun Alert 102985">
          <extend_definition comment="Solaris 9 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1683"/>
          <criterion comment="Sun Enterprise Authentication Mechanism (SEAM, SUNWkr5ma) installed" test_ref="oval:org.mitre.oval:tst:3971"/>
          <criterion comment="Key Distribution Center (kadmind) process running" test_ref="oval:org.mitre.oval:tst:3331"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 102985">
          <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
          <criterion comment="Sun Enterprise Authentication Mechanism (SEAM, SUNWkr5ma) installed" test_ref="oval:org.mitre.oval:tst:3971"/>
          <criterion comment="Key Distribution Center (kadmind) process running" test_ref="oval:org.mitre.oval:tst:3331"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 102985">
          <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
          <criterion comment="Sun Enterprise Authentication Mechanism (SEAM, SUNWkr5ma) installed" test_ref="oval:org.mitre.oval:tst:3971"/>
          <criterion comment="Key Distribution Center (kadmind) process running" test_ref="oval:org.mitre.oval:tst:3331"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:170" version="3" class="vulnerability">
      <metadata>
        <title>Sun Solaris Gzip Race condition and Directory Traversal Issues</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <platform>Sun Solaris 9</platform>
          <platform>Sun Solaris 10</platform>
          <product>gzip</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1228" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1228"/>
        <description>Directory traversal vulnerability in gunzip -N in gzip 1.2.4 through 1.3.5 allows remote attackers to write to arbitrary directories via a .. (dot dot) in the original filename within a compressed file.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-09-22T05:52:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-09-22T20:15:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-07T09:15:27.272-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:15:16.282-04:00">ACCEPTED</status_change>
            <modified comment="Added title. Implemented by Jon Baker of The MITRE Corporation." date="2007-02-13T14:05:00.064-05:00">
              <contributor organization="Security-Database">Nabil Ouchn</contributor>
            </modified>
            <status_change date="2007-02-13T14:07:07.091-05:00">INTERIM</status_change>
            <status_change date="2007-03-21T16:17:00.447-04:00">ACCEPTED</status_change>
            <modified comment="Corrected sparc criterion that was intended to be x86." date="2009-07-17T11:09:00.287-04:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </modified>
            <status_change date="2009-07-17T11:27:44.296-04:00">INTERIM</status_change>
            <status_change date="2009-08-03T04:00:02.600-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Solaris 8 (SPARC) meets Sun Alert ID 101816 criteria.">
          <criterion comment="Solaris 8 Installed" test_ref="oval:org.mitre.oval:tst:3437"/>
          <criterion comment="sparc architecture" test_ref="oval:org.mitre.oval:tst:3237"/>
          <criterion comment="Patch 112668-03 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:4005"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 8 (x86) meets Sun Alert ID 101816 criteria.">
          <criterion comment="Solaris 8 Installed" test_ref="oval:org.mitre.oval:tst:3437"/>
          <criterion comment="ix86 architecture" test_ref="oval:org.mitre.oval:tst:3912"/>
          <criterion comment="Patch 112669-03 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:4070"/>
        </criter
