<?xml version="1.0" encoding="UTF-8"?>
<oval_definitions xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-definitions-5 oval-definitions-schema.xsd http://oval.mitre.org/XMLSchema/oval-definitions-5#esx esx-definitions-schema.xsd http://oval.mitre.org/XMLSchema/oval-common-5 oval-common-schema.xsd" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:oval="http://oval.mitre.org/XMLSchema/oval-common-5" xmlns:oval-def="http://oval.mitre.org/XMLSchema/oval-definitions-5">
  <generator>
    <oval:product_name>The OVAL Repository</oval:product_name>
    <oval:schema_version>5.9</oval:schema_version>
    <oval:timestamp>2012-01-27T05:11:27.297-05:00</oval:timestamp>
  </generator>
  <definitions>
    <definition id="oval:org.mitre.oval:def:13242" version="4" class="vulnerability">
      <metadata>
        <title>Firmware ESXi and ESX Denial of Service and third party updates for Likewise components and ESX Service Console</title>
        <affected family="unix">
          <platform>VMWare ESX Server 4.0</platform>
          <platform>VMWare ESX Server 4.1</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2011-1785" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1785"/>
        <description>VMware ESXi 4.0 and 4.1 and ESX 4.0 and 4.1 allow remote attackers to cause a denial of service (socket exhaustion) via unspecified network traffic.</description>
        <oval_repository>
          <dates>
            <submitted date="2011-09-06T11:35:29.000-05:00">
              <contributor organization="Hewlett-Packard">Aslesha Nargolkar</contributor>
            </submitted>
            <status_change date="2011-10-24T17:01:48.433-04:00">DRAFT</status_change>
            <status_change date="2011-11-14T04:00:15.942-05:00">INTERIM</status_change>
            <status_change date="2011-12-05T04:00:14.677-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="esx 4.0 without patch">
          <extend_definition comment="VMware ESX Server 4.0 is installed" definition_ref="oval:org.mitre.oval:def:6293"/>
          <criterion comment="Patch ESX400-201104401-SG does not exist" test_ref="oval:org.mitre.oval:tst:43845"/>
        </criteria>
        <criteria operator="AND" comment="esx 4.1 and patch">
          <extend_definition comment="VMware ESX Server 4.1 is installed" definition_ref="oval:org.mitre.oval:def:13012"/>
          <criterion comment="Patch ESX410-201104401-SG does not exist" test_ref="oval:org.mitre.oval:tst:44418"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6293" version="1" class="inventory">
      <metadata>
        <title>VMware ESX Server 4.0 is installed</title>
        <affected family="unix">
          <platform>VMware ESX Server 4</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/o:vmware:esx:4.0"/>
        <description>The operating system installed on the system is VMware ESX Server 4.0.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-09-22T15:10:44.000-05:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2009-12-17T17:22:13.496-05:00">DRAFT</status_change>
            <status_change date="2010-01-04T04:01:45.305-05:00">INTERIM</status_change>
            <status_change date="2010-01-25T04:00:14.212-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="VMware ESX Server 4.0 is installed" test_ref="oval:org.mitre.oval:tst:11154"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:13086" version="4" class="vulnerability">
      <metadata>
        <title>VMSA-2011-0010 VMware ESX third party updates for Service Console packages glibc and dhcp</title>
        <affected family="unix">
          <platform>VMWare ESX Server 4.1</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2011-0536" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-0536"/>
        <description>Multiple untrusted search path vulnerabilities in elf/dl-object.c in certain modified versions of the GNU C Library (aka glibc or libc6), including glibc-2.5-49.el5_5.6 and glibc-2.12-1.7.el6_0.3 in Red Hat Enterprise Linux, allow local users to gain privileges via a crafted dynamic shared object (DSO) in a subdirectory of the current working directory during execution of a (1) setuid or (2) setgid program that has $ORIGIN in (a) RPATH or (b) RUNPATH within the program itself or a referenced library. NOTE: this issue exists because of an incorrect fix for CVE-2010-3847.</description>
        <oval_repository>
          <dates>
            <submitted date="2011-09-06T16:14:19.000-05:00">
              <contributor organization="Hewlett-Packard">Aslesha Nargolkar</contributor>
            </submitted>
            <status_change date="2011-10-24T17:01:49.085-04:00">DRAFT</status_change>
            <status_change date="2011-11-14T04:00:12.607-05:00">INTERIM</status_change>
            <status_change date="2011-12-05T04:00:11.149-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="Patch ESX400-201104401-SG does not exist" test_ref="oval:org.mitre.oval:tst:43845"/>
        <criteria operator="OR" comment="esx 4.1 and patch">
          <extend_definition comment="VMware ESX Server 4.1 is installed" definition_ref="oval:org.mitre.oval:def:13012"/>
          <criterion comment="Patch ESX410-201104401-SG does not exist" test_ref="oval:org.mitre.oval:tst:44418"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:12853" version="4" class="vulnerability">
      <metadata>
        <title>VMSA-2011-0010 VMware ESX third party updates for Service Console packages glibc and dhcp</title>
        <affected family="unix">
          <platform>VMWare ESX Server 4.0</platform>
          <platform>VMWare ESX Server 4.1</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2011-1071" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1071"/>
        <description>The GNU C Library (aka glibc or libc6) before 2.12.2 and Embedded GLIBC (EGLIBC) allow context-dependent attackers to execute arbitrary code or cause a denial of service (memory consumption) via a long UTF8 string that is used in an fnmatch call, aka a "stack extension attack," a related issue to CVE-2010-2898, CVE-2010-1917, and CVE-2007-4782, as originally reported for use of this library by Google Chrome.</description>
        <oval_repository>
          <dates>
            <submitted date="2011-09-06T16:14:19.000-05:00">
              <contributor organization="Hewlett-Packard">Aslesha Nargolkar</contributor>
            </submitted>
            <status_change date="2011-10-24T17:01:49.534-04:00">DRAFT</status_change>
            <status_change date="2011-11-14T04:00:10.187-05:00">INTERIM</status_change>
            <status_change date="2011-12-05T04:00:09.114-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="Patch ESX400-201104401-SG does not exist" test_ref="oval:org.mitre.oval:tst:43845"/>
        <criteria operator="OR" comment="esx 4.1 and patch">
          <extend_definition comment="VMware ESX Server 4.1 is installed" definition_ref="oval:org.mitre.oval:def:13012"/>
          <criterion comment="Patch ESX410-201104401-SG does not exist" test_ref="oval:org.mitre.oval:tst:44418"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:12812" version="4" class="vulnerability">
      <metadata>
        <title>VMSA-2011-0010 VMware ESX third party updates for Service Console packages glibc and dhcp</title>
        <affected family="unix">
          <platform>VMWare ESX Server 4.0</platform>
          <platform>VMWare ESX Server 4.1</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2011-0997" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-0997"/>
        <description>dhclient in ISC DHCP 3.0.x through 4.2.x before 4.2.1-P1, 3.1-ESV before 3.1-ESV-R1, and 4.1-ESV before 4.1-ESV-R2 allows remote attackers to execute arbitrary commands via shell metacharacters in a hostname obtained from a DHCP message, as demonstrated by a hostname that is provided to dhclient-script.</description>
        <oval_repository>
          <dates>
            <submitted date="2011-09-06T16:14:19.000-05:00">
              <contributor organization="Hewlett-Packard">Aslesha Nargolkar</contributor>
            </submitted>
            <status_change date="2011-10-24T17:01:49.276-04:00">DRAFT</status_change>
            <status_change date="2011-11-14T04:00:09.923-05:00">INTERIM</status_change>
            <status_change date="2011-12-05T04:00:08.832-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="Patch ESX400-201104401-SG does not exist" test_ref="oval:org.mitre.oval:tst:43845"/>
        <criteria operator="OR" comment="esx 4.1 and patch">
          <extend_definition comment="VMware ESX Server 4.1 is installed" definition_ref="oval:org.mitre.oval:def:13012"/>
          <criterion comment="Patch ESX410-201104401-SG does not exist" test_ref="oval:org.mitre.oval:tst:44418"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:12272" version="4" class="vulnerability">
      <metadata>
        <title>VMSA-2011-0010 VMware ESX third party updates for Service Console packages glibc and dhcp</title>
        <affected family="unix">
          <platform>VMWare ESX Server 4.0</platform>
          <platform>VMWare ESX Server 4.1</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2011-1095" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1095"/>
        <description>locale/programs/locale.c in locale in the GNU C Library (aka glibc or libc6) before 2.13 does not quote its output, which might allow local users to gain privileges via a crafted localization environment variable, in conjunction with a program that executes a script that uses the eval function.</description>
        <oval_repository>
          <dates>
            <submitted date="2011-09-06T16:14:19.000-05:00">
              <contributor organization="Hewlett-Packard">Aslesha Nargolkar</contributor>
            </submitted>
            <status_change date="2011-10-24T17:01:49.708-04:00">DRAFT</status_change>
            <status_change date="2011-11-14T04:00:06.637-05:00">INTERIM</status_change>
            <status_change date="2011-12-05T04:00:03.208-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="Patch ESX400-201104401-SG does not exist" test_ref="oval:org.mitre.oval:tst:43845"/>
        <criteria operator="OR" comment="esx 4.1 and patch">
          <extend_definition comment="VMware ESX Server 4.1 is installed" definition_ref="oval:org.mitre.oval:def:13012"/>
          <criterion comment="Patch ESX410-201104401-SG does not exist" test_ref="oval:org.mitre.oval:tst:44418"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:13012" version="3" class="inventory">
      <metadata>
        <title>VMware ESX Server 4.1 is installed</title>
        <affected family="unix">
          <platform>VMware ESX Server 1</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/o:vmware:esx:4.1"/>
        <description>The operating system installed on the system is VMware ESX Server 4.1.</description>
        <oval_repository>
          <dates>
            <submitted date="2011-10-21T15:10:44.000-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </submitted>
            <status_change date="2011-10-24T17:01:48.305-04:00">DRAFT</status_change>
            <status_change date="2011-11-14T04:00:11.400-05:00">INTERIM</status_change>
            <status_change date="2011-12-05T04:00:10.278-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="VMware ESX Server 4.1 is installed" test_ref="oval:org.mitre.oval:tst:43962"/>
      </criteria>
    </definition>
  </definitions>
  <tests>
    <version_test id="oval:org.mitre.oval:tst:11154" version="1" comment="VMware ESX Server 4.0 is installed" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#esx">
      <object object_ref="oval:org.mitre.oval:obj:5705"/>
      <state state_ref="oval:org.mitre.oval:ste:5574"/>
    </version_test>
    <version_test id="oval:org.mitre.oval:tst:43962" version="1" comment="VMware ESX Server 4.1 is installed" check_existence="all_exist" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#esx">
      <object object_ref="oval:org.mitre.oval:obj:16042"/>
      <state state_ref="oval:org.mitre.oval:ste:13458"/>
    </version_test>
    <patch56_test id="oval:org.mitre.oval:tst:44418" version="1" comment="Patch ESX410-201104401-SG does not exist" check_existence="none_exist" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#esx">
      <object object_ref="oval:org.mitre.oval:obj:16402"/>
    </patch56_test>
    <patch56_test id="oval:org.mitre.oval:tst:43845" version="1" comment="Patch ESX400-201104401-SG does not exist" check_existence="none_exist" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#esx">
      <object object_ref="oval:org.mitre.oval:obj:16344"/>
    </patch56_test>
  </tests>
  <objects>
    <version_object id="oval:org.mitre.oval:obj:5705" version="1" comment="The single version object." xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#esx"/>
    <version_object id="oval:org.mitre.oval:obj:16042" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#esx"/>
    <patch56_object id="oval:org.mitre.oval:obj:16402" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#esx">
      <patch_name>ESX410-201104401-SG</patch_name>
    </patch56_object>
    <patch56_object id="oval:org.mitre.oval:obj:16344" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#esx">
      <patch_name>ESX400-201104401-SG</patch_name>
    </patch56_object>
  </objects>
  <states>
    <version_state id="oval:org.mitre.oval:ste:5574" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#esx">
      <release datatype="version">4.0.0</release>
    </version_state>
    <version_state id="oval:org.mitre.oval:ste:13458" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#esx">
      <release datatype="version">4.1.0</release>
    </version_state>
  </states>
</oval_definitions>
