<?xml version="1.0" encoding="UTF-8"?>
<oval_definitions xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix unix-definitions-schema.xsd http://oval.mitre.org/XMLSchema/oval-definitions-5#independent independent-definitions-schema.xsd http://oval.mitre.org/XMLSchema/oval-definitions-5 oval-definitions-schema.xsd http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris solaris-definitions-schema.xsd http://oval.mitre.org/XMLSchema/oval-common-5 oval-common-schema.xsd" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:oval="http://oval.mitre.org/XMLSchema/oval-common-5" xmlns:oval-def="http://oval.mitre.org/XMLSchema/oval-definitions-5">
  <generator>
    <oval:product_name>The OVAL Repository</oval:product_name>
    <oval:schema_version>5.5</oval:schema_version>
    <oval:timestamp>2008-10-07T09:09:56.205-04:00</oval:timestamp>
  </generator>
  <definitions>
    <definition id="oval:org.mitre.oval:def:5884" version="0" class="vulnerability">
      <metadata>
        <title>Manipulated Tag Files used with Solaris Text Editors May Lead to Execution of Arbitrary Code</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <platform>Sun Solaris 9</platform>
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-4131" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-4131"/>
        <description>Multiple unspecified vulnerabilities in Sun Solaris 8 through 10 allow local users to gain privileges via vectors related to handling of tags with (1) the -t option and (2) the :tag command in the (a) vi, (b) ex, (c) vedit, (d) view, and (e) edit programs.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-09-24T10:35:21.000-04:00">
              <contributor organization="Hewlett-Packard">Todd Dolinsky</contributor>
            </submitted>
            <status_change date="2008-09-29T13:59:05.488-04:00">DRAFT</status_change>
          </dates>
          <status>DRAFT</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND" comment="Solaris 8 (SPARC) meets Sun Alert 237987">
          <extend_definition comment="Solaris 8 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1539"/>
          <criterion negate="true" comment="Patch 110903-08 or later installed" test_ref="oval:org.mitre.oval:tst:8986"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (SPARC) meets Sun Alert 237987">
          <extend_definition comment="Solaris 9 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1457"/>
          <criterion negate="true" comment="Patch 113031-04 or later installed" test_ref="oval:org.mitre.oval:tst:9138"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 237987">
          <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
          <criterion negate="true" comment="Patch 120830-06 or later installed" test_ref="oval:org.mitre.oval:tst:9109"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 8 (x86) meets Sun Alert 237987">
          <extend_definition comment="Solaris 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:2059"/>
          <criterion negate="true" comment="Patch 110904-08 or later installed" test_ref="oval:org.mitre.oval:tst:9009"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (x86) meets Sun Alert 237987">
          <extend_definition comment="Solaris 9 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1683"/>
          <criterion negate="true" comment="Patch 116479-02 or later installed" test_ref="oval:org.mitre.oval:tst:9291"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 237987">
          <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
          <criterion negate="true" comment="Patch 120831-06 or later installed" test_ref="oval:org.mitre.oval:tst:9137"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5453" version="0" class="vulnerability">
      <metadata>
        <title>Covert Channel Security Vulnerability in the Solaris Kernel</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <platform>Sun Solaris 9</platform>
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-3875" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-3875"/>
        <description>The kernel in Sun Solaris 8 through 10 and OpenSolaris before snv_90 allows local users to bypass chroot, zones, and the Solaris Trusted Extensions multi-level security policy, and establish a covert communication channel, via unspecified vectors involving system calls.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-09-03T10:23:55.000-04:00">
              <contributor organization="Hewlett-Packard">Nicholas Hansen</contributor>
            </submitted>
            <status_change date="2008-09-09T10:51:57.209-04:00">DRAFT</status_change>
            <status_change date="2008-09-29T04:00:42.720-04:00">INTERIM</status_change>
          </dates>
          <status>INTERIM</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND" comment="Solaris 8 (SPARC) meets Sun Alert 240706">
          <extend_definition comment="Solaris 8 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1539"/>
          <criterion negate="true" comment="Patch 117350-56 or later installed" test_ref="oval:org.mitre.oval:tst:9150"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 8 (x86) meets Sun Alert 240706">
          <extend_definition comment="Solaris 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:2059"/>
          <criterion negate="true" comment="Patch 117351-56 or later installed" test_ref="oval:org.mitre.oval:tst:8843"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (SPARC) meets Sun Alert 240706">
          <extend_definition comment="Solaris 9 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1457"/>
          <criterion negate="true" comment="Patch 122300-30 or later installed" test_ref="oval:org.mitre.oval:tst:9046"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (x86) meets Sun Alert 240706">
          <extend_definition comment="Solaris 9 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1683"/>
          <criterion negate="true" comment="Patch 122301-30 or later installed" test_ref="oval:org.mitre.oval:tst:9227"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 240706">
          <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
          <criterion negate="true" comment="Patch 137111-05 or later installed" test_ref="oval:org.mitre.oval:tst:9075"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 240706">
          <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
          <criterion negate="true" comment="Patch 137112-05 or later installed" test_ref="oval:org.mitre.oval:tst:8905"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5742" version="1" class="vulnerability">
      <metadata>
        <title>Security Vulnerability in Solaris snoop(1M) when Displaying SMB Traffic</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <platform>Sun Solaris 9</platform>
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-0965" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-0965"/>
        <description>Multiple format string vulnerabilities in snoop on Sun Solaris 8 through 10 and OpenSolaris before snv_96, when the -o option is omitted, allow remote attackers to execute arbitrary code via format string specifiers in an SMB packet.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-08-11T12:08:06.000-04:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2008-08-14T15:03:06.340-04:00">DRAFT</status_change>
            <status_change date="2008-09-01T04:01:05.820-04:00">INTERIM</status_change>
            <status_change date="2008-09-22T04:00:30.399-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 240101">
          <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
          <criterion negate="true" comment="Patch 138083-01 or later installed" test_ref="oval:org.mitre.oval:tst:9062"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (SPARC) meets Sun Alert 240101">
          <extend_definition comment="Solaris 9 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1457"/>
          <criterion negate="true" comment="Patch 112915-05 or later installed" test_ref="oval:org.mitre.oval:tst:9103"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 8 (SPARC) meets Sun Alert 240101">
          <extend_definition comment="Solaris 8 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1539"/>
          <criterion negate="true" comment="Patch 108964-11 or later installed" test_ref="oval:org.mitre.oval:tst:8936"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 240101">
          <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
          <criterion negate="true" comment="Patch 138084-01 or later installed" test_ref="oval:org.mitre.oval:tst:8152"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (x86) meets Sun Alert 240101">
          <extend_definition comment="Solaris 9 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1683"/>
          <criterion negate="true" comment="Patch 114262-04 or later installed" test_ref="oval:org.mitre.oval:tst:8854"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 8 (x86) meets Sun Alert 240101">
          <extend_definition comment="Solaris 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:2059"/>
          <criterion negate="true" comment="Patch 108965-11 or later installed" test_ref="oval:org.mitre.oval:tst:9126"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5609" version="1" class="vulnerability">
      <metadata>
        <title>A Security Vulnerability in the namefs Kernel module may result in Arbitrary Code Execution or a Denial of Service (DoS)</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <platform>Sun Solaris 9</platform>
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-3450" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-3450"/>
        <description>Unspecified vulnerability in the namefs kernel module in Sun Solaris 8 through 10 allows local users to gain privileges or cause a denial of service (panic) via unspecified vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-08-05T10:37:22.000-04:00">
              <contributor organization="Hewlett-Packard">Nicholas Hansen</contributor>
            </submitted>
            <status_change date="2008-08-11T11:11:36.400-04:00">DRAFT</status_change>
            <status_change date="2008-09-01T04:01:01.503-04:00">INTERIM</status_change>
            <status_change date="2008-09-22T04:00:26.767-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND" comment="Solaris 8 (SPARC) meets Sun Alert 237986">
          <extend_definition comment="Solaris 8 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1539"/>
          <criterion negate="true" comment="Patch 114984-02 or later installed" test_ref="oval:org.mitre.oval:tst:9052"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 8 (x86) meets Sun Alert 237986">
          <extend_definition comment="Solaris 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:2059"/>
          <criterion negate="true" comment="Patch 114985-02 or later installed" test_ref="oval:org.mitre.oval:tst:9021"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (SPARC) meets Sun Alert 237986">
          <extend_definition comment="Solaris 9 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1457"/>
          <criterion negate="true" comment="Patch 114971-03 or later installed" test_ref="oval:org.mitre.oval:tst:9022"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (x86) meets Sun Alert 237986">
          <extend_definition comment="Solaris 9 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1683"/>
          <criterion negate="true" comment="Patch 138570-01 or later installed" test_ref="oval:org.mitre.oval:tst:8942"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 237986">
          <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
          <criterion negate="true" comment="Patch 136716-01 or later installed" test_ref="oval:org.mitre.oval:tst:8779"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 237986">
          <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
          <criterion negate="true" comment="Patch 136717-01 or later installed" test_ref="oval:org.mitre.oval:tst:9079"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5318" version="1" class="vulnerability">
      <metadata>
        <title>Security Vulnerability in Solaris snoop(1M) when Displaying SMB Traffic</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <platform>Sun Solaris 9</platform>
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-0964" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-0964"/>
        <description>Multiple stack-based buffer overflows in snoop on Sun Solaris 8 through 10 and OpenSolaris before snv_96, when the -o option is omitted, allow remote attackers to execute arbitrary code via a crafted SMB packet.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-08-11T12:08:06.000-04:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2008-08-14T15:03:14.279-04:00">DRAFT</status_change>
            <status_change date="2008-09-01T04:00:54.664-04:00">INTERIM</status_change>
            <status_change date="2008-09-22T04:00:22.547-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 240101">
          <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
          <criterion negate="true" comment="Patch 138083-01 or later installed" test_ref="oval:org.mitre.oval:tst:9062"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (SPARC) meets Sun Alert 240101">
          <extend_definition comment="Solaris 9 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1457"/>
          <criterion negate="true" comment="Patch 112915-05 or later installed" test_ref="oval:org.mitre.oval:tst:9103"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 8 (SPARC) meets Sun Alert 240101">
          <extend_definition comment="Solaris 8 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1539"/>
          <criterion negate="true" comment="Patch 108964-11 or later installed" test_ref="oval:org.mitre.oval:tst:8936"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 240101">
          <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
          <criterion negate="true" comment="Patch 138084-01 or later installed" test_ref="oval:org.mitre.oval:tst:8152"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (x86) meets Sun Alert 240101">
          <extend_definition comment="Solaris 9 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1683"/>
          <criterion negate="true" comment="Patch 114262-04 or later installed" test_ref="oval:org.mitre.oval:tst:8854"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 8 (x86) meets Sun Alert 240101">
          <extend_definition comment="Solaris 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:2059"/>
          <criterion negate="true" comment="Patch 108965-11 or later installed" test_ref="oval:org.mitre.oval:tst:9126"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:4725" version="1" class="vulnerability">
      <metadata>
        <title>Security Vulnerability in the Solaris crontab(1) utility may allow execution of Arbitrary Code</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <platform>Sun Solaris 9</platform>
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-2538" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-2538"/>
        <description>Unspecified vulnerability in crontab on Sun Solaris 8 through 10, and OpenSolaris before snv_93, allows local users to insert cron jobs into the crontab files of arbitrary users via unspecified vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-06-05T11:19:56.000-04:00">
              <contributor organization="Hewlett-Packard">Nicholas Hansen</contributor>
            </submitted>
            <status_change date="2008-06-05T14:00:22.164-04:00">DRAFT</status_change>
            <status_change date="2008-06-23T04:00:11.562-04:00">INTERIM</status_change>
            <modified comment="Fixed duplicate criteria for Solaris 9" date="2008-07-02T16:52:00.808-04:00">
              <contributor organization="Secure Elements, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2008-07-21T04:00:08.039-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND" comment="Solaris 8 (SPARC) meets Sun Alert 237864">
          <extend_definition comment="Solaris 8 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1539"/>
          <criterion negate="true" comment="Patch 109007-26 or later installed" test_ref="oval:org.mitre.oval:tst:7905"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (SPARC) meets Sun Alert 237864">
          <extend_definition comment="Solaris 9 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1457"/>
          <criterion negate="true" comment="Patch 122300-27 or later installed" test_ref="oval:org.mitre.oval:tst:7763"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 237864">
          <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
          <criterion negate="true" comment="Patch 137017-02 or later installed" test_ref="oval:org.mitre.oval:tst:8027"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 8 (x86) meets Sun Alert 237864">
          <extend_definition comment="Solaris 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:2059"/>
          <criterion negate="true" comment="Patch 109008-26 or later installed" test_ref="oval:org.mitre.oval:tst:7968"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (x86) meets Sun Alert 237864">
          <extend_definition comment="Solaris 9 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1683"/>
          <criterion negate="true" comment="Patch 122301-27 or later installed" test_ref="oval:org.mitre.oval:tst:7797"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 237864">
          <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
          <criterion negate="true" comment="Patch 137018-02 or later installed" test_ref="oval:org.mitre.oval:tst:8019"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:307" version="3" class="vulnerability">
      <metadata>
        <title>CGI.pm start_form Cross-Site Scripting Vulnerability</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <platform>Sun Solaris 9</platform>
          <product>Perl</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0615" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0615"/>
        <description>Cross-site scripting (XSS) vulnerability in start_form() of CGI.pm allows remote attackers to insert web script via a URL that is fed into the form's action parameter.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-09-22T05:52:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-09-22T20:15:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-07T09:15:45.271-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:15:52.795-04:00">ACCEPTED</status_change>
            <modified comment="Added title. Implemented by Jon Baker of The MITRE Corporation." date="2007-02-13T14:07:00.888-05:00">
              <contributor organization="Security-Database">Nabil Ouchn</contributor>
            </modified>
            <status_change date="2007-02-13T14:07:47.915-05:00">INTERIM</status_change>
            <status_change date="2007-03-21T16:17:15.663-04:00">ACCEPTED</status_change>
            <modified comment="Updated criteria for Solaris 9 and updated comments." date="2008-06-16T16:47:00.045-04:00">
              <contributor organization="Secure Elements, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2008-06-16T16:51:14.059-04:00">INTERIM</status_change>
            <status_change date="2008-07-07T04:00:16.879-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software section">
        <criteria operator="AND" comment="Solaris 8 (SPARC) meets Sun Alert ID 200205 (formerly 101426) criteria.">
          <extend_definition comment="Solaris 8 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1539"/>
          <criterion negate="true" comment="Patch 122091-01 or later installed" test_ref="oval:org.mitre.oval:tst:7556"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 8 (x86) meets Sun Alert ID 200205 (formerly 101426) criteria.">
          <extend_definition comment="Solaris 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:2059"/>
          <criterion negate="true" comment="Patch 122092-01 or later installed" test_ref="oval:org.mitre.oval:tst:7630"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (SPARC) meets Sun Alert ID 200205 (formerly 101426) criteria.">
          <extend_definition comment="Solaris 9 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1457"/>
          <criterion negate="true" comment="Patch 119449-01 or later installed" test_ref="oval:org.mitre.oval:tst:3644"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (x86) meets Sun Alert ID 200205 (formerly 101426) criteria.">
          <extend_definition comment="Solaris 9 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1683"/>
          <criterion negate="true" comment="Patch 119450-01 or later installed" test_ref="oval:org.mitre.oval:tst:3771"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1160" version="3" class="vulnerability">
      <metadata>
        <title>Safe.PM Unsafe Code Execution Vulnerability</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <platform>Sun Solaris 9</platform>
          <product>Perl</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-1323" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-1323"/>
        <description>Safe.pm 2.0.7 and earlier, when used in Perl 5.8.0 and earlier, may allow attackers to break out of safe compartments in (1) Safe::reval or (2) Safe::rdo using a redefined @_ variable, which is not reset between successive calls.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-09-22T05:52:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-09-22T20:15:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-07T09:15:13.239-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:15:02.270-04:00">ACCEPTED</status_change>
            <modified comment="Added title. Implemented by Jon Baker of The MITRE Corporation." date="2007-02-13T14:04:00.485-05:00">
              <contributor organization="Security-Database">Nabil Ouchn</contributor>
            </modified>
            <status_change date="2007-02-13T14:05:50.516-05:00">INTERIM</status_change>
            <status_change date="2007-03-21T16:16:43.305-04:00">ACCEPTED</status_change>
            <modified comment="Updated criteria for Solaris 9 and updated comments." date="2008-06-16T16:47:00.258-04:00">
              <contributor organization="Secure Elements, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2008-06-16T16:51:33.274-04:00">INTERIM</status_change>
            <status_change date="2008-07-07T04:00:13.994-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software section">
        <criteria operator="AND" comment="Solaris 8 (SPARC) meets Sun Alert ID 200205 (formerly 101426) criteria.">
          <extend_definition comment="Solaris 8 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1539"/>
          <criterion negate="true" comment="Patch 122091-01 or later installed" test_ref="oval:org.mitre.oval:tst:7098"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 8 (x86) meets Sun Alert ID 200205 (formerly 101426) criteria.">
          <extend_definition comment="Solaris 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:2059"/>
          <criterion negate="true" comment="Patch 122092-01 or later installed" test_ref="oval:org.mitre.oval:tst:7522"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (SPARC) meets  Sun Alert ID 200205 (formerly 101426) criteria.">
          <extend_definition comment="Solaris 9 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1457"/>
          <criterion negate="true" comment="Patch 119449-01 or later installed" test_ref="oval:org.mitre.oval:tst:3644"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (x86) meets  Sun Alert ID 200205 (formerly 101426) criteria.">
          <extend_definition comment="Solaris 9 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1683"/>
          <criterion negate="true" comment="Patch 119450-01 or later installed" test_ref="oval:org.mitre.oval:tst:3771"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5269" version="1" class="vulnerability">
      <metadata>
        <title>Security Vulnerabilities in Solaris Print Service May Lead to Denial of Service (DoS) or Execution of Arbitrary Code</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <platform>Sun Solaris 9</platform>
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-2144" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-2144"/>
        <description>Multiple unspecified vulnerabilities in Solaris print service for Sun Solaris 8, 9, and 10 allow remote attackers to cause a denial of service or execute arbitrary code via unknown vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-05-14T13:20:42.000-04:00">
              <contributor organization="Hewlett-Packard">Nicholas Hansen</contributor>
            </submitted>
            <status_change date="2008-05-15T14:47:17.480-04:00">DRAFT</status_change>
            <status_change date="2008-06-02T04:00:08.809-04:00">INTERIM</status_change>
            <status_change date="2008-06-23T04:00:12.580-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND" comment="Solaris 8 (SPARC) meets Sun Alert 236884">
          <extend_definition comment="Solaris 8 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1539"/>
          <criterion negate="true" comment="Patch 109320-20 or later installed" test_ref="oval:org.mitre.oval:tst:7494"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 8 (x86) meets Sun Alert 236884">
          <extend_definition comment="Solaris 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:2059"/>
          <criterion negate="true" comment="Patch 109321-20 or later installed" test_ref="oval:org.mitre.oval:tst:7873"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (SPARC) meets Sun Alert 236884">
          <extend_definition comment="Solaris 9 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1457"/>
          <criterion negate="true" comment="Patch 113329-19 or later installed" test_ref="oval:org.mitre.oval:tst:7921"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (x86) meets Sun Alert 236884">
          <extend_definition comment="Solaris 9 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1683"/>
          <criterion negate="true" comment="Patch 114980-20 or later installed" test_ref="oval:org.mitre.oval:tst:7759"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 236884">
          <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
          <criterion negate="true" comment="Patch 127127-11 or later installed" test_ref="oval:org.mitre.oval:tst:7382"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 236884">
          <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
          <criterion negate="true" comment="Patch 127128-11 or later installed" test_ref="oval:org.mitre.oval:tst:7793"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:4848" version="1" class="vulnerability">
      <metadata>
        <title>A Security Vulnerability in the Handling of Self Encapsulated IP Packets may Lead to a Denial of Service (DOS) Condition.</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <platform>Sun Solaris 9</platform>
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-1779" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1779"/>
        <description>Sun Solaris 8, 9, and 10 allows "remote privileged" users to cause a denial of service (panic) via unknown vectors related to self encapsulated IP packets.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-04-15T07:48:47.000-04:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2008-04-15T12:06:17.868-04:00">DRAFT</status_change>
            <status_change date="2008-05-05T04:00:21.938-04:00">INTERIM</status_change>
            <status_change date="2008-05-26T04:00:15.482-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND" comment="Solaris 8 (SPARC) meets Sun Alert 235901">
          <extend_definition comment="Solaris 8 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1539"/>
          <criterion negate="true" comment="Patch 116965-32 or later installed" test_ref="oval:org.mitre.oval:tst:7947"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (SPARC) meets Sun Alert 235901">
          <extend_definition comment="Solaris 9 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1457"/>
          <criterion negate="true" comment="Patch 114344-34 or later installed" test_ref="oval:org.mitre.oval:tst:7482"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 235901">
          <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
          <criterion negate="true" comment="Patch 127111-11 or later installed" test_ref="oval:org.mitre.oval:tst:7975"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 8 (x86) meets Sun Alert 235901">
          <extend_definition comment="Solaris 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:2059"/>
          <criterion negate="true" comment="Patch 116966-31 or later installed" test_ref="oval:org.mitre.oval:tst:7668"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (x86) meets Sun Alert 235901">
          <extend_definition comment="Solaris 9 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1683"/>
          <criterion negate="true" comment="Patch 119435-22 or later installed" test_ref="oval:org.mitre.oval:tst:7881"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 235901">
          <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
          <criterion negate="true" comment="Patch 127112-11 or later installed" test_ref="oval:org.mitre.oval:tst:7822"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5511" version="1" class="vulnerability">
      <metadata>
        <title>Security Vulnerability May Allow Firewall Compromise or Creation of Denial of Service (DoS) Condition</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <platform>Sun Solaris 9</platform>
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-1095" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1095"/>
        <description>Unspecified vulnerability in the Internet Protocol (IP) implementation in Sun Solaris 8, 9, and 10 allows remote attackers to bypass intended firewall policies or cause a denial of service (panic) via unknown vectors, possibly related to ICMP packets and IP fragment reassembly.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-03-04T08:44:56.000-05:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2008-03-06T08:35:11.775-05:00">DRAFT</status_change>
            <status_change date="2008-03-24T04:00:48.629-04:00">INTERIM</status_change>
            <status_change date="2008-04-14T04:00:10.100-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND" comment="Solaris 8 (SPARC) meets Sun Alert 200183">
          <extend_definition comment="Solaris 8 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1539"/>
          <criterion negate="true" comment="Patch 116965-30 or later installed" test_ref="oval:org.mitre.oval:tst:7533"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (SPARC) meets Sun Alert 200183">
          <extend_definition comment="Solaris 9 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1457"/>
          <criterion negate="true" comment="Patch 114344-32 or later installed" test_ref="oval:org.mitre.oval:tst:7854"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 200183">
          <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
          <criterion negate="true" comment="Patch 118822-27 or later installed" test_ref="oval:org.mitre.oval:tst:7608"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 8 (x86) meets Sun Alert 200183">
          <extend_definition comment="Solaris 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:2059"/>
          <criterion negate="true" comment="Patch 116966-29 or later installed" test_ref="oval:org.mitre.oval:tst:7656"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (x86) meets Sun Alert 200183">
          <extend_definition comment="Solaris 9 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1683"/>
          <criterion negate="true" comment="Patch 119435-20 or later installed" test_ref="oval:org.mitre.oval:tst:6892"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 200183">
          <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
          <criterion negate="true" comment="Patch 118844-28 or later installed" test_ref="oval:org.mitre.oval:tst:7175"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5485" version="1" class="vulnerability">
      <metadata>
        <title>Security Vulnerability in Solaris 8 Directory Functions</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-1115" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1115"/>
        <description>Unspecified vulnerability in Sun Solaris 8 directory functions allows local users to cause a denial of service (panic) via an unspecified sequence of system calls or commands.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-03-04T08:44:57.000-05:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2008-03-06T08:35:12.523-05:00">DRAFT</status_change>
            <status_change date="2008-03-24T04:00:48.080-04:00">INTERIM</status_change>
            <status_change date="2008-04-14T04:00:09.676-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND" comment="Solaris 8 (SPARC) meets Sun Alert 200163">
          <extend_definition comment="Solaris 8 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1539"/>
          <criterion negate="true" comment="Patch 117350-53 or later installed" test_ref="oval:org.mitre.oval:tst:7711"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 8 (x86) meets Sun Alert 200163">
          <extend_definition comment="Solaris 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:2059"/>
          <criterion negate="true" comment="Patch 117351-53 or later installed" test_ref="oval:org.mitre.oval:tst:7677"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:2590" version="1" class="vulnerability">
      <metadata>
        <title>OpenSSL Double-free Vulnerability</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <platform>Sun Solaris 9</platform>
          <product>Sun Cluster</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0545" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0545"/>
        <description>Double free vulnerability in OpenSSL 0.9.7 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via an SSL client certificate with a certain invalid ASN.1 encoding.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-10-19T03:11:00.000-04:00">
              <contributor organization="The MITRE Corporation">Brian Soby</contributor>
            </submitted>
            <status_change date="2004-10-20T02:35:00.000-04:00">DRAFT</status_change>
            <status_change date="2004-11-03T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-12-09T08:46:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="AND" comment="Software section">
          <criteria operator="OR" comment="Solaris 8 or 9 installed">
            <criterion comment="Solaris 8 Installed" test_ref="oval:org.mitre.oval:tst:3145"/>
            <criterion comment="Solaris 9 Installed" test_ref="oval:org.mitre.oval:tst:3051"/>
          </criteria>
          <criterion negate="true" comment="Patch 113505-02 or later installed" test_ref="oval:org.mitre.oval:tst:511"/>
          <criterion negate="true" comment="Patch 113508-02 or later installed" test_ref="oval:org.mitre.oval:tst:510"/>
          <criterion negate="true" comment="Patch 115054-01 or later installed" test_ref="oval:org.mitre.oval:tst:509"/>
          <criterion negate="true" comment="Patch 115055-01 or later installed" test_ref="oval:org.mitre.oval:tst:508"/>
          <criterion comment="SunCluster Component SUNWscvw installed" test_ref="oval:org.mitre.oval:tst:507"/>
          <criterion comment="Apache (SUNWapchu) installed" test_ref="oval:org.mitre.oval:tst:653"/>
        </criteria>
        <criteria operator="AND" comment="Configuration section">
          <criterion comment="Apache running with SunPlex Manager config" test_ref="oval:org.mitre.oval:tst:506"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5393" version="1" class="vulnerability">
      <metadata>
        <title>Security Vulnerability in the Solaris X Server May Lead to Unauthorized Disclosure of Information on Access Restricted Files and Directories</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <platform>Sun Solaris 9</platform>
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-5958" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5958"/>
        <description>X.Org Xserver before 1.4.1 allows local users to determine the existence of arbitrary files via a filename argument in the -sp option to the X program, which produces different error messages depending on whether the filename exists.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-02-12T08:48:34.000-05:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2008-02-13T09:26:36.813-05:00">DRAFT</status_change>
            <status_change date="2008-03-03T04:00:16.207-05:00">INTERIM</status_change>
            <status_change date="2008-03-24T04:00:46.668-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND" comment="Solaris 8 (SPARC) meets Sun Alert 230901">
          <extend_definition comment="Solaris 8 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1539"/>
          <criterion negate="true" comment="Patch 119067-09 or later installed" test_ref="oval:org.mitre.oval:tst:7606"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (SPARC) meets Sun Alert 230901">
          <extend_definition comment="Solaris 9 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1457"/>
          <criterion negate="true" comment="Patch 112785-63 or later installed" test_ref="oval:org.mitre.oval:tst:7770"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
          <criteria operator="OR">
            <criteria operator="AND">
              <criterion comment="File Xsun exists" test_ref="oval:org.mitre.oval:tst:3109"/>
              <criterion negate="true" comment="Patch 119059-38 or later installed" test_ref="oval:org.mitre.oval:tst:7694"/>
            </criteria>
            <criteria operator="AND">
              <criterion comment="File Xorg exists" test_ref="oval:org.mitre.oval:tst:1336"/>
              <criterion negate="true" comment="Patch 125719-07 or later installed" test_ref="oval:org.mitre.oval:tst:7744"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Solaris 8 (x86) meets Sun Alert 230901">
          <extend_definition comment="Solaris 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:2059"/>
          <criterion negate="true" comment="Patch 119068-09 or later installed" test_ref="oval:org.mitre.oval:tst:7681"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="Solaris 9 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1683"/>
          <criteria operator="OR">
            <criteria operator="AND">
              <criterion comment="File Xsun exists" test_ref="oval:org.mitre.oval:tst:3109"/>
              <criterion negate="true" comment="Patch 112786-52 or later installed" test_ref="oval:org.mitre.oval:tst:7415"/>
            </criteria>
            <criteria operator="AND">
              <criterion comment="File Xorg exists" test_ref="oval:org.mitre.oval:tst:1336"/>
              <criterion negate="true" comment="Patch 118908-04 or later installed" test_ref="oval:org.mitre.oval:tst:7428"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
          <criteria operator="OR">
            <criteria operator="AND">
              <criterion comment="File Xsun exists" test_ref="oval:org.mitre.oval:tst:3109"/>
              <criterion negate="true" comment="Patch 119060-37 or later installed" test_ref="oval:org.mitre.oval:tst:7764"/>
            </criteria>
            <criteria operator="AND">
              <criterion comment="File Xorg exists" test_ref="oval:org.mitre.oval:tst:1336"/>
              <criterion negate="true" comment="Patch 125720-17 or later installed" test_ref="oval:org.mitre.oval:tst:7423"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5532" version="1" class="vulnerability">
      <metadata>
        <title>Security Vulnerability in FreeType 2 Font Engine May Allow Privilege Escalation Due to Heap Overflow</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <platform>Sun Solaris 9</platform>
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-2754" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2754"/>
        <description>Integer signedness error in truetype/ttgload.c in Freetype 2.3.4 and earlier might allow remote attackers to execute arbitrary code via a crafted TTF image with a negative n_points value, which leads to an integer overflow and heap-based buffer overflow.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-01-09T07:41:41.000-05:00">
              <contributor organization="Hewlett-Packard">Nicholas Hansen</contributor>
            </submitted>
            <status_change date="2008-01-09T14:14:49.552-05:00">DRAFT</status_change>
            <status_change date="2008-02-04T10:19:29.641-05:00">INTERIM</status_change>
            <status_change date="2008-02-25T04:00:11.261-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND" comment="Solaris 8 (SPARC) meets Sun Alert 103171">
          <extend_definition comment="Solaris 8 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1539"/>
          <criterion negate="true" comment="Patch 124420-03 or later installed" test_ref="oval:org.mitre.oval:tst:7777"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (SPARC) meets Sun Alert 103171">
          <extend_definition comment="Solaris 9 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1457"/>
          <criterion negate="true" comment="Patch 116105-08 or later installed" test_ref="oval:org.mitre.oval:tst:7445"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 103171">
          <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
          <criterion negate="true" comment="Patch 119812-05 or later installed" test_ref="oval:org.mitre.oval:tst:7736"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 8 (x86) meets Sun Alert 103171">
          <extend_definition comment="Solaris 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:2059"/>
          <criterion negate="true" comment="Patch 124421-03 or later installed" test_ref="oval:org.mitre.oval:tst:7493"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (x86) meets Sun Alert 103171">
          <extend_definition comment="Solaris 9 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1683"/>
          <criterion negate="true" comment="Patch 116106-07 or later installed" test_ref="oval:org.mitre.oval:tst:7547"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 103171">
          <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
          <criterion negate="true" comment="Patch 119813-07 or later installed" test_ref="oval:org.mitre.oval:tst:6931"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:4532" version="1" class="vulnerability">
      <metadata>
        <title>Security Vulnerability With Loading Arbitrary Kernel Modules in Solaris Kernel</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <platform>Sun Solaris 9</platform>
          <platform>Sun Solaris 7</platform>
          <platform>Sun Solaris 2.6</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-1767" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1767"/>
        <description>The kernel in Solaris 2.6, 7, 8, and 9 allows local users to gain privileges by loading arbitrary loadable kernel modules (LKM), possibly involving the modload function.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-09-25T11:24:50.000-04:00">
              <contributor organization="Hewlett-Packard">Nicholas Hansen</contributor>
            </submitted>
            <status_change date="2007-12-13T15:33:46.112-05:00">DRAFT</status_change>
            <status_change date="2007-12-31T04:01:18.435-05:00">INTERIM</status_change>
            <status_change date="2008-02-04T10:16:58.394-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND" comment="Solaris 7 (SPARC) meets Sun Alert 57479">
          <extend_definition comment="Solaris 7 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:2107"/>
          <criterion negate="true" comment="Patch 106541-29 or later installed" test_ref="oval:org.mitre.oval:tst:4002"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 8 (SPARC) meets Sun Alert 57479">
          <extend_definition comment="Solaris 8 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1539"/>
          <criterion negate="true" comment="Patch 108528-27 or later installed" test_ref="oval:org.mitre.oval:tst:4228"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (SPARC) meets Sun Alert 57479">
          <extend_definition comment="Solaris 9 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1457"/>
          <criterion negate="true" comment="Patch 112233-11 or later installed" test_ref="oval:org.mitre.oval:tst:3814"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 7 (x86) meets Sun Alert 57479">
          <extend_definition comment="Solaris 7 (x86) is installed" definition_ref="oval:org.mitre.oval:def:2036"/>
          <criterion negate="true" comment="Patch 106542-29 or later installed" test_ref="oval:org.mitre.oval:tst:3686"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 8 (x86) meets Sun Alert 57479">
          <extend_definition comment="Solaris 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:2059"/>
          <criterion negate="true" comment="Patch 108529-27 or later installed" test_ref="oval:org.mitre.oval:tst:4247"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (x86) meets Sun Alert 57479">
          <extend_definition comment="Solaris 9 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1683"/>
          <criterion negate="true" comment="Patch 112234-11 or later installed" test_ref="oval:org.mitre.oval:tst:3937"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 2.6 (SPARC) meets Sun Alert 57479">
          <extend_definition comment="Solaris 2.6 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1361"/>
          <criterion negate="true" comment="Patch 105181-37 or later installed" test_ref="oval:org.mitre.oval:tst:3794"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 2.6 (x86) meets Sun Alert 57479">
          <extend_definition comment="Solaris 2.6 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1967"/>
          <criterion negate="true" comment="Patch 105182-37 or later installed" test_ref="oval:org.mitre.oval:tst:3479"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:2426" version="0" class="vulnerability">
      <metadata>
        <title>BSM Audit Kernel Panic</title>
        <affected family="unix">
          <platform>Sun Solaris 7</platform>
          <platform>Sun Solaris 8</platform>
          <platform>Sun Solaris 9</platform>
          <product>Basic Security Module</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0654" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0654"/>
        <description>Unknown vulnerability in the Basic Security Module (BSM), when configured to audit either the Administrative (ad) or the System-Wide Administration (as) audit class in Solaris 7, 8, and 9, allows local users to cause a denial of service (kernel panic).</description>
        <oval_repository>
          <dates>
            <submitted date="2004-10-12T09:40:00.000-04:00">
              <contributor organization="The MITRE Corporation">Brian Soby</contributor>
            </submitted>
            <status_change date="2004-10-13T01:15:00.000-04:00">DRAFT</status_change>
            <modified comment="Operation changed from not equal to equals for object oval:org.mitre.oval:obj:458." date="2007-12-28T11:37:00.427-05:00">
              <contributor organization="Secure Elements, Inc.">Sudhir Gandhe</contributor>
            </modified>
          </dates>
          <status>DRAFT</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Patch 106541-33 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:542"/>
          <criterion comment="Patch 109007-18 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:541"/>
          <criterion comment="Patch 114332-12 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:540"/>
          <criteria operator="OR" comment="Solaris 7,8,or 9 installed">
            <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3145"/>
            <criterion comment="Solaris 7 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3045"/>
            <criterion comment="Solaris 9 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3051"/>
          </criteria>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="Basic Security Module enabled" negate="false" test_ref="oval:org.mitre.oval:tst:539"/>
          <criterion comment="Auditing Administrative or System-Wide Administrative audit classes" negate="false" test_ref="oval:org.mitre.oval:tst:538"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:3162" version="1" class="vulnerability">
      <metadata>
        <title>Security Vulnerability in RPCSEC_GSS (rpcsec_gss(3NSL)) Affects Kerberos Administration Daemon (kadmind(1M))</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <platform>Sun Solaris 9</platform>
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-3999" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3999"/>
        <description>Stack-based buffer overflow in the svcauth_gss_validate function in lib/rpc/svc_auth_gss.c in the RPCSEC_GSS RPC library (librpcsecgss) in MIT Kerberos 5 (krb5) 1.4 through 1.6.2, as used by the Kerberos administration daemon (kadmind) and some third-party applications that use krb5, allows remote attackers to cause a denial of service (daemon crash) and probably execute arbitrary code via a long string in an RPC message.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-10-31T12:34:51.000-04:00">
              <contributor organization="Opsware, Inc.">Nicholas Hansen</contributor>
            </submitted>
            <status_change date="2007-11-01T12:41:43.692-04:00">DRAFT</status_change>
            <status_change date="2007-11-16T08:14:50.135-05:00">INTERIM</status_change>
            <status_change date="2007-12-03T04:01:50.066-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND" comment="Solaris 8 (SPARC) meets Sun Alert 103060">
          <extend_definition comment="Solaris 8 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1539"/>
          <criterion negate="true" comment="Patch 126928-02 or later installed" test_ref="oval:org.mitre.oval:tst:5410"/>
          <criterion comment="Key Distribution Center (kadmind) process running" test_ref="oval:org.mitre.oval:tst:3331"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (SPARC) meets Sun Alert 103060">
          <extend_definition comment="Solaris 9 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1457"/>
          <criterion negate="true" comment="Patch 113318-32 or later installed" test_ref="oval:org.mitre.oval:tst:5371"/>
          <criterion comment="Key Distribution Center (kadmind) process running" test_ref="oval:org.mitre.oval:tst:3331"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 103060">
          <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
          <criterion negate="true" comment="Patch 126661-02 or later installed" test_ref="oval:org.mitre.oval:tst:5581"/>
          <criterion comment="Key Distribution Center (kadmind) process running" test_ref="oval:org.mitre.oval:tst:3331"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 8 (x86) meets Sun Alert 103060">
          <extend_definition comment="Solaris 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:2059"/>
          <criterion negate="true" comment="Patch 126929-02 or later installed" test_ref="oval:org.mitre.oval:tst:5434"/>
          <criterion comment="Key Distribution Center (kadmind) process running" test_ref="oval:org.mitre.oval:tst:3331"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (x86) meets Sun Alert 103060">
          <extend_definition comment="Solaris 9 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1683"/>
          <criterion negate="true" comment="Patch 117468-18 or later installed" test_ref="oval:org.mitre.oval:tst:5207"/>
          <criterion comment="Key Distribution Center (kadmind) process running" test_ref="oval:org.mitre.oval:tst:3331"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 103060">
          <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
          <criterion negate="true" comment="Patch 126662-02 or later installed" test_ref="oval:org.mitre.oval:tst:5538"/>
          <criterion comment="Key Distribution Center (kadmind) process running" test_ref="oval:org.mitre.oval:tst:3331"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:3027" version="1" class="vulnerability">
      <metadata>
        <title>Security Vulnerabilities in Solaris Kernel Statistics Retrieval Process May Allow a Denial of Service (DoS)</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <platform>Sun Solaris 9</platform>
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-5632" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5632"/>
        <description>Multiple unspecified vulnerabilities in the kernel in Sun Solaris 8 through 10 allow local users to cause a denial of service (panic), related to the support for retrieval of kernel statistics, and possibly related to the sfmmu_mlspl_enter or sfmmu_mlist_enter functions.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-10-24T12:32:39.000-04:00">
              <contributor organization="Opsware, Inc.">Nicholas Hansen</contributor>
            </submitted>
            <status_change date="2007-10-24T17:06:05.258-04:00">DRAFT</status_change>
            <status_change date="2007-11-13T12:01:11.224-05:00">INTERIM</status_change>
            <status_change date="2007-12-03T04:01:12.772-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND" comment="Solaris 8 (SPARC) meets Sun Alert 103064">
          <extend_definition comment="Solaris 8 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1539"/>
          <criterion negate="true" comment="Patch 117350-50 or later installed" test_ref="oval:org.mitre.oval:tst:5260"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (SPARC) meets Sun Alert 103064">
          <extend_definition comment="Solaris 9 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1457"/>
          <criterion negate="true" comment="Patch 122300-13 or later installed" test_ref="oval:org.mitre.oval:tst:4570"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 103064">
          <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
          <criterion negate="true" comment="Patch 127111-01 or later installed" test_ref="oval:org.mitre.oval:tst:5241"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 8 (x86) meets Sun Alert 103064">
          <extend_definition comment="Solaris 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:2059"/>
          <criterion negate="true" comment="Patch 117351-50 or later installed" test_ref="oval:org.mitre.oval:tst:5306"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (x86) meets Sun Alert 103064">
          <extend_definition comment="Solaris 9 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1683"/>
          <criterion negate="true" comment="Patch 122301-13 or later installed" test_ref="oval:org.mitre.oval:tst:5341"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 103064">
          <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
          <criterion negate="true" comment="Patch 127112-01 or later installed" test_ref="oval:org.mitre.oval:tst:5374"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:2154" version="1" class="vulnerability">
      <metadata>
        <title>Security Vulnerability in BIND 8 May Allow Cache Poisoning Attack</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <platform>Sun Solaris 9</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-2930" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2930"/>
        <description>The (1) NSID_SHUFFLE_ONLY and (2) NSID_USE_POOL PRNG algorithms in ISC BIND 8 before 8.4.7-P1 generate predictable DNS query identifiers when sending outgoing queries such as NOTIFY messages when answering questions as a resolver, which allows remote attackers to poison DNS caches via unknown vectors.  NOTE: this issue is different from CVE-2007-2926.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-10-16T10:34:50.000-04:00">
              <contributor organization="Opsware, Inc.">Todd Dolinsky</contributor>
            </submitted>
            <status_change date="2007-10-16T14:50:58.416-04:00">DRAFT</status_change>
            <status_change date="2007-11-02T07:17:39.538-04:00">INTERIM</status_change>
            <status_change date="2007-11-19T04:01:00.472-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND" comment="Software and Criteria Section">
        <criteria operator="OR" comment="Software Section">
          <criteria operator="AND" comment="Solaris 8 (SPARC) meets Sun Alert 103063" negate="false">
            <extend_definition comment="Solaris 8 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1539"/>
            <criterion comment="Patch 109326-20 or later installed" test_ref="oval:org.mitre.oval:tst:4282" negate="true"/>
          </criteria>
          <criteria operator="AND" comment="Solaris 8 (x86) meets Sun Alert 103063" negate="false">
            <extend_definition comment="Solaris 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:2059"/>
            <criterion comment="Patch 109327-20 or later installed" test_ref="oval:org.mitre.oval:tst:4431" negate="true"/>
          </criteria>
          <criteria operator="AND" comment="Solaris 9 (SPARC) meets Sun Alert 103063" negate="false">
            <extend_definition comment="Solaris 9 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1457"/>
            <criterion comment="Patch 112837-14 or later installed" test_ref="oval:org.mitre.oval:tst:4470" negate="true"/>
          </criteria>
          <criteria operator="AND" comment="Solaris 9 (x86) meets Sun Alert 103063" negate="false">
            <extend_definition comment="Solaris 9 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1683"/>
            <criterion comment="Patch 114265-13 or later installed" test_ref="oval:org.mitre.oval:tst:4525" negate="true"/>
          </criteria>
        </criteria>
        <criterion comment="in.named running" negate="false" test_ref="oval:org.mitre.oval:tst:2624"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1989" version="1" class="vulnerability">
      <metadata>
        <title>Security Vulnerability in the vuidmice(7M) STREAMS Modules May Lead to a Denial of Service (DoS) Condition</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <platform>Sun Solaris 9</platform>
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-5319" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5319"/>
        <description>Unspecified vulnerability in the vuidmice STREAMS modules in Sun Solaris 8, 9, and 10 allows local users with console (/dev/console) access to cause a denial of service ("unusable" system console) via unspecified vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-10-10T07:52:08.000-04:00">
              <contributor organization="Opsware, Inc.">Nicholas Hansen</contributor>
            </submitted>
            <status_change date="2007-10-10T13:53:56.573-04:00">DRAFT</status_change>
            <status_change date="2007-10-25T13:04:40.350-04:00">INTERIM</status_change>
            <status_change date="2007-11-13T12:01:04.274-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND" comment="Solaris 8 (x86) meets Sun Alert 103065">
          <extend_definition comment="Solaris 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:2059"/>
          <criterion negate="true" comment="Patch 114154-02 or later installed" test_ref="oval:org.mitre.oval:tst:4419"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (x86) meets Sun Alert 103065">
          <extend_definition comment="Solaris 9 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1683"/>
          <criterion negate="true" comment="Patch 117419-03 or later installed" test_ref="oval:org.mitre.oval:tst:3534"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 103065">
          <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
          <criterion negate="true" comment="Patch 127751-01 or later installed" test_ref="oval:org.mitre.oval:tst:4460"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:2170" version="1" class="vulnerability">
      <metadata>
        <title>Security Vulnerability in Solaris Named Pipes (pipe(2)) May Allow Unauthorized Data Access</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <platform>Sun Solaris 9</platform>
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-5225" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5225"/>
        <description>Integer signedness error in FIFO filesystems (named pipes) on Sun Solaris 8 through 10 allows local users to read the contents of unspecified memory locations via a negative value to the I_PEEK ioctl.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-10-10T07:52:08.000-04:00">
              <contributor organization="Opsware, Inc.">Nicholas Hansen</contributor>
            </submitted>
            <status_change date="2007-10-10T13:53:56.913-04:00">DRAFT</status_change>
            <status_change date="2007-10-25T13:04:40.663-04:00">INTERIM</status_change>
            <status_change date="2007-11-13T12:01:06.734-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND" comment="Solaris 8 (SPARC) meets Sun Alert 103061">
          <extend_definition comment="Solaris 8 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1539"/>
          <criterion negate="true" comment="Patch 109454-06 or later installed" test_ref="oval:org.mitre.oval:tst:4308"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (SPARC) meets Sun Alert 103061">
          <extend_definition comment="Solaris 9 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1457"/>
          <criterion negate="true" comment="Patch 117471-04 or later installed" test_ref="oval:org.mitre.oval:tst:3569"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 103061">
          <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
          <criterion negate="true" comment="Patch 127737-01 or later installed" test_ref="oval:org.mitre.oval:tst:4494"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 8 (x86) meets Sun Alert 103061">
          <extend_definition comment="Solaris 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:2059"/>
          <criterion negate="true" comment="Patch 109455-06 or later installed" test_ref="oval:org.mitre.oval:tst:4095"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (x86) meets Sun Alert 103061">
          <extend_definition comment="Solaris 9 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1683"/>
          <criterion negate="true" comment="Patch 117472-04 or later installed" test_ref="oval:org.mitre.oval:tst:4375"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 103061">
          <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
          <criterion negate="true" comment="Patch 127738-01 or later installed" test_ref="oval:org.mitre.oval:tst:4523"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:2021" version="1" class="vulnerability">
      <metadata>
        <title>Security Vulnerability in the Human Interface Device (HID) Class Driver for Solaris</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <platform>Sun Solaris 9</platform>
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-5118" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5118"/>
        <description>Unspecified vulnerability in the HID (Human Interface Device) class driver in Sun Solaris 8, 9, and 10 before 20070925 allows local users to cause a denial of service (panic) via unspecified vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-09-28T13:03:00.000-04:00">
              <contributor organization="Opsware, Inc.">Nicholas Hansen</contributor>
            </submitted>
            <status_change date="2007-10-02T08:04:40.419-04:00">DRAFT</status_change>
            <status_change date="2007-10-18T21:59:19.829-04:00">INTERIM</status_change>
            <status_change date="2007-11-02T07:17:35.588-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND" comment="Solaris 8 (SPARC) meets Sun Alert 102883" negate="false">
          <extend_definition comment="Solaris 8 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1539"/>
          <criterion comment="Patch 109896-35 or later installed" test_ref="oval:org.mitre.oval:tst:3285" negate="true"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (SPARC) meets Sun Alert 102883" negate="false">
          <extend_definition comment="Solaris 9 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1457"/>
          <criterion comment="Patch 115553-28 or later installed" test_ref="oval:org.mitre.oval:tst:4284" negate="true"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 102883" negate="false">
          <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
          <criterion comment="Patch 125123-01 or later installed" test_ref="oval:org.mitre.oval:tst:3599" negate="true"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (x86) meets Sun Alert 102883" negate="false">
          <extend_definition comment="Solaris 9 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1683"/>
          <criterion comment="Patch 115554-24 or later installed" test_ref="oval:org.mitre.oval:tst:4255" negate="true"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 102883" negate="false">
          <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
          <criterion comment="Patch 125124-01 or later installed" test_ref="oval:org.mitre.oval:tst:4246" negate="true"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:2214" version="1" class="vulnerability">
      <metadata>
        <title>A Security Vulnerability in the Handling of Thread Contexts in the Solaris Kernel May Allow a Denial of Service (DoS)</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <platform>Sun Solaris 9</platform>
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-5132" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5132"/>
        <description>Race condition in the kernel in Sun Solaris 8 through 10 allows local users to cause a denial of service (panic) via unspecified vectors related to "the handling of thread contexts."</description>
        <oval_repository>
          <dates>
            <submitted date="2007-09-28T13:02:59.000-04:00">
              <contributor organization="Opsware, Inc.">Nicholas Hansen</contributor>
            </submitted>
            <status_change date="2007-10-02T08:04:40.234-04:00">DRAFT</status_change>
            <status_change date="2007-10-18T21:59:20.303-04:00">INTERIM</status_change>
            <status_change date="2007-11-02T07:17:42.208-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND" comment="Solaris 8 (SPARC) meets Sun Alert 103084" negate="false">
          <extend_definition comment="Solaris 8 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1539"/>
          <criterion comment="Patch 117350-48 or later installed" test_ref="oval:org.mitre.oval:tst:4094" negate="true"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (SPARC) meets Sun Alert 103084" negate="false">
          <extend_definition comment="Solaris 9 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1457"/>
          <criterion comment="Patch 122300-10 or later installed" test_ref="oval:org.mitre.oval:tst:3262" negate="true"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 103084" negate="false">
          <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
          <criterion comment="Patch 125100-02 or later installed" test_ref="oval:org.mitre.oval:tst:3554" negate="true"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 8 (x86) meets Sun Alert 103084" negate="false">
          <extend_definition comment="Solaris 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:2059"/>
          <criterion comment="Patch 117351-48 or later installed" test_ref="oval:org.mitre.oval:tst:4106" negate="true"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (x86) meets Sun Alert 103084" negate="false">
          <extend_definition comment="Solaris 9 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1683"/>
          <criterion comment="Patch 122301-10 or later installed" test_ref="oval:org.mitre.oval:tst:4263" negate="true"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 103084" negate="false">
          <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
          <criterion comment="Patch 125101-02 or later installed" test_ref="oval:org.mitre.oval:tst:3275" negate="true"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1381" version="1" class="vulnerability">
      <metadata>
        <title>Security Vulnerability With Loading Arbitrary Kernel Modules in Solaris Kernel</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <platform>Sun Solaris 9</platform>
          <platform>Sun Solaris 7</platform>
          <platform>Sun Solaris 2.6</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-2686" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-2686"/>
        <description>Directory traversal vulnerability in the vfs_getvfssw function in Solaris 2.6, 7, 8, and 9 allows local users to load arbitrary kernel modules via crafted (1) mount or (2) sysfs system calls.  NOTE: this might be the same issue as CVE-2004-1767, but there are insufficient details to be sure.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-09-25T11:24:50.000-04:00">
              <contributor organization="Opsware, Inc.">Nicholas Hansen</contributor>
            </submitted>
            <status_change date="2007-09-27T10:35:10.155-04:00">DRAFT</status_change>
            <status_change date="2007-10-12T07:56:13.245-04:00">INTERIM</status_change>
            <status_change date="2007-10-28T20:27:10.742-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND" comment="Solaris 7 (SPARC) meets Sun Alert 57479" negate="false">
          <extend_definition comment="Solaris 7 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:2107"/>
          <criterion comment="Patch 106541-29 or later installed" test_ref="oval:org.mitre.oval:tst:4002" negate="true"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 8 (SPARC) meets Sun Alert 57479" negate="false">
          <extend_definition comment="Solaris 8 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1539"/>
          <criterion comment="Patch 108528-27 or later installed" test_ref="oval:org.mitre.oval:tst:4228" negate="true"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (SPARC) meets Sun Alert 57479" negate="false">
          <extend_definition comment="Solaris 9 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1457"/>
          <criterion comment="Patch 112233-11 or later installed" test_ref="oval:org.mitre.oval:tst:3814" negate="true"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 7 (x86) meets Sun Alert 57479" negate="false">
          <extend_definition comment="Solaris 7 (x86) is installed" definition_ref="oval:org.mitre.oval:def:2036"/>
          <criterion comment="Patch 106542-29 or later installed" test_ref="oval:org.mitre.oval:tst:3686" negate="true"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 8 (x86) meets Sun Alert 57479" negate="false">
          <extend_definition comment="Solaris 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:2059"/>
          <criterion comment="Patch 108529-27 or later installed" test_ref="oval:org.mitre.oval:tst:4247" negate="true"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (x86) meets Sun Alert 57479" negate="false">
          <extend_definition comment="Solaris 9 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1683"/>
          <criterion comment="Patch 112234-11 or later installed" test_ref="oval:org.mitre.oval:tst:3937" negate="true"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 2.6 (SPARC) meets Sun Alert 57479" negate="false">
          <extend_definition comment="Solaris 2.6 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1361"/>
          <criterion comment="Patch 105181-37 or later installed" test_ref="oval:org.mitre.oval:tst:3794" negate="true"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 2.6 (x86) meets Sun Alert 57479" negate="false">
          <extend_definition comment="Solaris 2.6 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1967"/>
          <criterion comment="Patch 105182-37 or later installed" test_ref="oval:org.mitre.oval:tst:3479" negate="true"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:2107" version="1" class="inventory">
      <metadata>
        <title>Solaris 7 (SPARC) is installed</title>
        <affected family="unix">
          <platform>Sun Solaris 7</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/o:sun:sunos:5.7::sparc"/>
        <description>The operating system installed on the system is Sun Solaris 7 for SPARC.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-07-12T08:00:00.000-04:00">
              <contributor organization="Opsware, Inc.">Pai Peng</contributor>
            </submitted>
            <status_change date="2007-07-16T08:59:43.660-04:00">DRAFT</status_change>
            <status_change date="2007-08-01T22:26:15.690-04:00">INTERIM</status_change>
            <status_change date="2007-08-20T08:04:40.447-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="Solaris 7 Installed" test_ref="oval:org.mitre.oval:tst:3576"/>
        <criterion comment="sparc architecture" test_ref="oval:org.mitre.oval:tst:3237"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:2036" version="1" class="inventory">
      <metadata>
        <title>Solaris 7 (x86) is installed</title>
        <affected family="unix">
          <platform>Sun Solaris 7</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/o:sun:sunos:5.7::ix86"/>
        <description>The operating system installed on the system is Sun Solaris 7 for x86.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-07-12T08:00:00.000-04:00">
              <contributor organization="Opsware, Inc.">Pai Peng</contributor>
            </submitted>
            <status_change date="2007-07-16T08:59:43.497-04:00">DRAFT</status_change>
            <status_change date="2007-08-01T22:26:15.456-04:00">INTERIM</status_change>
            <status_change date="2007-08-20T08:04:39.997-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="Solaris 7 Installed" test_ref="oval:org.mitre.oval:tst:3576"/>
        <criterion comment="ix86 architecture" test_ref="oval:org.mitre.oval:tst:3912"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1967" version="1" class="inventory">
      <metadata>
        <title>Solaris 2.6 (x86) is installed</title>
        <affected family="unix">
          <platform>Sun Solaris 2.6</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/o:sun:sunos:5.6::ix86"/>
        <description>The operating system installed on the system is Sun Solaris 2.6 for x86.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-09-25T11:24:50.000-04:00">
              <contributor organization="Opsware, Inc.">Nicholas Hansen</contributor>
            </submitted>
            <status_change date="2007-09-27T10:35:09.992-04:00">DRAFT</status_change>
            <status_change date="2007-10-12T07:56:13.373-04:00">INTERIM</status_change>
            <status_change date="2007-10-28T20:27:10.989-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="Solaris 2.6 Installed" test_ref="oval:org.mitre.oval:tst:4234"/>
        <criterion comment="ix86 architecture" test_ref="oval:org.mitre.oval:tst:3912"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1361" version="1" class="inventory">
      <metadata>
        <title>Solaris 2.6 (SPARC) is installed</title>
        <affected family="unix">
          <platform>Sun Solaris 2.6</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/o:sun:sunos:5.6::sparc"/>
        <description>The operating system installed on the system is Sun Solaris 2.6 for SPARC.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-09-25T11:24:50.000-04:00">
              <contributor organization="Opsware, Inc.">Nicholas Hansen</contributor>
            </submitted>
            <status_change date="2007-09-27T10:35:09.808-04:00">DRAFT</status_change>
            <status_change date="2007-10-12T07:56:12.824-04:00">INTERIM</status_change>
            <status_change date="2007-10-28T20:27:10.225-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="Solaris 2.6 Installed" test_ref="oval:org.mitre.oval:tst:4234"/>
        <criterion comment="sparc architecture" test_ref="oval:org.mitre.oval:tst:3237"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:2173" version="1" class="vulnerability">
      <metadata>
        <title>A Security Vulnerability With the Special File System (SPECFS) strfreectty() Function May Allow a Local Unprivileged User to Panic a System</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <platform>Sun Solaris 9</platform>
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-4732" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4732"/>
        <description>Unspecified vulnerability in the strfreectty function in the Special File System (SPECFS) in Sun Solaris 8 through 10 allows local users to cause a denial of service (system panic), related to passing a NULL pointer to the pgsignal function.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-09-10T09:34:14.000-04:00">
              <contributor organization="Opsware, Inc.">Todd Dolinsky</contributor>
            </submitted>
            <status_change date="2007-09-10T14:41:52.544-04:00">DRAFT</status_change>
            <status_change date="2007-09-27T08:57:45.669-04:00">INTERIM</status_change>
            <status_change date="2007-10-12T07:56:14.294-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND" comment="Solaris 8 (SPARC) meets Sun Alert 103009" negate="false">
          <extend_definition comment="Solaris 8 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1539"/>
          <criterion comment="Patch 109025-07 or later installed" test_ref="oval:org.mitre.oval:tst:4230" negate="true"/>
          <criterion comment="Patch 117350-49 or later installed" test_ref="oval:org.mitre.oval:tst:3903" negate="true"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (SPARC) meets Sun Alert 103009" negate="false">
          <extend_definition comment="Solaris 9 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1457"/>
          <criterion comment="Patch 122300-11 or later installed" test_ref="oval:org.mitre.oval:tst:3307" negate="true"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 103009" negate="false">
          <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
          <criterion comment="Patch 118822-24 or later installed" test_ref="oval:org.mitre.oval:tst:3780" negate="true"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 8 (x86) meets Sun Alert 103009" negate="false">
          <extend_definition comment="Solaris 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:2059"/>
          <criterion comment="Patch 109026-08 or later installed" test_ref="oval:org.mitre.oval:tst:3708" negate="true"/>
          <criterion comment="Patch 117351-49 or later installed" test_ref="oval:org.mitre.oval:tst:3841" negate="true"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (x86) meets Sun Alert 103009" negate="false">
          <extend_definition comment="Solaris 9 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1683"/>
          <criterion comment="Patch 122301-11 or later installed" test_ref="oval:org.mitre.oval:tst:3697" negate="true"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 103009" negate="false">
          <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
          <criterion comment="Patch 118844-24 or later installed" test_ref="oval:org.mitre.oval:tst:4200" negate="true"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1374" version="1" class="vulnerability">
      <metadata>
        <title>Solaris Hosts are Vulnerable to a Denial of Service Induced by an Internet Transmission Control Protocol (TCP) "ACK Storm"</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <platform>Sun Solaris 9</platform>
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-3920" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-3920"/>
        <description>The TCP implementation in Sun Solaris 8, 9, and 10 before 20060726 allows remote attackers to cause a denial of service (resource exhaustion) via a TCP packet with an incorrect sequence number, which triggers an ACK storm.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-08-10T12:25:26.000-04:00">
              <contributor organization="Opsware, Inc.">Pai Peng</contributor>
            </submitted>
            <status_change date="2007-08-13T13:57:13.981-04:00">DRAFT</status_change>
            <status_change date="2007-09-06T09:13:27.040-04:00">INTERIM</status_change>
            <status_change date="2007-09-27T08:57:40.046-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND" comment="Solaris 8 (SPARC) meets Sun Alert 102206" negate="false">
          <extend_definition comment="Solaris 8 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1539"/>
          <criterion comment="Patch 116965-17 or later installed" test_ref="oval:org.mitre.oval:tst:3268" negate="true"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (SPARC) meets Sun Alert 102206" negate="false">
          <extend_definition comment="Solaris 9 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1457"/>
          <criterion comment="Patch 118305-07 or later installed" test_ref="oval:org.mitre.oval:tst:4029" negate="true"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 102206" negate="false">
          <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
          <criterion comment="Patch 118833-12 or later installed" test_ref="oval:org.mitre.oval:tst:3185" negate="true"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 8 (x86) meets Sun Alert 102206" negate="false">
          <extend_definition comment="Solaris 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:2059"/>
          <criterion comment="Patch 116966-16 or later installed" test_ref="oval:org.mitre.oval:tst:3767" negate="true"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (x86) meets Sun Alert 102206" negate="false">
          <extend_definition comment="Solaris 9 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1683"/>
          <criterion comment="Patch 117470-06 or later installed" test_ref="oval:org.mitre.oval:tst:3792" negate="true"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 102206" negate="false">
          <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
          <criterion comment="Patch 118855-10 or later installed" test_ref="oval:org.mitre.oval:tst:4131" negate="true"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1495" version="1" class="vulnerability">
      <metadata>
        <title>Security Vulnerability in the kcms_calibrate(1) Command</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <platform>Sun Solaris 9</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-0503" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0503"/>
        <description>Unspecified vulnerability in kcms_calibrate in Sun Solaris 8 and 9 before 20071122 allows local users to execute arbitrary commands via unknown vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-08-10T12:25:20.000-04:00">
              <contributor organization="Opsware, Inc.">Pai Peng</contributor>
            </submitted>
            <status_change date="2007-08-13T13:57:11.677-04:00">DRAFT</status_change>
            <status_change date="2007-09-06T09:13:27.207-04:00">INTERIM</status_change>
            <status_change date="2007-09-27T08:57:40.285-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND" comment="Solaris 8 (SPARC) meets Sun Alert 102728" negate="false">
          <extend_definition comment="Solaris 8 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1539"/>
          <criterion comment="Patch 111400-04 or later installed" test_ref="oval:org.mitre.oval:tst:4123" negate="true"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (SPARC) meets Sun Alert 102728" negate="false">
          <extend_definition comment="Solaris 9 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1457"/>
          <criterion comment="Patch 114636-04 or later installed" test_ref="oval:org.mitre.oval:tst:3416" negate="true"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 8 (x86) meets Sun Alert 102728" negate="false">
          <extend_definition comment="Solaris 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:2059"/>
          <criterion comment="Patch 111401-04 or later installed" test_ref="oval:org.mitre.oval:tst:3456" negate="true"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (x86) meets Sun Alert 102728" negate="false">
          <extend_definition comment="Solaris 9 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1683"/>
          <criterion comment="Patch 114637-04 or later installed" test_ref="oval:org.mitre.oval:tst:3583" negate="true"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1527" version="1" class="vulnerability">
      <metadata>
        <title>Security Vulnerability May Allow Users With the "File System Management" RBAC Profile to Gain Elevated Privileges</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <platform>Sun Solaris 9</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-4306" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-4306"/>
        <description>Unspecified vulnerability in Sun Solaris 8 and 9 before 20060821 allows local users to execute arbitrary commands via unspecified vectors, involving the default Role-Based Access Control (RBAC) settings in the "File System Management" profile.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-08-10T12:25:26.000-04:00">
              <contributor organization="Opsware, Inc.">Pai Peng</contributor>
            </submitted>
            <status_change date="2007-08-13T13:57:13.873-04:00">DRAFT</status_change>
            <status_change date="2007-09-06T09:13:27.303-04:00">INTERIM</status_change>
            <status_change date="2007-09-27T08:57:40.395-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND" comment="Solaris 8 (SPARC) meets Sun Alert 102514" negate="false">
          <extend_definition comment="Solaris 8 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1539"/>
          <criterion comment="Patch 108975-10 or later installed" test_ref="oval:org.mitre.oval:tst:3837" negate="true"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (SPARC) meets Sun Alert 102514" negate="false">
          <extend_definition comment="Solaris 9 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1457"/>
          <criterion comment="Patch 113072-08 or later installed" test_ref="oval:org.mitre.oval:tst:4119" negate="true"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 8 (x86) meets Sun Alert 102514" negate="false">
          <extend_definition comment="Solaris 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:2059"/>
          <criterion comment="Patch 108976-10 or later installed" test_ref="oval:org.mitre.oval:tst:3332" negate="true"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (x86) meets Sun Alert 102514" negate="false">
          <extend_definition comment="Solaris 9 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1683"/>
          <criterion comment="Patch 114423-07 or later installed" test_ref="oval:org.mitre.oval:tst:3870" negate="true"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1573" version="1" class="vulnerability">
      <metadata>
        <title>Security Vulnerability May Allow Users With the "File System Management" RBAC Profile to Gain Elevated Privileges</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <platform>Sun Solaris 9</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-4307" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-4307"/>
        <description>Unspecified vulnerability in the format command in Sun Solaris 8 and 9 before 20060821 allows local users to modify arbitrary files via unspecified vectors involving profiles that permit running format with elevated privileges, a different issue than CVE-2006-4306 and CVE-2006-4319.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-08-10T12:25:25.000-04:00">
              <contributor organization="Opsware, Inc.">Pai Peng</contributor>
            </submitted>
            <status_change date="2007-08-13T13:57:13.830-04:00">DRAFT</status_change>
            <status_change date="2007-09-06T09:13:27.463-04:00">INTERIM</status_change>
            <status_change date="2007-09-27T08:57:40.578-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND" comment="Solaris 8 (SPARC) meets Sun Alert 102514" negate="false">
          <extend_definition comment="Solaris 8 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1539"/>
          <criterion comment="Patch 108975-10 or later installed" test_ref="oval:org.mitre.oval:tst:3837" negate="true"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (SPARC) meets Sun Alert 102514" negate="false">
          <extend_definition comment="Solaris 9 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1457"/>
          <criterion comment="Patch 113072-08 or later installed" test_ref="oval:org.mitre.oval:tst:4119" negate="true"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 8 (x86) meets Sun Alert 102514" negate="false">
          <extend_definition comment="Solaris 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:2059"/>
          <criterion comment="Patch 108976-10 or later installed" test_ref="oval:org.mitre.oval:tst:3332" negate="true"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (x86) meets Sun Alert 102514" negate="false">
          <extend_definition comment="Solaris 9 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1683"/>
          <criterion comment="Patch 114423-07 or later installed" test_ref="oval:org.mitre.oval:tst:3870" negate="true"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1626" version="1" class="vulnerability">
      <metadata>
        <title>A Security Vulnerability in the Solaris Kernel May Allow a Denial of Service (DoS) Condition to Occur</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <platform>Sun Solaris 9</platform>
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-6275" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-6275"/>
        <description>Race condition in the kernel in Sun Solaris 8 through 10 allows local users to cause a denial of service (panic) via unspecified vectors, possibly related to the exitlwps function and SIGKILL and /proc PCAGENT signals.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-08-10T12:25:21.000-04:00">
              <contributor organization="Opsware, Inc.">Pai Peng</contributor>
            </submitted>
            <status_change date="2007-08-13T13:57:12.817-04:00">DRAFT</status_change>
            <status_change date="2007-09-06T09:13:27.633-04:00">INTERIM</status_change>
            <status_change date="2007-09-27T08:57:40.779-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND" comment="Solaris 8 (SPARC) meets Sun Alert 102574" negate="false">
          <extend_definition comment="Solaris 8 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1539"/>
          <criterion comment="Patch 117350-40 or later installed" test_ref="oval:org.mitre.oval:tst:3986" negate="true"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 8 (SPARC) meets Sun Alert 102574" negate="false">
          <extend_definition comment="Solaris 8 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1539"/>
          <criterion comment="Patch 123703-01 or later installed" test_ref="oval:org.mitre.oval:tst:4110" negate="true"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 8 (x86) meets Sun Alert 102574" negate="false">
          <extend_definition comment="Solaris 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:2059"/>
          <criterion comment="Patch 123704-01 or later installed" test_ref="oval:org.mitre.oval:tst:3681" negate="true"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 8 (x86) meets Sun Alert 102574" negate="false">
          <extend_definition comment="Solaris 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:2059"/>
          <criterion comment="Patch 116960-15 or later installed" test_ref="oval:org.mitre.oval:tst:3895" negate="true"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (x86) meets Sun Alert 102574" negate="false">
          <extend_definition comment="Solaris 9 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1683"/>
          <criterion comment="Patch 118559-30 or later installed" test_ref="oval:org.mitre.oval:tst:3545" negate="true"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (x86) meets Sun Alert 102574" negate="false">
          <extend_definition comment="Solaris 9 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1683"/>
          <criterion comment="Patch 120884-02 or later installed" test_ref="oval:org.mitre.oval:tst:3804" negate="true"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (x86) meets Sun Alert 102574" negate="false">
          <extend_definition comment="Solaris 9 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1683"/>
          <criterion comment="Patch 121317-02 or later installed" test_ref="oval:org.mitre.oval:tst:3661" negate="true"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (x86) meets Sun Alert 102574" negate="false">
          <extend_definition comment="Solaris 9 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1683"/>
          <criterion comment="Patch 119439-06 or later installed" test_ref="oval:org.mitre.oval:tst:3522" negate="true"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 102574" negate="false">
          <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
          <criterion comment="Patch 120662-04 or later installed" test_ref="oval:org.mitre.oval:tst:3712" negate="true"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 102574" negate="false">
          <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
          <criterion comment="Patch 118844-19 or later installed" test_ref="oval:org.mitre.oval:tst:3175" negate="true"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 8 (SPARC) meets Sun Alert 102574" negate="false">
          <extend_definition comment="Solaris 8 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1539"/>
          <criterion comment="Patch 116959-15 or later installed" test_ref="oval:org.mitre.oval:tst:3349" negate="true"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (SPARC) meets Sun Alert 102574" negate="false">
          <extend_definition comment="Solaris 9 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1457"/>
          <criterion comment="Patch 118558-30 or later installed" test_ref="oval:org.mitre.oval:tst:3713" negate="true"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (SPARC) meets Sun Alert 102574" negate="false">
          <extend_definition comment="Solaris 9 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1457"/>
          <criterion comment="Patch 117125-03 or later installed" test_ref="oval:org.mitre.oval:tst:3881" negate="true"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (SPARC) meets Sun Alert 102574" negate="false">
          <extend_definition comment="Solaris 9 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1457"/>
          <criterion comment="Patch 121316-02 or later installed" test_ref="oval:org.mitre.oval:tst:4159" negate="true"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (SPARC) meets Sun Alert 102574" negate="false">
          <extend_definition comment="Solaris 9 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1457"/>
          <criterion comment="Patch 113278-14 or later installed" test_ref="oval:org.mitre.oval:tst:3472" negate="true"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 102574" negate="false">
          <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
          <criterion comment="Patch 120661-03 or later installed" test_ref="oval:org.mitre.oval:tst:3180" negate="true"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 102574" negate="false">
          <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
          <criterion comment="Patch 118822-19 or later installed" test_ref="oval:org.mitre.oval:tst:3190" negate="true"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 8 (x86) meets Sun Alert 102574" negate="false">
          <extend_definition comment="Solaris 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:2059"/>
          <criterion comment="Patch 117351-40 or later installed" test_ref="oval:org.mitre.oval:tst:3264" negate="true"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1760" version="1" class="vulnerability">
      <metadata>
        <title>Security Vulnerability in X Display Manager (xdm(1)) Xsession Script</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <platform>Sun Solaris 9</platform>
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-5214" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-5214"/>
        <description>Race condition in the Xsession script, as used by X Display Manager (xdm) in NetBSD before 20060212, X.Org before 20060225, and Solaris 8 through 10 before 20061006, causes a user's Xsession errors file to have weak permissions before a chmod is performed, which allows local users to read Xsession errors files of other users.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-08-10T12:25:23.000-04:00">
              <contributor organization="Opsware, Inc.">Pai Peng</contributor>
            </submitted>
            <status_change date="2007-08-13T13:57:13.122-04:00">DRAFT</status_change>
            <status_change date="2007-09-06T09:13:28.241-04:00">INTERIM</status_change>
            <status_change date="2007-09-27T08:57:41.428-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND" comment="Solaris 8 (SPARC) meets Sun Alert 102652" negate="false">
          <extend_definition comment="Solaris 8 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1539"/>
          <criterion comment="Patch 111844-04 or later installed" test_ref="oval:org.mitre.oval:tst:3324" negate="true"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (SPARC) meets Sun Alert 102652" negate="false">
          <extend_definition comment="Solaris 9 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1457"/>
          <criterion comment="Patch 124830-01 or later installed" test_ref="oval:org.mitre.oval:tst:3994" negate="true"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 102652" negate="false">
          <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
          <criterion comment="Patch 124457-01 or later installed" test_ref="oval:org.mitre.oval:tst:3954" negate="true"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 8 (x86) meets Sun Alert 102652" negate="false">
          <extend_definition comment="Solaris 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:2059"/>
          <criterion comment="Patch 111845-04 or later installed" test_ref="oval:org.mitre.oval:tst:4176" negate="true"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (x86) meets Sun Alert 102652" negate="false">
          <extend_definition comment="Solaris 9 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1683"/>
          <criterion comment="Patch 124831-01 or later installed" test_ref="oval:org.mitre.oval:tst:3585" negate="true"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 102652" negate="false">
          <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
          <criterion comment="Patch 124458-01 or later installed" test_ref="oval:org.mitre.oval:tst:3425" negate="true"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1798" version="1" class="vulnerability">
      <metadata>
        <title>Buffer Overflow Vulnerability in libX11</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <platform>Sun Solaris 9</platform>
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-4655" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-4655"/>
        <description>Buffer overflow in the Strcmp function in the XKEYBOARD extension in X Window System X11R6.4 and earlier, as used in SCO UnixWare 7.1.3 and Sun Solaris 8 through 10, allows local users to gain privileges via a long _XKB_CHARSET environment variable value.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-08-10T12:25:24.000-04:00">
              <contributor organization="Opsware, Inc.">Pai Peng</contributor>
            </submitted>
            <status_change date="2007-08-13T13:57:13.571-04:00">DRAFT</status_change>
            <status_change date="2007-09-06T09:13:28.351-04:00">INTERIM</status_change>
            <status_change date="2007-09-27T08:57:41.950-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND" comment="Solaris 8 (SPARC) meets Sun Alert 102570" negate="false">
          <extend_definition comment="Solaris 8 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1539"/>
          <criterion comment="Patch 119067-03 or later installed" test_ref="oval:org.mitre.oval:tst:3849" negate="true"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (SPARC) meets Sun Alert 102570" negate="false">
          <extend_definition comment="Solaris 9 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1457"/>
          <criterion comment="Patch 112785-56 or later installed" test_ref="oval:org.mitre.oval:tst:4065" negate="true"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 102570" negate="false">
          <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
          <criterion comment="Patch 119059-16 or later installed" test_ref="oval:org.mitre.oval:tst:3650" negate="true"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 8 (x86) meets Sun Alert 102570" negate="false">
          <extend_definition comment="Solaris 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:2059"/>
          <criterion comment="Patch 119068-03 or later installed" test_ref="oval:org.mitre.oval:tst:3615" negate="true"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (x86) meets Sun Alert 102570" negate="false">
          <extend_definition comment="Solaris 9 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1683"/>
          <criterion comment="Patch 112786-45 or later installed" test_ref="oval:org.mitre.oval:tst:4004" negate="true"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 102570" negate="false">
          <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
          <criterion comment="Patch 119060-15 or later installed" test_ref="oval:org.mitre.oval:tst:3329" negate="true"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1909" version="1" class="vulnerability">
      <metadata>
        <title>Security Vulnerabilities in Solaris ld.so.1(1) may Lead to Execution of Arbitrary Code with Elevated Privileges</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <platform>Sun Solaris 9</platform>
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-6495" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-6495"/>
        <description>Stack-based buffer overflow in ld.so.1 in Sun Solaris 8, 9, and 10 allows local users to execute arbitrary code via large precision padding values in a format string specifier in the format parameter of the doprf function.  NOTE: this issue normally does not cross privilege boundaries, except in cases of external introduction of malicious message files, or if it is leveraged with other vulnerabilities such as CVE-2006-6494.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-08-10T12:25:21.000-04:00">
              <contributor organization="Opsware, Inc.">Pai Peng</contributor>
            </submitted>
            <status_change date="2007-08-13T13:57:12.283-04:00">DRAFT</status_change>
            <status_change date="2007-09-06T09:13:28.806-04:00">INTERIM</status_change>
            <status_change date="2007-09-27T08:57:42.313-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND" comment="Solaris 8 (SPARC) meets Sun Alert 102724" negate="false">
          <extend_definition comment="Solaris 8 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1539"/>
          <criterion comment="Patch 109147-42 or later installed" test_ref="oval:org.mitre.oval:tst:3395" negate="true"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (SPARC) meets Sun Alert 102724" negate="false">
          <extend_definition comment="Solaris 9 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1457"/>
          <criterion comment="Patch 112963-27 or later installed" test_ref="oval:org.mitre.oval:tst:3790" negate="true"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert 102724" negate="false">
          <extend_definition comment="Solaris 10 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1440"/>
          <criterion comment="Patch 124922-01 or later installed" test_ref="oval:org.mitre.oval:tst:3922" negate="true"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 8 (x86) meets Sun Alert 102724" negate="false">
          <extend_definition comment="Solaris 8 (x86) is installed" definition_ref="oval:org.mitre.oval:def:2059"/>
          <criterion comment="Patch 109148-41 or later installed" test_ref="oval:org.mitre.oval:tst:3236" negate="true"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (x86) meets Sun Alert 102724" negate="false">
          <extend_definition comment="Solaris 9 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1683"/>
          <criterion comment="Patch 113986-22 or later installed" test_ref="oval:org.mitre.oval:tst:3819" negate="true"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert 102724" negate="false">
          <extend_definition comment="Solaris 10 (x86) is installed" definition_ref="oval:org.mitre.oval:def:1926"/>
          <criterion comment="Patch 124923-01 or later installed" test_ref="oval:org.mitre.oval:tst:3173" negate="true"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1920" version="1" class="vulnerability">
      <metadata>
        <title>Security Vulnerability in Sun Remote Services (SRS) Net Connect Software</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <platform>Sun Solaris 9</platform>
          <platform>Sun Solaris 10</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-2617" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2617"/>
        <description>srsexec in Sun Remote Services (SRS) Net Connect Software Proxy Core package in Sun Solaris 10 does not enforce file permissions when opening files, which allows local users to read the first line of arbitrary files via the -d and -v options.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-08-10T12:25:19.000-04:00">
              <contributor organization="Opsware, Inc.">Pai Peng</contributor>
            </submitted>
            <status_change date="2007-08-13T13:57:11.321-04:00">DRAFT</status_change>
            <status_change date="2007-09-06T09:13:28.914-04:00">INTERIM</status_change>
            <status_change date="2007-09-27T08:57:42.438-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR" comment="Software Section">
        <criteria operator="AND" comment="Solaris 8 (SPARC) meets Sun Alert 102891" negate="false">
          <extend_definition comment="Solaris 8 (SPARC) is installed" definition_ref="oval:org.mitre.oval:def:1539"/>
          <criterion comment="Patch 125713-01 or later installed" test_ref="oval:org.mitre.oval:tst:3206" negate="true"/>
          <criterion comment="SRS Net Connect Software 3.2.3 is installed" test_ref="oval:org.mitre.oval:tst:4171"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (SPARC) meets Sun Alert 102891" negate="false">
          <extend_definition comment="Solaris 9 (SPARC) is i