<?xml version="1.0" encoding="UTF-8"?>
<oval_definitions xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix unix-definitions-schema.xsd http://oval.mitre.org/XMLSchema/oval-definitions-5#independent independent-definitions-schema.xsd http://oval.mitre.org/XMLSchema/oval-definitions-5 oval-definitions-schema.xsd http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris solaris-definitions-schema.xsd http://oval.mitre.org/XMLSchema/oval-common-5 oval-common-schema.xsd" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:oval="http://oval.mitre.org/XMLSchema/oval-common-5" xmlns:oval-def="http://oval.mitre.org/XMLSchema/oval-definitions-5">
  <generator>
    <oval:product_name>The OVAL Repository</oval:product_name>
    <oval:schema_version>5.4</oval:schema_version>
    <oval:timestamp>2008-08-21T09:09:25.459-04:00</oval:timestamp>
  </generator>
  <definitions>
    <definition id="oval:org.mitre.oval:def:5128" version="0" class="vulnerability">
      <metadata>
        <title>A Security Vulnerability in Solaris 10 involving the sendfilev() system call could result in Denial of Service (DoS) due to System Panic</title>
        <affected family="unix">
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-3666" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-3666"/>
        <description>Unspecified vulnerability in Sun Solaris 10 and OpenSolaris before snv_96 allows (1) context-dependent attackers to cause a denial of service (panic) via vectors involving creation of a crafted file and use of the sendfilev system call, as demonstrated by a file served by an Apache 2.2.x web server with EnableSendFile configured; and (2) local users to cause a denial of service (panic) via a call to sendfilev or sendfile.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-08-14T11:25:43.000-04:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2008-08-14T15:03:16.477-04:00">DRAFT</status_change>
          </dates>
          <status>DRAFT</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 239186">
          <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
          <criterion negate="true" comment="Patch 137111-04 or later installed" test_ref="oval:org.mitre.oval:tst:9073"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 239186">
          <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
          <criterion negate="true" comment="Patch 137112-04 or later installed" test_ref="oval:org.mitre.oval:tst:8753"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5318" version="0" class="vulnerability">
      <metadata>
        <title>Security Vulnerability in Solaris snoop(1M) when Displaying SMB Traffic</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <platform>Sun Solaris 9</platform>
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-0964" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-0964"/>
        <description>Unspecified vulnerability in snoop on Sun Solaris 8 through 10 and OpenSolaris before snv_96, when the -o option is omitted, allows remote attackers to execute arbitrary code via a crafted SMB packet, a different vulnerability than CVE-2008-0965.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-08-11T12:08:06.000-04:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2008-08-14T15:03:14.279-04:00">DRAFT</status_change>
          </dates>
          <status>DRAFT</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 240101">
          <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
          <criterion negate="true" comment="Patch 138083-01 or later installed" test_ref="oval:org.mitre.oval:tst:9062"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (SPARC) meets Sun Alert 240101">
          <extend_definition comment="Solaris 9 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1457"/>
          <criterion negate="true" comment="Patch 112915-05 or later installed" test_ref="oval:org.mitre.oval:tst:9103"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 8 (SPARC) meets Sun Alert 240101">
          <extend_definition comment="Solaris 8 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1539"/>
          <criterion negate="true" comment="Patch 108964-11 or later installed" test_ref="oval:org.mitre.oval:tst:8936"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 240101">
          <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
          <criterion negate="true" comment="Patch 138084-01 or later installed" test_ref="oval:org.mitre.oval:tst:8152"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (x86) meets Sun Alert 240101">
          <extend_definition comment="Solaris 9 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1683"/>
          <criterion negate="true" comment="Patch 114262-04 or later installed" test_ref="oval:org.mitre.oval:tst:8854"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 8 (x86) meets Sun Alert 240101">
          <extend_definition comment="Solaris 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:2059"/>
          <criterion negate="true" comment="Patch 108965-11 or later installed" test_ref="oval:org.mitre.oval:tst:9126"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5446" version="0" class="vulnerability">
      <metadata>
        <title>Security Vulnerabilities in the Solaris Priority Inherited pthread mutex API May Result in a Denial of Service (DoS) Condition</title>
        <affected family="unix">
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-3549" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-3549"/>
        <description>Unspecified vulnerability in the pthread_mutex_reltimedlock_np API in Sun Solaris 10 and OpenSolaris before snv_90 allows local users to cause a denial of service (system hang or panic) via unknown vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-08-11T17:42:55.000-04:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2008-08-14T15:03:12.846-04:00">DRAFT</status_change>
          </dates>
          <status>DRAFT</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 239387">
          <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
          <criterion negate="true" comment="Patch 137111-04 or later installed" test_ref="oval:org.mitre.oval:tst:9095"/>
          <criterion comment="deadman feature is enabled (kernel variable 'snooping' has a value of one)" test_ref="oval:org.mitre.oval:tst:8414"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 239387">
          <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
          <criterion negate="true" comment="Patch 137112-04 or later installed" test_ref="oval:org.mitre.oval:tst:9125"/>
          <criterion comment="deadman feature is enabled (kernel variable 'snooping' has a value of one)" test_ref="oval:org.mitre.oval:tst:8414"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5742" version="0" class="vulnerability">
      <metadata>
        <title>Security Vulnerability in Solaris snoop(1M) when Displaying SMB Traffic</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <platform>Sun Solaris 9</platform>
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-0965" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-0965"/>
        <description>Unspecified vulnerability in snoop on Sun Solaris 8 through 10 and OpenSolaris before snv_96, when the -o option is omitted, allows remote attackers to execute arbitrary code via a crafted SMB packet, a different vulnerability than CVE-2008-0964.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-08-11T12:08:06.000-04:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2008-08-14T15:03:06.340-04:00">DRAFT</status_change>
          </dates>
          <status>DRAFT</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 240101">
          <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
          <criterion negate="true" comment="Patch 138083-01 or later installed" test_ref="oval:org.mitre.oval:tst:9062"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (SPARC) meets Sun Alert 240101">
          <extend_definition comment="Solaris 9 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1457"/>
          <criterion negate="true" comment="Patch 112915-05 or later installed" test_ref="oval:org.mitre.oval:tst:9103"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 8 (SPARC) meets Sun Alert 240101">
          <extend_definition comment="Solaris 8 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1539"/>
          <criterion negate="true" comment="Patch 108964-11 or later installed" test_ref="oval:org.mitre.oval:tst:8936"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 240101">
          <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
          <criterion negate="true" comment="Patch 138084-01 or later installed" test_ref="oval:org.mitre.oval:tst:8152"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (x86) meets Sun Alert 240101">
          <extend_definition comment="Solaris 9 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1683"/>
          <criterion negate="true" comment="Patch 114262-04 or later installed" test_ref="oval:org.mitre.oval:tst:8854"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 8 (x86) meets Sun Alert 240101">
          <extend_definition comment="Solaris 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:2059"/>
          <criterion negate="true" comment="Patch 108965-11 or later installed" test_ref="oval:org.mitre.oval:tst:9126"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5609" version="0" class="vulnerability">
      <metadata>
        <title>A Security Vulnerability in the namefs Kernel module may result in Arbitrary Code Execution or a Denial of Service (DoS)</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <platform>Sun Solaris 9</platform>
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-3450" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-3450"/>
        <description>Unspecified vulnerability in the namefs kernel module in Sun Solaris 8 through 10 allows local users to gain privileges or cause a denial of service (panic) via unspecified vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-08-05T10:37:22.000-04:00">
              <contributor organization="Hewlett-Packard">Nicholas Hansen</contributor>
            </submitted>
            <status_change date="2008-08-11T11:11:36.400-04:00">DRAFT</status_change>
          </dates>
          <status>DRAFT</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND" comment="Solaris 8 (SPARC) meets Sun Alert 237986">
          <extend_definition comment="Solaris 8 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1539"/>
          <criterion negate="true" comment="Patch 114984-02 or later installed" test_ref="oval:org.mitre.oval:tst:9052"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 8 (x86) meets Sun Alert 237986">
          <extend_definition comment="Solaris 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:2059"/>
          <criterion negate="true" comment="Patch 114985-02 or later installed" test_ref="oval:org.mitre.oval:tst:9021"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (SPARC) meets Sun Alert 237986">
          <extend_definition comment="Solaris 9 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1457"/>
          <criterion negate="true" comment="Patch 114971-03 or later installed" test_ref="oval:org.mitre.oval:tst:9022"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (x86) meets Sun Alert 237986">
          <extend_definition comment="Solaris 9 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1683"/>
          <criterion negate="true" comment="Patch 138570-01 or later installed" test_ref="oval:org.mitre.oval:tst:8942"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 237986">
          <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
          <criterion negate="true" comment="Patch 136716-01 or later installed" test_ref="oval:org.mitre.oval:tst:8779"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 237986">
          <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
          <criterion negate="true" comment="Patch 136717-01 or later installed" test_ref="oval:org.mitre.oval:tst:9079"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5762" version="1" class="vulnerability">
      <metadata>
        <title>Vulnerability in the Solaris 10 Event Port Implementation May Lead to a System Panic, Resulting in a Denial of Service (DoS)</title>
        <affected family="unix">
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-2706" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-2706"/>
        <description>Unspecified vulnerability in the event port implementation in Sun Solaris 10 allows local users to cause a denial of service (panic) by submitting and retrieving user-defined events, probably related to a NULL dereference.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-06-17T14:54:16.000-04:00">
              <contributor organization="Hewlett-Packard">Todd Dolinsky</contributor>
            </submitted>
            <status_change date="2008-06-18T17:12:08.386-04:00">DRAFT</status_change>
            <status_change date="2008-07-07T04:00:36.344-04:00">INTERIM</status_change>
            <status_change date="2008-07-28T04:00:26.268-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 235122">
          <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
          <criterion negate="true" comment="Patch 137111-01 or later installed" test_ref="oval:org.mitre.oval:tst:7853"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 235122">
          <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
          <criterion negate="true" comment="Patch 137112-01 or later installed" test_ref="oval:org.mitre.oval:tst:8065"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5731" version="1" class="vulnerability">
      <metadata>
        <title>A Security Vulnerability in IP Multicast Filter processing of Sockets may lead to a system panic or possible execution of Arbitrary Code</title>
        <affected family="unix">
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-2710" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-2710"/>
        <description>Integer signedness error in the ip_set_srcfilter function in the IP Multicast Filter in uts/common/inet/ip/ip_multi.c in the kernel in Sun Solaris 10 and OpenSolaris before snv_92 allows local users to execute arbitrary code in other Solaris Zones via an SIOCSIPMSFILTER IOCTL request with a large value of the imsf->imsf_numsrc field, which triggers an out-of-bounds write of kernel memory.  NOTE: this was reported as an integer overflow, but the root cause involves the bypass of a signed comparison.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-06-17T14:54:16.000-04:00">
              <contributor organization="Hewlett-Packard">Todd Dolinsky</contributor>
            </submitted>
            <status_change date="2008-06-18T17:12:08.608-04:00">DRAFT</status_change>
            <status_change date="2008-07-07T04:00:34.971-04:00">INTERIM</status_change>
            <status_change date="2008-07-28T04:00:24.214-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 237965">
          <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
          <criterion negate="true" comment="Patch 137111-01 or later installed" test_ref="oval:org.mitre.oval:tst:7853"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 237965">
          <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
          <criterion negate="true" comment="Patch 137112-01 or later installed" test_ref="oval:org.mitre.oval:tst:8065"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:4725" version="1" class="vulnerability">
      <metadata>
        <title>Security Vulnerability in the Solaris crontab(1) utility may allow execution of Arbitrary Code</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <platform>Sun Solaris 9</platform>
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-2538" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-2538"/>
        <description>Unspecified vulnerability in crontab on Sun Solaris 8 through 10, and OpenSolaris before snv_93, allows local users to insert cron jobs into the crontab files of arbitrary users via unspecified vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-06-05T11:19:56.000-04:00">
              <contributor organization="Hewlett-Packard">Nicholas Hansen</contributor>
            </submitted>
            <status_change date="2008-06-05T14:00:22.164-04:00">DRAFT</status_change>
            <status_change date="2008-06-23T04:00:11.562-04:00">INTERIM</status_change>
            <modified comment="Fixed duplicate criteria for Solaris 9" date="2008-07-02T16:52:00.808-04:00">
              <contributor organization="Secure Elements, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2008-07-21T04:00:08.039-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND" comment="Solaris 8 (SPARC) meets Sun Alert 237864">
          <extend_definition comment="Solaris 8 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1539"/>
          <criterion negate="true" comment="Patch 109007-26 or later installed" test_ref="oval:org.mitre.oval:tst:7905"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (SPARC) meets Sun Alert 237864">
          <extend_definition comment="Solaris 9 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1457"/>
          <criterion negate="true" comment="Patch 122300-27 or later installed" test_ref="oval:org.mitre.oval:tst:7763"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 237864">
          <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
          <criterion negate="true" comment="Patch 137017-02 or later installed" test_ref="oval:org.mitre.oval:tst:8027"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 8 (x86) meets Sun Alert 237864">
          <extend_definition comment="Solaris 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:2059"/>
          <criterion negate="true" comment="Patch 109008-26 or later installed" test_ref="oval:org.mitre.oval:tst:7968"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (x86) meets Sun Alert 237864">
          <extend_definition comment="Solaris 9 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1683"/>
          <criterion negate="true" comment="Patch 122301-27 or later installed" test_ref="oval:org.mitre.oval:tst:7797"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 237864">
          <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
          <criterion negate="true" comment="Patch 137018-02 or later installed" test_ref="oval:org.mitre.oval:tst:8019"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5346" version="1" class="vulnerability">
      <metadata>
        <title>Security Vulnerability in the Solaris 10 STREAMS Administrative Driver ("sad") May Allow a Denial of Service (System panic)</title>
        <affected family="unix">
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-2418" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-2418"/>
        <description>Race condition in the STREAMS Administrative Driver (sad) in Sun Solaris 10 allows local users to cause a denial of service (panic) via unknown vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-05-29T14:40:41.000-04:00">
              <contributor organization="Hewlett-Packard">Nicholas Hansen</contributor>
            </submitted>
            <status_change date="2008-06-02T10:54:28.218-04:00">DRAFT</status_change>
            <status_change date="2008-06-23T04:00:13.629-04:00">INTERIM</status_change>
            <status_change date="2008-07-14T04:00:20.599-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 237584">
          <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
          <criterion negate="true" comment="Patch 127743-01 or later installed" test_ref="oval:org.mitre.oval:tst:7719"/>
          <criterion comment="Patch 120011-06 or later installed" test_ref="oval:org.mitre.oval:tst:7858"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 237584">
          <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
          <criterion negate="true" comment="Patch 127744-01 or later installed" test_ref="oval:org.mitre.oval:tst:8071"/>
          <criterion comment="Patch 120012-06 or later installed" test_ref="oval:org.mitre.oval:tst:8036"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5269" version="1" class="vulnerability">
      <metadata>
        <title>Security Vulnerabilities in Solaris Print Service May Lead to Denial of Service (DoS) or Execution of Arbitrary Code</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <platform>Sun Solaris 9</platform>
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-2144" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-2144"/>
        <description>Multiple unspecified vulnerabilities in Solaris print service for Sun Solaris 8, 9, and 10 allow remote attackers to cause a denial of service or execute arbitrary code via unknown vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-05-14T13:20:42.000-04:00">
              <contributor organization="Hewlett-Packard">Nicholas Hansen</contributor>
            </submitted>
            <status_change date="2008-05-15T14:47:17.480-04:00">DRAFT</status_change>
            <status_change date="2008-06-02T04:00:08.809-04:00">INTERIM</status_change>
            <status_change date="2008-06-23T04:00:12.580-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND" comment="Solaris 8 (SPARC) meets Sun Alert 236884">
          <extend_definition comment="Solaris 8 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1539"/>
          <criterion negate="true" comment="Patch 109320-20 or later installed" test_ref="oval:org.mitre.oval:tst:7494"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 8 (x86) meets Sun Alert 236884">
          <extend_definition comment="Solaris 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:2059"/>
          <criterion negate="true" comment="Patch 109321-20 or later installed" test_ref="oval:org.mitre.oval:tst:7873"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (SPARC) meets Sun Alert 236884">
          <extend_definition comment="Solaris 9 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1457"/>
          <criterion negate="true" comment="Patch 113329-19 or later installed" test_ref="oval:org.mitre.oval:tst:7921"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (x86) meets Sun Alert 236884">
          <extend_definition comment="Solaris 9 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1683"/>
          <criterion negate="true" comment="Patch 114980-20 or later installed" test_ref="oval:org.mitre.oval:tst:7759"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 236884">
          <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
          <criterion negate="true" comment="Patch 127127-11 or later installed" test_ref="oval:org.mitre.oval:tst:7382"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 236884">
          <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
          <criterion negate="true" comment="Patch 127128-11 or later installed" test_ref="oval:org.mitre.oval:tst:7793"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5258" version="1" class="vulnerability">
      <metadata>
        <title>Security Vulnerability in Solaris 10 Involving the SCTP Protocol May Result in a Denial of Network Services Due to Network Flooding</title>
        <affected family="unix">
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-2090" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-2090"/>
        <description>Unspecified vulnerability in the SCTP protocol implementation in Sun Solaris 10 allows remote attackers to cause a denial of service (CPU consumption and network traffic amplification) via a crafted SCTP packet.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-05-05T13:33:55.000-04:00">
              <contributor organization="Hewlett-Packard">Nicholas Hansen</contributor>
            </submitted>
            <status_change date="2008-05-08T13:36:09.054-04:00">DRAFT</status_change>
            <status_change date="2008-05-26T04:00:20.600-04:00">INTERIM</status_change>
            <status_change date="2008-06-16T04:00:07.192-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 236521">
          <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
          <criterion negate="true" comment="Patch 127127-08 or later installed" test_ref="oval:org.mitre.oval:tst:7996"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 236521">
          <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
          <criterion negate="true" comment="Patch 127128-08 or later installed" test_ref="oval:org.mitre.oval:tst:7373"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5165" version="1" class="vulnerability">
      <metadata>
        <title>Security Vulnerability in Solaris 10 Involving the SCTP Protocol May Result in a Panic and Denial of Service (DoS)</title>
        <affected family="unix">
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-2089" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-2089"/>
        <description>Unspecified vulnerability in the SCTP protocol implementation in Sun Solaris 10 allows remote attackers to cause a denial of service (panic) via a crafted SCTP packet.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-05-05T13:33:55.000-04:00">
              <contributor organization="Hewlett-Packard">Nicholas Hansen</contributor>
            </submitted>
            <status_change date="2008-05-08T13:36:09.338-04:00">DRAFT</status_change>
            <status_change date="2008-05-26T04:00:19.762-04:00">INTERIM</status_change>
            <status_change date="2008-06-16T04:00:06.194-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 236321">
          <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
          <criterion negate="true" comment="Patch 127127-08 or later installed" test_ref="oval:org.mitre.oval:tst:7996"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 236321">
          <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
          <criterion negate="true" comment="Patch 127128-08 or later installed" test_ref="oval:org.mitre.oval:tst:7373"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:4950" version="1" class="vulnerability">
      <metadata>
        <title>A Security Vulnerability in Floating Point Context Switch Implementation May Result in a Denial of Service (DoS) or Data Integrity Issues</title>
        <affected family="unix">
          <platform>Sun Solaris 9</platform>
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-1778" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1778"/>
        <description>Unspecified vulnerability in the floating point context switch implementation in Sun Solaris 9 and 10 on x86 platforms might allow local users to cause a denial of service (application exit), corrupt data, or trigger incorrect calculations via unknown vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-04-15T07:48:47.000-04:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2008-04-15T12:06:15.409-04:00">DRAFT</status_change>
            <status_change date="2008-05-05T04:00:22.388-04:00">INTERIM</status_change>
            <status_change date="2008-05-26T04:00:19.375-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND" comment="Solaris 9 (x86) meets Sun Alert 233921">
          <extend_definition comment="Solaris 9 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1683"/>
          <criterion negate="true" comment="Patch 122301-23 or later installed" test_ref="oval:org.mitre.oval:tst:7682"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 233921">
          <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
          <criterion negate="true" comment="Patch 127112-10 or later installed" test_ref="oval:org.mitre.oval:tst:7749"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:4848" version="1" class="vulnerability">
      <metadata>
        <title>A Security Vulnerability in the Handling of Self Encapsulated IP Packets may Lead to a Denial of Service (DOS) Condition.</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <platform>Sun Solaris 9</platform>
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-1779" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1779"/>
        <description>Sun Solaris 8, 9, and 10 allows "remote privileged" users to cause a denial of service (panic) via unknown vectors related to self encapsulated IP packets.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-04-15T07:48:47.000-04:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2008-04-15T12:06:17.868-04:00">DRAFT</status_change>
            <status_change date="2008-05-05T04:00:21.938-04:00">INTERIM</status_change>
            <status_change date="2008-05-26T04:00:15.482-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND" comment="Solaris 8 (SPARC) meets Sun Alert 235901">
          <extend_definition comment="Solaris 8 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1539"/>
          <criterion negate="true" comment="Patch 116965-32 or later installed" test_ref="oval:org.mitre.oval:tst:7947"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (SPARC) meets Sun Alert 235901">
          <extend_definition comment="Solaris 9 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1457"/>
          <criterion negate="true" comment="Patch 114344-34 or later installed" test_ref="oval:org.mitre.oval:tst:7482"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 235901">
          <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
          <criterion negate="true" comment="Patch 127111-11 or later installed" test_ref="oval:org.mitre.oval:tst:7975"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 8 (x86) meets Sun Alert 235901">
          <extend_definition comment="Solaris 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:2059"/>
          <criterion negate="true" comment="Patch 116966-31 or later installed" test_ref="oval:org.mitre.oval:tst:7668"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (x86) meets Sun Alert 235901">
          <extend_definition comment="Solaris 9 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1683"/>
          <criterion negate="true" comment="Patch 119435-22 or later installed" test_ref="oval:org.mitre.oval:tst:7881"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 235901">
          <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
          <criterion negate="true" comment="Patch 127112-11 or later installed" test_ref="oval:org.mitre.oval:tst:7822"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5369" version="1" class="vulnerability">
      <metadata>
        <title>Security Vulnerability in inetd(1M) Daemon When Debug Logging is Enabled</title>
        <affected family="unix">
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-1684" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1684"/>
        <description>inetd on Sun Solaris 10, when debug logging is enabled, allows local users to write to arbitrary files via a symlink attack on the /var/tmp/inetd.log temporary file.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-04-08T07:20:30.000-04:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2008-04-09T13:51:36.728-04:00">DRAFT</status_change>
            <status_change date="2008-04-28T04:00:15.519-04:00">INTERIM</status_change>
            <status_change date="2008-05-19T04:00:13.301-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="Software Section">
          <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 233284">
            <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
            <criterion negate="true" comment="Patch 127718-05 or later installed" test_ref="oval:org.mitre.oval:tst:7859"/>
          </criteria>
          <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 233284">
            <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
            <criterion negate="true" comment="Patch 127719-05 or later installed" test_ref="oval:org.mitre.oval:tst:7909"/>
          </criteria>
        </criteria>
        <criterion comment="File /var/tmp/inetd.log exists" test_ref="oval:org.mitre.oval:tst:7756"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:4814" version="1" class="vulnerability">
      <metadata>
        <title>A Security Vulnerability in Solaris 10 libexif May Allow Code Execution or a Denial of Service (DoS) Condition</title>
        <affected family="unix">
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-6352" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6352"/>
        <description>Integer overflow in libexif 0.6.16 and earlier allows context-dependent attackers to execute arbitrary code via an image with crafted EXIF tags, possibly involving the exif_data_load_data_thumbnail function in exif-data.c.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-03-25T13:04:49.000-04:00">
              <contributor organization="Hewlett-Packard">Nicholas Hansen</contributor>
            </submitted>
            <status_change date="2008-03-26T16:26:15.177-04:00">DRAFT</status_change>
            <status_change date="2008-04-14T04:00:08.823-04:00">INTERIM</status_change>
            <status_change date="2008-05-05T04:00:21.678-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 234701">
          <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
          <criterion negate="true" comment="Patch 121095-02 or later installed" test_ref="oval:org.mitre.oval:tst:7952"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 234701">
          <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
          <criterion negate="true" comment="Patch 121096-02 or later installed" test_ref="oval:org.mitre.oval:tst:7912"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5431" version="1" class="vulnerability">
      <metadata>
        <title>Multiple Security Vulnerabilities in ICU 3.2 Library Regular Expression Processing May Cause a Denial of Service (DoS)</title>
        <affected family="unix">
          <platform>Sun Solaris 9</platform>
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-4771" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4771"/>
        <description>Heap-based buffer overflow in the doInterval function in regexcmp.cpp in libicu in International Components for Unicode (ICU) 3.8.1 and earlier allows context-dependent attackers to cause a denial of service (memory consumption) and possibly have unspecified other impact via a regular expression that writes a large amount of data to the backtracking stack.  NOTE: some of these details are obtained from third party information.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-03-11T10:54:48.000-04:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2008-03-12T09:38:12.118-04:00">DRAFT</status_change>
            <status_change date="2008-03-31T04:00:09.181-04:00">INTERIM</status_change>
            <status_change date="2008-04-21T04:00:22.018-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND" comment="Solaris 9 (SPARC) meets Sun Alert 233922">
          <extend_definition comment="Solaris 9 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1457"/>
          <criterion negate="true" comment="Patch 114677-15 or later installed" test_ref="oval:org.mitre.oval:tst:7086"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 233922">
          <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
          <criterion negate="true" comment="Patch 119810-05 or later installed" test_ref="oval:org.mitre.oval:tst:7683"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (x86) meets Sun Alert 233922">
          <extend_definition comment="Solaris 9 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1683"/>
          <criterion negate="true" comment="Patch 114678-15 or later installed" test_ref="oval:org.mitre.oval:tst:7869"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 233922">
          <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
          <criterion negate="true" comment="Patch 119811-05 or later installed" test_ref="oval:org.mitre.oval:tst:6971"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5507" version="1" class="vulnerability">
      <metadata>
        <title>Multiple Security Vulnerabilities in ICU 3.2 Library Regular Expression Processing May Cause a Denial of Service (DoS)</title>
        <affected family="unix">
          <platform>Sun Solaris 9</platform>
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-4770" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4770"/>
        <description>libicu in International Components for Unicode (ICU) 3.8.1 and earlier attempts to process backreferences to the nonexistent capture group zero (aka \0), which might allow context-dependent attackers to read from, or write to, out-of-bounds memory locations, related to corruption of REStackFrames.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-03-11T10:54:47.000-04:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2008-03-12T09:38:11.814-04:00">DRAFT</status_change>
            <status_change date="2008-03-31T04:00:11.544-04:00">INTERIM</status_change>
            <status_change date="2008-04-21T04:00:22.668-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND" comment="Solaris 9 (SPARC) meets Sun Alert 233922">
          <extend_definition comment="Solaris 9 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1457"/>
          <criterion negate="true" comment="Patch 114677-15 or later installed" test_ref="oval:org.mitre.oval:tst:7086"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 233922">
          <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
          <criterion negate="true" comment="Patch 119810-05 or later installed" test_ref="oval:org.mitre.oval:tst:7683"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (x86) meets Sun Alert 233922">
          <extend_definition comment="Solaris 9 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1683"/>
          <criterion negate="true" comment="Patch 114678-15 or later installed" test_ref="oval:org.mitre.oval:tst:7869"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 233922">
          <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
          <criterion negate="true" comment="Patch 119811-05 or later installed" test_ref="oval:org.mitre.oval:tst:6971"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5511" version="1" class="vulnerability">
      <metadata>
        <title>Security Vulnerability May Allow Firewall Compromise or Creation of Denial of Service (DoS) Condition</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <platform>Sun Solaris 9</platform>
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-1095" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1095"/>
        <description>Unspecified vulnerability in the Internet Protocol (IP) implementation in Sun Solaris 8, 9, and 10 allows remote attackers to bypass intended firewall policies or cause a denial of service (panic) via unknown vectors, possibly related to ICMP packets and IP fragment reassembly.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-03-04T08:44:56.000-05:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2008-03-06T08:35:11.775-05:00">DRAFT</status_change>
            <status_change date="2008-03-24T04:00:48.629-04:00">INTERIM</status_change>
            <status_change date="2008-04-14T04:00:10.100-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND" comment="Solaris 8 (SPARC) meets Sun Alert 200183">
          <extend_definition comment="Solaris 8 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1539"/>
          <criterion negate="true" comment="Patch 116965-30 or later installed" test_ref="oval:org.mitre.oval:tst:7533"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (SPARC) meets Sun Alert 200183">
          <extend_definition comment="Solaris 9 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1457"/>
          <criterion negate="true" comment="Patch 114344-32 or later installed" test_ref="oval:org.mitre.oval:tst:7854"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 200183">
          <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
          <criterion negate="true" comment="Patch 118822-27 or later installed" test_ref="oval:org.mitre.oval:tst:7608"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 8 (x86) meets Sun Alert 200183">
          <extend_definition comment="Solaris 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:2059"/>
          <criterion negate="true" comment="Patch 116966-29 or later installed" test_ref="oval:org.mitre.oval:tst:7656"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (x86) meets Sun Alert 200183">
          <extend_definition comment="Solaris 9 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1683"/>
          <criterion negate="true" comment="Patch 119435-20 or later installed" test_ref="oval:org.mitre.oval:tst:6892"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 200183">
          <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
          <criterion negate="true" comment="Patch 118844-28 or later installed" test_ref="oval:org.mitre.oval:tst:7175"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5476" version="1" class="vulnerability">
      <metadata>
        <title>Two Security Vulnerabilities Exist Within the cpc(3CPC) Sub-System of the Solaris Kernel</title>
        <affected family="unix">
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-0933" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-0933"/>
        <description>Multiple race conditions in the CPU Performance Counters (cpc) subsystem in the kernel in Sun Solaris 10 allow local users to cause a denial of service (panic) via unspecified vectors related to kcpc_unbind and kcpc_restore.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-02-27T15:10:44.000-05:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2008-02-28T09:30:27.469-05:00">DRAFT</status_change>
            <status_change date="2008-03-17T04:00:23.723-04:00">INTERIM</status_change>
            <status_change date="2008-04-07T04:00:10.576-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 231466">
          <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
          <criterion negate="true" comment="Patch 127111-08 or later installed" test_ref="oval:org.mitre.oval:tst:7708"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 231466">
          <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
          <criterion negate="true" comment="Patch 127112-08 or later installed" test_ref="oval:org.mitre.oval:tst:7275"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5451" version="1" class="vulnerability">
      <metadata>
        <title>Security Vulnerability in the Solaris 10 DTrace Dynamic Tracing Framework May Allow Unauthorized Kernel Level Tracing</title>
        <affected family="unix">
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-0938" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-0938"/>
        <description>Unspecified vulnerability in the dynamic tracing framework (DTrace) in Sun Solaris 10 allows local users with PRIV_DTRACE_USER or PRIV_DTRACE_PROC privileges to obtain sensitive kernel information via unspecified vectors, a different vulnerability than CVE-2007-4126.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-02-27T15:10:45.000-05:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2008-02-28T09:30:27.910-05:00">DRAFT</status_change>
            <status_change date="2008-03-17T04:00:23.061-04:00">INTERIM</status_change>
            <status_change date="2008-04-07T04:00:09.767-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 231803">
          <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
          <criterion negate="true" comment="Patch 120011-04 or later installed" test_ref="oval:org.mitre.oval:tst:7688"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 231803">
          <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
          <criterion negate="true" comment="Patch 120012-04 or later installed" test_ref="oval:org.mitre.oval:tst:7520"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5216" version="1" class="vulnerability">
      <metadata>
        <title>Security Vulnerability in the libxml2 Library May Lead to a Denial of Service (DoS)</title>
        <affected family="unix">
          <platform>Sun Solaris 9</platform>
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-6284" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6284"/>
        <description>The xmlCurrentChar function in libxml2 before 2.6.31 allows context-dependent attackers to cause a denial of service (infinite loop) via XML containing invalid UTF-8 sequences.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-02-12T08:48:33.000-05:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2008-02-13T09:26:34.461-05:00">DRAFT</status_change>
            <status_change date="2008-03-03T04:00:10.886-05:00">INTERIM</status_change>
            <status_change date="2008-03-24T04:00:40.950-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND" comment="Solaris 9 (SPARC) meets Sun Alert 201514">
          <extend_definition comment="Solaris 9 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1457"/>
          <criterion negate="true" comment="Patch 114014-18 or later installed" test_ref="oval:org.mitre.oval:tst:7816"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 201514">
          <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
          <criterion negate="true" comment="Patch 125731-02 or later installed" test_ref="oval:org.mitre.oval:tst:7732"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (x86) meets Sun Alert 201514">
          <extend_definition comment="Solaris 9 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1683"/>
          <criterion negate="true" comment="Patch 114015-18 or later installed" test_ref="oval:org.mitre.oval:tst:7223"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 201514">
          <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
          <criterion negate="true" comment="Patch 125732-02 or later installed" test_ref="oval:org.mitre.oval:tst:7419"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5337" version="1" class="vulnerability">
      <metadata>
        <title>Security Vulnerability in Solaris 10 OpenSSL SSL_get_shared_ciphers() Function</title>
        <affected family="unix">
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-5135" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5135"/>
        <description>Off-by-one error in the SSL_get_shared_ciphers function in OpenSSL 0.9.7 up to 0.9.7l, and 0.9.8 up to 0.9.8f, might allow remote attackers to execute arbitrary code via a crafted packet that triggers a one-byte buffer underflow.  NOTE: this issue was introduced as a result of a fix for CVE-2006-3738.  As of 20071012, it is unknown whether code execution is possible.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-02-14T08:25:18.000-05:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2008-02-14T15:57:58.357-05:00">DRAFT</status_change>
            <status_change date="2008-03-03T04:00:13.537-05:00">INTERIM</status_change>
            <status_change date="2008-03-24T04:00:43.411-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 200858">
          <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
          <criterion negate="true" comment="Patch 127111-08 or later installed" test_ref="oval:org.mitre.oval:tst:7721"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 200858">
          <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
          <criterion negate="true" comment="Patch 127112-08 or later installed" test_ref="oval:org.mitre.oval:tst:7761"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5393" version="1" class="vulnerability">
      <metadata>
        <title>Security Vulnerability in the Solaris X Server May Lead to Unauthorized Disclosure of Information on Access Restricted Files and Directories</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <platform>Sun Solaris 9</platform>
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-5958" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5958"/>
        <description>X.Org Xserver before 1.4.1 allows local users to determine the existence of arbitrary files via a filename argument in the -sp option to the X program, which produces different error messages depending on whether the filename exists.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-02-12T08:48:34.000-05:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2008-02-13T09:26:36.813-05:00">DRAFT</status_change>
            <status_change date="2008-03-03T04:00:16.207-05:00">INTERIM</status_change>
            <status_change date="2008-03-24T04:00:46.668-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND" comment="Solaris 8 (SPARC) meets Sun Alert 230901">
          <extend_definition comment="Solaris 8 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1539"/>
          <criterion negate="true" comment="Patch 119067-09 or later installed" test_ref="oval:org.mitre.oval:tst:7606"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (SPARC) meets Sun Alert 230901">
          <extend_definition comment="Solaris 9 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1457"/>
          <criterion negate="true" comment="Patch 112785-63 or later installed" test_ref="oval:org.mitre.oval:tst:7770"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
          <criteria operator="OR">
            <criteria operator="AND">
              <criterion comment="File Xsun exists" test_ref="oval:org.mitre.oval:tst:3109"/>
              <criterion negate="true" comment="Patch 119059-38 or later installed" test_ref="oval:org.mitre.oval:tst:7694"/>
            </criteria>
            <criteria operator="AND">
              <criterion comment="File Xorg exists" test_ref="oval:org.mitre.oval:tst:1336"/>
              <criterion negate="true" comment="Patch 125719-07 or later installed" test_ref="oval:org.mitre.oval:tst:7744"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Solaris 8 (x86) meets Sun Alert 230901">
          <extend_definition comment="Solaris 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:2059"/>
          <criterion negate="true" comment="Patch 119068-09 or later installed" test_ref="oval:org.mitre.oval:tst:7681"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="Solaris 9 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1683"/>
          <criteria operator="OR">
            <criteria operator="AND">
              <criterion comment="File Xsun exists" test_ref="oval:org.mitre.oval:tst:3109"/>
              <criterion negate="true" comment="Patch 112786-52 or later installed" test_ref="oval:org.mitre.oval:tst:7415"/>
            </criteria>
            <criteria operator="AND">
              <criterion comment="File Xorg exists" test_ref="oval:org.mitre.oval:tst:1336"/>
              <criterion negate="true" comment="Patch 118908-04 or later installed" test_ref="oval:org.mitre.oval:tst:7428"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
          <criteria operator="OR">
            <criteria operator="AND">
              <criterion comment="File Xsun exists" test_ref="oval:org.mitre.oval:tst:3109"/>
              <criterion negate="true" comment="Patch 119060-37 or later installed" test_ref="oval:org.mitre.oval:tst:7764"/>
            </criteria>
            <criteria operator="AND">
              <criterion comment="File Xorg exists" test_ref="oval:org.mitre.oval:tst:1336"/>
              <criterion negate="true" comment="Patch 125720-17 or later installed" test_ref="oval:org.mitre.oval:tst:7423"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5474" version="1" class="vulnerability">
      <metadata>
        <title>A Security Vulnerability in the USB Mouse STREAMS Module May Lead to a System Panic</title>
        <affected family="unix">
          <platform>Sun Solaris 9</platform>
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-0718" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-0718"/>
        <description>Unspecified vulnerability in the USB Mouse STREAMS module (usbms) in Sun Solaris 9 and 10, when 64-bit mode is enabled, allows local users to cause a denial of service (panic) via unspecified vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-02-13T12:25:59.000-05:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2008-02-13T16:34:39.778-05:00">DRAFT</status_change>
            <status_change date="2008-03-03T04:00:18.196-05:00">INTERIM</status_change>
            <status_change date="2008-03-24T04:00:47.661-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="Software Section">
          <criteria operator="AND" comment="Solaris 9 (SPARC) meets Sun Alert 201316">
            <extend_definition comment="Solaris 9 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1457"/>
            <criterion negate="true" comment="Patch 115553-29 or later installed" test_ref="oval:org.mitre.oval:tst:7796"/>
          </criteria>
          <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 201316">
            <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
            <criterion negate="true" comment="Patch 123402-01 or later installed" test_ref="oval:org.mitre.oval:tst:7809"/>
          </criteria>
          <criteria operator="AND" comment="Solaris 9 (x86) meets Sun Alert 201316">
            <extend_definition comment="Solaris 9 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1683"/>
            <criterion negate="true" comment="Patch 115554-25 or later installed" test_ref="oval:org.mitre.oval:tst:6972"/>
          </criteria>
          <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 201316">
            <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
            <criterion negate="true" comment="Patch 123403-01 or later installed" test_ref="oval:org.mitre.oval:tst:7804"/>
          </criteria>
        </criteria>
        <criterion comment="system is running in 64-bit mode" test_ref="oval:org.mitre.oval:tst:3884"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5545" version="1" class="vulnerability">
      <metadata>
        <title>Security Vulnerability in Simplified Chinese, Traditional Chinese, Korean, and Thai Language Input Methods</title>
        <affected family="unix">
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-0730" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-0730"/>
        <description>The (1) Simplified Chinese, (2) Traditional Chinese, (3) Korean, and (4) Thai language input methods in Sun Solaris 10 create files and directories with weak permissions under (a) .iiim/le and (b) .Xlocale in home directories, which might allow local users to write to, or read from, the home directories of other users.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-02-13T12:26:00.000-05:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2008-02-13T16:34:40.858-05:00">DRAFT</status_change>
            <status_change date="2008-03-03T04:00:18.561-05:00">INTERIM</status_change>
            <status_change date="2008-03-24T04:00:48.962-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="Software Section">
          <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 201315">
            <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
            <criteria operator="OR">
              <criterion negate="true" comment="Patch 120412-08 or later installed" test_ref="oval:org.mitre.oval:tst:7399"/>
              <criterion negate="true" comment="Patch 120414-20 or later installed" test_ref="oval:org.mitre.oval:tst:7700"/>
            </criteria>
          </criteria>
          <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 201315">
            <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
            <criteria operator="OR">
              <criterion negate="true" comment="Patch 120413-08 or later installed" test_ref="oval:org.mitre.oval:tst:7743"/>
              <criterion negate="true" comment="Patch 120415-20 or later installed" test_ref="oval:org.mitre.oval:tst:7675"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="OR" comment="Configuration Section">
          <criterion comment="Package SUNWcleu2 (Simplified Chinese) is installed" test_ref="oval:org.mitre.oval:tst:6860"/>
          <criterion comment="Package SUNWhleu2 (Traditional Chinese) is installed" test_ref="oval:org.mitre.oval:tst:7614"/>
          <criterion comment="PPackage SUNWhkleu (Traditional Chinese (Hong Kong)) is installed" test_ref="oval:org.mitre.oval:tst:7115"/>
          <criterion comment="Package SUNWkleu (Korean) is installed" test_ref="oval:org.mitre.oval:tst:7155"/>
          <criterion comment="Package SUNWtleu (Thai) is installed" test_ref="oval:org.mitre.oval:tst:7742"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5532" version="1" class="vulnerability">
      <metadata>
        <title>Security Vulnerability in FreeType 2 Font Engine May Allow Privilege Escalation Due to Heap Overflow</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <platform>Sun Solaris 9</platform>
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-2754" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2754"/>
        <description>Integer signedness error in truetype/ttgload.c in Freetype 2.3.4 and earlier might allow remote attackers to execute arbitrary code via a crafted TTF image with a negative n_points value, which leads to an integer overflow and heap-based buffer overflow.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-01-09T07:41:41.000-05:00">
              <contributor organization="Hewlett-Packard">Nicholas Hansen</contributor>
            </submitted>
            <status_change date="2008-01-09T14:14:49.552-05:00">DRAFT</status_change>
            <status_change date="2008-02-04T10:19:29.641-05:00">INTERIM</status_change>
            <status_change date="2008-02-25T04:00:11.261-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND" comment="Solaris 8 (SPARC) meets Sun Alert 103171">
          <extend_definition comment="Solaris 8 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1539"/>
          <criterion negate="true" comment="Patch 124420-03 or later installed" test_ref="oval:org.mitre.oval:tst:7777"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (SPARC) meets Sun Alert 103171">
          <extend_definition comment="Solaris 9 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1457"/>
          <criterion negate="true" comment="Patch 116105-08 or later installed" test_ref="oval:org.mitre.oval:tst:7445"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 103171">
          <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
          <criterion negate="true" comment="Patch 119812-05 or later installed" test_ref="oval:org.mitre.oval:tst:7736"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 8 (x86) meets Sun Alert 103171">
          <extend_definition comment="Solaris 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:2059"/>
          <criterion negate="true" comment="Patch 124421-03 or later installed" test_ref="oval:org.mitre.oval:tst:7493"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (x86) meets Sun Alert 103171">
          <extend_definition comment="Solaris 9 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1683"/>
          <criterion negate="true" comment="Patch 116106-07 or later installed" test_ref="oval:org.mitre.oval:tst:7547"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 103171">
          <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
          <criterion negate="true" comment="Patch 119813-07 or later installed" test_ref="oval:org.mitre.oval:tst:6931"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5400" version="1" class="vulnerability">
      <metadata>
        <title>Security Vulnerability in Solaris 10 Related to the dotoprocs() Routine</title>
        <affected family="unix">
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-0269" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-0269"/>
        <description>Unspecified vulnerability in the dotoprocs function in Sun Solaris 10 allows local users to cause a denial of service (panic) via unspecified vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-01-16T09:18:15.000-05:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2008-01-17T09:53:53.580-05:00">DRAFT</status_change>
            <status_change date="2008-02-04T10:19:21.179-05:00">INTERIM</status_change>
            <status_change date="2008-02-25T04:00:10.927-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 103188">
          <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
          <criterion negate="true" comment="Patch 127111-06 or later installed" test_ref="oval:org.mitre.oval:tst:7472"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 103188">
          <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
          <criterion negate="true" comment="Patch 127112-06 or later installed" test_ref="oval:org.mitre.oval:tst:7670"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5211" version="1" class="vulnerability">
      <metadata>
        <title>A Security Vulnerability in libdevinfo(3LIB) May Allow Unauthorized Access to Files on the System</title>
        <affected family="unix">
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-0242" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-0242"/>
        <description>Unspecified vulnerability in libdevinfo in Sun Solaris 10 allows local users to access files and gain privileges via unknown vectors, related to login device permissions.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-01-15T11:52:30.000-05:00">
              <contributor organization="Hewlett-Packard">Yuzheng Zhou</contributor>
            </submitted>
            <status_change date="2008-01-17T09:54:51.531-05:00">DRAFT</status_change>
            <status_change date="2008-02-04T10:19:00.101-05:00">INTERIM</status_change>
            <status_change date="2008-02-25T04:00:10.261-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 103165">
          <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
          <criterion negate="true" comment="Patch 125251-02 installed" test_ref="oval:org.mitre.oval:tst:7347"/>
          <criterion comment="Patch 118833-04 or later installed" test_ref="oval:org.mitre.oval:tst:7841"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 103165">
          <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
          <criterion negate="true" comment="Patch 125252-02 installed" test_ref="oval:org.mitre.oval:tst:7106"/>
          <criterion comment="Patch 118855-03 or later installed" test_ref="oval:org.mitre.oval:tst:7786"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:4356" version="1" class="vulnerability">
      <metadata>
        <title>Security Vulnerabilities in OpenSSL May Lead to a Denial of Service (DoS) to Applications or Execution of Arbitrary Code With Elevated Privileges</title>
        <affected family="unix">
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-4343" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-4343"/>
        <description>The get_server_hello function in the SSLv2 client code in OpenSSL 0.9.7 before 0.9.7l, 0.9.8 before 0.9.8d, and earlier versions allows remote servers to cause a denial of service (client crash) via unknown vectors that trigger a null pointer dereference.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-12-04T09:53:52.000-05:00">
              <contributor organization="Hewlett-Packard">Todd Dolinsky</contributor>
            </submitted>
            <status_change date="2007-12-06T15:39:49.237-05:00">DRAFT</status_change>
            <status_change date="2007-12-24T04:06:29.015-05:00">INTERIM</status_change>
            <status_change date="2008-01-14T04:00:06.896-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 102711">
          <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
          <criteria operator="OR">
            <criterion negate="true" comment="Patch 121229-02 or later installed" test_ref="oval:org.mitre.oval:tst:6483"/>
            <criteria operator="AND">
              <criterion comment="Patch 121229-02 or later installed" test_ref="oval:org.mitre.oval:tst:6483"/>
              <criterion negate="true" comment="Patch 118562-13 or later installed" test_ref="oval:org.mitre.oval:tst:6849"/>
              <criterion comment="Pkg SUNWcry (Supplemental Encryption) is installed" test_ref="oval:org.mitre.oval:tst:3198"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 102711">
          <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
          <criteria operator="OR">
            <criterion negate="true" comment="Patch 121230-02 or later installed" test_ref="oval:org.mitre.oval:tst:6715"/>
            <criteria operator="AND">
              <criterion comment="Patch 121230-02 or later installed" test_ref="oval:org.mitre.oval:tst:6715"/>
              <criterion negate="true" comment="Patch 118563-13 or later installed" test_ref="oval:org.mitre.oval:tst:6121"/>
              <criterion comment="Pkg SUNWcry (Supplemental Encryption) is installed" test_ref="oval:org.mitre.oval:tst:3198"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:4256" version="1" class="vulnerability">
      <metadata>
        <title>Security Vulnerabilities in OpenSSL May Lead to a Denial of Service (DoS) to Applications or Execution of Arbitrary Code With Elevated Privileges</title>
        <affected family="unix">
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-3738" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-3738"/>
        <description>Buffer overflow in the SSL_get_shared_ciphers function in OpenSSL 0.9.7 before 0.9.7l, 0.9.8 before 0.9.8d, and earlier versions has unspecified impact and remote attack vectors involving a long list of ciphers.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-12-04T09:53:52.000-05:00">
              <contributor organization="Hewlett-Packard">Todd Dolinsky</contributor>
            </submitted>
            <status_change date="2007-12-06T15:39:48.901-05:00">DRAFT</status_change>
            <status_change date="2007-12-24T04:06:15.412-05:00">INTERIM</status_change>
            <status_change date="2008-01-14T04:00:05.944-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 102711">
          <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
          <criteria operator="OR">
            <criterion negate="true" comment="Patch 121229-02 or later installed" test_ref="oval:org.mitre.oval:tst:6483"/>
            <criteria operator="AND">
              <criterion comment="Patch 121229-02 or later installed" test_ref="oval:org.mitre.oval:tst:6483"/>
              <criterion negate="true" comment="Patch 118562-13 or later installed" test_ref="oval:org.mitre.oval:tst:6849"/>
              <criterion comment="Pkg SUNWcry (Supplemental Encryption) is installed" test_ref="oval:org.mitre.oval:tst:3198"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 102711">
          <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
          <criteria operator="OR">
            <criterion negate="true" comment="Patch 121230-02 or later installed" test_ref="oval:org.mitre.oval:tst:6715"/>
            <criteria operator="AND">
              <criterion comment="Patch 121230-02 or later installed" test_ref="oval:org.mitre.oval:tst:6715"/>
              <criterion negate="true" comment="Patch 118563-13 or later installed" test_ref="oval:org.mitre.oval:tst:6121"/>
              <criterion comment="Pkg SUNWcry (Supplemental Encryption) is installed" test_ref="oval:org.mitre.oval:tst:3198"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:4095" version="1" class="vulnerability">
      <metadata>
        <title>A Security Vulnerability in Solaris Volume Manager (SVM) May Allow a Denial of Service (DoS)</title>
        <affected family="unix">
          <platform>Sun Solaris 9</platform>
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-5921" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5921"/>
        <description>Unspecified vulnerability in the ioctl interface in the Solaris Volume Manager (SVM) in Sun Solaris 9 and 10 allows local users to cause a denial of service (panic) via unspecified vectors, a different vulnerability than CVE-2004-1346.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-11-14T13:46:57.000-05:00">
              <contributor organization="Hewlett-Packard">Nicholas Hansen</contributor>
            </submitted>
            <status_change date="2007-11-16T08:53:16.185-05:00">DRAFT</status_change>
            <status_change date="2007-12-03T04:05:58.160-05:00">INTERIM</status_change>
            <status_change date="2007-12-24T04:05:42.679-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 103143">
          <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
          <criterion negate="true" comment="Patch 124256-03 or later installed" test_ref="oval:org.mitre.oval:tst:6439"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 103143">
          <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
          <criterion negate="true" comment="Patch 126257-04 or later installed" test_ref="oval:org.mitre.oval:tst:6587"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (SPARC) meets Sun Alert 103143">
          <extend_definition comment="Solaris 9 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1457"/>
          <criterion negate="true" comment="Patch 116669-31 or later installed" test_ref="oval:org.mitre.oval:tst:5870"/>
          <criteria operator="OR" comment="Solaris 9 (SPARC) Sun Alert 103143 extra patches">
            <criterion comment="Patch 113026-03 or later installed" test_ref="oval:org.mitre.oval:tst:6795"/>
            <criterion comment="Patch 113073-11 or later installed" test_ref="oval:org.mitre.oval:tst:6844"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (x86) meets Sun Alert 103143">
          <extend_definition comment="Solaris 9 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1683"/>
          <criterion negate="true" comment="Patch 122371-07 or later installed" test_ref="oval:org.mitre.oval:tst:6632"/>
          <criteria operator="OR" comment="Solaris 9 (x86) Sun Alert 103143 extra patches">
            <criterion comment="Patch 113994-02 or later installed" test_ref="oval:org.mitre.oval:tst:6596"/>
            <criterion comment="Patch 118559-12 or later installed" test_ref="oval:org.mitre.oval:tst:6809"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:3270" version="1" class="vulnerability">
      <metadata>
        <title>Security Vulnerability in the Solaris 10 Internet Protocol (ip(7P)) may Lead to a Denial of Service (DoS) Condition</title>
        <affected family="unix">
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-5716" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5716"/>
        <description>Unspecified vulnerability in the Internet Protocol (IP) functionality in Sun Solaris 10 allows local users to cause a denial of service (panic) via unspecified vectors, probably related to a UDP packet.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-11-05T11:19:05.000-05:00">
              <contributor organization="Opsware, Inc.">Pai Peng</contributor>
            </submitted>
            <status_change date="2007-11-06T13:03:43.139-05:00">DRAFT</status_change>
            <status_change date="2007-11-26T04:00:04.347-05:00">INTERIM</status_change>
            <status_change date="2007-12-17T04:00:05.181-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 103087">
          <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
          <criterion comment="Patch 118833-04 or later installed" test_ref="oval:org.mitre.oval:tst:5394"/>
          <criterion negate="true" comment="Patch 127111-02 or later installed" test_ref="oval:org.mitre.oval:tst:5429"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 103087">
          <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
          <criterion comment="Patch 118855-03 or later installed" test_ref="oval:org.mitre.oval:tst:5577"/>
          <criterion negate="true" comment="Patch 127112-02 or later installed" test_ref="oval:org.mitre.oval:tst:5048"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:3162" version="1" class="vulnerability">
      <metadata>
        <title>Security Vulnerability in RPCSEC_GSS (rpcsec_gss(3NSL)) Affects Kerberos Administration Daemon (kadmind(1M))</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <platform>Sun Solaris 9</platform>
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-3999" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3999"/>
        <description>Stack-based buffer overflow in the svcauth_gss_validate function in lib/rpc/svc_auth_gss.c in the RPCSEC_GSS RPC library (librpcsecgss) in MIT Kerberos 5 (krb5) 1.4 through 1.6.2, as used by the Kerberos administration daemon (kadmind) and some third-party applications that use krb5, allows remote attackers to cause a denial of service (daemon crash) and probably execute arbitrary code via a long string in an RPC message.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-10-31T12:34:51.000-04:00">
              <contributor organization="Opsware, Inc.">Nicholas Hansen</contributor>
            </submitted>
            <status_change date="2007-11-01T12:41:43.692-04:00">DRAFT</status_change>
            <status_change date="2007-11-16T08:14:50.135-05:00">INTERIM</status_change>
            <status_change date="2007-12-03T04:01:50.066-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND" comment="Solaris 8 (SPARC) meets Sun Alert 103060">
          <extend_definition comment="Solaris 8 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1539"/>
          <criterion negate="true" comment="Patch 126928-02 or later installed" test_ref="oval:org.mitre.oval:tst:5410"/>
          <criterion comment="Key Distribution Center (kadmind) process running" test_ref="oval:org.mitre.oval:tst:3331"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (SPARC) meets Sun Alert 103060">
          <extend_definition comment="Solaris 9 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1457"/>
          <criterion negate="true" comment="Patch 113318-32 or later installed" test_ref="oval:org.mitre.oval:tst:5371"/>
          <criterion comment="Key Distribution Center (kadmind) process running" test_ref="oval:org.mitre.oval:tst:3331"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 103060">
          <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
          <criterion negate="true" comment="Patch 126661-02 or later installed" test_ref="oval:org.mitre.oval:tst:5581"/>
          <criterion comment="Key Distribution Center (kadmind) process running" test_ref="oval:org.mitre.oval:tst:3331"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 8 (x86) meets Sun Alert 103060">
          <extend_definition comment="Solaris 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:2059"/>
          <criterion negate="true" comment="Patch 126929-02 or later installed" test_ref="oval:org.mitre.oval:tst:5434"/>
          <criterion comment="Key Distribution Center (kadmind) process running" test_ref="oval:org.mitre.oval:tst:3331"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (x86) meets Sun Alert 103060">
          <extend_definition comment="Solaris 9 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1683"/>
          <criterion negate="true" comment="Patch 117468-18 or later installed" test_ref="oval:org.mitre.oval:tst:5207"/>
          <criterion comment="Key Distribution Center (kadmind) process running" test_ref="oval:org.mitre.oval:tst:3331"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 103060">
          <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
          <criterion negate="true" comment="Patch 126662-02 or later installed" test_ref="oval:org.mitre.oval:tst:5538"/>
          <criterion comment="Key Distribution Center (kadmind) process running" test_ref="oval:org.mitre.oval:tst:3331"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:3027" version="1" class="vulnerability">
      <metadata>
        <title>Security Vulnerabilities in Solaris Kernel Statistics Retrieval Process May Allow a Denial of Service (DoS)</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <platform>Sun Solaris 9</platform>
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-5632" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5632"/>
        <description>Multiple unspecified vulnerabilities in the kernel in Sun Solaris 8 through 10 allow local users to cause a denial of service (panic), related to the support for retrieval of kernel statistics, and possibly related to the sfmmu_mlspl_enter or sfmmu_mlist_enter functions.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-10-24T12:32:39.000-04:00">
              <contributor organization="Opsware, Inc.">Nicholas Hansen</contributor>
            </submitted>
            <status_change date="2007-10-24T17:06:05.258-04:00">DRAFT</status_change>
            <status_change date="2007-11-13T12:01:11.224-05:00">INTERIM</status_change>
            <status_change date="2007-12-03T04:01:12.772-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND" comment="Solaris 8 (SPARC) meets Sun Alert 103064">
          <extend_definition comment="Solaris 8 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1539"/>
          <criterion negate="true" comment="Patch 117350-50 or later installed" test_ref="oval:org.mitre.oval:tst:5260"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (SPARC) meets Sun Alert 103064">
          <extend_definition comment="Solaris 9 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1457"/>
          <criterion negate="true" comment="Patch 122300-13 or later installed" test_ref="oval:org.mitre.oval:tst:4570"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 103064">
          <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
          <criterion negate="true" comment="Patch 127111-01 or later installed" test_ref="oval:org.mitre.oval:tst:5241"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 8 (x86) meets Sun Alert 103064">
          <extend_definition comment="Solaris 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:2059"/>
          <criterion negate="true" comment="Patch 117351-50 or later installed" test_ref="oval:org.mitre.oval:tst:5306"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (x86) meets Sun Alert 103064">
          <extend_definition comment="Solaris 9 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1683"/>
          <criterion negate="true" comment="Patch 122301-13 or later installed" test_ref="oval:org.mitre.oval:tst:5341"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 103064">
          <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
          <criterion negate="true" comment="Patch 127112-01 or later installed" test_ref="oval:org.mitre.oval:tst:5374"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:2096" version="1" class="vulnerability">
      <metadata>
        <title>Security Vulnerability in the Solaris Auditing (BSM) Related to Network Auditing May Lead to Denial of Service (DoS)</title>
        <affected family="unix">
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-5422" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5422"/>
        <description>Unspecified vulnerability in "Solaris Auditing" in the Basic Security Module (BSM) in Sun Solaris 10, when configured for auditing of networking (nt) events, allows local users to cause a denial of service (panic) via unspecified vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-10-16T10:34:50.000-04:00">
              <contributor organization="Opsware, Inc.">Todd Dolinsky</contributor>
            </submitted>
            <status_change date="2007-10-16T14:50:57.377-04:00">DRAFT</status_change>
            <status_change date="2007-11-02T07:17:37.733-04:00">INTERIM</status_change>
            <status_change date="2007-11-19T04:00:56.246-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software and Configuration sections" operator="AND">
        <criteria operator="OR" comment="Software Section">
          <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 103096" negate="false">
            <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
            <criterion comment="Patch 127111-01 or later installed" test_ref="oval:org.mitre.oval:tst:3953" negate="true"/>
          </criteria>
          <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 103096" negate="false">
            <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
            <criterion comment="Patch 127112-01 or later installed" test_ref="oval:org.mitre.oval:tst:4336" negate="true"/>
          </criteria>
        </criteria>
        <criterion comment="Solaris auditing is enabled" negate="false" test_ref="oval:org.mitre.oval:tst:4548"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1933" version="1" class="vulnerability">
      <metadata>
        <title>Security Vulnerability in the Solaris 10 Virtual File System (VFS) may Lead to a Denial of Service (DoS) Condition</title>
        <affected family="unix">
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-5367" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5367"/>
        <description>Unspecified vulnerability in the Virtual File System (VFS) in Sun Solaris 10 allows local users to cause a denial of service (kernel memory consumption) via unspecified vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-10-12T07:38:45.000-04:00">
              <contributor organization="Opsware, Inc.">Pai Peng</contributor>
            </submitted>
            <status_change date="2007-10-15T18:16:19.589-04:00">DRAFT</status_change>
            <status_change date="2007-11-02T07:17:33.539-04:00">INTERIM</status_change>
            <status_change date="2007-11-19T04:00:45.447-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 103088" negate="false">
          <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
          <criterion comment="Patch 127111-01 or later installed" test_ref="oval:org.mitre.oval:tst:3557" negate="true"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 103088" negate="false">
          <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
          <criterion comment="Patch 127112-01 or later installed" test_ref="oval:org.mitre.oval:tst:4169" negate="true"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1892" version="1" class="vulnerability">
      <metadata>
        <title>Security Vulnerabilities in the Solaris Trusted Extensions "labeld" Service May Lead to a Denial of Service (DoS) Condition</title>
        <affected family="unix">
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-5368" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5368"/>
        <description>Multiple unspecified vulnerabilities in labeld in Trusted Extensions in Sun Solaris 10 allow local users to cause a denial of service (multiple application hang) via unspecified vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-10-12T07:38:45.000-04:00">
              <contributor organization="Opsware, Inc.">Pai Peng</contributor>
            </submitted>
            <status_change date="2007-10-15T18:16:19.852-04:00">DRAFT</status_change>
            <status_change date="2007-11-02T07:17:32.943-04:00">INTERIM</status_change>
            <status_change date="2007-11-19T04:00:43.393-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 103109" negate="false">
          <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
          <criterion comment="Patch 126448-04 or later installed" test_ref="oval:org.mitre.oval:tst:4307" negate="true"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 103109" negate="false">
          <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
          <criterion comment="Patch 126449-04 or later installed" test_ref="oval:org.mitre.oval:tst:4545" negate="true"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1726" version="2" class="vulnerability">
      <metadata>
        <title>Security Vulnerability in the Kerberos Administration Daemon (kadmind(1M)) May Lead to Arbitrary Code Execution</title>
        <affected family="unix">
          <platform>Sun Solaris 9</platform>
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-2798" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2798"/>
        <description>Stack-based buffer overflow in the rename_principal_2_svc function in kadmind for MIT Kerberos 1.5.3, 1.6.1, and other versions allows remote authenticated users to execute arbitrary code via a crafted request to rename a principal.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-06-28T09:00:00.000-04:00">
              <contributor organization="Opsware, Inc.">Nicholas Hansen</contributor>
            </submitted>
            <status_change date="2007-06-29T09:24:18.908-04:00">DRAFT</status_change>
            <status_change date="2007-07-16T09:55:10.258-04:00">INTERIM</status_change>
            <status_change date="2007-08-01T22:26:14.499-04:00">ACCEPTED</status_change>
            <modified comment="The test references for all the criterion were inverted. This fix corrects the test_refs and updates the criteria comments to include the Sun Alert reference." date="2007-11-01T13:08:00.938-04:00">
              <contributor organization="Opsware, Inc.">Nicholas Hansen</contributor>
            </modified>
            <status_change date="2007-11-01T13:11:21.000-04:00">INTERIM</status_change>
            <status_change date="2007-11-16T08:14:19.297-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software section">
        <criteria operator="AND" comment="Solaris 8 (SPARC) meets Sun Alert 102985">
          <extend_definition comment="Solaris 8 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1539"/>
          <criterion comment="Sun Enterprise Authentication Mechanism (SEAM, SUNWkr5ma) installed" test_ref="oval:org.mitre.oval:tst:3971"/>
          <criterion comment="Key Distribution Center (kadmind) process running" test_ref="oval:org.mitre.oval:tst:3331"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 8 (x86) meets Sun Alert 102985">
          <extend_definition comment="Solaris 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:2059"/>
          <criterion comment="Sun Enterprise Authentication Mechanism (SEAM, SUNWkr5ma) installed" test_ref="oval:org.mitre.oval:tst:3971"/>
          <criterion comment="Key Distribution Center (kadmind) process running" test_ref="oval:org.mitre.oval:tst:3331"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (SPARC) meets Sun Alert 102985">
          <extend_definition comment="Solaris 9 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1457"/>
          <criterion comment="Sun Enterprise Authentication Mechanism (SEAM, SUNWkr5ma) installed" test_ref="oval:org.mitre.oval:tst:3971"/>
          <criterion comment="Key Distribution Center (kadmind) process running" test_ref="oval:org.mitre.oval:tst:3331"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (x86) meets Sun Alert 102985">
          <extend_definition comment="Solaris 9 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1683"/>
          <criterion comment="Sun Enterprise Authentication Mechanism (SEAM, SUNWkr5ma) installed" test_ref="oval:org.mitre.oval:tst:3971"/>
          <criterion comment="Key Distribution Center (kadmind) process running" test_ref="oval:org.mitre.oval:tst:3331"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 102985">
          <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
          <criterion comment="Sun Enterprise Authentication Mechanism (SEAM, SUNWkr5ma) installed" test_ref="oval:org.mitre.oval:tst:3971"/>
          <criterion comment="Key Distribution Center (kadmind) process running" test_ref="oval:org.mitre.oval:tst:3331"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 102985">
          <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
          <criterion comment="Sun Enterprise Authentication Mechanism (SEAM, SUNWkr5ma) installed" test_ref="oval:org.mitre.oval:tst:3971"/>
          <criterion comment="Key Distribution Center (kadmind) process running" test_ref="oval:org.mitre.oval:tst:3331"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1989" version="1" class="vulnerability">
      <metadata>
        <title>Security Vulnerability in the vuidmice(7M) STREAMS Modules May Lead to a Denial of Service (DoS) Condition</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <platform>Sun Solaris 9</platform>
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-5319" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5319"/>
        <description>Unspecified vulnerability in the vuidmice STREAMS modules in Sun Solaris 8, 9, and 10 allows local users with console (/dev/console) access to cause a denial of service ("unusable" system console) via unspecified vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-10-10T07:52:08.000-04:00">
              <contributor organization="Opsware, Inc.">Nicholas Hansen</contributor>
            </submitted>
            <status_change date="2007-10-10T13:53:56.573-04:00">DRAFT</status_change>
            <status_change date="2007-10-25T13:04:40.350-04:00">INTERIM</status_change>
            <status_change date="2007-11-13T12:01:04.274-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND" comment="Solaris 8 (x86) meets Sun Alert 103065">
          <extend_definition comment="Solaris 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:2059"/>
          <criterion negate="true" comment="Patch 114154-02 or later installed" test_ref="oval:org.mitre.oval:tst:4419"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (x86) meets Sun Alert 103065">
          <extend_definition comment="Solaris 9 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1683"/>
          <criterion negate="true" comment="Patch 117419-03 or later installed" test_ref="oval:org.mitre.oval:tst:3534"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 103065">
          <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
          <criterion negate="true" comment="Patch 127751-01 or later installed" test_ref="oval:org.mitre.oval:tst:4460"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:2170" version="1" class="vulnerability">
      <metadata>
        <title>Security Vulnerability in Solaris Named Pipes (pipe(2)) May Allow Unauthorized Data Access</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <platform>Sun Solaris 9</platform>
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-5225" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5225"/>
        <description>Integer signedness error in FIFO filesystems (named pipes) on Sun Solaris 8 through 10 allows local users to read the contents of unspecified memory locations via a negative value to the I_PEEK ioctl.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-10-10T07:52:08.000-04:00">
              <contributor organization="Opsware, Inc.">Nicholas Hansen</contributor>
            </submitted>
            <status_change date="2007-10-10T13:53:56.913-04:00">DRAFT</status_change>
            <status_change date="2007-10-25T13:04:40.663-04:00">INTERIM</status_change>
            <status_change date="2007-11-13T12:01:06.734-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND" comment="Solaris 8 (SPARC) meets Sun Alert 103061">
          <extend_definition comment="Solaris 8 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1539"/>
          <criterion negate="true" comment="Patch 109454-06 or later installed" test_ref="oval:org.mitre.oval:tst:4308"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (SPARC) meets Sun Alert 103061">
          <extend_definition comment="Solaris 9 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1457"/>
          <criterion negate="true" comment="Patch 117471-04 or later installed" test_ref="oval:org.mitre.oval:tst:3569"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 103061">
          <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
          <criterion negate="true" comment="Patch 127737-01 or later installed" test_ref="oval:org.mitre.oval:tst:4494"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 8 (x86) meets Sun Alert 103061">
          <extend_definition comment="Solaris 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:2059"/>
          <criterion negate="true" comment="Patch 109455-06 or later installed" test_ref="oval:org.mitre.oval:tst:4095"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (x86) meets Sun Alert 103061">
          <extend_definition comment="Solaris 9 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1683"/>
          <criterion negate="true" comment="Patch 117472-04 or later installed" test_ref="oval:org.mitre.oval:tst:4375"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 103061">
          <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
          <criterion negate="true" comment="Patch 127738-01 or later installed" test_ref="oval:org.mitre.oval:tst:4523"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:2021" version="1" class="vulnerability">
      <metadata>
        <title>Security Vulnerability in the Human Interface Device (HID) Class Driver for Solaris</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <platform>Sun Solaris 9</platform>
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-5118" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5118"/>
        <description>Unspecified vulnerability in the HID (Human Interface Device) class driver in Sun Solaris 8, 9, and 10 before 20070925 allows local users to cause a denial of service (panic) via unspecified vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-09-28T13:03:00.000-04:00">
              <contributor organization="Opsware, Inc.">Nicholas Hansen</contributor>
            </submitted>
            <status_change date="2007-10-02T08:04:40.419-04:00">DRAFT</status_change>
            <status_change date="2007-10-18T21:59:19.829-04:00">INTERIM</status_change>
            <status_change date="2007-11-02T07:17:35.588-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND" comment="Solaris 8 (SPARC) meets Sun Alert 102883" negate="false">
          <extend_definition comment="Solaris 8 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1539"/>
          <criterion comment="Patch 109896-35 or later installed" test_ref="oval:org.mitre.oval:tst:3285" negate="true"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (SPARC) meets Sun Alert 102883" negate="false">
          <extend_definition comment="Solaris 9 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1457"/>
          <criterion comment="Patch 115553-28 or later installed" test_ref="oval:org.mitre.oval:tst:4284" negate="true"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 102883" negate="false">
          <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
          <criterion comment="Patch 125123-01 or later installed" test_ref="oval:org.mitre.oval:tst:3599" negate="true"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (x86) meets Sun Alert 102883" negate="false">
          <extend_definition comment="Solaris 9 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1683"/>
          <criterion comment="Patch 115554-24 or later installed" test_ref="oval:org.mitre.oval:tst:4255" negate="true"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 102883" negate="false">
          <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
          <criterion comment="Patch 125124-01 or later installed" test_ref="oval:org.mitre.oval:tst:4246" negate="true"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:2214" version="1" class="vulnerability">
      <metadata>
        <title>A Security Vulnerability in the Handling of Thread Contexts in the Solaris Kernel May Allow a Denial of Service (DoS)</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <platform>Sun Solaris 9</platform>
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-5132" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5132"/>
        <description>Race condition in the kernel in Sun Solaris 8 through 10 allows local users to cause a denial of service (panic) via unspecified vectors related to "the handling of thread contexts."</description>
        <oval_repository>
          <dates>
            <submitted date="2007-09-28T13:02:59.000-04:00">
              <contributor organization="Opsware, Inc.">Nicholas Hansen</contributor>
            </submitted>
            <status_change date="2007-10-02T08:04:40.234-04:00">DRAFT</status_change>
            <status_change date="2007-10-18T21:59:20.303-04:00">INTERIM</status_change>
            <status_change date="2007-11-02T07:17:42.208-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND" comment="Solaris 8 (SPARC) meets Sun Alert 103084" negate="false">
          <extend_definition comment="Solaris 8 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1539"/>
          <criterion comment="Patch 117350-48 or later installed" test_ref="oval:org.mitre.oval:tst:4094" negate="true"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (SPARC) meets Sun Alert 103084" negate="false">
          <extend_definition comment="Solaris 9 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1457"/>
          <criterion comment="Patch 122300-10 or later installed" test_ref="oval:org.mitre.oval:tst:3262" negate="true"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 103084" negate="false">
          <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
          <criterion comment="Patch 125100-02 or later installed" test_ref="oval:org.mitre.oval:tst:3554" negate="true"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 8 (x86) meets Sun Alert 103084" negate="false">
          <extend_definition comment="Solaris 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:2059"/>
          <criterion comment="Patch 117351-48 or later installed" test_ref="oval:org.mitre.oval:tst:4106" negate="true"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (x86) meets Sun Alert 103084" negate="false">
          <extend_definition comment="Solaris 9 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1683"/>
          <criterion comment="Patch 122301-10 or later installed" test_ref="oval:org.mitre.oval:tst:4263" negate="true"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 103084" negate="false">
          <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
          <criterion comment="Patch 125101-02 or later installed" test_ref="oval:org.mitre.oval:tst:3275" negate="true"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:2173" version="1" class="vulnerability">
      <metadata>
        <title>A Security Vulnerability With the Special File System (SPECFS) strfreectty() Function May Allow a Local Unprivileged User to Panic a System</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <platform>Sun Solaris 9</platform>
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-4732" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4732"/>
        <description>Unspecified vulnerability in the strfreectty function in the Special File System (SPECFS) in Sun Solaris 8 through 10 allows local users to cause a denial of service (system panic), related to passing a NULL pointer to the pgsignal function.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-09-10T09:34:14.000-04:00">
              <contributor organization="Opsware, Inc.">Todd Dolinsky</contributor>
            </submitted>
            <status_change date="2007-09-10T14:41:52.544-04:00">DRAFT</status_change>
            <status_change date="2007-09-27T08:57:45.669-04:00">INTERIM</status_change>
            <status_change date="2007-10-12T07:56:14.294-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND" comment="Solaris 8 (SPARC) meets Sun Alert 103009" negate="false">
          <extend_definition comment="Solaris 8 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1539"/>
          <criterion comment="Patch 109025-07 or later installed" test_ref="oval:org.mitre.oval:tst:4230" negate="true"/>
          <criterion comment="Patch 117350-49 or later installed" test_ref="oval:org.mitre.oval:tst:3903" negate="true"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (SPARC) meets Sun Alert 103009" negate="false">
          <extend_definition comment="Solaris 9 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1457"/>
          <criterion comment="Patch 122300-11 or later installed" test_ref="oval:org.mitre.oval:tst:3307" negate="true"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 103009" negate="false">
          <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
          <criterion comment="Patch 118822-24 or later installed" test_ref="oval:org.mitre.oval:tst:3780" negate="true"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 8 (x86) meets Sun Alert 103009" negate="false">
          <extend_definition comment="Solaris 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:2059"/>
          <criterion comment="Patch 109026-08 or later installed" test_ref="oval:org.mitre.oval:tst:3708" negate="true"/>
          <criterion comment="Patch 117351-49 or later installed" test_ref="oval:org.mitre.oval:tst:3841" negate="true"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (x86) meets Sun Alert 103009" negate="false">
          <extend_definition comment="Solaris 9 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1683"/>
          <criterion comment="Patch 122301-11 or later installed" test_ref="oval:org.mitre.oval:tst:3697" negate="true"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 103009" negate="false">
          <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
          <criterion comment="Patch 118844-24 or later installed" test_ref="oval:org.mitre.oval:tst:4200" negate="true"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1249" version="1" class="vulnerability">
      <metadata>
        <title>A Security Vulnerability in Solaris 10 ICMP Handling May Allow a SystemPanic and Result in Denial of Service (DoS)</title>
        <affected family="unix">
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-0634" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0634"/>
        <description>Unspecified vulnerability in Sun Solaris 10 before 20070130 allows remote attackers to cause a denial of service (system crash) via certain ICMP packets.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-08-10T12:25:20.000-04:00">
              <contributor organization="Opsware, Inc.">Pai Peng</contributor>
            </submitted>
            <status_change date="2007-08-13T13:57:11.559-04:00">DRAFT</status_change>
            <status_change date="2007-09-06T09:13:26.664-04:00">INTERIM</status_change>
            <status_change date="2007-09-27T08:57:39.476-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 102697" negate="false">
          <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
          <criterion comment="Patch 118833-28 or later installed" test_ref="oval:org.mitre.oval:tst:3688" negate="true"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 102697" negate=